field Provisional
Verified 2026-09-18 · registry updated
2026-08-28Timing-Allow-Origin
Allows selected origins to read detailed cross-origin Resource Timing data.
Use a narrow origin allowlist when exposing timing information; timing data can reveal resource behavior and endpoints.
httpheadercorsprivacy
Reference (http)
Timing-Allow-Origin: https://app.example.com
Use a narrow origin allowlist when exposing timing information; timing data can reveal resource behavior and endpoints.
Editorial status: this registry value is provisional. Review compatibility before deploying it and do not present it as a current default.
Common mistakes
- Assuming CORS response access automatically exposes Resource Timing details.
IANA registry: http-fields/field-names
Registry reference: Resource Timing Level 1