Skip to main content
DevTools24

Riferimento Header HTTP

Riferimento header HTTP.

Acceptrequestcontent
Media types the client can handle
Accept: application/json
Accept-Encodingrequestcontent
Compression algorithms the client supports
Accept-Encoding: gzip, deflate, br
Accept-Languagerequestcontent
Preferred languages for the response
Accept-Language: en-US,en;q=0.9
Authorizationrequestauth
Credentials for authentication
Authorization: Bearer <token>
Cookierequestauth
Cookies previously sent by server
Cookie: session=abc123; user=john
Hostrequestrouting
Domain name of the server
Host: www.example.com
Originrequestcors
Origin of the request (for CORS)
Origin: https://example.com
Refererrequestrouting
URL of the previous page
Referer: https://example.com/page
User-Agentrequestinfo
Browser/client identification string
User-Agent: Mozilla/5.0...
X-Requested-Withrequestinfo
Indicates AJAX request
X-Requested-With: XMLHttpRequest
If-Modified-Sincerequestcache
Conditional request based on date
If-Modified-Since: Wed, 21 Oct 2023 07:28:00 GMT
If-None-Matchrequestcache
Conditional request based on ETag
If-None-Match: "abc123"
Access-Control-Allow-Originresponsecors
Origins allowed to access resource
Access-Control-Allow-Origin: *
Access-Control-Allow-Methodsresponsecors
HTTP methods allowed for CORS
Access-Control-Allow-Methods: GET, POST, PUT
Access-Control-Allow-Headersresponsecors
Headers allowed in CORS requests
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Max-Ageresponsecors
How long CORS preflight is cached
Access-Control-Max-Age: 86400
Cache-Controlreq/rescache
Caching directives
Cache-Control: max-age=3600, public
Content-Dispositionresponsecontent
How content should be displayed
Content-Disposition: attachment; filename="file.pdf"
Content-Encodingresponsecontent
Compression used on the body
Content-Encoding: gzip
Content-Typereq/rescontent
Media type of the body
Content-Type: application/json; charset=utf-8
Content-Lengthreq/rescontent
Size of the body in bytes
Content-Length: 1234
ETagresponsecache
Identifier for a specific version
ETag: "abc123"
Expiresresponsecache
Date after which response is stale
Expires: Thu, 01 Dec 2023 16:00:00 GMT
Last-Modifiedresponsecache
Date of last modification
Last-Modified: Wed, 21 Oct 2023 07:28:00 GMT
Locationresponserouting
Redirect URL
Location: https://example.com/new-page
Set-Cookieresponseauth
Send cookies to the client
Set-Cookie: session=abc123; Path=/; HttpOnly
Strict-Transport-Securityresponsesecurity
Force HTTPS connections
Strict-Transport-Security: max-age=31536000; includeSubDomains
Content-Security-Policyresponsesecurity
Control resources the client can load
Content-Security-Policy: default-src 'self'
X-Content-Type-Optionsresponsesecurity
Prevent MIME type sniffing
X-Content-Type-Options: nosniff
X-Frame-Optionsresponsesecurity
Control iframe embedding
X-Frame-Options: DENY
X-XSS-Protectionresponsesecurity
Enable XSS filter (legacy)
X-XSS-Protection: 1; mode=block
Referrer-Policyresponsesecurity
Control referrer information
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policyresponsesecurity
Control browser features
Permissions-Policy: camera=(), microphone=()
WWW-Authenticateresponseauth
Authentication method required
WWW-Authenticate: Bearer realm="api"
Retry-Afterresponseinfo
When to retry after rate limiting
Retry-After: 120
X-RateLimit-Limitresponseinfo
Rate limit ceiling
X-RateLimit-Limit: 1000
X-RateLimit-Remainingresponseinfo
Remaining requests in window
X-RateLimit-Remaining: 999
X-Request-Idresponseinfo
Unique request identifier
X-Request-Id: abc123-def456

HTTP Headers - Dettagli tecnici

HTTP headers let clients and servers pass additional information with requests and responses. They're essential for authentication, caching, content negotiation, and security. Understanding headers is crucial for API development.

Alternativa da riga di comando

# Common security headers\nContent-Security-Policy: default-src 'self'\nStrict-Transport-Security: max-age=31536000\nX-Content-Type-Options: nosniff

Riferimento

Visualizza specifica ufficiale