Common HTTP Headers
Common HTTP Headers
HTTP headers are an important part of communication between a client and a web server. They provide additional information about an HTTP request or response, such as the data format, caching behavior, supported content types, and details about the client making the request.
Understanding common HTTP headers is essential for software developers, QA engineers, API testers, automation engineers, and web developers. In this tutorial, we will learn about four commonly used HTTP headers:
- Content-Type
- Cache-Control
- Accept
- User-Agent
What Are HTTP Headers?
HTTP headers are key-value pairs sent between an HTTP client and server. They contain metadata about the request or response.
For example:
Content-Type: application/json
Accept: application/json
Cache-Control: no-cache
User-Agent: Mozilla/5.0
Some headers are primarily used in requests, some in responses, and some can be used in both directions depending on their purpose.
1. Content-Type HTTP Header
The Content-Type header indicates the media type, or format, of the message body being sent.
It is commonly used when a client sends data to a server, such as in a POST, PUT, or PATCH request.
Syntax
Content-Type: media-type
Common Content-Type Values
| Content-Type | Description |
|---|---|
application/json |
JSON data |
application/xml |
XML data |
text/plain |
Plain text |
text/html |
HTML content |
application/x-www-form-urlencoded |
Form URL-encoded data |
multipart/form-data |
Form data, commonly used for file uploads |
Example: JSON API Request
POST /api/users HTTP/1.1
Host: example.com
Content-Type: application/json
{
"name": "John",
"email": "john@example.com"
}
Here, Content-Type: application/json tells the server that the request body contains JSON data.
Why Is Content-Type Important?
The server uses the Content-Type value to determine how the request body should be interpreted. Sending the wrong content type can result in parsing errors, validation failures, or unexpected application behavior.
2. Cache-Control HTTP Header
The Cache-Control header specifies caching instructions for HTTP requests and responses. It allows clients, browsers, proxies, and other caches to understand how a resource may be cached and reused.
Syntax
Cache-Control: directive
Common Cache-Control Directives
| Directive | Purpose |
|---|---|
no-cache |
Requires cached content to be revalidated before reuse. |
no-store |
Instructs caches not to store the response. |
max-age |
Specifies how long a response can be considered fresh, in seconds. |
public |
Allows a response to be stored by shared caches. |
private |
Indicates that the response is intended for a private cache, such as a browser. |
Example
Cache-Control: max-age=3600
This indicates that the response may be considered fresh for 3600 seconds, or one hour.
Another example is:
Cache-Control: no-store
This is commonly used when a response should not be stored in a cache.
Why Is Cache-Control Important?
Proper caching can reduce network traffic, improve application performance, and decrease server load. Incorrect caching rules, however, can result in users receiving stale content or can create security and privacy concerns.
3. Accept HTTP Header
The Accept header indicates which media types the client is prepared to receive in the HTTP response.
This is different from Content-Type. The Content-Type header describes the format of the message body being sent, while Accept describes the response formats the client can handle.
Syntax
Accept: media-type
Example
GET /api/products HTTP/1.1
Host: example.com
Accept: application/json
Here, the client is indicating that it prefers a response in JSON format.
Multiple Accepted Formats
A client can specify multiple media types:
Accept: application/json, application/xml
The server can use content negotiation to select an appropriate representation of the requested resource.
Using Quality Values
The client can also express a preference by using quality values:
Accept: application/json, application/xml;q=0.8
In this example, JSON has a higher preference than XML.
Why Is Accept Important?
The Accept header is especially useful for APIs that can return resources in different formats. It helps the client communicate its response format preferences to the server.
4. User-Agent HTTP Header
The User-Agent header provides information about the client making the HTTP request. It can identify the browser, application, operating system, or other client software.
Example
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/140.0.0.0 Safari/537.36
A typical User-Agent string may contain information that helps a server identify the software and platform making the request.
Where Is User-Agent Used?
