HTTP Headers Reference
Complete guide to HTTP headers — learn what each header does, how to configure it, and why it matters for security and performance.
Security
Content-Security-PolicyCross-Origin-Opener-PolicyCross-Origin-Resource-PolicyPermissions-PolicyReferrer-PolicyStrict-Transport-SecurityX-Content-Type-OptionsX-Frame-OptionsX-XSS-ProtectionResponse
ConnectionContent-DispositionContent-EncodingContent-LengthContent-TypeDateETagLast-ModifiedLocationRetry-AfterServerSet-CookieTransfer-EncodingWWW-AuthenticateCaching
AgeCache-ControlExpiresPragmaVaryCORS
Access-Control-Allow-CredentialsAccess-Control-Allow-HeadersAccess-Control-Allow-MethodsAccess-Control-Allow-OriginAccess-Control-Max-AgeRequest
AcceptAccept-EncodingAccept-LanguageAuthorizationCookieHostIf-Modified-SinceIf-None-MatchOriginRangeRefererUser-AgentCheck your website's HTTP headers right now
Check headers →