Skip to content
UniKit

HTTP headers cheat sheet

A searchable cheat sheet of 113 common HTTP request and response headers with direction and category filters, copy-to-clipboard, example values and RFC references.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Direction

Matched 113 / 113 headers

  • AcceptRequestNegotiation & targeting

    客户端可接受的响应媒体类型,用 q 值表示优先级。

  • Accept-CharsetRequestNegotiation & targeting

    客户端可接受的字符集,现代浏览器基本不再发送。

  • Accept-EncodingRequestNegotiation & targeting

    客户端可接受的内容编码,用于协商压缩算法。

  • Accept-LanguageRequestNegotiation & targeting

    客户端偏好的自然语言,服务端据此返回对应文案。

  • Accept-PatchResponseNegotiation & targeting

    告知该资源支持的补丁媒体类型,常用于 415 响应。

  • Accept-PostResponseNegotiation & targeting

    告知该资源在 POST 请求中接受的媒体类型。

  • Accept-RangesResponseRange requests

    声明服务器是否支持范围请求,bytes 表示支持。

  • Access-Control-Allow-CredentialsResponseCORS

    是否允许携带 Cookie 等凭证,为 true 时来源不能是 *。

  • Access-Control-Allow-HeadersResponseCORS

    预检响应中允许的请求头列表。

  • Access-Control-Allow-MethodsResponseCORS

    预检响应中允许的请求方法列表。

  • Access-Control-Allow-OriginResponseCORS

    允许访问该资源的源,或通配符 *。

  • Access-Control-Expose-HeadersResponseCORS

    允许前端 JS 读取的响应头白名单。

  • Access-Control-Max-AgeResponseCORS

    预检结果的缓存秒数,用于减少 OPTIONS 请求。

  • Access-Control-Request-HeadersRequestCORS

    预检请求中声明实际请求要使用的自定义头。

  • Access-Control-Request-MethodRequestCORS

    预检请求中声明实际请求要使用的方法。

  • AgeResponseCaching & conditional requests

    响应在缓存中已经存活的秒数,由缓存生成。

  • AllowResponseNegotiation & targeting

    资源允许的 HTTP 方法列表,常见于 405 响应。

  • Alt-SvcResponseConnection & transport

    告知客户端该资源在别的协议或地址上也可访问,如 h3。

  • Authentication-InfoResponseAuthentication

    认证成功后的附加信息,如下一个 nonce。

  • AuthorizationRequestAuthentication

    携带客户端凭证,如 Bearer 令牌或 Basic 用户名密码。

  • Cache-ControlBothCaching & conditional requests

    缓存指令,控制缓存能否存储、复用与校验,是缓存行为的核心头。

  • Cache-StatusResponseCaching & conditional requests

    由缓存追加的状态信息,用于排查缓存命中情况。

  • CDN-Cache-ControlResponseCaching & conditional requests

    只作用于 CDN 边缘缓存的指令,优先级高于 Cache-Control。

  • Clear-Site-DataResponseSecurity policies

    让浏览器清除本站的 Cookie、缓存或存储,常用于登出。

  • ConnectionBothConnection & transport

    控制当前连接行为,并列出逐跳(hop-by-hop)头字段。

  • Content-DigestBothPayload & entity

    实体的结构化摘要,支持 sha-256 等算法。

  • Content-DispositionBothPayload & entity

    声明内容是内联展示还是作为附件下载,并给出文件名。

  • Content-EncodingBothPayload & entity

    实体已经使用的内容编码,如 gzip、br。

  • Content-LanguageBothNegotiation & targeting

    实体内容面向的自然语言。

  • Content-LengthBothPayload & entity

    实体字节数,用于确定消息体边界。

  • Content-LocationBothNegotiation & targeting

    实体对应的备用资源地址。

  • Content-MD5BothPayload & entityDeprecated

    实体的 MD5 摘要,已废弃,改用摘要字段族。

  • Content-RangeBothRange requests

    响应 206 时说明当前片段在完整实体中的位置。

  • Content-Security-PolicyResponseSecurity policies

    限制脚本、样式、图片等资源的加载来源,缓解 XSS。

  • Content-Security-Policy-Report-OnlyResponseSecurity policies

    只上报 CSP 违规而不阻断请求,适合灰度上线策略。

