Header category
CORS
The cross-origin negotiation. A small, closed set of headers that decide whether a browser is allowed to see a response it already received.
13 headers
92 provider declarations
| Header | Providers | Status | |
|---|---|---|---|
| Access-Control-Allow-Origin | 30 | permanent | regulated |
| Access-Control-Allow-Headers | 16 | permanent | |
| Access-Control-Allow-Methods | 16 | permanent | |
| Origin | 14 | permanent | |
| Access-Control-Allow-Credentials | 11 | permanent | |
| Access-Control-Expose-Headers | 4 | permanent | |
| Access-Control-Max-Age | 1 | permanent | |
| Access-Control-Request-Headers | — | permanent | |
| Access-Control-Request-Method | — | permanent | |
| Method-Check | — | obsoleted | |
| Method-Check-Expires | — | obsoleted | |
| Timing-Allow-Origin | — | provisional | |
| Access-Control | — | obsoleted |
All categories
Authentication Authorization & Scope Caching Conditional Requests & Concurrency Content Negotiation Representation Metadata Connection & Transport CORS Security Policy Privacy & Consent Rate Limiting & Quota Tracing & Correlation Idempotency & Reliability Versioning & Lifecycle Integrity & Signing Async & Long-Running Cost & Metering Agent & Bot Identity