▣

Security Headers Cheat Sheet

A plain-English reference for the essential HTTP security headers — Content-Security-Policy, HSTS, X-Frame-Options, Referrer-Policy and more — with recommended values and what each one protects against.

Headers a production web app should ship. Recommended values are starting points — tighten them for your app.

Strict-Transport-Security

Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

Forces HTTPS. Stops protocol-downgrade and cookie-hijacking over plain HTTP.

Content-Security-Policy

Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'

Primary XSS defense. Restricts what scripts/styles can load and where the page can be framed.

X-Frame-Options

X-Frame-Options: DENY

Blocks clickjacking by preventing the page from being framed. frame-ancestors in CSP supersedes it; ship both for legacy browsers.

X-Content-Type-Options

X-Content-Type-Options: nosniff

Stops MIME sniffing — browsers won't reinterpret a JSON/script response as HTML.

Referrer-Policy

Referrer-Policy: strict-origin-when-cross-origin

Limits what URL info leaks in the Referer header when leaving your site.

Permissions-Policy

Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=()

Disables browser features (camera, mic, geo) your site doesn’t need, reducing the attack surface of those APIs.

Cross-Origin-Resource-Policy

Cross-Origin-Resource-Policy: same-origin

Tells browsers not to let other origins load your resources, mitigating Spectre-style cross-origin reads.

Cross-Origin-Opener-Policy

Cross-Origin-Opener-Policy: same-origin

Isolates your window from cross-origin popups — paired with COEP it enables powerful browser isolation features.

Cross-Origin-Embedder-Policy

Cross-Origin-Embedder-Policy: require-corp

Requires cross-origin resources to declare CORS/CORP, locking down subresource loading. Opt-in, can break third-party embeds.

Cache-Control

Cache-Control: no-store

For pages with sensitive data, keeps browsers and CDNs from caching responses.

How to use this reference

This is a lookup reference, not a calculator. Each header below lists a recommended value and what it protects against. To grade a live site against these headers, open the Security Header Scanner and run it on a URL.

FAQ

What is a security header?

A response header that tells the browser how to behave more safely — for example, forcing HTTPS, restricting what scripts can load, or blocking the page from being framed. They are cheap, low-risk hardening wins.

Which ones matter most?

Content-Security-Policy and HSTS have the biggest impact. X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy are quick adds many sites miss.

How do I actually set these?

Add them in your web server config, a reverse proxy/CDN ruleset, or your framework’s headers middleware. The exact place depends on your stack — the values here are the “what”; your platform is the “how.”

What grade should I be aiming for?

Treat an A as the goal. Start by shipping the four or five cheapest headers, then tighten CSP and add the isolation-oriented CORP/COOP once you’ve verified nothing breaks.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.