FreeToGenerate.com

The registry has no request-or-response column. Every list that sorts headers that way is sorting them by somebody's judgement.

257 fields

What the labels mean

script may set
Nothing in the Fetch standard stops script sending this on a request it makes.
script may not set
Named in the Fetch standard's forbidden list, so the browser keeps control of it and silently drops any attempt to set it.
closed by prefix
Its name begins with a reserved prefix, so no script can ever set it. That is the point of the namespace: headers minted inside it cannot be forged by page code.
depends on the value
Forbidden only when the value names a method the browser refuses to override.
CORS-safelisted name
Safelisting also depends on the value, so this name alone does not mean a request avoids a preflight.
script cannot read it
The Fetch standard forbids script reading this off a response, whatever the CORS headers say.
not a field
Registered with the comment (reserved) — that is, registered so that nobody ever registers it.
Structured type
How the value parses under the structured fields specification, which replaces reading the ABNF by hand.

Permanent

Registered for good, with a specification behind it.

*script may setnot a field

Reference: RFC 9110 §12.5.5

(reserved)

A-IMscript may set

Reference: RFC 3229

Acceptscript may setCORS-safelisted name

Reference: RFC 9110 §12.5.1

Accept-Additionsscript may set

Reference: RFC 2324

Accept-CHscript may setList

Reference: RFC 8942 §3.1

Accept-Datetimescript may set

Reference: RFC 7089

Accept-Encodingscript may not set

Reference: RFC 9110 §12.5.3

Accept-Featuresscript may set

Reference: RFC 2295

Accept-Languagescript may setCORS-safelisted name

Reference: RFC 9110 §12.5.4

Accept-Patchscript may set

Reference: RFC 5789

Accept-Postscript may set

Reference: Linked Data Platform 1.0

Accept-Queryscript may setList

Reference: RFC 10008 §3

Accept-Rangesscript may set

Reference: RFC 9110 §14.3

Accept-Signaturescript may set

Reference: RFC 9421 §5.1

Access-Control-Allow-Credentialsscript may set

Reference: Fetch

Access-Control-Allow-Headersscript may set

Reference: Fetch

Access-Control-Allow-Methodsscript may set

Reference: Fetch

Access-Control-Allow-Originscript may set

Reference: Fetch

Access-Control-Expose-Headersscript may set

Reference: Fetch

Access-Control-Max-Agescript may set

Reference: Fetch

Access-Control-Request-Headersscript may not set

Reference: Fetch

Access-Control-Request-Methodscript may not set

Reference: Fetch

Agescript may set

Reference: RFC 9111 §5.1

Allowscript may set

Reference: RFC 9110 §10.2.1

ALPNscript may set

Reference: RFC 7639 §2

Alt-Svcscript may set

Reference: RFC 7838

Alt-Usedscript may set

Reference: RFC 7838

Alternatesscript may set

Reference: RFC 2295

Apply-To-Redirect-Refscript may set

Reference: RFC 4437

Authentication-Controlscript may set

Reference: RFC 8053 §4

Authentication-Infoscript may set

Reference: RFC 9110 §11.6.3

Authorizationscript may set

Reference: RFC 9110 §11.6.2

Available-Dictionaryscript may setItem

Reference: RFC 9842 §2.2

Cache-Controlscript may set

Reference: RFC 9111 §5.2

Cache-Group-Invalidationscript may setList

Reference: RFC 9875

Cache-Groupsscript may setList

Reference: RFC 9875

Cache-Statusscript may setList

Reference: RFC 9211

Cal-Managed-IDscript may set

Reference: RFC 8607 §5.1

CalDAV-Timezonesscript may set

Reference: RFC 7809 §7.1

Capsule-Protocolscript may setItem

Reference: RFC 9297

CDN-Cache-Controlscript may setDictionary

Reference: RFC 9213

Cache directives targeted at content delivery networks

CDN-Loopscript may set

Reference: RFC 8586

Cert-Not-Afterscript may set

Reference: RFC 8739 §3.3

Cert-Not-Beforescript may set

Reference: RFC 8739 §3.3

Clear-Site-Datascript may set

Reference: Clear Site Data

Client-Certscript may setItem

Reference: RFC 9440 §2

Client-Cert-Chainscript may setList

Reference: RFC 9440 §2

Closescript may setnot a field

Reference: RFC 9112 §9.6

(reserved)

