HTTP Header Generator
Build and format HTTP request or response headers online, then copy them as raw HTTP, cURL, Fetch, JSON, or server configuration. Free and private — processing stays in your browser.
HTTP header builder
Free and private. Names, values, URLs, and tokens stay in this browser and are not uploaded.
HTTP Header Generator Quick Answer
HTTP headers are name/value fields that travel with an HTTP message. Request headers describe the call: the format the client accepts, the resource it wants, and how it authenticates. Response headers describe what came back: the media type, cache lifetime, redirect target, or cookie.
This HTTP header generator builds either set in your browser and formats it as raw HTTP, a cURL command, a JavaScript Fetch call, a JSON object, or Nginx, Apache, and Node/Express configuration. Header text stays on your device. The page does not upload the URL, tokens, or cookies.
How to Use the HTTP Header Generator
- Choose request or response. Use request headers for an API call. Use response headers for the status line and fields the server sends back.
- Start from a preset or a blank list. Load a REST GET, JSON POST, bearer token, basic auth, CORS, cache, or security example, or clear the list and type your own rows.
- Set the method, URL, or status. Request mode needs the method and URL. Response mode needs the status code and reason phrase.
- Add header names and values. Search a common header or type a custom name. The page flags invalid characters, line breaks, and duplicate names before you copy.
- Copy or download a format. Switch between raw HTTP, cURL, Fetch, JSON, Nginx, Apache, and Node. The output updates as you type.
HTTP Request Headers vs Response Headers
A request header is sent by the client. Accept: application/json tells the server the client can read JSON. Authorization carries a credential. A response header is sent by the server with the status line. Content-Type: application/json names the body. Location gives a redirect URL. Cache-Control tells caches how long they may reuse the response.
The same name can do a different job on each side. Content-Type on a request describes the body you are sending. Content-Type on a response describes the body you received. Build the request in this tool, then use the URL Builder if the path and query string still need work.
Common HTTP Headers
These are the fields people add most often. A name in this table is not required, and a custom name is valid when it uses HTTP token characters.
| Header | Type | Purpose | Example |
|---|---|---|---|
| Authorization | Request | Sends credentials such as a bearer token or basic auth. | Bearer example-token |
| Content-Type | Request and response | Names the media type of the body. | application/json |
| Accept | Request | Lists media types the client can handle. | application/json |
| User-Agent | Request | Identifies the client software. | EverydayToolsHeaderExample/1.0 |
| Cache-Control | Request and response | Tells caches whether to store the message and for how long. | public, max-age=3600 |
| Origin | Request | States the origin of a browser request. | https://app.example.com |
| Referer | Request | States the page that started the request. | https://app.example.com/docs |
| ETag | Response | Identifies one representation for conditional requests. | "example-etag" |
| Location | Response | Gives a redirect target or the URL of a new resource. | https://api.example.com/v1/items/42 |
| Vary | Response | Names request headers that change the representation. | Accept-Encoding |
| Access-Control-Allow-Origin | Response | Names the origin allowed to read the response in a browser. | https://app.example.com |
| X-Content-Type-Options | Response | Tells browsers not to MIME-sniff the body. | nosniff |
| X-Frame-Options | Response | Controls whether the page may be framed. | DENY |
HTTP Header Examples
REST API request
A GET that asks for JSON. Use it when you need an HTTP request headers example for a read endpoint.
GET /v1/items HTTP/1.1
Accept: application/json
Accept-Language: en-US,en;q=0.9
User-Agent: EverydayToolsHeaderExample/1.0
JSON POST request
Content-Type names the JSON body you send. Accept names the JSON you want back.
POST /v1/items HTTP/1.1
Content-Type: application/json
Accept: application/json
DELETE request
A delete call still sends Accept so an error body comes back as JSON.
DELETE /v1/items/42 HTTP/1.1
Accept: application/json
Bearer authorization
The token below is the placeholder example-token, not a live credential.
GET /v1/profile HTTP/1.1
Authorization: Bearer example-token
Accept: application/json
Basic authentication
The Basic value is base64 of the placeholder username:password. It is not a real account.
GET /v1/account HTTP/1.1
Authorization: Basic dXNlcm5hbWU6cGFzc3dvcmQ=
Accept: application/json
CORS response
A single allowed origin plus the methods and request headers a preflight often needs. Build a full policy in the CORS Header Generator.
HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://app.example.com
Access-Control-Allow-Methods: GET, POST, OPTIONS
Access-Control-Allow-Headers: Content-Type, Authorization
Vary: Origin
Cache-Control response
A public response that caches for one hour, with an example ETag and Vary so compressed and uncompressed copies stay separate.
HTTP/1.1 200 OK
Cache-Control: public, max-age=3600
ETag: "example-etag"
Vary: Accept-Encoding
Security response headers
A short baseline for HTTPS, framing, sniffing, and a default-src policy. Test it on your app before you enforce it.
HTTP/1.1 200 OK
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Referrer-Policy: strict-origin-when-cross-origin
Content-Security-Policy: default-src 'self'
Permissions-Policy: camera=(), microphone=(), geolocation=()
How HTTP Header Generation Works
- You choose request or response. That decides whether the output starts with a request line or a status line, and which server syntax is valid.
- You pick a header name from the library or type a custom name, then enter the value as it should appear.
