"New on the Web": For a given set of browsers, what APIs became stable and when, ordered reverse chronologically.
It's a great source of information for posts like this
Below is a list of features that are in Edge and Safari, ordered reverse chronologically by when they became stable (i.e, available in the last browser).
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Accept-Encoding.zstd π | Edge | 3/22/2024 | Safari | 2/11/2026 | 691 | Safari: Before macOS 26.3 Tahoe, this header value is not sent. |
| http.headers.Content-Encoding.zstd π | Edge | 3/22/2024 | Safari | 2/11/2026 | 691 | Safari: Before macOS 26.3 Tahoe, Safari cannot decode Zstandard responses. |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.script-src.inline-speculation-rules | Edge | 2/9/2023 | Safari | 12/12/2025 | 1037 | |
| http.headers.Content-Security-Policy.style-src-elem π | Edge | 1/15/2020 | Safari | 12/12/2025 | 2158 | Safari: The style-src-elem directive was parsed, but had no effect. See bug 276931.Safari on iOS: The style-src-elem directive was parsed, but had no effect. See bug 276931.WebView on iOS: The style-src-elem directive was parsed, but had no effect. See bug 276931. |
| http.headers.Sec-Purpose.speculationrules | Edge | 2/9/2023 | Safari | 12/12/2025 | 1037 | |
| http.headers.Sec-Speculation-Tags π | Edge | 5/1/2025 | Safari | 12/12/2025 | 225 | |
| http.headers.Set-Cookie.Partitioned π | Edge | 6/2/2023 | Safari | 12/12/2025 | 924 | |
| http.headers.Speculation-Rules π | Edge | 1/25/2024 | Safari | 12/12/2025 | 687 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.require-trusted-types-for π | Edge | 5/21/2020 | Safari | 9/15/2025 | 1943 | |
| http.headers.Content-Security-Policy.trusted-types π | Edge | 5/21/2020 | Safari | 9/15/2025 | 1943 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Cross-Origin-Opener-Policy.noopener-allow-popups π | Edge | 11/14/2024 | Safari | 3/31/2025 | 137 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Link.fetchpriority π | Edge | 6/23/2022 | Safari | 12/11/2023 | 536 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Alt-Svc π | Edge | 1/15/2020 | Safari | 9/18/2023 | 1342 | Firefox: Only supports draft-04Firefox for Android: Only supports draft-04 |
| http.headers.Clear-Site-Data π | Edge | 1/15/2020 | Safari | 9/18/2023 | 1342 | |
| http.headers.Clear-Site-Data.cache π | Edge | 1/15/2020 | Safari | 9/18/2023 | 1342 | Chrome: Setting this value may increase response duration (see bug 40233601.Chrome: Setting this value may prevent a page from fully load (see bug 41343050.Chrome Android: Setting this value may increase response duration (see bug 40233601.Chrome Android: Setting this value may prevent a page from fully load (see bug 41343050.Edge: Setting this value may increase response duration (see bug 40233601.Quest Browser: Setting this value may increase response duration (see bug 40233601.Opera: Setting this value may increase response duration (see bug 40233601.Opera: Setting this value may prevent a page from fully load (see bug 41343050.Opera Android: Setting this value may increase response duration (see bug 40233601.Opera Android: Setting this value may prevent a page from fully load (see bug 41343050.Samsung Internet: Setting this value may increase response duration (see bug 40233601.WebView Android: Setting this value may increase response duration (see bug 40233601.WebView Android: Setting this value may prevent a page from fully load (see bug 41343050. |
| http.headers.Clear-Site-Data.cookies π | Edge | 1/15/2020 | Safari | 9/18/2023 | 1342 | |
| http.headers.Clear-Site-Data.secure_context_required | Edge | 1/15/2020 | Safari | 9/18/2023 | 1342 | |
| http.headers.Clear-Site-Data.storage π | Edge | 1/15/2020 | Safari | 9/18/2023 | 1342 | |
| http.headers.Clear-Site-Data.wildcard π | Edge | 9/15/2023 | Safari | 9/18/2023 | 3 | |
| http.headers.Link π | Edge | 6/23/2022 | Safari | 9/18/2023 | 452 | |
| http.status.103 π | Edge | 6/23/2022 | Safari | 9/18/2023 | 452 | Chrome: Supported in HTTP/2 and later only.Chrome Android: Supported in HTTP/2 and later only.Edge: Supported in HTTP/2 and later only.Quest Browser: Supported in HTTP/2 and later only.Opera: Supported in HTTP/2 and later only.Opera Android: Supported in HTTP/2 and later only.Safari: Supported in HTTP/2 and later only.Safari on iOS: Supported in HTTP/2 and later only.Samsung Internet: Supported in HTTP/2 and later only.WebView Android: Supported in HTTP/2 and later only.WebView on iOS: Supported in HTTP/2 and later only. |
