Skip to content

Instantly share code, notes, and snippets.

@sesh
Created December 6, 2021 01:35
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save sesh/92cc960b67a51fe87fc3f76197cdfc5c to your computer and use it in GitHub Desktop.
Save sesh/92cc960b67a51fe87fc3f76197cdfc5c to your computer and use it in GitHub Desktop.
List of unique header keys
accept-ch
accept-ch-lifetime
accept-encoding
accept-ranges
access-control-allow-credentials
access-control-allow-everything
access-control-allow-headers
access-control-allow-methods
access-control-allow-origin
access-control-expose-headers
access-control-max-age
access-control-request-headers
access-control-request-method
aclu-req-hosts
age
akamai-cache-status
allow
alt-srv
alt-svc
amo-request-id
apigw-requestid
apple-news-services-handled
apple-news-services-host
apple-news-services-parsed-url
apple-news-services-request-url
application
authorization
backend
belfrage-cache-status
bid
branch
brequestid
browser-expires
bsig
build
cache-control
cache-hit
cache-tag
cache-tags
caf
canary
cdn-cache
cdn-cache-control
cdn-cachedat
cdn-caching-enabled
cdn-edgestorageid
cdn-proxyver
cdn-pullzone
cdn-requestcountrycode
cdn-requestid
cdn-requestpullcode
cdn-requestpullsuccess
cdn-status
cdn-uid
cdnuuid
cf-apo-via
cf-cache-status
cf-chl-bypass
cf-debug
cf-edge-cache
cf-ray
charset
connection
content-disposition
content-encoding
content-language
content-length
content-location
content-md5
content-modified
content-security-policy
content-security-policy-report-only
content-type
content-type-options
cross-origin-embedder-policy
cross-origin-embedder-policy-report-only
cross-origin-opener-policy
cross-origin-opener-policy-report-only
cross-origin-resource-policy
cross-origin-window-policy
date
di_verbos
discourse-proxy-id
display
document-policy
eagleeye-traceid
edge-cache-tag
edge-control
elastic-vi
environment
etag
expect-ct
expires
expiry
fastcgi-cache
fastly-debug-states
fastly-restarts
fastly-sie
fastly-swr
feature-policy
fly-request-id
fly-served-from
front-end-https
function-execution-id
gannett-cam-experience-id
geoip-city
geoip-countryname
geoip-latitude
geoip-postalcode
ghost-age
ghost-cache
ghost-fastly
grace
hello
host
host-header
host-sni
hummingbird-cache
id
if-none-match
keep-alive
last-modified
last-updatedl
link
location
mime-version
ms-cv
nar-site
nel
nvidia_language
nvidia_region
onion-location
origin
origin-agent-cluster
ot-requestid
p3-content-language
p3p
pagespeed
payment
permissions-policy
permissions_policy
pragma
pressidium-rid
priority
product
public-key-pins
public-key-pins-report-only
pw_value
referrer-policy
refresh
remote_server_name
replit-cluster
report-to
req-svc-chain
request-context
request-limit
response
response-time
retry-after
rh_cmdb
rqid
sbgi-protocol
sbgi-realpath
sbgi-rendertime
served-by
server
server-ip
server-timing
serverid
service-worker-allowed
servus-and-hello
session
set-cookie
slash_log_data
smug-cdn
sniply-options
sp-trace-id
spotify-request-id
srv
state
status
strict-transport-security
superexpress
surge-cache
surge-stamp
surrogate-control
surrogate-key
t-request-id
tcn
timing-allow-origin
tpic
traceparent
