← All headersRequest header

What is an Origin header?

Identifies the origin (scheme, host, port) that initiated a cross-origin request, used by CORS.

Origin tells a website's server exactly which site (scheme, host, and port) a cross-origin request is coming from, and it's the header the server's CORS logic inspects to decide whether to allow the request at all. A website that gets CORS handling wrong here either blocks legitimate cross-origin clients or, more dangerously, ends up allowing origins it never meant to trust - both worth testing explicitly rather than assuming same-origin checks cover it.

Common use case

An API checks the incoming Origin header against an allowlist of approved frontend domains before deciding whether to include a matching Access-Control-Allow-Origin in its response.

Example

Origin: https://app.example.com

History

Standardised as part of the CORS specification and RFC 6454 (2011), building on earlier same-origin-policy concepts.

Did you know?

Unlike Referer, Origin never includes a path or query string - by design, it only ever reveals the scheme, host, and port, nothing about which specific page made the request.