| http.status.103.preconnect | Edge | 6/23/2022 | Safari | 9/18/2023 | 452 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.report-to π | Edge | 1/15/2020 | Safari | 3/27/2023 | 1167 | |
| http.headers.Reporting-Endpoints π | Edge | 11/19/2021 | Safari | 3/27/2023 | 493 | |
| http.headers.Sec-Fetch-Dest π | Edge | 2/7/2020 | Safari | 3/27/2023 | 1144 | |
| http.headers.Sec-Fetch-Mode π | Edge | 1/15/2020 | Safari | 3/27/2023 | 1167 | |
| http.headers.Sec-Fetch-Site π | Edge | 1/15/2020 | Safari | 3/27/2023 | 1167 | |
| http.headers.Server-Timing π | Edge | 1/15/2020 | Safari | 3/27/2023 | 1167 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.script-src.wasm-unsafe-eval | Edge | 1/6/2022 | Safari | 9/12/2022 | 249 | |
| http.headers.Range.cors_safe | Edge | 3/3/2022 | Safari | 9/12/2022 | 193 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.script-src.external_scripts π | Edge | 1/15/2020 | Safari | 7/20/2022 | 917 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.worker-src π | Edge | 1/15/2020 | Safari | 5/16/2022 | 852 | Chrome: Chrome 59 and higher skips the deprecated child-src directive.Chrome Android: Chrome Android 59 and higher skips the deprecated child-src directive.Quest Browser: Quest Browser 5.0 and higher skips the deprecated child-src directive.Opera: Opera 46 and higher skips the deprecated child-src directive.Opera Android: Opera Android 43 and higher skips the deprecated child-src directive.WebView Android: WebView Android 59 and higher skips the deprecated child-src directive. |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.report-sample | Edge | 1/15/2020 | Safari | 3/14/2022 | 789 | |
| http.headers.Content-Security-Policy.script-src-attr π | Edge | 1/15/2020 | Safari | 3/14/2022 | 789 | |
| http.headers.Content-Security-Policy.script-src-elem π | Edge | 1/15/2020 | Safari | 3/14/2022 | 789 | |
| http.headers.Content-Security-Policy.strict-dynamic | Edge | 1/15/2020 | Safari | 3/14/2022 | 789 | |
| http.headers.Content-Security-Policy.style-src-attr π | Edge | 1/15/2020 | Safari | 3/14/2022 | 789 | |
| http.headers.Content-Security-Policy.unsafe-hashes | Edge | 1/15/2020 | Safari | 3/14/2022 | 789 | |
| http.headers.Service-Worker-Navigation-Preload π | Edge | 10/2/2018 | Safari | 3/14/2022 | 1259 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Cross-Origin-Embedder-Policy π | Edge | 5/21/2020 | Safari | 12/13/2021 | 571 | |
| http.headers.Cross-Origin-Opener-Policy π | Edge | 5/21/2020 | Safari | 12/13/2021 | 571 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Referrer-Policy.default_strict-origin-when-cross-origin | Edge | 8/27/2020 | Safari | 9/20/2021 | 389 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.data-url.top_level_navigation_blocked | Edge | 1/15/2020 | Safari | 9/16/2020 | 245 | |
| http.headers.Cache-Control.stale-while-revalidate π | Edge | 1/15/2020 | Safari | 9/16/2020 | 245 | |
| http.headers.Referer.length_limit_4096B | Edge | 1/15/2020 | Safari | 9/16/2020 | 245 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.data-url.html_files | Safari | 3/18/2008 | Edge | 1/15/2020 | 4320 | |
| http.headers.Access-Control-Allow-Headers.wildcard | Safari | 9/19/2019 | Edge | 1/15/2020 | 118 | |
| http.headers.Access-Control-Allow-Methods.wildcard | Safari | 9/19/2019 | Edge | 1/15/2020 | 118 | |
| http.headers.Access-Control-Expose-Headers.wildcard | Safari | 9/19/2019 | Edge | 1/15/2020 | 118 | |
| http.headers.Authorization.Digest π | Safari | 6/23/2003 | Edge | 1/15/2020 | 6050 | |
| http.headers.Authorization.Digest.md5 | Safari | 6/23/2003 | Edge | 1/15/2020 | 6050 | |
| http.headers.Authorization.NTLM | Safari | 10/22/2013 | Edge | 1/15/2020 | 2276 | |
| http.headers.Authorization.Negotiate π | Safari | 10/22/2013 | Edge | 1/15/2020 | 2276 | |
| http.headers.Content-Length.cors_response_safelist | Safari | 3/25/2019 | Edge | 1/15/2020 | 296 | |
| http.headers.Content-Security-Policy.base-uri π | Safari | 9/20/2016 | Edge | 1/15/2020 | 1212 | |
| http.headers.Content-Security-Policy.block-all-mixed-content | Safari | 9/20/2016 | Edge | 1/15/2020 | 1212 | Chrome: Will be removed, see bug 40260100.Chrome Android: Will be removed, see bug 40260100.Edge: Will be removed, see bug 40260100.Quest Browser: Will be removed, see bug 40260100.Opera: Will be removed, see bug 40260100.Opera Android: Will be removed, see bug 40260100.Samsung Internet: Will be removed, see bug 40260100.WebView Android: Will be removed, see bug 40260100. |
