Access-Control-Allow-Headers

HTTP response header

The Access-Control-Allow-Headers response header is used in response to a preflight request which includes the Access-Control-Request-Headers to indicate which HTTP headers can be used during the actual request. This header is required if the request has an Access-Control-Request-Headers header

Header usage statistics

Access-Control-Allow-Headers response header information and usage statistics.
Websites using header Access-Control-Allow-Headers553,405
Percentage of websites that use Access-Control-Allow-Headers header0.91%
Total discovered header valuesMore than 10,000
Header uses directivesYes
Header values are unique or randomNo
Most popular in the country United States

Access-Control-Allow-Headers directives (18 total)

  • *
  • accept
  • access_token
  • authorization
  • cache-control
  • client-security-token
  • content-type
  • dnt
  • if-modified-since
  • keep-alive
  • origin
  • soapaction
  • typeform-version
  • user-agent
  • x-accept-charset
  • x-customheader
  • x-requested-with
  • x-typeform-key

Access-Control-Allow-Headers Directives

Access-Control-Allow-Headers directives value information and usage statistics
DirectiveShareWebsites countUnique Values
content-type78.32%433,4062
x-requested-with49.27%272,6811
authorization41.63%230,3892
origin31.68%175,3111
accept27.01%149,4701
cache-control13.11%72,5441
user-agent12.58%69,6451
*11.94%66,0741
if-modified-since11.22%62,1161
dnt10.01%55,4151
keep-alive7.10%39,2761
x-customheader3.61%19,9551
client-security-token1.72%9,5311
x-accept-charset1.43%7,9351
soapaction0.40%2,1951
typeform-version0.37%2,0321
x-typeform-key0.37%2,0321
access_tokenless than 0.1%3521

Connected technologies

Technologies that utilize the header
Ckan, category Content Management System, total 432 websites
Tealeaf, category Analytics, total 414 websites

Websites utilizing Access-Control-Allow-Headers

List of websites that use Access-Control-Allow-Headers header
DomainCountryRankContacts
static.parastorage.com United States31
siteassets.parastorage.com United States34
player.vimeo.com United States51
schema.org United States64
nytimes.com United States77
unpkg.com United States96
See full domain list

Common header values

List of top common Access-Control-Allow-Headers header values
Header valueValue prevalence
Content-Type, Authorization13%
*11%
origin, x-requested-with, content-type8%
Content-Type7%
Origin, X-Requested-With, Content-Type, Accept3%
X-Requested-With2%
accept, x-request, x-requested-with2%
Origin, X-Requested-With, Content-Type, Accept, Authorization2%
DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range1%
X-Accept-Charset,X-Accept,Content-Type1%
x-sap-service1%
Content-Type, Authorization, X-Requested-With1%
X-Requested-With,content-type1%
DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type1%
Content-Type,Accept1%
Origin,Content-Type,Accept,User-Agent,Cookie,Authorization,X-Auth-Token,X-Requested-With1%
Authorization, Content-Type1%
x-requested-with, Content-Type, origin, authorization, accept, client-security-token0%
DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization0%
Content-Type, Authorization, Accept, X-Requested-With0%