By ToolzHive · Updated
Names are case-insensitive; values follow field-specific syntax. Inspect actual responses rather than assuming a setting reached the browser.
Reference table
| Header | Example value | Purpose |
|---|---|---|
| Content-Type | application/json | Format |
| Content-Encoding | gzip | Representation compression |
| Accept-Encoding | gzip, br | Accepted encodings |
| Cache-Control | public, max-age=3600 | Cache policy |
| ETag | "version-1" | Validator |
| If-None-Match | "version-1" | Conditional request |
| Vary | Accept-Encoding | Cache selection |
| Location | https://example.com/new | Redirect destination |
| Retry-After | 120 | Retry delay in seconds here |
| Authorization | Bearer <token> | Credentials |
| Set-Cookie | sid=<value>; Secure; HttpOnly | Cookie; choose SameSite too |
| Strict-Transport-Security | max-age=31536000 | Require HTTPS after secure response |
| X-Content-Type-Options | nosniff | Restrict MIME sniffing |
| Content-Security-Policy | default-src 'self' | Resource source policy |
| Access-Control-Allow-Origin | https://example.com | Permitted cross-origin reader |
Copyable example
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Vary: Accept-Encoding Compression
A request accepting gzip can receive Content-Encoding: gzip. Vary: Accept-Encoding helps caches distinguish encoding-dependent representations.
Policy changes
Test CSP with the application’s actual resources. HSTS arrives over HTTPS. includeSubDomains extends its scope and should be chosen deliberately.
Try the related tools
- HTTP Headers Checker — View the HTTP response headers and status code of any URL, with a security header review.
- GZIP Compression Checker — Test whether a website uses GZIP or Brotli compression and how much it saves.