Search tools...
Developer Tools

HTTP Headers Reference गाइड: हर ज़रूरी Header (2026)

HTTP request और response headers का practical reference — क्या करते हैं, कब use करें, common values।

8 मिनट पढ़ेंUpdated May 8, 2026HTTP, Web, API

HTTP headers reference हर backend, frontend और DevOps engineer के पास होनी चाहिए। Headers caching, CORS, authentication, security, content negotiation control करते हैं — HTTP में लगभग हर cross-cutting concern।

इस गाइड में actually use होने वाले headers grouped हैं, हर एक का काम और common values के साथ।

Free Tool

HTTP Headers Reference — Free

Searchable reference हर HTTP header के लिए।

HTTP Headers Reference खोलें ->

Common Request Headers

HeaderPurpose
AuthorizationCredentials (Bearer, Basic)
AcceptContent types client handles
Accept-LanguagePreferred languages
Content-TypeBody format on POST/PUT
User-AgentClient identification
CookieSession state
If-None-MatchConditional GET (ETag)

Common Response Headers

HeaderPurpose
Content-TypeResponse body format
Cache-ControlCaching directives
ETagResource version
Set-CookieCookie set करता है
LocationRedirect target (3xx)

Security Headers (Essential)

HeaderPurpose
Content-Security-PolicyAllowed scripts whitelist
Strict-Transport-SecurityForce HTTPS (HSTS)
X-Content-Type-Optionsnosniff — MIME sniffing prevent
X-Frame-OptionsClickjacking protection
Referrer-PolicyReferer leak control

CORS Headers

HeaderPurpose
Access-Control-Allow-OriginAllowed origin
Access-Control-Allow-MethodsPermitted methods
Access-Control-Allow-HeadersPermitted custom headers
Access-Control-Allow-CredentialsCross-origin cookies

CORS errors? Server response पर इनमें से कोई missing है।

Caching Headers

Cache-Control directives:

  • public — Cacheable by any cache।
  • private — Browser only।
  • no-store — Never cache।
  • no-cache — Cache but revalidate।
  • max-age=N — N seconds cache।
  • immutable — Never check (hash-based filenames)।

Hashed assets के लिए: Cache-Control: public, max-age=31536000, immutable

Authorization Header Formats

SchemeFormat
BasicAuthorization: Basic base64(user:pass)
Bearer (JWT)Authorization: Bearer eyJ...
API KeyX-API-Key: your-key

How to Use the Tool (Step by Step)

  1. 1

    Category Pick करें

    Request, response, security, CORS।

  2. 2

    Headers Browse करें

    Purpose, valid values, examples।

  3. 3

    Search करें

    Specific header by name।

  4. 4

    Examples Copy करें

    Server config या fetch call में।

  5. 5

    Validate करें

    curl या DevTools से test।

Frequently Asked Questions

हर site पर कौन से security headers चाहिए?+

CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy।

CORS error कैसे fix करूं?+

Server response पर Access-Control-Allow-Origin add करें।

no-cache vs no-store?+

no-store never caches। no-cache caches लेकिन always revalidates।

Browser में request headers देख सकते हैं?+

हाँ — DevTools > Network tab > Headers section।

Static assets के लिए caching?+

Filename hash करें और Cache-Control: public, max-age=31536000, immutable।

Free — No Signup Required

HTTP Headers Reference — Free

Searchable reference हर HTTP header के लिए।

HTTP Headers Reference खोलें ->

Related Guides