# HTTP header reference — no upload

> A searchable reference of HTTP request and response headers with their purpose and typical values. Runs in your browser, nothing fetched.

Look up HTTP request and response headers — from Content-Type to Cache-Control — with what each does and common values. It's a built-in reference with nothing fetched.

Headers carry the metadata that makes HTTP work — content type, caching, auth, CORS. Knowing which header does what turns vague bugs (a resource won't cache, a request is blocked) into quick fixes.

For security-specific headers with recommended values, use the security header builder; to inspect live responses, use the HTTP client.

## How to

1. **Search a header.** Type a header name or keyword.
2. **Read its role.** See its purpose and typical values.
3. **Use it.** Apply the right header in your requests or responses.

## FAQ

### What does Cache-Control do?

It tells browsers and CDNs how long and under what conditions to cache a response — directives like max-age, no-store, and private control caching behavior precisely.

### Which headers matter for CORS?

The Access-Control-Allow-* family on responses, plus Origin on requests, govern cross-origin access. The reference explains each one's role.

### Is anything fetched?

No. The reference is built in, so it works offline.


## Related tools

- [Security headers](https://www.safepaper.app/dev/security-headers)
- [HTTP status codes](https://www.safepaper.app/dev/http-status-codes)
- [HTTP client](https://www.safepaper.app/dev/http-client)
- [MIME types](https://www.safepaper.app/dev/mime-types)

---

Canonical HTML: https://www.safepaper.app/dev/http-headers
Markdown: https://www.safepaper.app/dev/http-headers.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