Concealed-Auth-Exportscript may setItem

Reference: RFC 9729

Connectionscript may not set

Reference: RFC 9110 §7.6.1

Content-Digestscript may setDictionary

Reference: RFC 9530 §2

Content-Dispositionscript may set

Reference: RFC 6266

Content-Encodingscript may set

Reference: RFC 9110 §8.4

Content-Languagescript may setCORS-safelisted name

Reference: RFC 9110 §8.5

Content-Lengthscript may not set

Reference: RFC 9110 §8.6

Content-Locationscript may set

Reference: RFC 9110 §8.7

Content-Rangescript may set

Reference: RFC 9110 §14.4

Content-Security-Policyscript may set

Reference: Content Security Policy Level 3

Content-Security-Policy-Report-Onlyscript may set

Reference: Content Security Policy Level 3

Content-Typescript may setCORS-safelisted name

Reference: RFC 9110 §8.3

Cookiescript may not set

Reference: RFC-ietf-httpbis-rfc6265bis-22, Section 5.8.1

Cross-Origin-Embedder-Policyscript may setItem

Reference: HTML

Cross-Origin-Embedder-Policy-Report-Onlyscript may setItem

Reference: HTML

Cross-Origin-Opener-Policyscript may setItem

Reference: HTML

Cross-Origin-Opener-Policy-Report-Onlyscript may setItem

Reference: HTML

Cross-Origin-Resource-Policyscript may set

Reference: Fetch

DASLscript may set

Reference: RFC 5323

Datescript may not set

Reference: RFC 9110 §6.6.1

DAVscript may set

Reference: RFC 4918

Delta-Basescript may set

Reference: RFC 3229

Deprecationscript may setItem

Reference: RFC 9745 §2

Depthscript may set

Reference: RFC 4918

Destinationscript may set

Reference: RFC 4918

Detached-JWSscript may set

Reference: RFC 9635

Dictionary-IDscript may setItem

Reference: RFC 9842 §2.3

DPoPscript may set

Reference: RFC 9449

DPoP-Noncescript may set

Reference: RFC 9449

Early-Datascript may set

Reference: RFC 8470

ETagscript may set

Reference: RFC 9110 §8.8.3

Expectscript may not set

Reference: RFC 9110 §10.1.1

Expiresscript may set

Reference: RFC 9111 §5.3

Forwardedscript may set

Reference: RFC 7239

Fromscript may set

Reference: RFC 9110 §10.1.2

Hobaregscript may set

Reference: RFC 7486 §6.1.1

Hostscript may not set

Reference: RFC 9110 §7.2

Ifscript may set

Reference: RFC 4918

If-Matchscript may set

Reference: RFC 9110 §13.1.1

If-Modified-Sincescript may set

Reference: RFC 9110 §13.1.3

If-None-Matchscript may set

Reference: RFC 9110 §13.1.2

If-Rangescript may set

Reference: RFC 9110 §13.1.5

If-Schedule-Tag-Matchscript may set

Reference: RFC 6338

If-Unmodified-Sincescript may set

Reference: RFC 9110 §13.1.4

IMscript may set

Reference: RFC 3229

Include-Referred-Token-Binding-IDscript may set

Reference: RFC 8473

Incrementalscript may set

Reference: RFC-ietf-httpbis-incremental-04

Keep-Alivescript may not set

Reference: RFC 2068

Labelscript may set

Reference: RFC 3253

Last-Event-IDscript may set

Reference: HTML

Last-Modifiedscript may set

