Flask Response Object API

The Response class represents the HTTP response returned by Flask view functions. In most cases you don't need to create it directly—Flask automatically converts view function return values into Response objects.

When manual control is needed, usemake_response()function.


Constructor

Parameter Type Default value Description
response str / bytes / iterator Required Response body content
status int / str 200 HTTP status code or status text, such as 404 or "404 Not Found"
headers dict / list None Response headers, a dict or a list of (key, value) tuples
mimetype str None MIME type, e.g., "application/json"
content_type str None Content-Type header, including charset, e.g., "text/html; charset=utf-8"
direct_passthrough bool False When True, pass the response body through directly without any processing.

Core attributes

Property Type Description
status str Response status (in text form), such as "200 OK" or "404 Not Found"
status_code int HTTP status codes, such as 200, 404
headers Headers Response header object, supports dictionary-style operations
data bytes Byte representation of the response body
mimetype str MIME type (without encoding), such as "text/html"
content_type str Content-Type (including charset), e.g., "text/html; charset=utf-8"
content_length int Response body byte length

Response header operations

Methods Description
headers.get(key) Get the value of the specified response header
headers[key] = value Set response headers
headers.update(dict) Batch update response headers

Cookie operations

Methods Description
set_cookie(key, value, max_age, expires, path, domain, secure, httponly, samesite) Set a Cookie. max_age is in seconds, expires is a datetime, secure is HTTPS only
delete_cookie(key, path, domain) Delete the specified Cookie
set_cookie parameters: max_age Cookie lifetime in seconds, e.g., max_age=3600 means 1 hour
set_cookie parameters: secure Defaults to the SESSION_COOKIE_SECURE configuration value; when True, sent only over HTTPS
set_cookie parameters: httponly Defaults to True, preventing JavaScript from accessing this cookie
set_cookie parameters: samesite "Strict", "Lax", or None, controlling the sending behavior of cross-site cookies

Other methods

Methods Description
get_json(force=False, silent=False) Parse the response body as JSON (mainly used for testing).
freeze() Freeze the response to an immutable state
force_type(response, environ) Class method that forcibly converts other types of responses into the Response type.

Code Examples

Example

from flask import Flask, make_response

app = Flask(__name__)

@app.route("/custom")
def custom_response():
    # Use make_response to manually construct a response
    resp = make_response("<h1>Hello, EXAMPLE!</h1>")

    # Set the status code
    resp.status_code = 201

    # Set custom response headers
    resp.headers["X-Custom-Header"] = "my-value"

    # Set a Cookie
    resp.set_cookie("theme", "dark", max_age=86400)    # Valid for 24 hours
    resp.set_cookie("lang", "zh-CN", samesite="Lax")   # SameSite restriction

    return resp

@app.route("/delete-cookie")
def delete_cookie():
    resp = make_response("Cookie deleted")
    resp.delete_cookie("theme")
    return resp

@app.route("/api/data")
def api_data():
    # Return a dict directly; Flask automatically serializes it to a JSON Response
    return {"status": "ok", "data": [1, 2, 3]}
other extensions