HTTP Headers Reference
Tài liệu tham khảo đầy đủ về header của HTTP request và response.
33 headers
Media types the client can process (e.g. application/json, text/html).
Accept: text/html,application/xhtml+xmlContent encodings the client supports (gzip, deflate, br).
Accept-Encoding: gzip, deflate, brPreferred natural languages for the response.
Accept-Language: en-US,en;q=0.9Credentials for HTTP authentication.
Authorization: Bearer eyJhbGc...Directives for caching mechanisms in both requests and responses.
Cache-Control: no-cache, no-storeControl options for the current connection.
Connection: keep-aliveSize of the request/response body in bytes.
Content-Length: 348Media type of the request/response body.
Content-Type: application/json; charset=utf-8HTTP cookies previously sent by the server.
Cookie: session=abc123; user=johnDomain name and port of the server. Required in HTTP/1.1.
Host: www.example.com:443Makes the request conditional; returns 304 if not modified.
If-Modified-Since: Mon, 18 Jul 2016 02:36:04 GMTMakes request conditional using ETags.
If-None-Match: "737060cd8c284d8af7ad3082f209582d"The origin that initiated the request (for CORS).
Origin: https://developer.example.comAddress of the previous web page that linked to the current page.
Referer: https://developer.example.com/pageApplication, OS, vendor, and version of the requesting client.
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)Indicates whether the response can be shared with code from the given origin.
Access-Control-Allow-Origin: *HTTP methods allowed when accessing the resource for CORS.
Access-Control-Allow-Methods: GET, POST, PUTHeaders that can be used during the actual CORS request.
Access-Control-Allow-Headers: Content-Type, AuthorizationEncoding applied to the response body (gzip, br, etc.).
Content-Encoding: gzipControls resources the user agent is allowed to load.
Content-Security-Policy: default-src 'self'Identifier for a specific version of a resource (for caching).
ETag: "33a64df551425fcc55e4d42a148795d9f25f89d4"Date/time after which the response is considered stale.
Expires: Thu, 01 Dec 2025 16:00:00 GMTDate/time when the resource was last modified.
Last-Modified: Wed, 21 Oct 2015 07:28:00 GMTURL to redirect to for 3xx responses or the URL of the newly created resource.
Location: /new-pageHow long to wait before making another request (rate limiting/503).
Retry-After: 120Send a cookie from the server to the user agent.
Set-Cookie: id=a3fWa; Expires=Thu, 21 Oct 2025 07:28:00 GMT; Secure; HttpOnlyForce HTTPS for all future connections (HSTS).
Strict-Transport-Security: max-age=31536000; includeSubDomainsForm of encoding used to safely transfer the payload body.
Transfer-Encoding: chunkedDetermines which request headers to use for cache key.
Vary: Accept-Encoding, Accept-LanguageAuthentication method to access the resource (sent with 401).
WWW-Authenticate: Basic realm="Access to staging site"Prevent MIME type sniffing.
X-Content-Type-Options: nosniffIndicate whether the response can be framed (clickjacking protection).
X-Frame-Options: DENYEnable XSS filtering in older browsers (deprecated, use CSP instead).
X-XSS-Protection: 1; mode=blockGiới thiệu công cụ
HTTP Headers Reference liệt kê các request và response header được sử dụng phổ biến nhất, kèm mô tả dễ hiểu và giá trị ví dụ. Các header quan trọng về bảo mật được đánh dấu màu đỏ.
Lọc theo danh mục (Request, Response, hoặc Both) hoặc tìm kiếm theo tên header và từ khóa để nhanh chóng tìm thấy thứ bạn cần.
Cách sử dụng
- Nhập tên header hoặc từ khóa vào ô tìm kiếm để lọc danh sách ngay lập tức.
- Dùng menu chọn danh mục để chỉ hiển thị header Request, Response, hoặc Both.
- Mỗi mục hiển thị tên header, nhãn danh mục, mô tả và một giá trị ví dụ.
- Sử dụng các giá trị ví dụ làm điểm khởi đầu khi cấu hình server hoặc HTTP client của bạn.
Trường hợp sử dụng
Kỹ sư back-end thiết lập đúng các header bảo mật (CSP, HSTS, X-Frame-Options) trước khi triển khai. Nhà phát triển front-end gỡ lỗi các vấn đề CORS bằng các header Access-Control. Sinh viên học HTTP dùng tài liệu tham khảo này để hiểu cách giao thức hoạt động.
Câu hỏi thường gặp
- Sự khác biệt giữa request header và response header là gì? — Request header được client gửi để cung cấp ngữ cảnh (loại nội dung chấp nhận, xác thực). Response header được server gửi kèm metadata về phản hồi (loại nội dung, caching, bảo mật).
- Mọi trang web nên thêm những header nào để đảm bảo bảo mật? — Tối thiểu là: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, và X-Frame-Options trên mọi phản hồi.
- Tài liệu này có liệt kê tất cả các HTTP header không? — Không. Tài liệu tham khảo này tập trung vào các header chuẩn và bảo mật được sử dụng phổ biến nhất. Để xem danh sách đầy đủ, hãy tham khảo tài liệu HTTP headers của MDN.