transaction-id
transfer-encoding
tt-server
uber-trace-id
upgrade
upgrade-insecure-requests
user-cache-control
user-type
v-cache-ttl
v5requestid
v5router
vary
verso
via
vice-trace-id
wpo-cache-status
x-4fna
x-4vcta
x-77-cache
x-77-nzt
x-77-nzt-ray
x-77-pop
x-ac
x-accel-expires
x-accepted-fulllang
x-accepted-language
x-access
x-access-control-allow-origin
x-acquia-host
x-acquia-path
x-acquia-purge-tags
x-acquia-site
x-acs-version
x-activity-id
x-adblock-key
x-adobe-content
x-adobe-loc
x-adobe-source
x-age
x-ah-environment
x-aicache-os
x-akam-sw-version
x-akamai-erpolicy
x-akamai-erruleid
x-akamai-transformed
x-alternate-cache-key
x-amz-apigw-id
x-amz-bucket-region
x-amz-cf-id
x-amz-cf-pop
x-amz-id-1
x-amz-id-2
x-amz-meta-alexa-last-modified
x-amz-meta-cb-modifiedtime
x-amz-meta-content-md5
x-amz-meta-md5_hash
x-amz-meta-mtime
x-amz-meta-s3cmd-attrs
x-amz-replication-status
x-amz-request-id
x-amz-rid
x-amz-server-side-encryption
x-amz-storage-class
x-amz-version-id
x-amzn-remapped-content-length
x-amzn-requestid
x-amzn-trace-id
x-api-version
x-app-id
x-app-server
x-appengine-log-flush-count
x-appversion
x-arr-server
x-aspnet-version
x-aspnetmvc-version
x-authcache-get-key
x-authcache-status
x-auto-login
x-aws-id
x-az
x-azure-ref
x-azure-ref-originshield
x-b3-sampled
x-b3-spanid
x-b3-traceid
x-backend
x-backend-name
x-backend-server
x-backend-ttl
x-batcache-activated
x-battleship
x-bbc-edge-cache-status
x-bbc-origin-response-status
x-bcma
x-be-age
x-best-pony
x-bf-cdn-url
x-bigscoots-cache
x-bigscoots-cache-control
x-block-status
x-blockchain-cp-b
x-blockchain-cp-f
x-blockchain-language
x-blockchain-language-id
x-blockchain-server
x-build
x-build-back-better
x-build-id
x-by
x-cable-cache-id
x-cache
x-cache-aspx
x-cache-control
x-cache-date
x-cache-debug
x-cache-enabled
x-cache-group
x-cache-hit
x-cache-hits
x-cache-info
x-cache-key
x-cache-level
x-cache-lookup
x-cache-npr
x-cache-nxaccel
x-cache-operation
x-cache-rule
x-cache-status
x-cache-svr
x-cacheable
x-cached
x-cached-by
x-cambria-cache-control
x-career
x-cdn
x-cdn-cache-status
x-cdn-fetch
x-cdn-origin
x-cdn-rule
x-cf-worker
x-change-language
x-changelog-vanity-redirect
x-choker
x-cicero-cache
x-city-code
x-clacks-overhead
x-clb-cache
x-clb-hits
x-client-ip
x-cloud-trace-context
x-cluster-name
x-cnection
x-connection-hash
x-container
x-contensis-authorised
x-contensis-groups-authenticated
x-contensis-viewer-groups
x-content-digest
x-content-security-policy
x-content-type
x-content-type-options
x-contextid
x-country
x-country-code
x-country-code-real
x-datacenter
x-datadome
x-datadome-cid
x-dc
x-dc-location
x-debug-auth
x-debug-cache
x-debug-deliver
x-debug-info
x-debug-original-ttl
x-debug-path
x-debug-ttl
x-depends
x-dest
x-developers
x-device
x-device-class
x-device-type
x-diaspora-version
x-discourse-cached
x-discourse-route
x-discourse-trackview
x-dispatcher
x-distributor
x-dns-prefetch-control
x-do-a-kickflip
x-download-options
x-drupal-amp
x-drupal-cache
x-drupal-device
x-drupal-dynamic-cache
x-drupal-ff
x-drupal-mobile
x-drupal-theme
x-drupal-ua-device
x-dump-request-bodies
x-easter-egg
x-ec
x-edge-backend
x-edge-location