  • Content-Transfer-EncodingBothPayload & entityDeprecated

    MIME 的传输编码头,在 HTTP 中已经废弃。

  • Content-TypeBothNegotiation & targeting

    实体的媒体类型与字符集,决定浏览器如何解析响应体。

  • CookieRequestCookies & sessions

    浏览器回传的 Cookie 键值对,用分号分隔多个。

  • Cookie2RequestCookies & sessionsDeprecated

    RFC 2965 的旧版 Cookie 头,已被 RFC 6265 废弃。

  • Cross-Origin-Embedder-PolicyResponseCORS

    把文档置为跨源隔离状态,启用 SharedArrayBuffer 等能力。

  • Cross-Origin-Opener-PolicyResponseCORS

    隔离浏览上下文,防止跨源窗口互相持有引用。

  • Cross-Origin-Resource-PolicyResponseCORS

    声明资源可以被哪些源嵌入,用于阻断跨站读取。

  • DateBothCaching & conditional requests

    消息生成的时刻,是缓存计算 Age 的基准。

  • DigestBothPayload & entity

    早期摘要头,已被 Content-Digest 与 Repr-Digest 取代。

  • Early-DataRequestConnection & transport

    值为 1 表示请求来自 TLS 早期数据,存在重放风险。

  • ETagResponseCaching & conditional requests

    当前实体版本的标识符,用于条件请求与缓存校验。

  • ExpectRequestConnection & transport

    声明服务器必须满足的期望,如 100-continue。

  • Expect-CTResponseSecurity policiesDeprecated

    要求证书透明记录,已被浏览器弃用。

  • ExpiresResponseCaching & conditional requests

    响应过期的绝对时间,优先级低于 Cache-Control 的 max-age。

  • ForwardedBothProxies & forwarding

    标准化的代理转发信息,包含 for、by、proto、host 参数。

  • FromRequestTracing & diagnostics

    发起请求的用户的邮箱,供爬虫或运维脚本标识身份。

  • HostRequestConnection & transport

    HTTP/1.1 必带的请求头,指明目标虚拟主机与端口。

  • HTTP2-SettingsRequestConnection & transportDeprecated

    HTTP/1.1 升级到 HTTP/2 时携带的连接参数,已在 RFC 9113 移除。

  • If-MatchRequestCaching & conditional requests

    只有 ETag 匹配时才执行请求,用于乐观并发控制。

  • If-Modified-SinceRequestCaching & conditional requests

    若资源在该时间之后未修改则返回 304。

  • If-None-MatchRequestCaching & conditional requests

    携带缓存中的 ETag,匹配时服务器返回 304 以省流量。

  • If-RangeRequestRange requests

    条件范围请求:校验通过才返回片段,否则返回完整实体。

  • If-Unmodified-SinceRequestCaching & conditional requests

    若资源在该时间之后被修改则拒绝执行,常用于 PUT。

  • Keep-AliveBothConnection & transport

    事实标准:声明长连接的空闲超时与最大请求数。

  • Last-ModifiedResponseCaching & conditional requests

    资源最后一次修改时间,用于条件请求与启发式缓存。

  • LinkBothNegotiation & targeting

    附带资源关系,用于 preload、分页等场景。

  • LocationResponseNegotiation & targeting

    重定向目标地址,或新建资源的地址。

  • Max-ForwardsRequestProxies & forwarding

    限制 TRACE / OPTIONS 请求最多还能经过几跳代理。

  • OriginRequestCORS

    跨域请求的源(协议 + 主机 + 端口),是 CORS 校验的起点。

  • Origin-Agent-ClusterResponseSecurity policies

    按源隔离代理集群,避免同站跨源共享资源。

  • Permissions-PolicyResponseSecurity policies

    按来源开关摄像头、地理位置等浏览器特性。

  • PragmaBothCaching & conditional requestsDeprecated

    HTTP/1.0 时代的缓存指令,只有 no-cache 被广泛识别。

  • PreferRequestNegotiation & targeting

    请求服务器按偏好处理,如返回最小响应或异步执行。

  • Preference-AppliedResponseNegotiation & targeting

    告知服务器实际应用了哪些 Prefer 偏好。

  • Proxy-AuthenticateResponseAuthentication

    响应 407 时声明代理需要的认证方案。

  • Proxy-Authentication-InfoResponseAuthentication

    代理认证成功后的附加信息。

  • Proxy-AuthorizationRequestAuthentication

    向代理服务器提供的认证凭证。

