Provides technical information and tools about HTTP security headers.
About OWASP Secure Headers Project
βΉοΈ Purpose
The OWASP Secure Headers Project (also named OSHP) describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities. The OSHP intends to raise awareness and use of these headers.
π Content
While this page serves as the projectβs official OWASP identity card, the GitHub repository remains the sole source of truth. All master data and project content are managed and hosted exclusively on GitHub.
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.