x-elasticpress-query
x-element-page-cache
x-endurance-cache-level
x-env
x-envoy-decorator-operation
x-envoy-upstream-service-time
x-epic-correlation-id
x-eps-status
x-eps-time-spend
x-es-on
x-esi
x-ez-minify-html
x-ez-proxy-out
x-ezoic-cdn
x-fasada-cache
x-fastcgi-cache
x-fastly-backend
x-fastly-cache-status
x-fastly-request-id
x-fastly-x-is-cn
x-fastlyttl
x-fb-debug
x-fb-rlafr
x-fe-nginx-backend
x-fe-nginx-host
x-fe-nginx-ip
x-fetched-on
x-fh-no-setcookie-unroll
x-follow-me
x-format
x-forwarded-host
x-forwarded-proto
x-fpfis
x-frame-option
x-frame-options
x-frog-unsafe
x-from-cache
x-frontend-instance
x-frontend-version
x-ftr-backend
x-ftr-backend-server
x-ftr-balancer
x-ftr-buildid
x-ftr-cache-status
x-ftr-expires
x-ftr-request-id
x-ftr-trace
x-fw-dynamic
x-fw-hash
x-fw-serve
x-fw-server
x-fw-static
x-fw-type
x-fw-version
x-gateway-cache-key
x-gateway-cache-status
x-gateway-request-id
x-gateway-skip-cache
x-gdpr
x-gdpr-status
x-gen-mode
x-gender
x-generator
x-geoip
x-geoip-country-code
x-geoip-region-code
x-git-revision
x-git-update
x-github-backend
x-github-request-id
x-goog-generation
x-goog-hash
x-goog-meta-goog-reserved-file-mtime
x-goog-metageneration
x-goog-storage-class
x-goog-stored-content-encoding
x-goog-stored-content-length
x-googlenews-bot
x-grace
x-gu-edition
x-guploader-uploadid
x-gv-cacheability
x-gv-cl
x-gv-cp
x-hacker
x-has-esi
x-head-hash
x-hits
x-hnp-log
x-host
x-hosted-by
x-hostname
x-hp-trace-id
x-hp-webp
x-hs-cache-config
x-hs-cf-cache-status
x-hs-combine-css
x-hs-content-group-id
x-hs-content-id
x-hs-hub-id
x-hs-prerendered
x-html-minification-powered-by
x-httpd
x-httpd-host
x-hw
x-ibm-trace
x-id
x-iinfo
x-index-areacode
x-ipfs-gateway-host
x-ipfs-lb-pop
x-ipfs-path
x-ipfs-pop
x-is-gdpr
x-is-ssl
x-isphp
x-jitsi-region
x-jitsi-shard
x-join-the-band
x-jwt-state
x-ka-cached-trace-id
x-kinja
x-kinja-build
x-kinja-revision
x-kinja-server
x-koken-cache
x-kong-proxy-latency
x-kong-upstream-latency
x-kw-cache-control
x-kw-date
x-kw-expires
x-lambda-id
x-last-commmit-hash
x-latency
x-launchpad-revision
x-lb-nocache
x-li-fabric
x-li-pop
x-li-proto
x-li-uuid
x-lima-id
x-litespeed-cache
x-litespeed-tag
x-lj-flow-id
x-location
x-loop
x-magnolia-registration
x-matched-path
x-maxage
x-middleton-display
x-middleton-response
x-mkt-cache
x-mod-pagespeed
x-mol-georesp
x-moose
x-msedge-ref
x-myvhost
x-na
x-nananana
x-nc
x-neocities-cdn
x-netflix.nfstatus
x-netflix.proxy.execution-time
x-nextjs-page
x-nf-request-id
x-nginx-cache
x-nginx-cache-status
x-nid
x-node
x-nodejs
x-npr-trace-id
x-ns-authorization
x-nubis-build
x-nubis-project
x-nubis-version
x-nym-debug-backend
x-nyt-app-webview
x-nyt-data-last-modified
x-nyt-edge-cache
x-nyt-route
x-occrp-fasada-content
x-olaf
x-oracle-dms-ecid
x-oracle-dms-rid
x-orig-cache-control
x-origin-cache
x-origin-cache-control
x-origin-server
x-origin-time
x-original-host
x-originating-url
x-ot-span-context
x-pad
x-page-cache
x-page-speed
x-page-title
x-pagetype
x-pantheon-styx-hostname
x-pass-why
x-pavatar
x-permitted-cross-domain-policies
x-phapp
x-pingback
x-platform-cluster
x-platform-processor
x-platform-router
x-platform-server
x-pmd-backend
x-pmd-cache
