Headers
The Headers directives allow you to set, modify, and remove HTTP response headers and request headers. These are essential for security headers, CORS configuration, caching policies, and more.
Directive Reference
Section titled “Directive Reference”| Directive | Syntax | Description |
|---|---|---|
Header set | Header [always] set name value [env=VAR] | Set a response header, replacing any existing value |
Header unset | Header [always] unset name | Remove a response header |
Header append | Header [always] append name value | Append a value to an existing header (comma-separated) |
Header merge | Header [always] merge name value | Append a value only if it is not already present |
Header add | Header [always] add name value | Add a header, even if one with the same name exists |
Header edit | Header [always] edit name regex replacement | Edit a header value using a regex (first match only) |
Header edit* | Header [always] edit* name regex replacement | Edit a header value using a regex (all matches) |
RequestHeader set | RequestHeader set name value | Set a request header passed to the backend |
RequestHeader unset | RequestHeader unset name | Remove a request header before it reaches the backend |
The optional always keyword applies the header operation on all responses, including error responses (4xx, 5xx). Without always, headers are only applied to successful responses.
The optional env=VAR condition makes the header operation apply only when the environment variable VAR is set.
Examples
Section titled “Examples”Security Headers
Section titled “Security Headers”Header always set X-Content-Type-Options "nosniff"Header always set X-Frame-Options "SAMEORIGIN"Header always set X-XSS-Protection "1; mode=block"Header always set Referrer-Policy "strict-origin-when-cross-origin"Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"CORS Configuration
Section titled “CORS Configuration”Header set Access-Control-Allow-Origin "https://example.com"Header set Access-Control-Allow-Methods "GET, POST, OPTIONS"Header set Access-Control-Allow-Headers "Content-Type, Authorization"Conditional Headers with env
Section titled “Conditional Headers with env”SetEnvIf Request_URI "\.pdf$" is_pdfHeader set Content-Disposition "attachment" env=is_pdfEdit Headers with Regex
Section titled “Edit Headers with Regex”# Remove the Server version from the header valueHeader edit Server "Apache/.*" "Apache"
# Replace all occurrences of http with https in Location headersHeader edit* Location "http://" "https://"Remove Unwanted Headers
Section titled “Remove Unwanted Headers”Header unset X-Powered-ByHeader always unset ServerRequestHeader unset Proxy