HTTP Headers Reference
HTTP 請求與回應標頭完整參考
33 headers
Media types the client can process (e.g. application/json, text/html).
Accept: text/html,application/xhtml+xmlContent encodings the client supports (gzip, deflate, br).
Accept-Encoding: gzip, deflate, brPreferred natural languages for the response.
Accept-Language: en-US,en;q=0.9Credentials for HTTP authentication.
Authorization: Bearer eyJhbGc...Directives for caching mechanisms in both requests and responses.
Cache-Control: no-cache, no-storeControl options for the current connection.
Connection: keep-aliveSize of the request/response body in bytes.
Content-Length: 348Media type of the request/response body.
Content-Type: application/json; charset=utf-8HTTP cookies previously sent by the server.
Cookie: session=abc123; user=johnDomain name and port of the server. Required in HTTP/1.1.
Host: www.example.com:443Makes the request conditional; returns 304 if not modified.
If-Modified-Since: Mon, 18 Jul 2016 02:36:04 GMTMakes request conditional using ETags.
If-None-Match: "737060cd8c284d8af7ad3082f209582d"The origin that initiated the request (for CORS).
Origin: https://developer.example.comAddress of the previous web page that linked to the current page.
Referer: https://developer.example.com/pageApplication, OS, vendor, and version of the requesting client.
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)Indicates whether the response can be shared with code from the given origin.
Access-Control-Allow-Origin: *HTTP methods allowed when accessing the resource for CORS.
Access-Control-Allow-Methods: GET, POST, PUTHeaders that can be used during the actual CORS request.
Access-Control-Allow-Headers: Content-Type, AuthorizationEncoding applied to the response body (gzip, br, etc.).
Content-Encoding: gzipControls resources the user agent is allowed to load.
Content-Security-Policy: default-src 'self'Identifier for a specific version of a resource (for caching).
ETag: "33a64df551425fcc55e4d42a148795d9f25f89d4"Date/time after which the response is considered stale.
Expires: Thu, 01 Dec 2025 16:00:00 GMTDate/time when the resource was last modified.
Last-Modified: Wed, 21 Oct 2015 07:28:00 GMTURL to redirect to for 3xx responses or the URL of the newly created resource.
Location: /new-pageHow long to wait before making another request (rate limiting/503).
Retry-After: 120Send a cookie from the server to the user agent.
Set-Cookie: id=a3fWa; Expires=Thu, 21 Oct 2025 07:28:00 GMT; Secure; HttpOnlyForce HTTPS for all future connections (HSTS).
Strict-Transport-Security: max-age=31536000; includeSubDomainsForm of encoding used to safely transfer the payload body.
Transfer-Encoding: chunkedDetermines which request headers to use for cache key.
Vary: Accept-Encoding, Accept-LanguageAuthentication method to access the resource (sent with 401).
WWW-Authenticate: Basic realm="Access to staging site"Prevent MIME type sniffing.
X-Content-Type-Options: nosniffIndicate whether the response can be framed (clickjacking protection).
X-Frame-Options: DENYEnable XSS filtering in older browsers (deprecated, use CSP instead).
X-XSS-Protection: 1; mode=block關於本工具
HTTP 標頭參考涵蓋最常用的請求與回應標頭,以淺顯易懂的說明和範例值呈現。安全性關鍵標頭以紅色標示。
可依類別(請求、回應或兩者)篩選,或透過標頭名稱與關鍵字搜尋,快速找到所需內容。
使用方法
- 在搜尋框中輸入標頭名稱或關鍵字,即可即時篩選清單。
- 使用類別下拉選單,只顯示請求、回應或兩者的標頭。
- 每個項目會顯示標頭名稱、類別標籤、說明及範例值。
- 在設定伺服器或 HTTP 客戶端時,可將範例值作為起點參考。
使用情境
後端工程師在部署前設定正確的安全標頭(CSP、HSTS、X-Frame-Options)。前端開發者利用 Access-Control 標頭偵錯 CORS 問題。學習 HTTP 的學生則用此參考來理解該協定的運作方式。
常見問題
- 請求標頭與回應標頭有什麼不同? — 請求標頭由用戶端傳送,用於提供上下文資訊(可接受的類型、身分驗證)。回應標頭由伺服器傳送,包含關於回應的中繼資料(內容類型、快取、安全性)。
- 每個網站都應加入哪些安全標頭? — 至少應在所有回應中加入:Strict-Transport-Security、Content-Security-Policy、X-Content-Type-Options 及 X-Frame-Options。
- 這裡列出了所有的 HTTP 標頭嗎? — 沒有。本參考主要聚焦於最常用的標準與安全標頭。如需完整清單,請參閱 MDN 的 HTTP 標頭文件。