| http.headers.Content-Security-Policy.form-action.blocks_redirects | Safari | 4/12/2018 | Edge | 1/15/2020 | 643 | |
| http.headers.Content-Security-Policy.manifest-src π | Safari | 9/19/2017 | Edge | 1/15/2020 | 848 | |
| http.headers.Content-Security-Policy.worker_support | Safari | 9/20/2016 | Edge | 1/15/2020 | 1212 | |
| http.headers.Cross-Origin-Resource-Policy π | Safari | 9/17/2018 | Edge | 1/15/2020 | 485 | Chrome: Until version 75, downloads for files with this header would fail in Chrome. See bug 41452948.Chrome: From version 80 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 86, partial PDF loading is disabled.Chrome Android: Until version 75, downloads for files with this header would fail in Chrome Android. See bug 41452948.Chrome Android: From version 80 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 86, partial PDF loading is disabled.Quest Browser: Until version 7.0, downloads for files with this header would fail in Quest Browser. See bug 41452948.Quest Browser: From version 9.0 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 12.0, partial PDF loading is disabled.Opera: Until version 62, downloads for files with this header would fail in Opera. See bug 41452948.Opera: From version 67 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 72, partial PDF loading is disabled.Opera Android: Until version 54, downloads for files with this header would fail in Opera Android. See bug 41452948.Opera Android: From version 57 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 61, partial PDF loading is disabled.WebView Android: Until version 75, downloads for files with this header would fail in WebView Android. See bug 41452948.WebView Android: From version 80 to 85, linearized PDFs served inline with this header fail to render properly. See bug 40127935. From version 86, partial PDF loading is disabled. |
| http.headers.Origin π | Safari | 6/23/2003 | Edge | 1/15/2020 | 6050 | Edge: Not sent with POST requestsFirefox: Not sent with POST requests, see bug 446344.Firefox for Android: Not sent with POST requests, see bug 446344. |
| http.headers.Referrer-Policy π | Safari | 4/12/2018 | Edge | 1/15/2020 | 643 | |
| http.headers.Referrer-Policy.same-origin | Safari | 4/12/2018 | Edge | 1/15/2020 | 643 | |
| http.headers.Referrer-Policy.strict-origin | Safari | 4/12/2018 | Edge | 1/15/2020 | 643 | |
| http.headers.Referrer-Policy.strict-origin-when-cross-origin | Safari | 4/12/2018 | Edge | 1/15/2020 | 643 | |
| http.headers.Set-Cookie.host_secure_prefixes | Safari | 9/19/2019 | Edge | 1/15/2020 | 118 | |
| http.headers.SourceMap π | Safari | 10/22/2013 | Edge | 1/15/2020 | 2276 | Chrome: Not supported for ECMAScript Modules ( <script type="module">). See bug 40854862.Chrome Android: Not supported for ECMAScript Modules (<script type="module">). See bug 40854862.Edge: Not supported for ECMAScript Modules (<script type="module">). See bug 40854862.Quest Browser: Not supported for ECMAScript Modules (<script type="module">). See bug 40854862.Opera: Not supported for ECMAScript Modules (<script type="module">). See bug 40854862.Opera Android: Not supported for ECMAScript Modules (<script type="module">). See bug 40854862.Samsung Internet: Not supported for ECMAScript Modules (<script type="module">). See bug 40854862.WebView Android: Not supported for ECMAScript Modules (<script type="module">). See bug 40854862. |
| http.headers.Timing-Allow-Origin π | Safari | 9/19/2017 | Edge | 1/15/2020 | 848 | |
| http.headers.WWW-Authenticate.NTLM | Safari | 10/22/2013 | Edge | 1/15/2020 | 2276 | |
| http.headers.WWW-Authenticate.Negotiate π | Safari | 10/22/2013 | Edge | 1/15/2020 | 2276 | |
| http.mixed-content π | Safari | 3/21/2016 | Edge | 1/15/2020 | 1395 | |
| http.mixed-content.blockable_mixed_content π | Safari | 3/21/2016 | Edge | 1/15/2020 | 1395 | Chrome: From version 79 blocks iframes, scripts, and stylesheets.Chrome Android: From version 79 blocks iframes, scripts, and stylesheets.Edge: From version 79 blocks iframes, scripts, and stylesheets.Quest Browser: From version 8.0 blocks iframes, scripts, and stylesheets.Opera: From version 66 blocks iframes, scripts, and stylesheets.Opera Android: From version 57 blocks iframes, scripts, and stylesheets.Samsung Internet: From version 12.0 blocks iframes, scripts, and stylesheets.WebView Android: From version 79 blocks iframes, scripts, and stylesheets. |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Set-Cookie.SameSite π | Edge | 10/17/2017 | Safari | 9/19/2019 | 702 | Safari: Safari 13 on macOS 10.14 (Mojave), treats SameSite=None and invalid values as Strict. This is fixed in version 10.15 (Catalina) and later.Safari: Treats SameSite=None and invalid values as Strict in macOS before 10.15 Catalina. See bug 198181.Safari on iOS: Treats SameSite=None and invalid values as Strict in iOS before 13. See bug 198181.WebView on iOS: Treats SameSite=None and invalid values as Strict in iOS before 13. See bug 198181. |
