Mehdi Akiki
Published on

HTTP Header Field Names Are Case-Insensitive

Authors
  • Mehdi Akiki avatar
    Name
    Mehdi Akiki
    Twitter

Reference

HTTP field names are case-insensitive. A recipient interprets Content-Type, content-type, and CONTENT-TYPE as the same field name.

That rule comes from RFC 9110, section 5.1. It applies to field-name comparison, not necessarily to the bytes sent on every HTTP version.

Here's a quick example:

curl -H "Content-Type: application/json" https://api.example.com
curl -H "content-type: application/json" https://api.example.com

Both commands send the same Content-Type header, no matter the case.

The HTTP/2 detail

HTTP/2 is stricter on the wire. Field names containing uppercase characters make the message malformed, so an HTTP/2 implementation sends field names in lowercase. This is specified in RFC 9113, section 8.2.1.

Application code can still normally look up a header without caring about its case. Lowercase is a good convention when generating headers because it also matches the HTTP/2 representation.