Security Headers Cheat Sheet
A plain-English reference for the essential HTTP security headers — Content-Security-Policy, HSTS, X-Frame-Options, Referrer-Policy and more — with recommended values and what each one protects against.
Headers a production web app should ship. Recommended values are starting points — tighten them for your app.
Strict-Transport-Security
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Forces HTTPS. Stops protocol-downgrade and cookie-hijacking over plain HTTP.
Content-Security-Policy
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'
Primary XSS defense. Restricts what scripts/styles can load and where the page can be framed.
X-Frame-Options
X-Frame-Options: DENY
Blocks clickjacking by preventing the page from being framed. frame-ancestors in CSP supersedes it; ship both for legacy browsers.
X-Content-Type-Options
X-Content-Type-Options: nosniff
Stops MIME sniffing — browsers won't reinterpret a JSON/script response as HTML.
Referrer-Policy
Referrer-Policy: strict-origin-when-cross-origin
Limits what URL info leaks in the Referer header when leaving your site.
Permissions-Policy
Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=()
Disables browser features (camera, mic, geo) your site doesn’t need, reducing the attack surface of those APIs.
Cross-Origin-Resource-Policy
Cross-Origin-Resource-Policy: same-origin
Tells browsers not to let other origins load your resources, mitigating Spectre-style cross-origin reads.
Cross-Origin-Opener-Policy
Cross-Origin-Opener-Policy: same-origin
Isolates your window from cross-origin popups — paired with COEP it enables powerful browser isolation features.
Cross-Origin-Embedder-Policy
Cross-Origin-Embedder-Policy: require-corp
Requires cross-origin resources to declare CORS/CORP, locking down subresource loading. Opt-in, can break third-party embeds.
Cache-Control
Cache-Control: no-store
For pages with sensitive data, keeps browsers and CDNs from caching responses.
How to use this reference
This is a lookup reference, not a calculator. Each header below lists a recommended value and what it protects against. To grade a live site against these headers, open the Security Header Scanner and run it on a URL.
FAQ
What is a security header?
A response header that tells the browser how to behave more safely — for example, forcing HTTPS, restricting what scripts can load, or blocking the page from being framed. They are cheap, low-risk hardening wins.
Which ones matter most?
Content-Security-Policy and HSTS have the biggest impact. X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy are quick adds many sites miss.
How do I actually set these?
Add them in your web server config, a reverse proxy/CDN ruleset, or your framework’s headers middleware. The exact place depends on your stack — the values here are the “what”; your platform is the “how.”
What grade should I be aiming for?
Treat an A as the goal. Start by shipping the four or five cheapest headers, then tighten CSP and add the isolation-oriented CORP/COOP once you’ve verified nothing breaks.