← All headersRequest header

What is an Access-Control-Request-Method header?

Sent in a CORS preflight request to tell the server which HTTP method the actual request will use.

This header only ever appears on a CORS preflight OPTIONS request, telling the server which method (PUT, DELETE, etc.) the real follow-up request intends to use so the server can decide whether to allow it. A website's API that mishandles preflight requests will work fine when tested directly but fail silently for browser-based clients on a different origin - a gap that a monitor checking only same-origin requests won't catch.

Common use case

A browser automatically sends this ahead of a cross-origin DELETE or PUT request, letting the server's CORS policy approve or reject the method before the real request is ever made.

Example

Access-Control-Request-Method: DELETE

History

Defined as part of the Fetch and CORS specifications, standardised by the W3C/WHATWG starting around 2014.

Did you know?

It only ever appears on the automatic OPTIONS preflight the browser sends - no JavaScript API lets a developer set it directly, since the browser controls the entire preflight process itself.