What is an Allow header?
Lists the HTTP methods supported by a resource, typically sent with a 405 Method Not Allowed response.
Allow lists exactly which HTTP methods a given endpoint on a website supports, most commonly seen accompanying a 405 Method Not Allowed response so the client knows what it should have sent instead. It's a small but genuinely helpful piece of self-documentation that well-built APIs include, making a misbehaving client's mistake obvious instead of leaving it to guess.
Common use case
A client that mistakenly sends a DELETE to a read-only endpoint gets back a 405 along with Allow: GET, HEAD, telling it exactly which methods it should have tried instead.
Example
Allow: GET, POST, HEAD, OPTIONSHistory
Part of the original HTTP/1.0 specification, RFC 1945 (1996).
Did you know?
It's the one header the HTTP spec explicitly requires on every 405 Method Not Allowed response - a server that omits it is technically non-compliant, even though many do anyway.