Is It Safe to Send Data in Headers

Yes it is allowed – but note that it may cut off the ability to use proxies and sometimes http aware firewalls (they tend to inspect and rewrite headers).

What should be sent in headers?

  • Request and Response Body.
  • Request Authorization.
  • Response Caching.
  • Response Cookies.

Are authorization headers safe?

1 Answer. They are Base-64 encoded for transport, but this provides no confidentiality. You must secure your communications with TLS if you plan to use Basic authentication.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest