Header (HTTP header)
Also: 標頭 · 請求標頭 · HTTP header · Authorization
Notes attached to a request or response about this transfer: identity, content format, caching, where to redirect. The actual data is in the body; headers are the annotations on the envelope.
When you will meet it
Your API key travels in a header (Authorization: Bearer …). When a tool says "it sends your key in a header", or you get a 401 and cannot see where the key went, the culprit is almost always this line.
An analogy
Like the shipping label on a parcel: recipient, contents type, keep-refrigerated, fragile — all written outside the box for the carriers, while the stuff inside is the actual payload. Headers are that label.
Minimal example
# -D - 把回應標頭印到螢幕,-o /dev/null 把內文丟掉
curl -s -D - -o /dev/null https://example.comYou will see headers like Content-Type, Content-Length and Server. On the request side the critical one is Authorization: Bearer <your key> — that carries your identity — plus Content-Type: application/json to tell the server the body is JSON. Header names are case-insensitive; the values must be right.
What people get wrong
- Putting the key in the body or the URL instead of the Authorization header. In the URL it gets logged verbatim by servers — effectively broadcast — whereas the header is the right place.
- Forgetting Content-Type: application/json, so the server reads your JSON as plain text and returns a confusing 400. A missing header line is a very common, easily-missed mistake.
Related terms
Next
- 第一次呼叫 LLM API:Token、計費與常見錯誤21 minChinese only