Reference: RFC 9110 §8.8.2

Linkscript may set

Reference: RFC 8288

Link-Templatescript may set

Reference: RFC 9652

Locationscript may set

Reference: RFC 9110 §10.2.2

Lock-Tokenscript may set

Reference: RFC 4918

Max-Forwardsscript may set

Reference: RFC 9110 §7.6.2

Memento-Datetimescript may set

Reference: RFC 7089

Meterscript may set

Reference: RFC 2227

MIME-Versionscript may set

Reference: RFC 9112 App. B.1

Negotiatescript may set

Reference: RFC 2295

NELscript may set

Reference: Network Error Logging

OData-EntityIdscript may set

Reference: OData Version 4.01 Part 1, OASIS, Chet_Ensign

OData-Isolationscript may set

Reference: OData Version 4.01 Part 1, OASIS, Chet_Ensign

OData-MaxVersionscript may set

Reference: OData Version 4.01 Part 1, OASIS, Chet_Ensign

OData-Versionscript may set

Reference: OData Version 4.01 Part 1, OASIS, Chet_Ensign

Optional-WWW-Authenticatescript may set

Reference: RFC 8053 §3

Ordering-Typescript may set

Reference: RFC 3648

Originscript may not set

Reference: RFC 6454

Origin-Agent-Clusterscript may setItem

Reference: HTML

OSCOREscript may set

Reference: RFC 8613 §11.1

OSLC-Core-Versionscript may set

Reference: OASIS Project Specification 01, OASIS, Chet_Ensign

Overwritescript may set

Reference: RFC 4918

Ping-Fromscript may set

Reference: HTML

Ping-Toscript may set

Reference: HTML

Positionscript may set

Reference: RFC 3648

Preferscript may set

Reference: RFC 7240

Preference-Appliedscript may set

Reference: RFC 7240

Priorityscript may setDictionary

Reference: RFC 9218

Proxy-Authenticateclosed by prefix

Reference: RFC 9110 §11.7.1

Proxy-Authentication-Infoclosed by prefix

Reference: RFC 9110 §11.7.3

Proxy-Authorizationclosed by prefix

Reference: RFC 9110 §11.7.2

Proxy-Statusclosed by prefixList

Reference: RFC 9209

Public-Key-Pinsscript may set

Reference: RFC 7469

Public-Key-Pins-Report-Onlyscript may set

Reference: RFC 7469

Rangescript may setCORS-safelisted name

Reference: RFC 9110 §14.2

Redirect-Refscript may set

Reference: RFC 4437

Refererscript may not set

Reference: RFC 9110 §10.1.3

Referrer-Policyscript may set

Reference: Referrer Policy

The header name does not share the HTTP Referer header's misspelling.

Refreshscript may set

Reference: HTML

Replay-Noncescript may set

Reference: RFC 8555 §6.5.1

Repr-Digestscript may setDictionary

Reference: RFC 9530 §3

Retry-Afterscript may set

Reference: RFC 9110 §10.2.3

Schedule-Replyscript may set

Reference: RFC 6638

Schedule-Tagscript may set

Reference: RFC 6338

Sec-Fetch-Destclosed by prefixItem

Reference: w3.org

Sec-Fetch-Modeclosed by prefixItem

Reference: w3.org

Sec-Fetch-Siteclosed by prefixItem

Reference: w3.org

Sec-Fetch-Userclosed by prefixItem

Reference: w3.org

Sec-Purposeclosed by prefix

Reference: Fetch

Intended to replace the (not registered) Purpose and x-moz headers.

Sec-Token-Bindingclosed by prefix

Reference: RFC 8473

Sec-WebSocket-Acceptclosed by prefix

Reference: RFC 6455

Sec-WebSocket-Extensionsclosed by prefix

Reference: RFC 6455

Sec-WebSocket-Keyclosed by prefix

Reference: RFC 6455

Sec-WebSocket-Protocolclosed by prefix

Reference: RFC 6455

Sec-WebSocket-Versionclosed by prefix

Reference: RFC 6455

Serverscript may set

Reference: RFC 9110 §10.2.4

Server-Timingscript may set

Reference: Server Timing

Set-Cookiescript may not setscript cannot read it

Reference: RFC-ietf-httpbis-rfc6265bis-22, Section 5.8.1

Set-Txnscript may set

Reference: RFC 9967 §3

Signaturescript may setDictionary

Reference: RFC 9421 §4.2

Signature-Inputscript may setDictionary

Reference: RFC 9421 §4.1

SLUGscript may set

Reference: RFC 5023

SoapActionscript may set

Reference: Simple Object Access Protocol (SOAP) 1.1

Status-URIscript may set

Reference: RFC 2518

Strict-Transport-Securityscript may set

Reference: RFC 6797

Sunsetscript may set

Reference: RFC 8594

TCNscript may set

Reference: RFC 2295

TEscript may not set

Reference: RFC 9110 §10.1.4

Timeoutscript may set

Reference: RFC 4918

Topicscript may set

Reference: RFC 8030 §5.4

Traceparentscript may set

Reference: Trace Context

Tracestatescript may set

Reference: Trace Context

Trailerscript may not set

Reference: RFC 9110 §6.6.2

Transfer-Encodingscript may not set

Reference: RFC 9112 §6.1

TTLscript may set

Reference: RFC 8030 §5.2

Unencoded-Digestscript may setDictionary

Reference: RFC-ietf-httpbis-unencoded-digest-05, Section 3

Upgradescript may not set

Reference: RFC 9110 §7.8

Urgencyscript may set

Reference: RFC 8030 §5.3

Use-As-Dictionaryscript may setDictionary

Reference: RFC 9842 §2.1

User-Agentscript may set

Reference: RFC 9110 §10.1.5

Variant-Varyscript may set

Reference: RFC 2295

Varyscript may set

Reference: RFC 9110 §12.5.5

Viascript may not set

Reference: RFC 9110 §7.6.3

Want-Content-Digestscript may setDictionary

Reference: RFC 9530 §4

Want-Repr-Digestscript may setDictionary

Reference: RFC 9530 §4

Want-Unencoded-Digestscript may setDictionary

Reference: RFC-ietf-httpbis-unencoded-digest-05, Section 4

WWW-Authenticatescript may set

Reference: RFC 9110 §11.6.1

X-Content-Type-Optionsscript may set

Reference: Fetch

X-Frame-Optionsscript may set

Reference: HTML

Provisional

Registered, but the entry is not yet settled and may still change or go away.

Activate-Storage-Accessscript may setItem

Reference: privacycg.github.io

AMP-Cache-Transformscript may set

Reference: AMP-Cache-Transform HTTP request header

CMCD-Objectscript may set

Reference: CTA, CTA-5004 Common Media Client Data

CMCD-Requestscript may set

Reference: CTA, CTA-5004 Common Media Client Data

CMCD-Sessionscript may set

Reference: CTA, CTA-5004 Common Media Client Data

CMCD-Statusscript may set

Reference: CTA, CTA-5004 Common Media Client Data

CMSD-Dynamicscript may set

Reference: CTA, CTA-5006 Common Media Server Data (CMSD)

CMSD-Staticscript may set

Reference: CTA, CTA-5006 Common Media Server Data (CMSD)

Configuration-Contextscript may set

Reference: OSLC Configuration Management Version 1.0. Part 3

CTA-Common-Access-Tokenscript may set

Reference: CTA, Chris_Lemmons

EDIINT-Featuresscript may set

Reference: RFC 6017

Isolationscript may set

Reference: OData Version 4.01 Part 1, OASIS, Chet_Ensign

Permissions-Policyscript may set

Reference: Permissions Policy

Repeatability-Client-IDscript may set

Reference: Repeatable Requests Version 1.0, OASIS, Chet_Ensign

Repeatability-First-Sentscript may set

Reference: Repeatable Requests Version 1.0, OASIS, Chet_Ensign

Repeatability-Request-IDscript may set

Reference: Repeatable Requests Version 1.0, OASIS, Chet_Ensign

Repeatability-Resultscript may set

Reference: Repeatable Requests Version 1.0, OASIS, Chet_Ensign

Reporting-Endpointsscript may set

Reference: Reporting API

Sec-Fetch-Storage-Accessclosed by prefixToken

Reference: privacycg.github.io

Sec-GPCclosed by prefix

Reference: Global Privacy Control (GPC)

Surrogate-Capabilityscript may set

Reference: Edge Architecture Specification

Surrogate-Controlscript may set

Reference: Edge Architecture Specification

Timing-Allow-Originscript may set

Reference: Resource Timing Level 1

Deprecated

Still registered, and you are asked not to use it.

