← All headersRequest header

What is an Access-Control-Request-Headers header?

Sent in a CORS preflight request to tell the server which headers the actual request will include.

Alongside Access-Control-Request-Method, this header lists the custom headers (like Authorization or a custom API key header) that the actual cross-origin request plans to send, so the server's preflight response can explicitly allow them. Getting CORS configuration wrong here is a classic cause of 'it works on the server but not in the browser' bug reports, and it's worth including a real preflight check in your website's uptime monitoring if third-party or cross-origin clients depend on the API.

Common use case

A frontend hosted on a different origin than its API sends a custom X-API-Version header, and the browser lists it here during preflight so the server can explicitly allow it.

Example

Access-Control-Request-Headers: content-type, x-api-version

History

Defined as part of the CORS specification, standardised by the W3C starting around 2014.

Did you know?

It is always auto-generated by the browser from the actual request you're about to send - there's no way for application code to set it directly.