← All headersResponse header

What is an Access-Control-Expose-Headers header?

Lists which response headers a cross-origin script is allowed to access, beyond the small CORS-safelisted set.

By default, a cross-origin script can only read a small safelisted set of response headers - Access-Control-Expose-Headers is how a website explicitly opts additional ones in, like a custom rate-limit or pagination header an API client needs to read. Forgetting to expose a header your frontend actually depends on is a classic 'works when I curl it, breaks in the browser' bug.

Common use case

An API that returns pagination info via a custom X-Total-Count header must explicitly list it in Access-Control-Expose-Headers, or a cross-origin JavaScript client will be unable to read it even though the response includes it.

Example

Access-Control-Expose-Headers: X-Total-Count, X-RateLimit-Remaining

History

Defined as part of the CORS specification, standardised by the W3C starting around 2014.

Did you know?

The CORS-safelisted headers this exists to go beyond are a short, fixed list - Content-Type, Content-Length, and a handful of others - that browsers always expose regardless of this header.