What is an X-Requested-With header?
Historically used to identify an AJAX request, e.g. XMLHttpRequest, though the Fetch API often omits it.
X-Requested-With used to be the reliable way for a website's server to tell a JavaScript-driven AJAX request apart from a normal page navigation, back when XMLHttpRequest set it automatically. The modern Fetch API doesn't add it by default, so any server-side logic still branching on this header - including a subset of older CSRF protections that used it as a signal - is worth double-checking still works as intended.
Common use case
Older server-side frameworks branch on X-Requested-With to decide whether to return a full HTML page for a normal navigation or a partial HTML/JSON fragment for an AJAX call.
Example
X-Requested-With: XMLHttpRequestHistory
An informal convention popularised by early JavaScript frameworks like Prototype and jQuery in the mid-2000s, never part of an official HTTP standard.
Deprecated / legacy status
Effectively deprecated in practice since the Fetch API, now the standard way to make requests in JavaScript, doesn't set it automatically the way XMLHttpRequest did - code relying on it for CSRF protection or AJAX detection needs to add it explicitly.