Security Headers

Security headers tell browsers to enforce safer behavior.

They do not replace authentication, validation, or authorization, but they reduce common web risks.

Examples

Common security-related headers:

Helmet

Express apps often use Helmet:

import helmet from 'helmet'

app.use(helmet())

Helmet sets several useful security headers by default.

What headers help with

Security headers can reduce risk from:

Common mistake

Do not install Helmet and assume the app is secure.

Security also requires:

Interview answer

Security headers are HTTP headers that instruct browsers to apply safer behavior, such as preventing clickjacking, MIME sniffing, or unsafe resource loading. In Express, Helmet is commonly used to set many security headers, but it is only one part of application security.