Accept-Charsetscript may not set

Reference: RFC 9110 §12.5.2

C-PEP-Infoscript may set

Reference: PEP - an Extension Mechanism for HTTP

[Status change of HTTP experiments to Historic]

Content-IDscript may set

Reference: The HTTP Distribution and Replication Protocol

Differential-IDscript may set

Reference: The HTTP Distribution and Replication Protocol

Expect-CTscript may set

Reference: RFC 9163

Obsoleted by [IESG] [HTTPBIS]

Pragmascript may set

Reference: RFC 9111 §5.4

Protocol-Infoscript may set

Reference: White Paper

Protocol-Queryscript may set

Reference: White Paper

Obsoleted

Superseded. Listed so that old traffic can be understood, not so that new traffic can use it.

Access-Controlscript may set

Reference: Access Control for Cross-site Requests

C-Extscript may set

Reference: RFC 2774

[Status change of HTTP experiments to Historic]

C-Manscript may set

Reference: RFC 2774

[Status change of HTTP experiments to Historic]

C-Optscript may set

Reference: RFC 2774

[Status change of HTTP experiments to Historic]

C-PEPscript may set

Reference: PEP - an Extension Mechanism for HTTP

[Status change of HTTP experiments to Historic]

Content-Basescript may set

Reference: RFC 2068

Obsoleted by [RFC 2616: Hypertext Transfer Protocol -- HTTP/1.1]

Content-MD5script may set

Reference: RFC 2616 §14.15

Obsoleted by [RFC 7231, Appendix B: Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content]

Content-Script-Typescript may set

Reference: HTML 4.01 Specification

Content-Style-Typescript may set

Reference: HTML 4.01 Specification

Content-Versionscript may set

Reference: RFC 2068

Cookie2script may not set

Reference: RFC 2965

Obsoleted by [RFC 6265: HTTP State Management Mechanism]

Default-Stylescript may set

Reference: HTML 4.01 Specification

Derived-Fromscript may set

Reference: RFC 2068

Digestscript may set

Reference: RFC 3230

Obsoleted by [RFC 9530, Section 1.3: Digest Fields]

Extscript may set

Reference: RFC 2774

[Status change of HTTP experiments to Historic]

GetProfilescript may set

Reference: Implementation of OPS Over HTTP

HTTP2-Settingsscript may set

Reference: RFC 7540 §3.2.1

Obsolete; see Section 11.1 of [RFC9113]

Manscript may set

Reference: RFC 2774

[Status change of HTTP experiments to Historic]

Method-Checkscript may set

Reference: Access Control for Cross-site Requests

Method-Check-Expiresscript may set

Reference: Access Control for Cross-site Requests

Optscript may set

Reference: RFC 2774

[Status change of HTTP experiments to Historic]

P3Pscript may set

Reference: The Platform for Privacy Preferences 1.0 (P3P1.0) Specification

PEPscript may set

Reference: PEP - an Extension Mechanism for HTTP

PEP-Infoscript may set

Reference: PEP - an Extension Mechanism for HTTP

PICS-Labelscript may set

Reference: PICS Label Distribution Label Syntax and Communication Protocols

ProfileObjectscript may set

Reference: Implementation of OPS Over HTTP

Protocolscript may set

Reference: PICS Label Distribution Label Syntax and Communication Protocols

Protocol-Requestscript may set

Reference: PICS Label Distribution Label Syntax and Communication Protocols

Proxy-Featuresclosed by prefix

Reference: Notification for Proxy Caches

Proxy-Instructionclosed by prefix

Reference: Notification for Proxy Caches

Publicscript may set

Reference: RFC 2068

Referer-Rootscript may set

Reference: Access Control for Cross-site Requests

Safescript may set

Reference: RFC 2310

[Status change of HTTP experiments to Historic]

Security-Schemescript may set

Reference: RFC 2660

[Status change of HTTP experiments to Historic]

Set-Cookie2script may setscript cannot read it

Reference: RFC 2965

Obsoleted by [RFC 6265: HTTP State Management Mechanism]

SetProfilescript may set

Reference: Implementation of OPS Over HTTP

URIscript may set

Reference: RFC 2068

Want-Digestscript may set

Reference: RFC 3230

Obsoleted by [RFC 9530, Section 1.3: Digest Fields]

Warningscript may set

Reference: RFC 9111 §5.5

Read from the IANA registry on the date shown. The registry keeps moving; a table that does not say when it was taken is quietly claiming to be current. 2026-08-02

Also available in: Español · Português · Français · العربية

HTTP headers list

All 257 registered fields, each with the registry's own status and the one thing the registry does not record: whether a browser will let script set it.