The User-Agent header can be useful for:
- Identifying client software
- Analyzing traffic and logs
- Supporting browser or client compatibility
- Diagnosing client-specific problems
- Distinguishing automated clients and tools in some environments
However, User-Agent strings should not be treated as strong proof of a client’s identity because they can be modified or spoofed.
Content-Type vs Accept
One of the most common HTTP header mistakes is confusing Content-Type with Accept.
| Header | What It Describes | Typical Direction | Example |
|---|---|---|---|
Content-Type |
Format of the message body | Request or Response | application/json |
Accept |
Response formats the client can handle | Usually Request | application/json |
A simple way to remember the difference is:
Content-Type = "What format am I sending?"
Accept = "What format can I receive?"
Example of Common HTTP Headers in an API Request
GET /api/users HTTP/1.1
Host: example.com
Accept: application/json
Cache-Control: no-cache
User-Agent: MyApiClient/1.0
For a request that sends JSON data, you may see:
POST /api/users HTTP/1.1
Host: example.com
Content-Type: application/json
Accept: application/json
Cache-Control: no-cache
User-Agent: MyApiClient/1.0
{
"name": "John",
"role": "Tester"
}
Why HTTP Headers Matter in API Testing
HTTP headers are very important when testing REST APIs and other HTTP-based services. QA engineers and API testers should verify that headers are correctly sent and returned.
For example, an API test may validate that:
Content-Type = application/json
Accept = application/json
Cache-Control = no-cache
User-Agent = MyApiClient/1.0
Testers should also verify how the application behaves when headers are missing, contain unsupported values, or contain invalid values.
Common HTTP Header Testing Scenarios
Some useful test scenarios include checking whether the server:
- Correctly processes valid
Content-Typevalues. - Rejects unsupported or invalid media types when appropriate.
- Returns the expected content type in the response.
- Honors caching directives correctly.
- Handles different
Acceptheader values. - Provides appropriate responses for clients with different User-Agent values.
Common HTTP Header Errors
Incorrect Content-Type
Sending JSON data with an incorrect content type can cause the server to interpret the body incorrectly.
Confusing Accept and Content-Type
Setting Accept: application/json does not mean that the request body is JSON. When the request body is JSON, the client generally needs Content-Type: application/json as well.
Improper Cache-Control
Incorrect caching directives may cause stale data to be served or sensitive responses to be stored when they should not be.
Relying on User-Agent for Security
The User-Agent header can be changed by clients. It should therefore not be considered a reliable authentication or authorization mechanism.
Common HTTP Headers Cheat Sheet
| HTTP Header | Primary Purpose | Example |
|---|---|---|
Content-Type |
Specifies the format of the message body | application/json |
Cache-Control |
Controls caching behavior | max-age=3600 |
Accept |
Specifies acceptable response formats | application/json |
User-Agent |
Identifies the client software | Mozilla/5.0 |
Conclusion
HTTP headers provide essential metadata that helps clients and servers communicate effectively. Among the many HTTP headers available, Content-Type, Cache-Control, Accept, and User-Agent are particularly common.
Content-Type identifies the format of the message body, Accept communicates the response formats the client can handle, Cache-Control manages caching behavior, and User-Agent provides information about the requesting client.
A good understanding of these common HTTP headers is valuable for REST API testing, API automation, web development, debugging, and software testing.
Frequently Asked Questions (FAQ)
What is Content-Type in HTTP?
Content-Type specifies the media type of the message body, such as JSON, XML, HTML, or plain text.
What is Cache-Control in HTTP?
Cache-Control provides directives that control how HTTP responses are cached and reused.
What is the Accept header?
Accept tells the server which response media types the client can handle, such as JSON or XML.
What is the User-Agent header?
User-Agent identifies information about the client software making an HTTP request, such as a browser or API client.
What is the difference between Content-Type and Accept?
Content-Type describes the format of the message body, while Accept specifies the response formats the client is willing to receive.