| http.headers.Set-Cookie.SameSite.None | Edge | 10/17/2017 | Safari | 9/19/2019 | 702 | Chrome: Rejects cookies with SameSite=None. See SameSite=None: Known Incompatible Clients.Chrome Android: Rejects cookies with SameSite=None. See SameSite=None: Known Incompatible Clients.Quest Browser: Rejects cookies with SameSite=None. See SameSite=None: Known Incompatible Clients.Opera: Rejects cookies with SameSite=None. See SameSite=None: Known Incompatible Clients.Opera Android: Rejects cookies with SameSite=None. See SameSite=None: Known Incompatible Clients.Safari: Not supported before macOS version 10.15 (Catalina).Samsung Internet: Rejects cookies with SameSite=None. See SameSite=None: Known Incompatible Clients.WebView Android: Rejects cookies with SameSite=None. See SameSite=None: Known Incompatible Clients. |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.meta-element-support | Safari | 10/22/2013 | Edge | 10/2/2018 | 1806 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Set-Cookie.SameSite.Lax | Edge | 10/17/2017 | Safari | 9/17/2018 | 335 | |
| http.headers.Set-Cookie.SameSite.Strict | Edge | 10/17/2017 | Safari | 9/17/2018 | 335 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.upgrade-insecure-requests π | Safari | 3/27/2017 | Edge | 4/30/2018 | 399 | |
| http.headers.Upgrade-Insecure-Requests π | Safari | 3/27/2017 | Edge | 4/30/2018 | 399 | |
| http.headers.Service-Worker π | Edge | 10/17/2017 | Safari | 4/12/2018 | 177 | |
| http.headers.Service-Worker-Allowed π | Edge | 10/17/2017 | Safari | 4/12/2018 | 177 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Accept-Encoding.br π | Edge | 4/5/2017 | Safari | 9/19/2017 | 167 | Safari: Unsupported before macOS 10.13 High Sierra. |
| http.headers.Content-Encoding.br π | Edge | 4/5/2017 | Safari | 9/19/2017 | 167 | Safari: Unsupported before macOS 10.13 High Sierra. |
| http.headers.X-Content-Type-Options π | Edge | 7/29/2015 | Safari | 9/19/2017 | 783 | Chrome: Not supported for stylesheets.Chrome Android: Not supported for stylesheets.Opera: Not supported for stylesheets.Opera Android: Not supported for stylesheets.Samsung Internet: Not supported for stylesheets.WebView Android: Not supported for stylesheets. |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy.child-src π | Safari | 9/20/2016 | Edge | 4/5/2017 | 197 | |
| http.headers.Content-Security-Policy.form-action π | Safari | 9/20/2016 | Edge | 4/5/2017 | 197 | |
| http.headers.Content-Security-Policy.frame-ancestors π | Safari | 9/20/2016 | Edge | 4/5/2017 | 197 | Firefox: Before Firefox 58, frame-ancestors is ignored in Content-Security-Policy-Report-Only.Firefox for Android: Before Firefox for Android 58, frame-ancestors is ignored in Content-Security-Policy-Report-Only. |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.headers.Content-Security-Policy π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | Internet Explorer: Only supporting 'sandbox' directive. |
| http.headers.Content-Security-Policy.connect-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | Firefox: Before Firefox 50, ping attributes of <a> elements weren't covered by connect-src. |
| http.headers.Content-Security-Policy.default-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.font-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.frame-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.img-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.media-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.object-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.report-uri π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.sandbox π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.script-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy.style-src π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 | |
| http.headers.Content-Security-Policy-Report-Only π | Safari | 10/22/2013 | Edge | 8/2/2016 | 1015 |
| API | First Browser | Date | Last Browser | Date | Days | Notes |
|---|---|---|---|---|---|---|
