HTTP Response Headers

HTTP response headers are a series of header fields sent by the server when responding to a client's HTTP request. They provide additional information about the response and server instructions.

The following are some common HTTP response headers:

Response Header (English) Response Header (Chinese) Description
Date Date The date and time the response was generated. Example: Wed, 18 Apr 2024 12:00:00 GMT
Server Server The name and version of the server software. Example: Apache/2.4.1 (Unix)
Content-Type Content-Type The media type (MIME type) of the response body, such astext/html; charset=UTF-8, application/jsonetc.
Content-Length Content-Length The size of the response body in bytes. Example: 3145
Content-Encoding Content-Encoding The compression encoding of the response body, such asgzip, deflateetc.
Content-Language Content-Language The language of the response body. Example: zh-CN
Content-Location Content-Location The URI of the response body. Example: /index.html
Content-Range Content-Range The byte range of the response body, used for chunked transfer. Example: bytes 0-999/8000
Cache-Control Cache-Control Controls the caching behavior of the response. For example, no-cache means it must be requested again.
Connection Connection Manages connection options, such askeep-aliveorclose, keep-alive means the connection will not be closed after transfer..
Set-Cookie Set-Cookie Sets the client's cookie. Example: sessionId=abc123; Path=/; Secure
Expires Expires The expiration date and time of the response body. Example: Thu, 18 Apr 2024 12:00:00 GMT
Last-Modified Last-Modified The date and time when the resource was last modified. Example: Wed, 18 Apr 2024 11:00:00 GMT
ETag Entity Tag An identifier for a specific version of a resource. Example: "33a64df551425fcc55e6"
Location Location The URI used for redirection. Example: /newresource
Pragma Implementation-Specific Directives Contains implementation-specific directives, such asno-cache。
WWW-Authenticate Authentication Information Authentication information, typically used for HTTP authentication. Example: Basic realm="Access to the site"
Accept-Ranges Accept-Ranges Specifies the acceptable request range types. Example: bytes
Age Elapsed Time The number of seconds elapsed after the response was generated, from the origin server to the proxy server. Example: 24
Allow Allow Lists the HTTP methods allowed for the resource. Example: GET, POST, HEAD, etc.
Vary Vary Tells downstream proxies how to use response headers to determine whether a response can be fetched from the cache. Example: Accept
Strict-Transport-Security Strict-Transport-Security Instructs the browser to communicate with the server only over HTTPS. Example: max-age=31536000; includeSubDomains
X-Frame-Options Frame Options Controls whether the page is allowed to be displayed in a frame, preventing clickjacking attacks. Example: SAMEORIGIN
X-Content-Type-Options Content Type Options Instructs the browser not to attempt to guess the MIME type of a resource. Example: nosniff
X-XSS-Protection XSS Protection Controls the browser's XSS filtering and blocking. Example: 1; mode=block
Public-Key-Pins Public Key Pinning HTTP header for HTTP Public Key Pinning (HPKP), a security mechanism used to prevent man-in-the-middle attacks. Example: pin-sha256="base64+primarykey"; pin-sha256="base64+backupkey"; max-age=expireTime

These response headers may vary in actual HTTP responses; the specific values depend on the server's configuration and processing logic.

Other Extensions