What is an Upgrade-Insecure-Requests header?
Signals that the client prefers an encrypted, authenticated response and will follow an upgrade to HTTPS.
Upgrade-Insecure-Requests is a browser telling a website 'if you have an HTTPS version of this page, please send me that instead', which supports a smoother migration path from HTTP to HTTPS without breaking old bookmarked links. Most modern websites are HTTPS-only anyway, but it's a useful signal to check for if you're auditing a site that still serves any content over plain HTTP.
Common use case
A site midway through migrating from HTTP to HTTPS uses this header to automatically upgrade requests from browsers that support it, without needing a separate hard redirect rule for every URL.
Example
Upgrade-Insecure-Requests: 1History
Standardised by the W3C as part of the Mixed Content and Upgrade Insecure Requests specifications, around 2015.
Did you know?
It's sent automatically by every modern browser on every navigation request - there's no user-facing setting for it, it just quietly signals a general browser-wide preference for HTTPS.