HTTP Headers for spotify.com

Responds with HTTP 200 OK from envoy — 3 of 6 security headers present.

URL to Check
200 OKhttps://open.spotify.com/
Security Headers3/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (18)
accept-rangesbytes
connectionclose
content-encodinggzip
content-security-policyscript-src 'self' 'unsafe-eval' blob: open.spotifycdn.com open-review.spotifycdn.com quicksilver.scdn.co www.google-analytics.com www.googletagmanager.com static.ads-twitter.com analytics.twitter.com s.pinimg.com sc-static.net https://www.google.com/recaptcha/ cdn.ravenjs.com connect.facebook.net www.gstatic.com sb.scorecardresearch.com pixel-static.spotify.com cdn.cookielaw.org geolocation.onetrust.com www.fastly-insights.com static.hotjar.com script.hotjar.com https://www.googleadservices.com/pagead/conversion_async.js https://www.googleadservices.com/pagead/conversion/ https://analytics.tiktok.com/i18n/pixel/sdk.js https://analytics.tiktok.com/i18n/pixel/identify.js https://analytics.tiktok.com/i18n/pixel/config.js https://www.redditstatic.com/ads/pixel.js https://t.contentsquare.net/uxa/22f14577e19f3.js https://get.microsoft.com/badge/ms-store-badge.bundled.js https://cdn.us.heap-api.com https://heapanalytics.com 'sha256-WfsTi7oVogdF9vq5d14s2birjvCglqWF842fyHhzoNw=' 'sha256-KRzjHxCdT8icNaDOqPBdY0AlKiIh5F8r4bnbe1PQwss=' 'sha256-Z5wh7XXSBR1+mTxLSPFhywCZJt77+uP1GikAgPIsu2s=' 'sha256-o2wzIImHJ4+WWE5DCTR+myWU0UNml0+wwpDXRo++vII='; frame-ancestors 'self' https://adgen-dev.spotify.com/account/*/ad/*/details https://adgen-dev.spotify.com/preview/* https://local.spotify.net/account/*/ad/*/details https://local.spotify.net/preview/* https://app.smartly.io/*;
content-typetext/html; charset=utf-8
dateFri, 24 Apr 2026 10:08:21 GMT
serverenvoy
set-cookiesp_landing=https%3A%2F%2Fopen.spotify.com%2F; Max-Age=86400; Path=/; Domain=.spotify.com; HttpOnly; Secure
strict-transport-securitymax-age=31536000
varyAccept-Encoding
viaHTTP/1.1 fringe, HTTP/2 edgeproxy, 1.1 google, 1.1 varnish
x-cacheMISS, MISS
x-cache-hits0, 0
x-content-type-optionsnosniff
x-envoy-upstream-service-time37
x-served-bycache-iad-kiad7000174-IAD, cache-iad-kjyo7100140-IAD
x-spotify-open-indextrue
x-timerS1777025301.082458,VS0,VE122
Related
HTTP Headers for spotify.com — envoy | ProfileMyIP