
About
A response header is an HTTP header that can be used in an HTTP response and doesn’t relate to the content of the message; response headers like Age, Location or Server are used to give a more detailed context of the response1.
List
- Age
- Access-Control-Allow-Headers header
- Access-Control-Allow-Methods header
- Accept-CH
- Accept-Patch
- Accept-Post
- Accept-Ranges
- Allow header
- Alt-Svc header
- Content-Type
- Clear-Site-Data header
- Cross-Origin-Embedder-Policy (COEP) header
- Cross-Origin-Opener-Policy (COOP) header
- Cross-Origin-Resource-Policy (CORP) header
- Content-Security-Policy (CSP) header
- Content-Security-Policy-Report-Only (CSPRO) header
- ETag
- Expires header
- Strict-Transport-Security (HSTS) header
- Last-Modified header
- Location
- Proxy-Authenticate header
- Refresh header
- Referrer-Policy header
- Reporting-Endpoints header
- Retry-After header
- Permissions-Policy header
- Sec-WebSocket-Extensions header
- Sec-WebSocket-Protocol header
- Sec-WebSocket-Version header
- Set-Cookie header
- Server
- Server-Timing header
- Timing-Allow-Origin header
- WWW-Authenticate
- X-Content-Type-Options header
- X-Frame-Options (XFO) header
- X-Permitted-Cross-Domain-Policies header
Example
The following shows a few response and representation header after a GET request:
200 OK
Access-Control-Allow-Origin: *
Connection: Keep-Alive
Content-Encoding: gzip
Content-Type: text/html; charset=utf-8
Date: Fri, 16 May 2025 03:42:00 GMT
Etag: "c561c68d0ba92bbeb8b0f612a9199f722e3a621a"
Keep-Alive: timeout=5, max=997
Last-Modified: Fri, 16 May 2025 03:42:00 GMT
Server: Apache
Set-Cookie: my-key=my value; expires=Mon, 17-May-2025 16:06:00 GMT; Max-Age=31449600; Path=/; secure
Transfer-Encoding: chunked
Vary: Cookie, Accept-Encoding
X-Backend-Server: developer2.webapp.scl3.mozilla.com
X-Cache-Info: not cacheable; meta data too large
X-kuma-revision: 1085259
x-frame-options: DENY
Anki
Links
References
MDN. “HTTP Response headers”. Available at: https://developer.mozilla.org/en-US/docs/Glossary/Response_header. (Accessed: ). ↩︎