What is an Access-Control-Allow-Headers header?
Lists which headers are allowed in the actual request when making a cross-origin request.
This header lists which custom request headers a website's CORS policy will accept from a cross-origin client, mirroring the Access-Control-Request-Headers sent in the preflight. A very common real-world bug is adding a new custom header (an API version header, say) to a frontend without updating this list server-side, which breaks every cross-origin request using it while leaving same-origin requests completely unaffected.
Common use case
After a frontend team adds a new custom Authorization or X-API-Key header to their requests, the backend team must add it to Access-Control-Allow-Headers or every cross-origin call silently starts failing preflight.
Example
Access-Control-Allow-Headers: Content-Type, AuthorizationHistory
Defined as part of the CORS specification, standardised by the W3C starting around 2014.
Did you know?
A handful of headers (Accept, Accept-Language, Content-Language, and simple Content-Type values) are always allowed and never need to be listed here, since they're considered CORS-safelisted by default.