indicates, as part of the response to a preflight request, which header field names can be used during the actual request
Quick facts
Description
indicates, as part of the response to a preflight request, which header field names can be used during the actual request
Syntax
Access-Control-Allow-Headers: Content-Type, Authorization
Frequently asked questions
indicates, as part of the response to a preflight request, which header field names can be used during the actual request
It is classified as a response header and can appear in requests or responses depending on context.
Sources & standards
Updated 2026-08-18