A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Forbidden Request Header

About

A forbidden request header is an HTTP header name-value pair that cannot be set or modified programmatically in a request1. Modifying such headers is forbidden because the user agent retains full control over them. For example, the Date header is a forbidden request header, so this code cannot set the message Date field:

fetch("https://httpbin.org/get", {
  headers: {
    Date: new Date().toUTCString(),
  },
});

Names starting with Sec- are reserved for creating new headers safe from APIs that grant developers control over headers, such as fetch().

Types of Forbinned headers

Forbidden headers are one of the following:

Anki

References


  1. MDN. “Forbidden request header”. Available at: https://developer.mozilla.org/en-US/docs/Glossary/Forbidden_request_header. (Accessed: [2025-05-10 Sat 06:30]). ↩︎

Related Posts