HTTP Header
- In Turkish
- HTTP Başlığı
In short
An HTTP header is a name-and-value line sent with an HTTP request or response, carrying details such as the content type, caching rules or credentials.
What is an HTTP header?
Every HTTP message carries headers: lines of the form Name: value that come before the body and describe it. Requests use them to say who is asking and what they accept, and responses use them to say what is being sent and how to handle it. Header names are case-insensitive, so Content-Type and content-type are the same header.
A handful do most of the work. Content-Type names the format of the body, such as application/json; Authorization carries credentials such as a bearer token; Accept lists the formats the client wants; Cache-Control says whether, and for how long, a response may be cached; Cookie and Set-Cookie carry cookies; and Location tells the browser where to go after a redirect. Security headers such as Content-Security-Policy and Strict-Transport-Security tell the browser how to protect the page.
Headers are like the label on a parcel: they say what is inside, where it is going and how to handle it, without opening the box. You can read them in the Network panel of the browser's developer tools, or with curl -v. Custom headers used to start with X-, as in X-Request-Id; that convention is now discouraged, though many such headers are still around. HTTP/2 and HTTP/3 compress headers and always send their names in lowercase.
Key takeaways
- Headers are
Name: valuelines that describe an HTTP request or response. - Requests use them for credentials and preferences; responses, for format and handling.
- Common ones include
Content-Type,Authorization,Cache-ControlandSet-Cookie. - Header names are case-insensitive, and HTTP/2 sends them in lowercase.
Example
curl -v https://example.com -o /dev/null
# Sent by curl (>):
# > GET / HTTP/1.1
# > Host: example.com
# > User-Agent: curl/8.17.0
# > Accept: */*
#
# Sent back by the server (<), names in any case:
# < HTTP/1.1 200 OK
# < Content-Type: text/html; charset=utf-8
# < last-modified: Fri, 02 Oct 2026 16:11:02 GMT
# < allow: GET, HEAD
# < Age: 603Readers ask
What is the difference between headers and the body?
Headers are metadata: short lines that describe the message. The body is the content itself, such as an HTML page, JSON data or an image. A GET request usually has headers but no body.
Can JavaScript read every response header?
Not from another origin. In the browser, fetch exposes only a few safe response headers from other origins unless the server lists more in Access-Control-Expose-Headers, which is part of CORS. Some, such as Set-Cookie, are never readable from JavaScript.
See also
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- HTTP MethodBackend & APIs, p. 23An HTTP method is the verb in an HTTP request, such as GET, POST, PUT, PATCH or DELETE, that tells the server what action to perform on the requested resource.
- HTTP Status CodeWeb Development, p. 21An HTTP status code is a three-digit number a server sends with every response to tell the client whether the request succeeded, failed, or needs more action.
- CookieWeb Development, p. 6A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.
- CORSWeb Development, p. 8CORS is a browser security mechanism that lets a server declare which other websites may read its responses when they make requests from JavaScript.
- HTTP CachingBackend & APIs, p. 22HTTP caching is the reuse of stored HTTP responses by browsers, CDNs and proxies, controlled by headers like Cache-Control and ETag, to avoid repeat downloads.
- Content Security PolicySecurity, p. 7A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
Sources
Spotted a mistake or something missing on this page?Suggest an edit