HTTP headers cheat sheet
A searchable cheat sheet of 113 common HTTP request and response headers with direction and category filters, copy-to-clipboard, example values and RFC references.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Matched 113 / 113 headers
AcceptRequestNegotiation & targeting客户端可接受的响应媒体类型,用 q 值表示优先级。
Accept-CharsetRequestNegotiation & targeting客户端可接受的字符集,现代浏览器基本不再发送。
Accept-EncodingRequestNegotiation & targeting客户端可接受的内容编码,用于协商压缩算法。
Accept-LanguageRequestNegotiation & targeting客户端偏好的自然语言,服务端据此返回对应文案。
Accept-PatchResponseNegotiation & targeting告知该资源支持的补丁媒体类型,常用于 415 响应。
Accept-PostResponseNegotiation & targeting告知该资源在 POST 请求中接受的媒体类型。
Accept-RangesResponseRange requests声明服务器是否支持范围请求,bytes 表示支持。
Access-Control-Allow-CredentialsResponseCORS是否允许携带 Cookie 等凭证,为 true 时来源不能是 *。
Access-Control-Allow-HeadersResponseCORS预检响应中允许的请求头列表。
Access-Control-Allow-MethodsResponseCORS预检响应中允许的请求方法列表。
Access-Control-Allow-OriginResponseCORS允许访问该资源的源,或通配符 *。
Access-Control-Expose-HeadersResponseCORS允许前端 JS 读取的响应头白名单。
Access-Control-Max-AgeResponseCORS预检结果的缓存秒数,用于减少 OPTIONS 请求。
Access-Control-Request-HeadersRequestCORS预检请求中声明实际请求要使用的自定义头。
Access-Control-Request-MethodRequestCORS预检请求中声明实际请求要使用的方法。
AgeResponseCaching & conditional requests响应在缓存中已经存活的秒数,由缓存生成。
AllowResponseNegotiation & targeting资源允许的 HTTP 方法列表,常见于 405 响应。
Alt-SvcResponseConnection & transport告知客户端该资源在别的协议或地址上也可访问,如 h3。
Authentication-InfoResponseAuthentication认证成功后的附加信息,如下一个 nonce。
AuthorizationRequestAuthentication携带客户端凭证,如 Bearer 令牌或 Basic 用户名密码。
Cache-ControlBothCaching & conditional requests缓存指令,控制缓存能否存储、复用与校验,是缓存行为的核心头。
Cache-StatusResponseCaching & conditional requests由缓存追加的状态信息,用于排查缓存命中情况。
CDN-Cache-ControlResponseCaching & conditional requests只作用于 CDN 边缘缓存的指令,优先级高于 Cache-Control。
Clear-Site-DataResponseSecurity policies让浏览器清除本站的 Cookie、缓存或存储,常用于登出。
ConnectionBothConnection & transport控制当前连接行为,并列出逐跳(hop-by-hop)头字段。
Content-DigestBothPayload & entity实体的结构化摘要,支持 sha-256 等算法。
Content-DispositionBothPayload & entity声明内容是内联展示还是作为附件下载,并给出文件名。
Content-EncodingBothPayload & entity实体已经使用的内容编码,如 gzip、br。
Content-LanguageBothNegotiation & targeting实体内容面向的自然语言。
Content-LengthBothPayload & entity实体字节数,用于确定消息体边界。
Content-LocationBothNegotiation & targeting实体对应的备用资源地址。
Content-MD5BothPayload & entityDeprecated实体的 MD5 摘要,已废弃,改用摘要字段族。
Content-RangeBothRange requests响应 206 时说明当前片段在完整实体中的位置。
Content-Security-PolicyResponseSecurity policies限制脚本、样式、图片等资源的加载来源,缓解 XSS。
Content-Security-Policy-Report-OnlyResponseSecurity policies只上报 CSP 违规而不阻断请求,适合灰度上线策略。
Content-Transfer-EncodingBothPayload & entityDeprecatedMIME 的传输编码头,在 HTTP 中已经废弃。
Content-TypeBothNegotiation & targeting实体的媒体类型与字符集,决定浏览器如何解析响应体。
CookieRequestCookies & sessions浏览器回传的 Cookie 键值对,用分号分隔多个。
Cookie2RequestCookies & sessionsDeprecatedRFC 2965 的旧版 Cookie 头,已被 RFC 6265 废弃。
Cross-Origin-Embedder-PolicyResponseCORS把文档置为跨源隔离状态,启用 SharedArrayBuffer 等能力。
Cross-Origin-Opener-PolicyResponseCORS隔离浏览上下文,防止跨源窗口互相持有引用。
Cross-Origin-Resource-PolicyResponseCORS声明资源可以被哪些源嵌入,用于阻断跨站读取。
DateBothCaching & conditional requests消息生成的时刻,是缓存计算 Age 的基准。
DigestBothPayload & entity早期摘要头,已被 Content-Digest 与 Repr-Digest 取代。
Early-DataRequestConnection & transport值为 1 表示请求来自 TLS 早期数据,存在重放风险。
ETagResponseCaching & conditional requests当前实体版本的标识符,用于条件请求与缓存校验。
ExpectRequestConnection & transport声明服务器必须满足的期望,如 100-continue。
Expect-CTResponseSecurity policiesDeprecated要求证书透明记录,已被浏览器弃用。
ExpiresResponseCaching & conditional requests响应过期的绝对时间,优先级低于 Cache-Control 的 max-age。
