Tooldeveloper

HTTP Header Reference

A working reference for the most common request and response headers — what each does, its syntax, and the security gotchas (CSP, HSTS, CORP).

Works Offline100% Free

Processed 100% locally in your browserPrivate & Safe

HTTP Header Reference runs entirely on your device using Web API standards. No data is ever uploaded to UtilixVerse servers.

Your Input
➔
Browser
➔
Result
No Server UploadsNo Account RequiredWorks OfflineZero Data Logging

HTTP Header Reference

Popular Headers

Browse All Headers

Free HTTP Header Reference — Complete Guide for Developers

Welcome to the UtilixVerse HTTP Header Reference — a free, browser-based tool that lets you look up any HTTP headerby name, keyword, or category. Search for Cache-Control,CORS, or securityand get the full description, syntax, example, and related headersinstantly — all 100% privately in your browser.

Why Developers Need an HTTP Header Reference

HTTP headers control nearly every aspect of web communication — from caching and authentication to security and content negotiation. This tool covers55+ HTTP headers across all categories:

  1. 1. Request Headers — Host, User-Agent, Authorization, Cookie, Range, Referer, Origin, and more.
  2. 2. Response Headers — Set-Cookie, Location, WWW-Authenticate, Server, Retry-After, Allow, Vary.
  3. 3. Security Headers — Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, COOP/COEP.
  4. 4. CORS Headers — Access-Control-Allow-Origin, Allow-Methods, Allow-Headers, Expose-Headers, Max-Age, Allow-Credentials.
  5. 5. Caching, Negotiation, Entity & More — Cache-Control, ETag, Last-Modified, Accept, Content-Type, Content-Encoding, plus Client Hints and extension headers.

Search, Browse & Learn

Type a header name like Authorization or a keyword like cors to instantly filter results. Click popular headers from the chip bar, or browse the full list filtered by category. Every result shows the header name, category, summary, in-depth detail, example value, syntax, when it was introduced, and related headers you can click to explore.

Privacy & Performance

Everything runs entirely in your browser — the entire header database is built into the page. Nothing is uploaded, stored, or logged. Results update live as you type with zero round-trips, and the whole tool works offline after the page loads.

Pair this tool with our HTTP status lookup,MIME type lookup, andJSON formatterfor a complete developer toolkit.

Frequently Asked Questions About HTTP Headers

What are HTTP headers and why are they important?

HTTP headers are key-value pairs sent between the client and server with every HTTP request and response. They carry metadata about the request, response, and the body — such as content type, authentication credentials, caching policies, and security directives. Understanding headers is essential for configuring web servers, debugging APIs, implementing security, and optimizing performance.

What is the difference between request, response, and general headers?

Request headers are sent by the client (browser or API client) and include things like Host, User-Agent, Accept, and Authorization. Response headers are sent by the server and include Location, Set-Cookie, and WWW-Authenticate. General headers can appear in both directions, like Date, Cache-Control, and Connection. Entity headers describe the body, like Content-Type and Content-Length.

What are the most important security headers I should use?

The essential security headers are: Content-Security-Policy (controls which resources can load), Strict-Transport-Security (forces HTTPS), X-Content-Type-Options: nosniff (prevents MIME sniffing), X-Frame-Options: DENY (prevents clickjacking), and Referrer-Policy (controls referrer info). For modern apps, also consider Permissions-Policy (controls browser API access) and the COOP/COEP headers for cross-origin isolation.

What is CORS and how do CORS headers work?

CORS (Cross-Origin Resource Sharing) is a security mechanism that controls which websites can access resources from a different origin. When a browser makes a cross-origin request, it checks the server's CORS headers. The key headers are Access-Control-Allow-Origin (which origins are allowed), Access-Control-Allow-Methods (which HTTP methods), Access-Control-Allow-Headers (which custom headers), and Access-Control-Allow-Credentials (whether cookies can be sent).

What is the difference between Cache-Control, Expires, and ETag?

Cache-Control is the most powerful caching header — it uses directives like max-age, no-cache, and no-store. Expires is an older HTTP/1.0 header that specifies an absolute expiration date. If both are present, Cache-Control max-age takes precedence. ETag is a validation token — the client can send it back via If-None-Match to check if the cached version is still fresh, which avoids downloading unchanged content.

What is the difference between Authorization and WWW-Authenticate?

Authorization is a request header sent by the client containing credentials (e.g., Bearer token, Basic auth). WWW-Authenticate is a response header sent by the server when the server needs to challenge the client for authentication — it tells the client which authentication scheme to use. The typical flow: client requests a resource, server responds with 401 + WWW-Authenticate, client retries with Authorization.

What are X-Forwarded-For and X-Real-IP used for?

X-Forwarded-For is a de facto standard header added by proxies and load balancers to preserve the original client IP address. It can contain multiple IPs if there are multiple proxies. X-Real-IP is a simpler Nginx convention that contains only the original client IP. These are essential for applications that need to know the real client IP behind a proxy or CDN.

Is this HTTP Header Reference free and private?

Yes — completely free, no registration, and 100% private. The entire database of HTTP headers is built into the page and runs locally in your browser. Nothing is uploaded, stored, or logged. The tool works offline after the page loads.

Keep UtilixVerse Free

One-time contribution for hosting & new tools

Donate

Missing a Tool? Request It

Suggest new utilities or report bugs

Request Tool