  • Proxy-ConnectionRequestProxies & forwardingDeprecated

    旧版 Netscape 头,用于代理长连接,已被 Connection 取代。

  • RangeRequestRange requests

    请求实体的一个或多个字节区间,用于断点续传。

  • RefererRequestTracing & diagnostics

    发起请求的页面地址,拼写错误源自 HTTP/1.0 规范。

  • Referrer-PolicyResponseSecurity policies

    控制跳转时 Referer 头携带多少信息。

  • Repr-DigestBothPayload & entity

    表示(representation)的摘要,与传输编码无关。

  • Retry-AfterResponseCaching & conditional requests

    告知客户端多久之后可以重试,常用于 429 与 503。

  • ServerResponseTracing & diagnostics

    响应来源服务器使用的软件与版本信息。

  • Server-TimingResponseTracing & diagnostics

    把服务端各阶段耗时暴露给浏览器性能面板。

  • Set-CookieResponseCookies & sessions

    服务器下发的 Cookie,可带 Path、HttpOnly、SameSite 等属性。

  • Set-Cookie2ResponseCookies & sessionsDeprecated

    RFC 2965 的旧版 Set-Cookie 头,已被 RFC 6265 废弃。

  • Strict-Transport-SecurityResponseSecurity policies

    要求浏览器在指定时间内只用 HTTPS 访问本站。

  • TERequestConnection & transport

    声明客户端可接受的传输编码,trailers 表示接收尾部字段。

  • Timing-Allow-OriginResponseCORS

    允许哪些源读取 Resource Timing 的详细耗时数据。

  • TraceparentBothTracing & diagnostics

    W3C Trace Context 的标准化链路标识。

  • TracestateBothTracing & diagnostics

    W3C Trace Context 中厂商自定义的追踪状态。

  • TrailerBothConnection & transport

    声明消息尾部会出现哪些头字段。

  • Transfer-EncodingBothConnection & transport

    逐跳的消息传输编码,如 chunked。

  • UpgradeBothConnection & transport

    请求把连接切换到其他协议,如 WebSocket 或 HTTP/2。

  • User-AgentRequestTracing & diagnostics

    客户端软件标识,用于兼容处理与统计。

  • VaryResponseCaching & conditional requests

    声明响应随哪些请求头变化,供缓存正确选择变体。

  • ViaBothProxies & forwarding

    记录消息经过的每一跳代理及其协议版本。

  • Want-Content-DigestRequestPayload & entity

    声明客户端希望收到的 Content-Digest 算法。

  • Want-Repr-DigestRequestPayload & entity

    声明客户端希望收到的 Repr-Digest 算法。

  • WarningBothCaching & conditional requestsDeprecated

    缓存或转换过程中的告警信息,已被 RFC 9111 废弃。

  • WWW-AuthenticateResponseAuthentication

    响应 401 时声明需要哪种认证方案。

  • X-Amzn-Trace-IdBothTracing & diagnostics

    AWS X-Ray 的追踪头,含 Root、Parent、Sampled 字段。

  • X-B3-TraceIdBothTracing & diagnostics

    Zipkin B3 事实标准:16 或 32 位十六进制的追踪 ID。

  • X-Content-Type-OptionsResponseSecurity policies

    设为 nosniff 后禁止浏览器猜测 MIME 类型。

  • X-Correlation-IdBothTracing & diagnostics

    事实标准:跨系统链路追踪使用的关联 ID。

  • X-DNS-Prefetch-ControlResponseSecurity policies

    控制浏览器是否对页面中的链接做 DNS 预解析。

  • X-Download-OptionsResponseSecurity policies

    IE 专用,设为 noopen 阻止下载文件直接在站点上下文中打开。

  • X-Forwarded-ForRequestProxies & forwarding

    事实标准:记录客户端与各级代理的 IP 链。

  • X-Forwarded-HostRequestProxies & forwarding

    事实标准:记录客户端请求的原始 Host。

  • X-Forwarded-PortRequestProxies & forwarding

    事实标准:记录客户端访问的原始端口。

  • X-Forwarded-ProtoRequestProxies & forwarding

    事实标准:记录客户端与代理之间使用的协议。

  • X-Forwarded-ServerRequestProxies & forwarding

    事实标准:记录处理请求的代理服务器主机名。

  • X-Frame-OptionsResponseSecurity policies

    是否允许页面被 iframe 嵌入,用于防点击劫持。

  • X-Permitted-Cross-Domain-PoliciesResponseSecurity policies

