What is an Access-Control-Request-Method header?
Sent in a CORS preflight request to tell the server which HTTP method the actual request will use.
This header only ever appears on a CORS preflight OPTIONS request, telling the server which method (PUT, DELETE, etc.) the real follow-up request intends to use so the server can decide whether to allow it. A website's API that mishandles preflight requests will work fine when tested directly but fail silently for browser-based clients on a different origin - a gap that a monitor checking only same-origin requests won't catch.
Common use case
A browser automatically sends this ahead of a cross-origin DELETE or PUT request, letting the server's CORS policy approve or reject the method before the real request is ever made.
Example
Access-Control-Request-Method: DELETEHistory
Defined as part of the Fetch and CORS specifications, standardised by the W3C/WHATWG starting around 2014.
Did you know?
It only ever appears on the automatic OPTIONS preflight the browser sends - no JavaScript API lets a developer set it directly, since the browser controls the entire preflight process itself.