Access-Control-Allow-Headers

HTTP response header

The Access-Control-Allow-Headers response header is used in response to a preflight request which includes the Access-Control-Request-Headers to indicate which HTTP headers can be used during the actual request. This header is required if the request has an Access-Control-Request-Headers header

Header usage statistics

Access-Control-Allow-Headers response header information and usage statistics.
Websites using header Access-Control-Allow-Headers530,291
Percentage of websites that use Access-Control-Allow-Headers header0.84%
Total discovered header valuesMore than 10,000
Header uses directivesYes
Header values are unique or randomNo
Most popular in the country United States

Access-Control-Allow-Headers directives (18 total)

  • *
  • accept
  • access_token
  • authorization
  • cache-control
  • client-security-token
  • content-type
  • dnt
  • if-modified-since
  • keep-alive
  • origin
  • soapaction
  • typeform-version
  • user-agent
  • x-accept-charset
  • x-customheader
  • x-requested-with
  • x-typeform-key

Access-Control-Allow-Headers Directives

Access-Control-Allow-Headers directives value information and usage statistics
DirectiveShareWebsites countUnique Values
content-type78.91%418,4652
x-requested-with53.55%283,9741
authorization37.78%200,3662
origin35.24%186,8771
accept28.79%152,6741
cache-control13.59%72,0461
user-agent12.96%68,7411
*12.35%65,4691
if-modified-since12.19%64,6271
dnt10.28%54,5271
keep-alive7.10%37,6301
x-customheader3.34%17,7211
client-security-token2.05%10,8521
x-accept-charset1.02%5,3981
soapaction0.96%5,0991
typeform-version0.38%2,0311
x-typeform-key0.38%2,0311
access_token<0.1%3901

Connected technologies

Technologies that utilize the header
Tealeaf, category Analytics, total 551 websites
Ckan, category Content Management System, total 492 websites

Websites utilizing Access-Control-Allow-Headers

List of websites that use Access-Control-Allow-Headers header
DomainCountryRankContacts
static.parastorage.com United States31
siteassets.parastorage.com United States34
player.vimeo.com United States51
schema.org United States64
namecheap.com United States112
support.apple.com United States131
See full domain list

Common header values

List of top common Access-Control-Allow-Headers header values
Header valueValue prevalence
*11.53%
origin, x-requested-with, content-type9.86%
Content-Type, Authorization8.62%
content-type7.98%
Origin, X-Requested-With, Content-Type, Accept4.11%
X-Requested-With2.85%
Origin, X-Requested-With, Content-Type, Accept, Authorization2.05%
DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range2.01%
accept, x-request, x-requested-with1.92%
x-requested-with,content-type1.63%
DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type1.38%
Content-Type,Accept1.26%
Origin,Content-Type,Accept,User-Agent,Cookie,Authorization,X-Auth-Token,X-Requested-With1.19%
x-requested-with, Content-Type, origin, authorization, accept, client-security-token1.13%
Authorization, Content-Type1.03%
Content-Type, Authorization, X-Requested-With1.03%
X-Accept-Charset,X-Accept,Content-Type0.88%
Content-Type, soapaction0.80%
Content-Type, Authorization, Accept, X-Requested-With0.75%
Origin, Authorization, Content-Type0.65%