ForwardedBothProxies & forwarding标准化的代理转发信息,包含 for、by、proto、host 参数。
FromRequestTracing & diagnostics发起请求的用户的邮箱,供爬虫或运维脚本标识身份。
HostRequestConnection & transportHTTP/1.1 必带的请求头,指明目标虚拟主机与端口。
HTTP2-SettingsRequestConnection & transportDeprecatedHTTP/1.1 升级到 HTTP/2 时携带的连接参数,已在 RFC 9113 移除。
If-MatchRequestCaching & conditional requests只有 ETag 匹配时才执行请求,用于乐观并发控制。
If-Modified-SinceRequestCaching & conditional requests若资源在该时间之后未修改则返回 304。
If-None-MatchRequestCaching & conditional requests携带缓存中的 ETag,匹配时服务器返回 304 以省流量。
If-RangeRequestRange requests条件范围请求:校验通过才返回片段,否则返回完整实体。
If-Unmodified-SinceRequestCaching & conditional requests若资源在该时间之后被修改则拒绝执行,常用于 PUT。
Keep-AliveBothConnection & transport事实标准:声明长连接的空闲超时与最大请求数。
Last-ModifiedResponseCaching & conditional requests资源最后一次修改时间,用于条件请求与启发式缓存。
LinkBothNegotiation & targeting附带资源关系,用于 preload、分页等场景。
LocationResponseNegotiation & targeting重定向目标地址,或新建资源的地址。
Max-ForwardsRequestProxies & forwarding限制 TRACE / OPTIONS 请求最多还能经过几跳代理。
OriginRequestCORS跨域请求的源(协议 + 主机 + 端口),是 CORS 校验的起点。
Origin-Agent-ClusterResponseSecurity policies按源隔离代理集群,避免同站跨源共享资源。
Permissions-PolicyResponseSecurity policies按来源开关摄像头、地理位置等浏览器特性。
PragmaBothCaching & conditional requestsDeprecatedHTTP/1.0 时代的缓存指令,只有 no-cache 被广泛识别。
PreferRequestNegotiation & targeting请求服务器按偏好处理,如返回最小响应或异步执行。
Preference-AppliedResponseNegotiation & targeting告知服务器实际应用了哪些 Prefer 偏好。
Proxy-AuthenticateResponseAuthentication响应 407 时声明代理需要的认证方案。
Proxy-Authentication-InfoResponseAuthentication代理认证成功后的附加信息。
Proxy-AuthorizationRequestAuthentication向代理服务器提供的认证凭证。
Proxy-ConnectionRequestProxies & forwardingDeprecated旧版 Netscape 头,用于代理长连接,已被 Connection 取代。
RangeRequestRange requests请求实体的一个或多个字节区间,用于断点续传。
RefererRequestTracing & diagnostics发起请求的页面地址,拼写错误源自 HTTP/1.0 规范。
Referrer-PolicyResponseSecurity policies控制跳转时 Referer 头携带多少信息。
Repr-DigestBothPayload & entity表示(representation)的摘要,与传输编码无关。
Retry-AfterResponseCaching & conditional requests告知客户端多久之后可以重试,常用于 429 与 503。
ServerResponseTracing & diagnostics响应来源服务器使用的软件与版本信息。
Server-TimingResponseTracing & diagnostics把服务端各阶段耗时暴露给浏览器性能面板。
Set-CookieResponseCookies & sessions服务器下发的 Cookie,可带 Path、HttpOnly、SameSite 等属性。
Set-Cookie2ResponseCookies & sessionsDeprecatedRFC 2965 的旧版 Set-Cookie 头,已被 RFC 6265 废弃。
Strict-Transport-SecurityResponseSecurity policies要求浏览器在指定时间内只用 HTTPS 访问本站。
TERequestConnection & transport声明客户端可接受的传输编码,trailers 表示接收尾部字段。
Timing-Allow-OriginResponseCORS允许哪些源读取 Resource Timing 的详细耗时数据。
TraceparentBothTracing & diagnosticsW3C Trace Context 的标准化链路标识。
TracestateBothTracing & diagnosticsW3C Trace Context 中厂商自定义的追踪状态。
TrailerBothConnection & transport声明消息尾部会出现哪些头字段。
Transfer-EncodingBothConnection & transport逐跳的消息传输编码,如 chunked。
UpgradeBothConnection & transport请求把连接切换到其他协议,如 WebSocket 或 HTTP/2。
User-AgentRequestTracing & diagnostics客户端软件标识,用于兼容处理与统计。
VaryResponseCaching & conditional requests声明响应随哪些请求头变化,供缓存正确选择变体。
ViaBothProxies & forwarding记录消息经过的每一跳代理及其协议版本。
Want-Content-DigestRequestPayload & entity声明客户端希望收到的 Content-Digest 算法。
Want-Repr-DigestRequestPayload & entity声明客户端希望收到的 Repr-Digest 算法。
WarningBothCaching & conditional requestsDeprecated缓存或转换过程中的告警信息,已被 RFC 9111 废弃。
WWW-AuthenticateResponseAuthentication响应 401 时声明需要哪种认证方案。
X-Amzn-Trace-IdBothTracing & diagnosticsAWS X-Ray 的追踪头,含 Root、Parent、Sampled 字段。
X-B3-TraceIdBothTracing & diagnosticsZipkin B3 事实标准:16 或 32 位十六进制的追踪 ID。
X-Content-Type-OptionsResponseSecurity policies设为 nosniff 后禁止浏览器猜测 MIME 类型。
X-Correlation-IdBothTracing & diagnostics事实标准:跨系统链路追踪使用的关联 ID。
