Code tool

HTTP Headers Reference

Filter common HTTP headers, read their direction and purpose, and copy a header name for documentation or implementation.

In-browser processingNo account requiredPrivacy details ↗

Search by name, category, or purpose. Everything stays in this browser.

Acceptcontent

Describes the media types the client can process.

Request and response
Accept-Encodingcontent

Lists content codings the client can decode.

Request
Authorizationsecurity

Carries credentials for the requested resource.

Request
Cache-Controlcaching

Controls caching rules for browsers and intermediaries.

Request and response
Content-Lengthcontent

Gives the size of the message body in bytes.

Request and response
Content-Typecontent

Describes the media type and optional character set of the body.

Request and response
Cookiecookies

Sends stored cookies to the server for the current domain.

Request
ETagconditional

Identifies a specific representation for cache validation.

Response
Hostgeneral

Identifies the host and optional port targeted by the request.

Request
If-None-Matchconditional

Makes a request conditional on an ETag not matching.

Request
If-Modified-Sinceconditional

Requests a response only when a representation changed after a date.

Request
Locationgeneral

Provides a URL for redirects or a newly created resource.

Response
Origincors

Identifies the origin that initiated a request.

Request
Referergeneral

Identifies the address of the page that made the request.

Request
Set-Cookiecookies

Asks the browser to store a cookie.

Response
Strict-Transport-Securitysecurity

Tells browsers to use HTTPS for a host for a period of time.

Response
User-Agentgeneral

Identifies the client software making the request.

Request
Varycaching

Lists request headers that affect representation selection.

Response
WWW-Authenticatesecurity

Defines an authentication challenge for a protected resource.

Response
X-Content-Type-Optionssecurity

Prevents MIME sniffing when set to nosniff.

Response

A QUICK WALKTHROUGH

How to use this tool

  1. Search by a header name or purpose, or choose a direction and category.
  2. Review the header description and whether it belongs to requests, responses, or both.
  3. Copy the header name for your documentation or implementation.

A focused HTTP header reference

The list covers widely used standard, CORS, security, caching, content, and conditional request headers. It is a practical lookup, not a replacement for the specification.

Direction matters

Some headers are sent by clients, some by servers, and some are meaningful in both directions. The direction filter helps avoid copying a response-only header into a request.

Runs locally

The reference data is bundled with this page. Searching, filtering, and copying do not send your query or selected header to a server.

GOOD TO KNOW

Common questions

Does this include every registered HTTP header?

No. It focuses on common headers useful in everyday web development and includes a few established security and CORS headers.

Can I use every header in both directions?

No. Check the direction label. A request header is sent by a client, a response header by a server, and a general header may apply to either message.

Does searching contact a server?

No. The data and all interactions run locally in your browser.