← All headersRequest header

What is an X-Forwarded-Proto header?

Identifies the original protocol (http or https) the client used before reaching a proxy that terminated TLS.

X-Forwarded-Proto tells a website's origin server whether the visitor's original connection was HTTP or HTTPS, which matters a lot when a proxy or load balancer terminates TLS and then talks to the origin over plain HTTP internally. Get this wrong and a site can end up in an infinite HTTPS-to-HTTPS redirect loop, or worse, silently accept insecure connections it thinks are already secure - both worth catching with an uptime monitor that actually follows redirect chains rather than stopping at the first response.

Common use case

An origin server behind a load balancer that terminates TLS checks X-Forwarded-Proto to decide whether to issue a redirect to HTTPS, avoiding an infinite redirect loop it would hit if it only looked at its own (always-HTTP) connection.

Example

X-Forwarded-Proto: https

History

An informal convention, part of the same family as the other X-Forwarded-* headers, never formally standardised outside of the newer Forwarded header.

Did you know?

It's one of the most common causes of a subtle production-only bug: an app that works fine locally over plain HTTP can end up in an infinite redirect loop in production purely because this one header was never configured on the load balancer.