Origin header

Baseline Widely available

This feature is well established and works across many devices and browser versions. It’s been available across browsers since July 2020.

The HTTP Origin request header indicates the origin (scheme, hostname, and port) that caused the request. For example, if a user agent needs to request resources included in a page, or fetched by scripts that it executes, then the origin of the page may be included in the request.

Header type Request header
Forbidden request header Yes

Syntax

http
Origin: null
Origin: <scheme>://<hostname>
Origin: <scheme>://<hostname>:<port>

Directives

null

The origin is "privacy sensitive", or is an opaque origin (specific cases are listed in the description section).

<scheme>

The protocol that is used. Usually, it is the HTTP protocol or its secured version, HTTPS.

<hostname>

The domain name or the IP address of the origin server.

<port> Optional

Port number on which the server is listening. If no port is given, the default port for the requested service is implied from the scheme (e.g., 80 for an HTTP URL).

Description

The Origin header is similar to the Referer header, but does not disclose the path, and may be null. It is used to provide the security context for the origin request, except in cases where the origin information would be sensitive or unnecessary.

Broadly speaking, user agents add the Origin request header to:

There are some exceptions to the above rules; for example, if a cross-origin GET or HEAD request is made in no-cors mode, the Origin header will not be added.

The Origin header value may be null in a number of cases, including (non-exhaustively):

  • Origins whose scheme is not one of http, https, ftp, ws, wss, or gopher (including blob, file and data).
  • Cross-origin images and media data, including that in <img>, <video> and <audio> elements.
  • Documents created programmatically using createDocument(), generated from a data: URL, or that do not have a creator browsing context.
  • Redirects across origins.
  • Documents served with the Content-Security-Policy sandbox directive whose value doesn't include allow-same-origin.
  • iframes with a sandbox attribute whose value doesn't include allow-same-origin.
  • Responses that are network errors.
  • Referrer-Policy set to no-referrer for non-cors request modes (e.g., basic form posts).

Note: There is a more detailed listing of cases that may return null on Stack Overflow: When do browsers send the Origin header? When do browsers set the origin to null?

Examples

http
Origin: https://developer.mozilla.org
http
Origin: https://developer.mozilla.org:80

Specifications

Specification
The Web Origin Concept
# section-7
Fetch
# origin-header

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
Origin
Chrome – Full support
Chrome 1 (Release date: 2008-12-11)
footnote Full support
Edge – Partial support
Edge 12 – 18 (Release date: 2015-07-29)
footnote Partial support
footnote Not sent with POST requests
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Partial support
Firefox 1 – 69 (Release date: 2004-11-09)
footnote Partial support
footnote Not sent with POST requests, see bug 446344.
Firefox – Full support
Firefox 70 (Release date: 2019-10-22)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 1 (Release date: 2003-06-23)
footnote Full support
Chrome Android – Full support
Chrome Android 18 (Release date: 2012-06-27)
footnote Full support
Firefox for Android – Partial support
Firefox for Android 4 – 68 (Release date: 2011-03-29)
footnote Partial support
footnote Not sent with POST requests, see bug 446344.
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Opera Android – Full support
Opera Android 14 (Release date: 2013-05-21)
footnote Full support
Safari on iOS – Full support
Safari on iOS 1 (Release date: 2007-06-29)
footnote Full support
Samsung Internet – Full support
Samsung Internet 1 (Release date: 2013-04-27)
footnote Full support
WebView Android – Full support
WebView Android 4.4 (Release date: 2013-12-09)
footnote Full support
WebView on iOS – Full support
WebView on iOS 1 (Release date: 2007-06-29)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
Partial support
Partial support
Has more compatibility info.

See also