| Accept | Request | Media types the client can accept. |
| Accept-Encoding | Request | Content codings such as gzip or br accepted by the client. |
| Authorization | Request | Credentials for authenticating the request. |
| Cache-Control | Both | Caching directives for requests or responses. |
| Content-Type | Both | Media type of the message body. |
| Content-Length | Both | Body size in bytes when known. |
| Cookie | Request | Cookies sent by the client. |
| Host | Request | Target host and optional port. |
| If-None-Match | Request | Conditional request using an ETag. |
| Origin | Request | Origin that initiated a CORS request. |
| Referer | Request | Referring page URL when supplied. |
| User-Agent | Request | Client software identification string. |
| Access-Control-Allow-Origin | Response | Origins allowed by CORS policy. |
| Content-Disposition | Response | Inline/attachment handling and optional filename. |
| Content-Encoding | Response | Encoding applied to the response body. |
| Content-Security-Policy | Response | Browser content-loading and execution policy. |
| ETag | Response | Validator identifier for a representation. |
| Last-Modified | Response | Last modification timestamp for cache validation. |
| Location | Response | Target URL for redirects or created resources. |
| Referrer-Policy | Response | Controls referrer information sent by browsers. |
| Retry-After | Response | How long a client should wait before retrying. |
| Set-Cookie | Response | Sets or updates browser cookies. |
| Strict-Transport-Security | Response | Forces future HTTPS use by supporting browsers. |
| Vary | Response | Request headers that affect cached response selection. |
| X-Content-Type-Options | Response | Prevents MIME sniffing when set to nosniff. |