# HTTP Header

URL: https://softwaredictionary.org/terms/http-header
Category: Web Development
Last updated: 2026-10-05
In Turkish: HTTP Başlığı

In short: An HTTP header is a name-and-value line sent with an HTTP request or response, carrying details such as the content type, caching rules or credentials.

## What is an HTTP header?

Every HTTP message carries headers: lines of the form `Name: value` that come before the body and describe it. Requests use them to say who is asking and what they accept, and responses use them to say what is being sent and how to handle it. Header names are case-insensitive, so `Content-Type` and `content-type` are the same header.

A handful do most of the work. `Content-Type` names the format of the body, such as `application/json`; `Authorization` carries credentials such as a bearer token; `Accept` lists the formats the client wants; `Cache-Control` says whether, and for how long, a response may be cached; `Cookie` and `Set-Cookie` carry cookies; and `Location` tells the browser where to go after a redirect. Security headers such as `Content-Security-Policy` and `Strict-Transport-Security` tell the browser how to protect the page.

Headers are like the label on a parcel: they say what is inside, where it is going and how to handle it, without opening the box. You can read them in the Network panel of the browser's developer tools, or with `curl -v`. Custom headers used to start with `X-`, as in `X-Request-Id`; that convention is now discouraged, though many such headers are still around. HTTP/2 and HTTP/3 compress headers and always send their names in lowercase.

## Key takeaways

- Headers are `Name: value` lines that describe an HTTP request or response.
- Requests use them for credentials and preferences; responses, for format and handling.
- Common ones include `Content-Type`, `Authorization`, `Cache-Control` and `Set-Cookie`.
- Header names are case-insensitive, and HTTP/2 sends them in lowercase.

## Example: The headers of one request and its response, as curl shows them

```bash
curl -v https://example.com -o /dev/null
# Sent by curl (>):
# > GET / HTTP/1.1
# > Host: example.com
# > User-Agent: curl/8.17.0
# > Accept: */*
#
# Sent back by the server (<), names in any case:
# < HTTP/1.1 200 OK
# < Content-Type: text/html; charset=utf-8
# < last-modified: Fri, 02 Oct 2026 16:11:02 GMT
# < allow: GET, HEAD
# < Age: 603
```

## Frequently asked questions

**What is the difference between headers and the body?**

Headers are metadata: short lines that describe the message. The body is the content itself, such as an HTML page, JSON data or an image. A `GET` request usually has headers but no body.

**Can JavaScript read every response header?**

Not from another origin. In the browser, `fetch` exposes only a few safe response headers from other origins unless the server lists more in `Access-Control-Expose-Headers`, which is part of CORS. Some, such as `Set-Cookie`, are never readable from JavaScript.

## Sources

- [RFC 9110: HTTP Semantics, Fields](https://www.rfc-editor.org/rfc/rfc9110.html#name-fields)
- [MDN: HTTP headers](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
