When bunny.net fetches content from your origin, it forwards the visitor’s request headers and adds the headers below. Header names are case-insensitive. Origins that support HTTP/2 receive them in lowercase.
Compression
bunny.net replaces the visitor’s Accept-Encoding header on every request except POST requests and WebSocket upgrades, which keep the visitor’s value:
zstd, br, gzip when fetching compressible files, such as HTML, CSS, JavaScript, JSON, XML, SVG, fonts, documents and paths without a file extension, so your origin can return a compressed response.
identity for everything else, such as images, video, archives, range requests, and PUT, PATCH or DELETE requests.
- If all compression types are disabled on your pull zone, bunny.net forwards the single encoding the visitor supports best:
zstd, then br, then gzip.
Origin Shield
With Origin Shield enabled, your origin is contacted by the Origin Shield location rather than the location that received the visitor’s request:
CDN-ServerId, CDN-ServerZone and CDN-ConnectionId describe the Origin Shield server.
CDN-LoopCount is 2.
CDN-RequestId is assigned by the Origin Shield location, so it differs from the CDN-RequestId the visitor receives.
X-Real-IP, X-Forwarded-For, CDN-RequestCountryCode, CDN-RequestStateCode, CDN-JA4 and CDN-Bot still describe the visitor.
bunny.net forwards the visitor’s other request headers unchanged, including User-Agent, Accept, Accept-Language, Referer, Cookie, Authorization and custom headers. These are changed or removed:
X-Forwarded-For, X-Real-IP and Via sent by the visitor are replaced.
Host and Accept-Encoding are replaced as described above.
- Hop-by-hop headers (
Connection, Keep-Alive, TE, Expect and Upgrade) are not forwarded, except for WebSocket upgrades.
- For GET and HEAD requests, the visitor’s
Range, If-Range, If-Match, If-Unmodified-Since, If-None-Match and If-Modified-Since headers are not forwarded, because bunny.net fetches and caches the response itself. HEAD requests are sent to your origin as GET.
- Header names that contain an underscore (
_) are dropped.
X-HTTP-Method-Override is forwarded only on POST requests.
Requests from other bunny.net services
- Perma-Cache: on a Perma-Cache miss, Bunny Storage fetches the file from your origin with the same headers. A second, background request then copies the file into your Perma-Cache storage zone. Both come from Bunny Storage servers.
- Prerender and Markdown conversion: the converter requests the page through bunny.net again, so your origin receives a normal origin request with the converter’s
User-Agent.
- Edge Scripting: requests made with
fetch() in your script use the headers your script sets.
Notes
- bunny.net does not send
X-Forwarded-Host, X-Forwarded-Port, Forwarded or True-Client-IP. Use CDN-Host and X-Real-IP instead.
- Treat the
CDN-* headers that describe the visitor (country, state, JA4 fingerprint, bot) as informational, and don’t rely on them alone for access control.
Last modified on October 1, 2026