What is a Content-Disposition header?
Suggests how the browser should handle the response - inline, or as a download with a given filename.
Content-Disposition is what decides whether a website's response opens directly in the browser or triggers a file download dialog, and when set to attachment, it also lets the server suggest a filename for the saved file. Getting this wrong on something like an invoice or report endpoint is a small but genuinely annoying user experience bug - visitors expecting a download instead get a wall of raw text rendered in the browser tab.
Common use case
An invoice download endpoint sets Content-Disposition: attachment; filename="invoice-482.pdf" so clicking the link triggers a save dialog with a sensible filename instead of rendering the PDF inline.
Example
Content-Disposition: attachment; filename="report.csv"History
Originally defined for MIME email in RFC 1806 (1995), adapted for HTTP responses in RFC 2183 and later RFC 6266 (2011).
Did you know?
It also has a role in file upload forms, appearing on each part of a multipart/form-data request body to identify which form field and, for file inputs, original filename each chunk belongs to.