| http.data-url π | Safari | 3/18/2008 | Edge | 7/29/2015 | 2689 | Edge: Before Edge 79, the maximum size supported is 4GB.Internet Explorer: Since Internet Explorer 9, the maximum size supported is 4GB.Internet Explorer: In Internet Explorer 8, the maximum size supported is 32kB. |
| http.data-url.css_files | Safari | 3/18/2008 | Edge | 7/29/2015 | 2689 | |
| http.data-url.js_files | Safari | 3/18/2008 | Edge | 7/29/2015 | 2689 | |
| http.headers.Accept π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | Firefox: In Firefox 66, the default Accept header value changed to */*.Firefox for Android: In Firefox for Android 66, the default Accept header value changed to */*. |
| http.headers.Accept-Encoding π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Accept-Language π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Accept-Ranges π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Access-Control-Allow-Credentials π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Access-Control-Allow-Headers π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Access-Control-Allow-Methods π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Access-Control-Allow-Origin π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Access-Control-Expose-Headers π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Access-Control-Max-Age π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Access-Control-Request-Headers π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Access-Control-Request-Method π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.Age π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Authorization π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Authorization.Basic π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Cache-Control π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Connection π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Content-Disposition π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | Chrome: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 352093465.Chrome Android: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 352093465.Firefox: From version 82, if an <a> element's download attribute is set (for a same-origin URL) then the inline directive is ignored. Earlier versions did not match the specification and respected the header directive over the attribute. See bug 1658877.Firefox for Android: From version 82, if an <a> element's download attribute is set (for a same-origin URL) then the inline directive is ignored. Earlier versions did not match the specification and respected the header directive over the attribute. See bug 1658877.Quest Browser: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 352093465.Opera: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 352093465.Opera Android: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 352093465.Safari: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 18384.Safari on iOS: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 18384.Samsung Internet: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 352093465.WebView Android: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 352093465.WebView on iOS: When saving documents, the document title is used instead of the filename parameter if the disposition type is inline. See bug 18384. |
| http.headers.Content-Encoding π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Content-Language π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Content-Length π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Content-Location π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Content-Range π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Content-Type π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Cookie π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | Safari: Cookies with Secure flag are not sent to unsecured http://localhost/ endpoints. See bug 281149.Safari on iOS: Cookies with Secure flag are not sent to unsecured http://localhost/ endpoints. See bug 281149.WebView on iOS: Cookies with Secure flag are not sent to unsecured http://localhost/ endpoints. See bug 281149. |
