HTTP Headers: Negotiation, Auth & Caching
HTTP Headers are key-value metadata pairs included in both HTTP Requests and HTTP Responses. Headers communicate critical operational context: data representation formats, client identity, authorization credentials, caching policies, cookies, and browser security restrictions.
Headers follow the case-insensitive format Header-Name: value.
┌─────────────────────────────────────────────────────────────┐
│ Core HTTP Headers by Category │
├───────────────┬─────────────────────────────────────────────┤
│ Representation│ Content-Type, Accept, Content-Length, │
│ │ Content-Encoding (gzip, br) │
├───────────────┼─────────────────────────────────────────────┤
│ Authentication│ Authorization (Bearer <JWT>, Basic <base64>)│
├───────────────┼─────────────────────────────────────────────┤
│ State/Cookies │ Cookie, Set-Cookie (HttpOnly, Secure) │
├───────────────┼─────────────────────────────────────────────┤
│ Caching │ Cache-Control, ETag, If-None-Match, Expires │
├───────────────┼─────────────────────────────────────────────┤
│ Context/Sec │ Origin, Referer, User-Agent, Host, CSP │
└───────────────┴─────────────────────────────────────────────┘
1. Content Negotiation Headers
Content negotiation allows the client and server to agree on the optimal data format:
Content-Type: Informs the recipient of the media type of the sent payload.application/json: Standard JSON document.multipart/form-data: Binary file uploads.application/x-www-form-urlencoded: HTML form submissions.
Accept: Informs the server what media types the client understands:Accept: application/json, text/plain, */*
2. Authentication & Authorization Headers
Authorization: Bearer <token>: Transmits a JSON Web Token (JWT) or OAuth 2.0 access token to authenticate API requests.Authorization: Basic <base64-credentials>: Transmits base64-encodedusername:passwordpairs.
3. Caching Control Headers
Cache-Control: Dictates caching behavior across browsers, CDNs, and proxies:max-age=3600: Cache response for 1 hour (3600 seconds).no-cache: Must revalidate with server before serving cached copy.no-store: Never store response in any cache (confidential banking data).public/private: Allow CDN caching vs browser-only caching.
ETag: A unique fingerprint hash of the resource returned by the server.If-None-Match: "<hash>": Client passes cached ETag to server. If unchanged, server returns304 Not Modified.
4. Origin & Referrer Headers
Origin: Informs the server of the scheme, host, and port where the request originated (Origin: https://front-heaven.com). Used in CORS evaluation.Referer: The full URL of the preceding web page from which the link was followed.
Summary & Key Takeaways
- Headers communicate metadata for content negotiation, auth, caching, and security.
Content-Typedescribes the sent payload;Acceptrequests the desired return format.Authorization: Bearer <token>is the enterprise standard for API authentication.Cache-ControlandETagprevent redundant network transmissions.
Best Practices & Senior Guidance
- Always Set
Content-Type: application/jsonon POST/PUT: Failing to setContent-Typeoften causes backend body parsers to ignore JSON payloads. - Never Transmit Passwords in Custom Headers: Transmit credentials in standard
Authorizationheaders over HTTPS.