What is an Access-Control-Request-Headers header?
Sent in a CORS preflight request to tell the server which headers the actual request will include.
Alongside Access-Control-Request-Method, this header lists the custom headers (like Authorization or a custom API key header) that the actual cross-origin request plans to send, so the server's preflight response can explicitly allow them. Getting CORS configuration wrong here is a classic cause of 'it works on the server but not in the browser' bug reports, and it's worth including a real preflight check in your website's uptime monitoring if third-party or cross-origin clients depend on the API.
Common use case
A frontend hosted on a different origin than its API sends a custom X-API-Version header, and the browser lists it here during preflight so the server can explicitly allow it.
Example
Access-Control-Request-Headers: content-type, x-api-versionHistory
Defined as part of the CORS specification, standardised by the W3C starting around 2014.
Did you know?
It is always auto-generated by the browser from the actual request you're about to send - there's no way for application code to set it directly.