Skip to main content

Request headers sent to your origin

When bunny.net fetches content from your origin, it forwards the visitor’s request headers and adds the headers below. Header names are case-insensitive. Origins that support HTTP/2 receive them in lowercase.

Headers added to every origin request

Compression

bunny.net replaces the visitor’s Accept-Encoding header on every request except POST requests and WebSocket upgrades, which keep the visitor’s value:
  • zstd, br, gzip when fetching compressible files, such as HTML, CSS, JavaScript, JSON, XML, SVG, fonts, documents and paths without a file extension, so your origin can return a compressed response.
  • identity for everything else, such as images, video, archives, range requests, and PUT, PATCH or DELETE requests.
  • If all compression types are disabled on your pull zone, bunny.net forwards the single encoding the visitor supports best: zstd, then br, then gzip.

Headers added by specific features

Origin Shield

With Origin Shield enabled, your origin is contacted by the Origin Shield location rather than the location that received the visitor’s request:
  • CDN-ServerId, CDN-ServerZone and CDN-ConnectionId describe the Origin Shield server.
  • CDN-LoopCount is 2.
  • CDN-RequestId is assigned by the Origin Shield location, so it differs from the CDN-RequestId the visitor receives.
  • X-Real-IP, X-Forwarded-For, CDN-RequestCountryCode, CDN-RequestStateCode, CDN-JA4 and CDN-Bot still describe the visitor.

Headers bunny.net changes or removes

bunny.net forwards the visitor’s other request headers unchanged, including User-Agent, Accept, Accept-Language, Referer, Cookie, Authorization and custom headers. These are changed or removed:
  • X-Forwarded-For, X-Real-IP and Via sent by the visitor are replaced.
  • Host and Accept-Encoding are replaced as described above.
  • Hop-by-hop headers (Connection, Keep-Alive, TE, Expect and Upgrade) are not forwarded, except for WebSocket upgrades.
  • For GET and HEAD requests, the visitor’s Range, If-Range, If-Match, If-Unmodified-Since, If-None-Match and If-Modified-Since headers are not forwarded, because bunny.net fetches and caches the response itself. HEAD requests are sent to your origin as GET.
  • Header names that contain an underscore (_) are dropped.
  • X-HTTP-Method-Override is forwarded only on POST requests.

Requests from other bunny.net services

  • Perma-Cache: on a Perma-Cache miss, Bunny Storage fetches the file from your origin with the same headers. A second, background request then copies the file into your Perma-Cache storage zone. Both come from Bunny Storage servers.
  • Prerender and Markdown conversion: the converter requests the page through bunny.net again, so your origin receives a normal origin request with the converter’s User-Agent.
  • Edge Scripting: requests made with fetch() in your script use the headers your script sets.

Notes

  • bunny.net does not send X-Forwarded-Host, X-Forwarded-Port, Forwarded or True-Client-IP. Use CDN-Host and X-Real-IP instead.
  • Treat the CDN-* headers that describe the visitor (country, state, JA4 fingerprint, bot) as informational, and don’t rely on them alone for access control.
Last modified on October 1, 2026