    限制 Flash / PDF 读取 crossdomain.xml 的策略。

  • X-Real-IPRequestProxies & forwarding

    Nginx 常用的事实标准头,只保留最靠近代理的客户端 IP。

  • X-Request-IdBothTracing & diagnostics

    事实标准:一次请求的唯一 ID,便于跨服务串联日志。

  • X-XSS-ProtectionResponseSecurity policiesDeprecated

    旧版浏览器 XSS 过滤器的开关,已被现代浏览器移除。

What this tool does

  • Reach for the right header while writing an API or debugging a proxy: search 113 common request and response headers by name, meaning or example value, each with its RFC reference.
  • Work through the caching families in one place (Cache-Control, ETag, Vary, Age and friends) when you are untangling browser versus CDN caching.
  • Set up CORS by comparing the whole Origin / Access-Control-Allow-* family, so you can tell which field belongs in the preflight request and which in the preflight response.
  • Harden a site by reviewing the security block — CSP, HSTS, X-Frame-Options, Permissions-Policy — and copying the example values as a starting point.

Example

Input

cache-control

Output

Cache-Control: public, max-age=3600, must-revalidate

Exact name matches rank first, so this entry is the top hit for "cache-control". Copying yields the Name: example line, ready to drop into a config file or a curl command.

Frequently asked questions

Why can I search by meaning instead of the field name?

Matching covers the field name, its description and its example value, ranked as exact name > name prefix > name contains > meaning contains > example contains, with ties broken alphabetically. Search "caching" to pull a whole family, or "strict" to find entries whose example values contain the word.

Are deprecated headers still worth reading?

Yes, as long as you know their status. Pragma, Warning, Cookie2, X-XSS-Protection, Expect-CT and Content-MD5 carry a deprecated badge: they matter for reading old configs and old logs, but new projects should not use them.

How do I tell request, response and general headers apart?

Every entry has a direction badge. Request fields (Accept, Authorization, Host) are sent by the client, response fields (Set-Cookie, ETag, Location) come back from the server, and fields marked both (Cache-Control, Content-Type, Date) can appear in either. The direction filter keeps just one kind.

How reliable is the data?

Each entry cites its source: IETF specs such as RFC 9110/9111/9112, or standards like the Fetch Standard, HTML Standard and W3C Trace Context. A handful of de-facto fields (X-Forwarded-For, X-Request-Id) are labelled as such. A built-in check verifies duplicate names and valid direction/category values.

Can I paste the copied line straight into a config file?

Yes — the copy button produces a single Name: example line that works in Nginx, Apache and Caddy configs or a curl -H flag. The examples are typical rather than definitive, so tune max-age, allowed origins and similar values to your own setup.

Keywords:httphttp headersheader请求头响应头cheat sheet速查cache-controlcorsrfc

Related tools