HTTP headers provide additional information about an API request or response. In Postman, headers are used to tell the server how data should be interpreted, what response format is expected, and to provide information such as authentication tokens.
An HTTP header is a key-value pair that provides additional information about an HTTP request or response.
Example:
Content-Type: application/json
Here Content-Type is the header name and application/json is its value.
Headers help the client and server understand how to communicate with each other.
Headers can provide information about:
Postman provides a dedicated Headers section where you can add, edit, and remove request headers.
After selecting an HTTP method and entering the URL, open the Headers tab to work with request headers.
Every header normally contains a key and a value.
Key: Content-Type
Value: application/json
The key identifies the type of information and the value provides that information.
To add a header in Postman:
The Content-Type header tells the server what type of data is contained in the request body.
For JSON:
Content-Type: application/json
When a POST, PUT, or PATCH request sends JSON data, the Content-Type header can be set to:
Content-Type: application/json
This tells the server that the request body contains JSON.
The Accept header tells the server which response format the client can accept.
For example:
Accept: application/json
This indicates that the client expects JSON data.
| Header | Purpose |
|---|---|
| Content-Type | Describes the format of the request body |
| Accept | Describes the response format the client can accept |
A JSON API request may contain:
Content-Type: application/json
Accept: application/json
These headers provide information about the request and expected response.
The Authorization header is commonly used when an API requires authentication.
For example:
Authorization: Bearer YOUR_TOKEN
The token can be used by the server to identify and authorize the client.
A bearer token is commonly sent using the Authorization header.
Authorization: Bearer abc123xyz
The exact token format depends on the authentication system used by the API.
In Postman, an authorization header can be added manually through the Headers section.
Key: Authorization
Value: Bearer YOUR_TOKEN
Postman also provides authorization tools that can generate the appropriate request header.
An API can define its own custom headers when required.
For example:
X-App-Version: 1.0
Custom headers should follow the API's documentation and requirements.
A request may contain several headers:
Content-Type: application/json
Accept: application/json
Authorization: Bearer YOUR_TOKEN
Each header provides different information to the server.
Suppose we want to send a JSON POST request.
POST /api/students.php
Content-Type: application/json
Accept: application/json
The request body can then contain JSON data.
{
"name": "Rahul",
"course": "ADCA"
}
GET requests can also contain headers.
GET /api/students.php
Accept: application/json
The client can use the Accept header to indicate the desired response format.
A PUT request sending JSON data can contain:
Content-Type: application/json
Accept: application/json
The request body may contain the updated resource.
A PATCH request can also use JSON and authentication headers.
Content-Type: application/json
Accept: application/json
Authorization: Bearer YOUR_TOKEN
The body can contain only the fields that need to be updated.
DELETE requests can also use authentication headers when the API requires authorization.
Authorization: Bearer YOUR_TOKEN
The API can verify the token before allowing the delete operation.
Postman can automatically add certain headers depending on the request configuration.
For example, selecting JSON in the request body can result in a Content-Type header being added automatically.
Always review the Headers section when debugging an API request.
Before sending a request, open the Headers section in Postman and review the key-value pairs.
For example:
| Key | Value |
|---|---|
| Content-Type | application/json |
| Accept | application/json |
The server can also send headers back to the client in the response.
Postman displays response headers in the response section.
Examples can include:
Content-Type: application/json
| Request Headers | Response Headers |
|---|---|
| Sent by client | Sent by server |
| Provide information about the request | Provide information about the response |
| Configured in Postman's request | Displayed in Postman's response |
If an API request fails because of headers, check:
React Native applications can also send HTTP headers when communicating with REST APIs.
Content-Type: application/json
Accept: application/json
Authorization: Bearer YOUR_TOKEN
These headers can be configured using JavaScript or TypeScript API requests.
Method:
POST
URL:
http://localhost/api/students.php
Headers:
Content-Type: application/json
Accept: application/json
Body:
{
"name": "Amit Kumar",
"course": "React Native"
}
An authenticated API request may contain:
Content-Type: application/json
Accept: application/json
Authorization: Bearer YOUR_TOKEN
The server can use these headers to understand the request and verify authentication when required.
Headers provide additional information during API communication. In Postman, headers can be added through the Headers section and are commonly used for JSON data, response formats, authentication, and other API requirements.
Postman
↓
Request Headers
↓
REST API
↓
Response Headers
↓
Client
Question: Which HTTP header is commonly used to specify that the request body contains JSON?