What is an Origin header?
Identifies the origin (scheme, host, port) that initiated a cross-origin request, used by CORS.
Origin tells a website's server exactly which site (scheme, host, and port) a cross-origin request is coming from, and it's the header the server's CORS logic inspects to decide whether to allow the request at all. A website that gets CORS handling wrong here either blocks legitimate cross-origin clients or, more dangerously, ends up allowing origins it never meant to trust - both worth testing explicitly rather than assuming same-origin checks cover it.
Common use case
An API checks the incoming Origin header against an allowlist of approved frontend domains before deciding whether to include a matching Access-Control-Allow-Origin in its response.
Example
Origin: https://app.example.comHistory
Standardised as part of the CORS specification and RFC 6454 (2011), building on earlier same-origin-policy concepts.
Did you know?
Unlike Referer, Origin never includes a path or query string - by design, it only ever reveals the scheme, host, and port, nothing about which specific page made the request.