What is the HTTP headers list?

Every HTTP request and response carries header fields — Content-Type, Cache-Control, Authorization and the rest — and which names are real is not a matter of opinion. IANA keeps the HTTP Field Name Registry, and this page is that registry: 257 fields, each with the status IANA gave it and the specification it comes from.

Most published lists of HTTP headers are organised into request headers and response headers. That is worth knowing about, because the registry has no such column. Its five fields are the name, the status, the structured type, the reference and a free-text comment — nothing about direction. Plenty of fields travel in both directions anyway, so the split you see elsewhere is an editor's judgement presented as a fact.

What the registry does record is status, and it makes a distinction that copied tables flatten. 187 fields are permanent, 23 are provisional and still unsettled, 8 are deprecated, and 39 are obsoleted — kept so old traffic can be read, not so new traffic can use them. Nearly a fifth of the registry is something you should not be sending.

How to use it

  1. Search by name, by reference or by comment. One box covers all three, and results are ranked rather than merely filtered — an exact name comes first even when it would sort last alphabetically, so searching for range gives you Range and not Accept-Ranges.
  2. Read the badge beside each name. It says whether a browser will let script set that header on a request, and the ones it refuses are marked with which rule refuses them.
  3. Check the status heading above the group. Fields are grouped by what IANA says about them, so a deprecated or obsoleted name is never sitting silently beside a current one.

The column that is missing, and the one that answers it

The question people actually arrive with is not whether a header is a request or a response header. It is why setting one from JavaScript silently does nothing. That answer is in a different specification: the Fetch standard defines a forbidden request-header, and a browser drops any attempt to set one so that it keeps control of what it sends.

It is not a list. It is 21 names — Cookie, Host, Origin, Referer, Connection and company — plus two prefixes: proxy- and sec-. The prefix half is the interesting half, because it is unbounded. No header whose name begins with Sec- will ever be settable by page code, including ones nobody has invented yet, and the standard says why: the namespace is reserved so that new headers can be minted safe from the APIs that let developers set headers. That is what makes a header like Sec-Fetch-Site worth anything — a page cannot forge it.

Of the 257 registered fields, 218 are ones script may set, 20 are refused by name and 19 by prefix. One name on the forbidden list is not in the registry at all: DNT. The browser refuses to let script set a header IANA has never contained.

There is a smaller rule in the other direction too. Script can never read Set-Cookie or Set-Cookie2 off a response, whatever the CORS headers say, which is why a cookie set by a cross-origin API is invisible to the code that called it.

Honest limits, and three things worth knowing

This is a snapshot. The registry gains entries, and the date it was read is printed under the list rather than left for you to guess. A table that does not say when it was taken is quietly claiming to be current forever.

The registry also spells four of its own statuses with a capital letter, and all four are Sec-Fetch- fields. An exact-match filter on permanent returns 183 rather than 187 and drops precisely the modern fetch-metadata security headers. That is a real trap for anyone reading the CSV themselves, and it is why this page normalises the spelling.

Two entries are not headers. Close and a bare asterisk are registered with the comment reserved — that is, registered so that nobody registers them. Their status is permanent, so status alone will not tell you they are unusable, and yes, an asterisk really is a registered HTTP field name.

Some names you expect are absent. X-Forwarded-For, X-Requested-With, X-Powered-By and X-XSS-Protection are used everywhere and registered nowhere; the registered relative of the first is Forwarded. Exactly two X- fields are in the registry, and one of them is X-Frame-Options — listed as permanent, not obsoleted, which contradicts the common belief that CSP frame-ancestors retired it.

One more caveat about the safelist badge. A CORS-safelisted header avoids a preflight request only for certain values: Content-Type qualifies for three media types, so application/json preflights while text/plain does not, and every safelisted value is capped at 128 bytes. Safelisting is a property of the name and the value together, so treat that badge as a hint rather than a verdict.

Why is it free?

Because it costs nothing to run. The list is part of the page, the search happens in your browser, and nothing is uploaded or logged.

The data comes from IANA's own machine-readable file rather than from another list, the script rules come from the Fetch standard, and the script that reads both is committed alongside the data it produces so the figures on this page can be reproduced.