X-DNS-Prefetch-ControlResponseSecurity policies控制浏览器是否对页面中的链接做 DNS 预解析。
X-Download-OptionsResponseSecurity policiesIE 专用,设为 noopen 阻止下载文件直接在站点上下文中打开。
X-Forwarded-ForRequestProxies & forwarding事实标准:记录客户端与各级代理的 IP 链。
X-Forwarded-HostRequestProxies & forwarding事实标准:记录客户端请求的原始 Host。
X-Forwarded-PortRequestProxies & forwarding事实标准:记录客户端访问的原始端口。
X-Forwarded-ProtoRequestProxies & forwarding事实标准:记录客户端与代理之间使用的协议。
X-Forwarded-ServerRequestProxies & forwarding事实标准:记录处理请求的代理服务器主机名。
X-Frame-OptionsResponseSecurity policies是否允许页面被 iframe 嵌入,用于防点击劫持。
X-Permitted-Cross-Domain-PoliciesResponseSecurity policies限制 Flash / PDF 读取 crossdomain.xml 的策略。
X-Real-IPRequestProxies & forwardingNginx 常用的事实标准头,只保留最靠近代理的客户端 IP。
X-Request-IdBothTracing & diagnostics事实标准:一次请求的唯一 ID,便于跨服务串联日志。
X-XSS-ProtectionResponseSecurity policiesDeprecated旧版浏览器 XSS 过滤器的开关,已被现代浏览器移除。
What this tool does
- Reach for the right header while writing an API or debugging a proxy: search 113 common request and response headers by name, meaning or example value, each with its RFC reference.
- Work through the caching families in one place (Cache-Control, ETag, Vary, Age and friends) when you are untangling browser versus CDN caching.
- Set up CORS by comparing the whole Origin / Access-Control-Allow-* family, so you can tell which field belongs in the preflight request and which in the preflight response.
- Harden a site by reviewing the security block — CSP, HSTS, X-Frame-Options, Permissions-Policy — and copying the example values as a starting point.
Example
Input
cache-control
Output
Cache-Control: public, max-age=3600, must-revalidate
Exact name matches rank first, so this entry is the top hit for "cache-control". Copying yields the Name: example line, ready to drop into a config file or a curl command.
Frequently asked questions
Why can I search by meaning instead of the field name?
Matching covers the field name, its description and its example value, ranked as exact name > name prefix > name contains > meaning contains > example contains, with ties broken alphabetically. Search "caching" to pull a whole family, or "strict" to find entries whose example values contain the word.
Are deprecated headers still worth reading?
Yes, as long as you know their status. Pragma, Warning, Cookie2, X-XSS-Protection, Expect-CT and Content-MD5 carry a deprecated badge: they matter for reading old configs and old logs, but new projects should not use them.
How do I tell request, response and general headers apart?
Every entry has a direction badge. Request fields (Accept, Authorization, Host) are sent by the client, response fields (Set-Cookie, ETag, Location) come back from the server, and fields marked both (Cache-Control, Content-Type, Date) can appear in either. The direction filter keeps just one kind.
How reliable is the data?
Each entry cites its source: IETF specs such as RFC 9110/9111/9112, or standards like the Fetch Standard, HTML Standard and W3C Trace Context. A handful of de-facto fields (X-Forwarded-For, X-Request-Id) are labelled as such. A built-in check verifies duplicate names and valid direction/category values.
Can I paste the copied line straight into a config file?
Yes — the copy button produces a single Name: example line that works in Nginx, Apache and Caddy configs or a curl -H flag. The examples are typical rather than definitive, so tune max-age, allowed origins and similar values to your own setup.
Keywords:httphttp headersheader请求头响应头cheat sheet速查cache-controlcorsrfc