field Registered
Verified 2026-09-18 · registry updated 2026-08-28

HTTP field: Sec-WebSocket-Accept

Sec-WebSocket-Accept is a registered field in the IANA HTTP Field Name Registry.

HTTP fields are message metadata; their meaning depends on direction, combination rules, and the HTTP version carrying them. Use Sec-WebSocket-Accept only according to its defining specification. Defining reference: RFC 6455: The WebSocket Protocol.

httpheaderfieldregistrypermanent

Registry-backed field entry. The field is currently marked registered by IANA. Defining reference: RFC 6455: The WebSocket Protocol.

Check whether the field is end-to-end or hop-by-hop, whether it varies a cache response, and whether it carries security-sensitive data before forwarding or logging it.

Check the linked specification for its direction, combination rules, caching behavior, and security considerations before generating or trusting it.

IANA registry: http-fields/field-names

Registry reference: RFC 6455: The WebSocket Protocol

Permalink: https://merginit.com/reference/http/field-registry-sec-websocket-accept