indicates which headers are safe to expose to the API of a CORS API specification
Quick facts
Description
indicates which headers are safe to expose to the API of a CORS API specification
Syntax
Access-Control-Expose-Headers: X-Total-Count
Frequently asked questions
indicates which headers are safe to expose to the API of a CORS API specification
It is classified as a response header and can appear in requests or responses depending on context.
Sources & standards
Updated 2026-08-18