- The page checks the name against HTTP token rules, rejects line breaks in values, and flags duplicate names. Set-Cookie stays as separate headers.
- Valid rows become an ordered list. Values are not rewritten, trimmed, or merged.
- That list is rendered as raw HTTP, cURL, Fetch, JSON, Nginx, Apache, or Express. Switching format does not change the headers. To turn an existing cURL command into fetch code, use the cURL to Fetch Converter.
Common HTTP Header Mistakes
- Putting a response field such as Location or Set-Cookie on a request, or a request field such as Authorization on a response, without meaning to.
- Using a space or other character that HTTP does not allow in a header name.
- Repeating a name and assuming every server will keep both values.
- Pasting a live API token into a doc, ticket, or screenshot. Generate a throwaway value with the API Key Generator when you only need a realistic placeholder.
- Assuming browser fetch() can set Cookie, Host, Origin, Content-Length, or Sec-* headers. The snippet is still useful from Node.
- Treating one Access-Control-Allow-Origin line as a complete CORS policy. Credentials, preflight, and multiple origins belong in the CORS Header Generator.
- Joining several Set-Cookie values with commas. Use the Cookie Parser when you need to inspect each cookie.
- Pasting a Nginx or Express snippet into a different stack without checking that server’s header syntax.
Different Ways People Search for HTTP Headers
Some people search for an HTTP header generator, an HTTP headers generator, or an HTTP header builder. Others want a request header generator for an API call, a response header generator for a status line, or an API header generator for Authorization and Content-Type. The same task shows up as custom HTTP headers, generate headers for cURL, generate headers for Fetch, or an HTTP request headers example to paste into docs. This page covers that job: build the fields, check the syntax, and copy the format you need. If the JSON body next to those headers is what you need to inspect, use the JSON Formatter or the JSON Validator.
Frequently Asked Questions
What is an HTTP header generator?
An HTTP header generator builds the name/value fields that go with an HTTP request or response and formats them for cURL, Fetch, JSON, or a server config file. This one runs in your browser and does not send the request for you.
What is the difference between request and response headers?
Request headers travel from the client to the server. They cover preferences such as Accept, credentials such as Authorization, and context such as Origin. Response headers travel back with the status line. They cover the body type, caching, redirects, cookies, and browser security policy.
Can I generate HTTP request headers for an API?
Yes. Choose Request Headers, set the method and URL, and add fields such as Accept, Content-Type, Authorization, or a custom name such as X-API-Key. Copy the result as raw HTTP, cURL, Fetch, or JSON.
Can I generate cURL headers?
Yes. The cURL tab writes a command with the URL, -X when the method is not GET, and one -H flag per header. Values are single-quoted for POSIX shells such as macOS, Linux, and Git Bash.
Can I generate Fetch headers?
Yes. The Fetch tab writes a fetch() call whose headers object uses your names and values. If a header is controlled by the browser, the page warns you and still shows the snippet.
Can I generate response headers?
Yes. Choose Response Headers, set the status code and reason phrase, then add fields such as Content-Type, Cache-Control, Location, or Set-Cookie. Copy raw HTTP, JSON, Nginx, Apache, or Express.
Can I add custom HTTP headers?
Yes. Type any name that follows HTTP token rules, including names such as X-Request-ID. The library is a shortcut for common names, not a limit.
Does the generator send requests to a server?
No. It only formats headers on this page. Your URL, tokens, cookies, and header values are not uploaded to EverydayTools.
Can I use Authorization headers safely in this tool?
You can draft them locally. Keep production tokens out of screenshots and shared docs. The share button replaces Authorization, Cookie, Set-Cookie, and API key values before it creates the link.
Why can't some headers be set from browser JavaScript?
The Fetch standard marks some names as forbidden header names, so a page cannot override browser-controlled fields such as Cookie, Host, Origin, Content-Length, or Sec-* headers. The Fetch snippet still includes them so you can reuse it from a server-side client. User-Agent is not on that forbidden list, though a browser may still ignore an override.
What is the difference between Content-Type and Accept?
Content-Type names the media type of the body that is present. On a request it describes what you are sending. On a response it describes what came back. Accept is a request header that lists the media types the client is willing to receive.
Can HTTP headers be duplicated?
A message can contain the same field name more than once. For most names, servers and intermediaries may combine the values or keep one of them, so this page warns you. Set-Cookie is different: each Set-Cookie stays on its own line and is not merged.
Should I use CORS or security headers here?
You can add a few CORS or security headers as examples. For a full Access-Control policy, including preflight and credentials, use the CORS Header Generator. This page is not a dedicated content-security-policy builder or an API key generator.
Does the tool validate server compatibility?
No. It checks header-name syntax, line breaks, and duplicates. It does not connect to your server, CDN, or framework, and a copied Nginx or Express snippet can still need changes for that stack.
Related Developer Tools
Pair the headers with a mock body in the API Mock Generator, or browse the rest of the developer tools.
- CORS Header Generator
Access-Control-Allow-Origin, methods, credentials, and preflight headers.
- cURL to Fetch Converter
Turn a finished cURL command into a JavaScript fetch() call.
- API Mock Generator
Put a status code and these headers next to a JSON body.
- API Key Generator
Create a random key locally, then place it in X-API-Key or Authorization.
- JSON Formatter
Format the JSON body that travels with Content-Type.
- URL Builder
Build the request URL, including query parameters.