| [ Web Proxy ] |
| Viewing: https://developer.mozilla.org/docs/Web/HTTP/Headers/Server-Timing | [Back] [Original] |
Get to know MDN better
This feature is well established and works across many devices and browser versions. Its been available across browsers since March 2023.
* Some parts of this feature may have varying levels of support.
The HTTP Server-Timing response header communicates one or more performance metrics about the request-response cycle to the user agent.
It is used to surface backend server timing metrics (for example, database read/write, CPU time, file system access, etc.) in the developer tools in the user's browser or in the PerformanceServerTiming interface.
| Header type | Response header |
|---|
// A single metric
Server-Timing: <timing-metric>
// Multiple metrics as a comma-separated list
Server-Timing: <timing-metric>, , <timing-metricN>
A <timing-metric> has a name, and may include an optional duration and an optional description.
For example:
// A metric with a name only
Server-Timing: missedCache
// A metric with a duration
Server-Timing: cpu;dur=2.4
// A metric with a description and duration
Server-Timing: cache;desc="Cache Read";dur=23.2
// Two metrics with duration values
Server-Timing: db;dur=53, app;dur=47.2
<timing-metric>A comma-separated list of one or more metrics with the following components separated by semi-colons:
<name>A name token (no spaces or special characters) for the metric that is implementation-specific or defined by the server, like cacheHit.
<duration> OptionalA duration as the string dur, followed by =, followed by a value, like dur=23.2.
<description> OptionalA description as the string desc, followed by =, followed by a value as a token or a quoted string, like desc=prod or desc="DB lookup".
Names and descriptions should be kept as short as possible (for example, use abbreviations and omit optional values) to minimize HTTP data overhead.
The Server-Timing header may expose potentially sensitive application and infrastructure information.
Decide which metrics to send, when to send them, and who should see them based on the use case.
For example, you may decide to only show metrics to authenticated users and nothing on public responses.
In addition to having Server-Timing header metrics appear in the developer tools of the browser, the PerformanceServerTiming interface enables tools to automatically collect and process metrics from JavaScript. This interface is restricted to the same origin, but you can use the Timing-Allow-Origin header to specify the domains that are allowed to access the server metrics. The interface is only available in secure contexts (HTTPS) in some browsers.
The components of the Server-Timing header map to the PerformanceServerTiming properties as follows:
"name" -> PerformanceServerTiming.name"dur" -> PerformanceServerTiming.duration"desc" -> PerformanceServerTiming.descriptionThe following response includes a metric custom-metric with a duration of 123.45 milliseconds, and a description of "My custom metric":
Server-Timing: custom-metric;dur=123.45;desc="My custom metric"
In the following response, the Trailer header is used to indicate that a Server-Timing header will follow the response body.
A metric custom-metric with a duration of 123.4 milliseconds is sent.
HTTP/1.1 200 OK
Transfer-Encoding: chunked
Trailer: Server-Timing
--- response body ---
Server-Timing: custom-metric;dur=123.4
Warning:
Only the browser's DevTools can use the Server-Timing header as an HTTP trailer to display information in the Network -> Timings tab.
The Fetch API cannot access HTTP trailers.
See Browser compatibility for more information.
| Specification |
|---|
| Server Timing # the-server-timing-header-field |
PerformanceServerTimingTrailer headerThis page was last modified on Jul 28, 2026 by MDN contributors.
Reason: CORS disabledReason: CORS header 'Access-Control-Allow-Origin' does not match 'xyz'Reason: CORS header 'Access-Control-Allow-Origin' missingReason: CORS header 'Origin' cannot be addedReason: CORS preflight channel did not succeedReason: CORS request did not succeedReason: CORS request external redirect not allowedReason: CORS request not HTTPReason: Credential is not supported if the CORS header 'Access-Control-Allow-Origin' is '*'Reason: Did not find method in CORS header 'Access-Control-Allow-Methods'Reason: expected 'true' in CORS header 'Access-Control-Allow-Credentials'Reason: invalid token 'xyz' in CORS header 'Access-Control-Allow-Headers'Reason: invalid token 'xyz' in CORS header 'Access-Control-Allow-Methods'Reason: missing token 'xyz' in CORS header 'Access-Control-Allow-Headers' from CORS preflight channelReason: Multiple CORS header 'Access-Control-Allow-Origin' not