| http.headers.Date π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.ETag π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Expires π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.From π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Host π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.If-Match π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.If-Modified-Since π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.If-None-Match π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.If-Range π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.If-Unmodified-Since π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Keep-Alive π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Last-Modified π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Location π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Pragma π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Proxy-Authenticate π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Range π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Referer π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Refresh π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | Firefox: From version 136 the HTTP Referer header is sent following a refresh that redirects to another page (if permitted)Firefox for Android: From version 136 the HTTP Referer header is sent following a refresh that redirects to another page (if permitted) |
| http.headers.Sec-WebSocket-Accept π | Safari | 7/25/2012 | Edge | 7/29/2015 | 1099 | |
| http.headers.Sec-WebSocket-Extensions π | Safari | 7/25/2012 | Edge | 7/29/2015 | 1099 | |
| http.headers.Sec-WebSocket-Key π | Safari | 7/25/2012 | Edge | 7/29/2015 | 1099 | |
| http.headers.Sec-WebSocket-Protocol π | Safari | 7/25/2012 | Edge | 7/29/2015 | 1099 | |
| http.headers.Sec-WebSocket-Version π | Safari | 7/25/2012 | Edge | 7/29/2015 | 1099 | |
| http.headers.Server π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Set-Cookie π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | Safari: Cookies with Secure flag are not sent to unsecured http://localhost/ endpoints. See bug 281149.Safari on iOS: Cookies with Secure flag are not sent to unsecured http://localhost/ endpoints. See bug 281149.WebView on iOS: Cookies with Secure flag are not sent to unsecured http://localhost/ endpoints. See bug 281149. |
| http.headers.Set-Cookie.HttpOnly | Safari | 6/7/2010 | Edge | 7/29/2015 | 1878 | |
| http.headers.Set-Cookie.Max-Age | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Strict-Transport-Security π | Safari | 10/22/2013 | Edge | 7/29/2015 | 645 | |
| http.headers.TE π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Transfer-Encoding π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Upgrade π | Safari | 6/7/2010 | Edge | 7/29/2015 | 1878 | |
| http.headers.User-Agent π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Vary π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Via π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.WWW-Authenticate π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.WWW-Authenticate.Basic π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.WWW-Authenticate.Digest π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.WWW-Authenticate.Digest.md5 | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.Warning π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.headers.X-Frame-Options π | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | |
| http.headers.X-Frame-Options.SAMEORIGIN | Safari | 6/8/2009 | Edge | 7/29/2015 | 2242 | Chrome: Starting in Chrome 61, this applies to all of a frame's ancestors.Chrome Android: Starting in Chrome Android 61, this applies to all of a frame's ancestors.Firefox: Starting in Firefox 59, this applies to all of a frame's ancestors.Firefox for Android: Starting in Firefox for Android 59, this applies to all of a frame's ancestors.Quest Browser: Starting in Quest Browser 5.0, this applies to all of a frame's ancestors.Opera: Starting in Opera 48, this applies to all of a frame's ancestors.Opera Android: Starting in Opera Android 45, this applies to all of a frame's ancestors.Samsung Internet: Starting in Samsung Internet 8.0, this applies to all of a frame's ancestors.WebView Android: Starting in WebView Android 61, this applies to all of a frame's ancestors. |
| http.methods.CONNECT π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.methods.DELETE π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.methods.GET π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.methods.HEAD π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.methods.OPTIONS π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.methods.POST π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.methods.PUT π | Safari | 6/23/2003 | Edge | 7/29/2015 | 4419 | |
| http.status.308 π | Safari | 10/22/2013 | Edge | 7/29/2015 | 645 | Internet Explorer: Does not work below Windows 10. |