HTTP Headers for threads.net

Responds with HTTP 200 OK — 5 of 6 security headers present.

URL to Check
200 OKhttps://www.threads.net/
Security Headers5/6
HSTS
CSP
X-Frame-Options
X-Content-Type-Options
Referrer-Policy
Permissions-Policy
All Response Headers (28)
accept-chviewport-width,dpr,Sec-CH-Prefers-Color-Scheme,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Model
accept-ch-lifetime4838400
alt-svch3=":443"; ma=86400
cache-controlprivate, no-cache, no-store, must-revalidate
connectionclose
content-encodingbr
content-security-policydefault-src *.threads.com *.threads.net *.instagram.com *.facebook.com *.fbcdn.net blob:;script-src *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-FUa4mQ7y' blob: 'self' static.cdninstagram.com 'unsafe-eval';style-src data: blob: 'unsafe-inline' *.fbcdn.net *.threads.com *.threads.net *.facebook.com *.instagram.com static.cdninstagram.com;connect-src *.threads.com *.threads.net wss://*.threads.com:* wss://*.threads.net:* *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* ws://localhost:* blob: *.instagram.com *.cdninstagram.com wss://*.instagram.com:* 'self';font-src data: static.cdninstagram.com;img-src *.threads.com *.threads.net *.instagram.com *.facebook.com *.fbcdn.net *.cdninstagram.com data: blob: about.fb.com engineering.fb.com *.fbsbx.com android-webview-video-poster: pps.whatsapp.net *.oculuscdn.com *.tenor.co *.tenor.com *.giphy.com https://www.gstatic.com;media-src *.threads.com *.threads.net *.instagram.com *.facebook.com *.fbcdn.net *.cdninstagram.com data: blob: *.fbsbx.com android-webview-video-poster: *.tenor.co *.tenor.com https://*.giphy.com https://www.gstatic.com;child-src *.threads.com *.threads.net *.instagram.com *.facebook.com *.fbcdn.net data: blob:;frame-src *.fbsbx.com 'self';manifest-src *.threads.com *.threads.net *.instagram.com *.facebook.com *.fbcdn.net data: blob:;object-src *.threads.com *.threads.net *.instagram.com *.facebook.com *.fbcdn.net data: blob:;worker-src *.threads.com *.threads.net *.instagram.com *.facebook.com *.fbcdn.net data: blob:;block-all-mixed-content;upgrade-insecure-requests;
content-typetext/html; charset="utf-8"
cross-origin-embedder-policy-report-onlyrequire-corp;report-to="coep_report"
cross-origin-opener-policysame-origin-allow-popups
cross-origin-resource-policysame-origin
dateFri, 24 Apr 2026 10:08:02 GMT
document-policyforce-load-at-top, include-js-call-stacks-in-crash-reports
expiresSat, 01 Jan 2000 00:00:00 GMT
origin-agent-cluster?1
permissions-policyaccelerometer=(), attribution-reporting=(), autoplay=(), bluetooth=(), camera=(), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(), clipboard-write=(self), compute-pressure=(), display-capture=(), encrypted-media=(), fullscreen=(self), gamepad=(), geolocation=(self), gyroscope=(), hid=(), idle-detection=(), interest-cohort=(), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), otp-credentials=(), payment=(), picture-in-picture=(), private-state-token-issuance=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=();report-to="permissions_policy"
pragmano-cache
report-to{"max_age":2592000,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coop\/?minimize=0"}],"group":"coop_report","include_subdomains":true}, {"max_age":86400,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coep\/?minimize=0"}],"group":"coep_report"}, {"max_age":259200,"endpoints":[{"url":"https:\/\/www.threads.com\/ajax\/barcelona_error_reports\/?device_level=unknown&brsid=7632265466504866873&comet_app_key=122&cpp=C3&cv=1038061320&st=1777025281947"}]}, {"max_age":21600,"endpoints":[{"url":"https:\/\/www.threads.com\/ajax\/barcelona_error_reports\/"}],"group":"permissions_policy"}
reporting-endpointscoop_report="https://www.facebook.com/browser_reporting/coop/?minimize=0", coep_report="https://www.facebook.com/browser_reporting/coep/?minimize=0", default="https://www.threads.com/ajax/barcelona_error_reports/?device_level=unknown&brsid=7632265466504866873&comet_app_key=122&cpp=C3&cv=1038061320&st=1777025281947", permissions_policy="https://www.threads.com/ajax/barcelona_error_reports/"
set-cookiecsrftoken=pmFPP47EEsuZ-p3UJk-BJZ; expires=Sat, 29-May-2027 10:08:01 GMT; Max-Age=34560000; path=/; domain=.threads.net; secure
strict-transport-securitymax-age=31536000; preload; includeSubDomains
varyAccept-Encoding
x-content-type-optionsnosniff
x-fb-connection-qualityEXCELLENT; q=0.9, rtt=6, rtx=0, c=14, mss=1380, tbw=3714, tp=-1, tpl=-1, uplat=127, ullat=0
x-fb-debugKwps7vv7+JTMfLZVyxvo1KP6zqkQcA7xRh+n6JQv3x9Th7/JsEXSzuGQmbgxxoU72hKihvY2MzsMnaIiTYBMJA==
x-frame-optionsDENY
x-stackwww
x-xss-protection0
Related