allowedAcceptAccept-CHAccept-EncodingAccept-LanguageAccept-PatchAccept-PostAccept-RangesAccess-Control-Allow-CredentialsAccess-Control-Allow-HeadersAccess-Control-Allow-MethodsAccess-Control-Allow-OriginAccess-Control-Expose-HeadersAccess-Control-Max-AgeAccess-Control-Request-HeadersAccess-Control-Request-MethodActivate-Storage-AccessAgeAllowAlt-SvcAlt-UsedAttribution-Reporting-EligibleAttribution-Reporting-Register-SourceAttribution-Reporting-Register-TriggerAuthorizationAvailable-DictionaryCache-ControlClear-Site-DataConnectionContent-DigestContent-DispositionContent-DPRContent-EncodingContent-LanguageContent-LengthContent-LocationContent-RangeContent-Security-PolicyContent-Security-Policy-Report-OnlyContent-TypeCookieCritical-CHCross-Origin-Embedder-PolicyCross-Origin-Embedder-Policy-Report-OnlyCross-Origin-Opener-PolicyCross-Origin-Resource-PolicyDateDevice-MemoryDictionary-IDDNTDownlinkDPREarly-DataECTETagExpectExpect-CTExpiresForwardedFromHostIdempotency-KeyIf-MatchIf-Modified-SinceIf-None-MatchIf-RangeIf-Unmodified-SinceIntegrity-PolicyIntegrity-Policy-Report-OnlyKeep-AliveLast-ModifiedLinkLocationMax-ForwardsNELNo-Vary-SearchObserve-Browsing-TopicsOriginOrigin-Agent-ClusterPermissions-PolicyPermissions-Policy-Report-OnlyPragmaPreferPreference-AppliedPriorityProxy-AuthenticateProxy-AuthorizationRangeRefererReferrer-PolicyRefreshReport-ToReporting-EndpointsRepr-DigestRetry-AfterRTTSave-DataSec-Browsing-TopicsSec-CH-Device-MemorySec-CH-DPRSec-CH-Prefers-Color-SchemeSec-CH-Prefers-Reduced-MotionSec-CH-Prefers-Reduced-TransparencySec-CH-UASec-CH-UA-ArchSec-CH-UA-BitnessSec-CH-UA-Form-FactorsSec-CH-UA-Full-VersionSec-CH-UA-Full-Version-ListSec-CH-UA-MobileSec-CH-UA-ModelSec-CH-UA-PlatformSec-CH-UA-Platform-VersionSec-CH-UA-WoW64Sec-CH-Viewport-HeightSec-CH-Viewport-WidthSec-CH-WidthSec-Fetch-DestSec-Fetch-ModeSec-Fetch-SiteSec-Fetch-Storage-AccessSec-Fetch-UserSec-GPCSec-Private-State-TokenSec-Private-State-Token-Crypto-VersionSec-Private-State-Token-LifetimeSec-PurposeSec-Redemption-RecordSec-Speculation-TagsSec-WebSocket-AcceptSec-WebSocket-ExtensionsSec-WebSocket-KeySec-WebSocket-ProtocolSec-WebSocket-VersionServerServer-TimingService-WorkerService-Worker-AllowedService-Worker-Navigation-PreloadSet-CookieSet-LoginSourceMapSpeculation-RulesStrict-Transport-SecuritySupports-Loading-ModeTETiming-Allow-OriginTkTrailerTransfer-EncodingUpgradeUpgrade-Insecure-RequestsUse-As-DictionaryUser-AgentVaryViaViewport-WidthWant-Content-DigestWant-Repr-DigestWarningWidthWWW-AuthenticateX-Content-Type-OptionsX-DNS-Prefetch-ControlX-Forwarded-ForX-Forwarded-HostX-Forwarded-ProtoX-Frame-OptionsX-Permitted-Cross-Domain-PoliciesX-Powered-ByX-Robots-TagX-XSS-Protection100 Continue101 Switching Protocols102 Processing103 Early Hints200 OK201 Created202 Accepted203 Non-Authoritative Information204 No Content205 Reset Content206 Partial Content207 Multi-Status208 Already Reported226 IM Used300 Multiple Choices301 Moved Permanently302 Found303 See Other304 Not Modified307 Temporary Redirect308 Permanent Redirect400 Bad Request401 Unauthorized402 Payment Required403 Forbidden404 Not Found405 Method Not Allowed406 Not Acceptable407 Proxy Authentication Required408 Request Timeout409 Conflict410 Gone411 Length Required412 Precondition Failed413 Content Too Large414 URI Too Long415 Unsupported Media Type416 Range Not Satisfiable417 Expectation Failed418 I'm a teapot421 Misdirected Request422 Unprocessable Content423 Locked424 Failed Dependency425 Too Early426 Upgrade Required428 Precondition Required429 Too Many Requests431 Request Header Fields Too Large451 Unavailable For Legal Reasons500 Internal Server Error501 Not Implemented502 Bad Gateway503 Service Unavailable504 Gateway Timeout505 HTTP Version Not Supported506 Variant Also Negotiates507 Insufficient Storage508 Loop Detected510 Not Extended511 Network Authentication Requiredbase-uriblock-all-mixed-contentchild-srcconnect-srcdefault-srcfenced-frame-srcfont-srcform-actionframe-ancestorsframe-srcimg-srcmanifest-srcmedia-srcobject-srcprefetch-srcreport-toreport-urirequire-trusted-types-forsandboxscript-srcscript-src-attrscript-src-elemstyle-srcstyle-src-attrstyle-src-elemtrusted-typesupgrade-insecure-requestsworker-srcaccelerometerambient-light-sensoraria-notifyattribution-reportingautoplaybluetoothbrowsing-topicscameracaptured-surface-controlch-ua-high-entropy-valuescompute-pressurecross-origin-isolateddeferred-fetchdeferred-fetch-minimaldisplay-captureencrypted-mediafullscreengamepadgeolocationgyroscopehididentity-credentials-getidle-detectionlanguage-detectorlanguage-modellocal-fontslocal-networklocal-network-accessloopback-networkmagnetometermicrophonemidion-device-speech-recognitionotp-credentialspaymentpicture-in-pictureprivate-state-token-issuanceprivate-state-token-redemptionpublickey-credentials-createpublickey-credentials-getscreen-wake-lockserialspeaker-selectionstorage-accesssummarizertranslatorusbweb-sharewindow-managementxr-spatial-trackingYour blueprint for a better internet.
Portions of this content are 19982026 by individual mozilla.org contributors. Content available under a Creative Commons license.
| Web Proxy Viewer | New URL | Original Page |