x-postal-code
x-powered
x-powered-by
x-powered-by-plesk
x-presslabs-stats
x-pronouns
x-protected-by
x-provided-by
x-proxy-cache
x-proxy-cache-info
x-proxy-cache-status
x-proxy-host
x-proxy-region
x-public
x-pubstack
x-pw-round-time
x-q-stat
x-qz-test-group
x-rack-cache
x-ratelimit
x-ratelimit-burst-capacity
x-ratelimit-limit
x-ratelimit-remaining
x-ratelimit-replenish-rate
x-ratelimit-requested-tokens
x-ratelimit-reset
x-re-cache
x-readtime
x-rebelmouse-abtests
x-redhat-debug
x-refspec
x-region
x-render-time
x-rendering-stack
x-request-count
x-request-guid
x-request-host
x-request-id
x-resp-is-stale
x-response-time
x-rh-edge-alb-dc
x-rh-edge-cache-status
x-rh-edge-reference-id
x-rh-edge-request-id
x-rid
x-riotgames-cdn
x-rl
x-rm-cache-ttl
x-robots-tag
x-rocket-nginx-serving-static
x-rq
x-rs-ben
x-rs-ben-time
x-rs-ops
x-rs-time
x-rtd-domain
x-rtd-path
x-rtd-project
x-rtd-project-method
x-rtd-version
x-rtd-version-method
x-runtime
x-s
x-section
x-seen-by
x-seravo-request-id
x-served
x-served-by
x-servedbyhost
x-server
x-server-cache
x-server-id
x-server-name
x-server-nickname
x-server-powered-by
x-service-level
x-shard
x-shardid
x-shield-request-id
x-shopid
x-shopify-request-trackable
x-shopify-stage
x-site-id
x-slack-backend
x-slack-edge-shared-secret-outcome
x-slack-shared-secret-outcome
x-slate-uuid
x-smugmug-hiring
x-smugmug-values
x-sn-servicetimems
x-snr-routing
x-sol
x-sorting-hat-podid
x-sorting-hat-shopid
x-spr-cache
x-square
x-static-version
x-status-page-id
x-statuspage-skip-logging
x-statuspage-version
x-storage
x-storefront-renderer-rendered
x-styx-req-id
x-sucuri-cache
x-sucuri-id
x-target-backend
x-tec-api-origin
x-tec-api-root
x-tec-api-version
x-test
x-timer
x-tncms
x-tr
x-trace
x-traceid
x-ts
x-ttfb
x-ttfb-l
x-ttl
x-tumblr-pixel
x-tumblr-pixel-0
x-tumblr-pixel-1
x-tumblr-pixel-2
x-tumblr-pixel-3
x-tumblr-pixel-4
x-tumblr-user
x-turbo-charged-by
x-tx-id
x-type
x-tzla-edge-age
x-tzla-edge-backend-conn-time
x-tzla-edge-backend-fetch-if-stale
x-tzla-edge-backend-reason
x-tzla-edge-backend-retry
x-tzla-edge-backend-status
x-tzla-edge-backend-stream
x-tzla-edge-backend-ttfb
x-tzla-edge-cache-hit
x-tzla-edge-cache-hits
x-tzla-edge-client-req-ttl
x-tzla-edge-client-restarts
x-tzla-edge-grace
x-tzla-edge-grace-backend-unhealthy
x-tzla-edge-hostname-vcl
x-tzla-edge-server
x-tzla-edge-ttl
x-tzla-edge-was-304
x-ua-compatible
x-ua-device
x-uber-edge
x-uncacheable
x-upgrade-enabled
x-upstream
x-url
x-usage-input-ops
x-usage-output-ops
x-usage-quota-remaining
x-usage-request-cost
x-usage-system-time
x-usage-user-time
x-varnish
x-varnish-authentication
x-varnish-cache
x-varnish-edge-cache
x-varnish-grace
x-varnish-hostname
x-varnish-main-cache
x-vc-cache
x-vcache
x-vcap-request-id
x-vcs-revision
x-vdms-version
x-vercel-cache
x-vercel-id
x-version
x-vhost
x-via
x-vice-split-testing
x-view-name
x-vws-id
x-web-server
x-webcom-cache-status
x-webkit-csp
x-webserver
x-windy-backend
x-wix-request-id
x-wms-csrf
x-xms-page-cache-actions
x-xrds-location
x-xss
x-xss-protection
x-xss-pwnage
x-xss2
x-yadis-location
x-yourttl
x-zephr-cache
xkey
ykey
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment