https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Compression_dictionary_transport * Skip to main content * Skip to search * Skip to select language Open main menu * ReferencesReferences + Overview / Web Technology Web technology reference for developers + HTML Structure of content on the web + CSS Code used to describe document style + JavaScript General-purpose scripting language + HTTP Protocol for transmitting web resources + Web APIs Interfaces for building web applications + Web Extensions Developing extensions for web browsers + Accessibility Build web projects usable for all + Web Technology Web technology reference for developers * LearnLearn + Overview / MDN Learning Area Learn web development + MDN Learning Area Learn web development + HTML Learn to structure web content with HTML + CSS Learn to style content using CSS + JavaScript Learn to run scripts in the browser + Accessibility Learn to make the web accessible to all * PlusPlus + Overview A customized MDN experience + AI Help Get real-time assistance and support + Updates All browser compatibility updates at a glance + Documentation Learn how to use MDN Plus + FAQ Frequently asked questions about MDN Plus * Curriculum ^New * Blog * Tools + Playground Write, test and share your code + HTTP Observatory Scan a website for free + AI Help Get real-time assistance and support Search MDN[ ]Clear search inputSearch Theme * Log in * Sign up for free 1. References 2. HTTP 3. Guides 4. Compression Dictionary Transport Article Actions * English (US) + [ ]Remember language + Deutsch Filter sidebar[ ]Clear filter input In this article * Overview * Dictionary format * Existing resource as a dictionary * Separate dictionary * Creating dictionary-compressed responses * Restrictions * Specifications * Browser compatibility * See also 1. HTTP 2. Guides 3. Overview of HTTP 4. Evolution of HTTP 5. A typical HTTP session 6. HTTP messages 7. Media types 1. Common types 8. Compression in HTTP 9. HTTP caching 10. HTTP authentication 11. Using HTTP cookies 12. Redirections in HTTP 13. Conditional requests 14. Range requests 15. Client hints 16. Compression Dictionary Transport Experimental 17. Network Error Logging Experimental 18. Content negotiation 1. Default Accept values 19. Browser detection using the UA string 20. Connection management in HTTP/1.x 21. Protocol upgrade mechanism 22. Proxy servers and tunneling 1. Proxy Auto-Configuration (PAC) file 23. Security and privacy 1. HTTP Observatory 2. Practical implementation guides 3. Permissions Policy Experimental 4. Cross-Origin Resource Policy (CORP) 5. Cross-Origin Resource Sharing (CORS) 6. CORS errors 1. Reason: CORS disabled 2. Reason: CORS header 'Access-Control-Allow-Origin' does not match 'xyz' 3. Reason: CORS header 'Access-Control-Allow-Origin' missing 4. Reason: CORS header 'Origin' cannot be added 5. Reason: CORS preflight channel did not succeed 6. Reason: CORS request did not succeed 7. Reason: CORS request external redirect not allowed 8. Reason: CORS request not HTTP 9. Reason: Credential is not supported if the CORS header 'Access-Control-Allow-Origin' is '*' 10. Reason: Did not find method in CORS header 'Access-Control-Allow-Methods' 11. Reason: expected 'true' in CORS header 'Access-Control-Allow-Credentials' 12. Reason: invalid token 'xyz' in CORS header 'Access-Control-Allow-Headers' 13. Reason: invalid token 'xyz' in CORS header 'Access-Control-Allow-Methods' 14. Reason: missing token 'xyz' in CORS header 'Access-Control-Allow-Headers' from CORS preflight channel 15. Reason: Multiple CORS header 'Access-Control-Allow-Origin' not allowed 7. Content Security Policy (CSP) 1. Errors and warnings 24. Reference 25. HTTP headers 1. Accept 2. Accept-CH 3. Accept-Encoding 4. Accept-Language 5. Accept-Patch 6. Accept-Post 7. Accept-Ranges 8. Access-Control-Allow-Credentials 9. Access-Control-Allow-Headers 10. Access-Control-Allow-Methods 11. Access-Control-Allow-Origin 12. Access-Control-Expose-Headers 13. Access-Control-Max-Age 14. Access-Control-Request-Headers 15. Access-Control-Request-Method 16. Age 17. Allow 18. Alt-Svc 19. Alt-Used 20. Attribution-Reporting-Eligible Experimental 21. Attribution-Reporting-Register-Source Experimental 22. Attribution-Reporting-Register-Trigger Experimental 23. Authorization 24. Available-Dictionary Experimental 25. Cache-Control 26. Clear-Site-Data 27. Connection 28. Content-Digest 29. Content-Disposition 30. Content-DPR Non-standard Deprecated 31. Content-Encoding 32. Content-Language 33. Content-Length 34. Content-Location 35. Content-Range 36. Content-Security-Policy 37. Content-Security-Policy-Report-Only 38. Content-Type 39. Cookie 40. Critical-CH Experimental 41. Cross-Origin-Embedder-Policy 42. Cross-Origin-Opener-Policy 43. Cross-Origin-Resource-Policy 44. Date 45. Device-Memory 46. Dictionary-ID Experimental 47. DNT Non-standard Deprecated 48. Downlink Experimental 49. DPR Non-standard Deprecated 50. Early-Data Experimental 51. ECT Experimental 52. ETag 53. Expect 54. Expect-CT Deprecated 55. Expires 56. Forwarded 57. From 58. Host 59. If-Match 60. If-Modified-Since 61. If-None-Match 62. If-Range 63. If-Unmodified-Since 64. Integrity-Policy 65. Integrity-Policy-Report-Only 66. Keep-Alive 67. Last-Modified 68. Link 69. Location 70. Max-Forwards 71. NEL Experimental 72. No-Vary-Search Experimental 73. Observe-Browsing-Topics Experimental Non-standard 74. Origin 75. Origin-Agent-Cluster 76. Permissions-Policy Experimental 77. Pragma Deprecated 78. Prefer 79. Preference-Applied 80. Priority 81. Proxy-Authenticate 82. Proxy-Authorization 83. Range 84. Referer 85. Referrer-Policy 86. Refresh 87. Report-To Non-standard Deprecated 88. Reporting-Endpoints 89. Repr-Digest 90. Retry-After 91. RTT Experimental 92. Save-Data Experimental 93. Sec-Browsing-Topics Experimental Non-standard 94. Sec-CH-Prefers-Color-Scheme Experimental 95. Sec-CH-Prefers-Reduced-Motion Experimental 96. Sec-CH-Prefers-Reduced-Transparency Experimental 97. Sec-CH-UA Experimental 98. Sec-CH-UA-Arch Experimental 99. Sec-CH-UA-Bitness Experimental 100. Sec-CH-UA-Form-Factors Experimental 101. Sec-CH-UA-Full-Version Deprecated 102. Sec-CH-UA-Full-Version-List Experimental 103. Sec-CH-UA-Mobile Experimental 104. Sec-CH-UA-Model Experimental 105. Sec-CH-UA-Platform Experimental 106. Sec-CH-UA-Platform-Version Experimental 107. Sec-CH-UA-WoW64 Experimental 108. Sec-Fetch-Dest 109. Sec-Fetch-Mode 110. Sec-Fetch-Site 111. Sec-Fetch-User 112. Sec-GPC Experimental 113. Sec-Purpose 114. Sec-Speculation-Tags Experimental 115. Sec-WebSocket-Accept 116. Sec-WebSocket-Extensions 117. Sec-WebSocket-Key 118. Sec-WebSocket-Protocol 119. Sec-WebSocket-Version 120. Server 121. Server-Timing 122. Service-Worker 123. Service-Worker-Allowed 124. Service-Worker-Navigation-Preload 125. Set-Cookie 126. Set-Login 127. SourceMap 128. Speculation-Rules Experimental 129. Strict-Transport-Security 130. Supports-Loading-Mode Experimental 131. TE 132. Timing-Allow-Origin 133. Tk Non-standard Deprecated 134. Trailer 135. Transfer-Encoding 136. Upgrade 137. Upgrade-Insecure-Requests 138. Use-As-Dictionary Experimental 139. User-Agent 140. Vary 141. Via 142. Viewport-Width Non-standard Deprecated 143. Want-Content-Digest 144. Want-Repr-Digest 145. Warning Deprecated 146. Width Non-standard Deprecated 147. WWW-Authenticate 148. X-Content-Type-Options 149. X-DNS-Prefetch-Control Non-standard 150. X-Forwarded-For Non-standard 151. X-Forwarded-Host Non-standard 152. X-Forwarded-Proto Non-standard 153. X-Frame-Options 154. X-Permitted-Cross-Domain-Policies Non-standard 155. X-Powered-By Non-standard 156. X-Robots-Tag Non-standard 157. X-XSS-Protection Non-standard Deprecated 26. HTTP request methods 1. CONNECT 2. DELETE 3. GET 4. HEAD 5. OPTIONS 6. PATCH 7. POST 8. PUT 9. TRACE 27. HTTP response status codes 1. 100 Continue 2. 101 Switching Protocols 3. 102 Processing 4. 103 Early Hints 5. 200 OK 6. 201 Created 7. 202 Accepted 8. 203 Non-Authoritative Information 9. 204 No Content 10. 205 Reset Content 11. 206 Partial Content 12. 207 Multi-Status 13. 208 Already Reported 14. 226 IM Used 15. 300 Multiple Choices 16. 301 Moved Permanently 17. 302 Found 18. 303 See Other 19. 304 Not Modified 20. 307 Temporary Redirect 21. 308 Permanent Redirect 22. 400 Bad Request 23. 401 Unauthorized 24. 402 Payment Required 25. 403 Forbidden 26. 404 Not Found 27. 405 Method Not Allowed 28. 406 Not Acceptable 29. 407 Proxy Authentication Required 30. 408 Request Timeout 31. 409 Conflict 32. 410 Gone 33. 411 Length Required 34. 412 Precondition Failed 35. 413 Content Too Large 36. 414 URI Too Long 37. 415 Unsupported Media Type 38. 416 Range Not Satisfiable 39. 417 Expectation Failed 40. 418 I'm a teapot 41. 421 Misdirected Request 42. 422 Unprocessable Content 43. 423 Locked 44. 424 Failed Dependency 45. 425 Too Early 46. 426 Upgrade Required 47. 428 Precondition Required 48. 429 Too Many Requests 49. 431 Request Header Fields Too Large 50. 451 Unavailable For Legal Reasons 51. 500 Internal Server Error 52. 501 Not Implemented 53. 502 Bad Gateway 54. 503 Service Unavailable 55. 504 Gateway Timeout 56. 505 HTTP Version Not Supported 57. 506 Variant Also Negotiates 58. 507 Insufficient Storage 59. 508 Loop Detected 60. 510 Not Extended 61. 511 Network Authentication Required 28. CSP directives 1. base-uri 2. block-all-mixed-content Deprecated 3. child-src 4. connect-src 5. default-src 6. fenced-frame-src Experimental 7. font-src 8. form-action 9. frame-ancestors 10. frame-src 11. img-src 12. manifest-src 13. media-src 14. object-src 15. prefetch-src Non-standard Deprecated 16. report-to 17. report-uri Deprecated 18. require-trusted-types-for 19. sandbox 20. script-src 21. script-src-attr 22. script-src-elem 23. style-src 24. style-src-attr 25. style-src-elem 26. trusted-types 27. upgrade-insecure-requests 28. worker-src 29. Permissions-Policy directives Experimental 1. accelerometer Experimental 2. ambient-light-sensor Experimental 3. attribution-reporting Experimental 4. autoplay Experimental 5. bluetooth Experimental 6. browsing-topics Experimental Non-standard 7. camera Experimental 8. compute-pressure Experimental 9. cross-origin-isolated Experimental 10. deferred-fetch Experimental 11. deferred-fetch-minimal Experimental 12. display-capture Experimental 13. encrypted-media Experimental 14. fullscreen Experimental 15. gamepad Experimental 16. geolocation Experimental 17. gyroscope Experimental 18. hid Experimental 19. identity-credentials-get Experimental 20. idle-detection Experimental 21. language-detector Experimental 22. local-fonts Experimental 23. magnetometer Experimental 24. microphone Experimental 25. midi Experimental 26. otp-credentials Experimental 27. payment Experimental 28. picture-in-picture Experimental 29. publickey-credentials-create Experimental 30. publickey-credentials-get Experimental 31. screen-wake-lock Experimental 32. serial Experimental 33. speaker-selection Experimental 34. storage-access Experimental 35. summarizer Experimental 36. translator Experimental 37. usb Experimental 38. web-share Experimental 39. window-management Experimental 40. xr-spatial-tracking Experimental 30. HTTP resources and specifications In this article * Overview * Dictionary format * Existing resource as a dictionary * Separate dictionary * Creating dictionary-compressed responses * Restrictions * Specifications * Browser compatibility * See also Compression Dictionary Transport Experimental: This is an experimental technology Check the Browser compatibility table carefully before using this in production. Compression Dictionary Transport is a way of using a shared compression dictionary to dramatically reduce the transport size of HTTP responses. Overview Compression algorithms are used in HTTP to reduce the size of resources downloaded over the network, reducing bandwidth cost and the time taken to load pages. Lossless HTTP compression algorithms work by finding redundancy in the source: for example, places where text like the string "function" is repeated. They then include just one copy of the redundant string, and replace occurrences of it in the resource with references to that copy. Since the references are shorter than the string, the compressed version is shorter. Note: A previous attempt at this technology was called SDCH (Shared Dictionary Compression for HTTP) but was never widely supported and was removed in 2017. Compression Dictionary Transport is a better-specified and more robust implementation with broader industry consensus. For example, take this JavaScript: js function a() { console.log("Hello World!"); } function b() { console.log("I am here"); } This could be compressed by replacing repeated strings with references to a previous location and number of characters, like this: function a() { console.log("Hello World!"); } [0:9]b[10:20]I am here[42:46] In this example, [0:9] refers to copying the 9 characters starting at character 0. Note this is a simplified example to demonstrate the concept and the actual algorithms are more complex than this. Clients can then reverse the compression after download to recreate the original, uncompressed resource. Compression dictionaries Algorithms like Brotli compression and Zstandard compression achieve even greater efficiency by allowing the use of dictionaries of commonly encountered strings, so you don't need any copies of them in the compressed resource. These algorithms ship with a predefined default dictionary that is used when compressing HTTP responses. Compression Dictionary Transport builds on this by enabling you to provide your own dictionary which is especially applicable to a particular set of resources. The compression algorithm can then reference it as a source of bytes when compressing and decompressing the resource. Assuming the references from the previous example are included in that common dictionary, this could be further reduced to this: [d0:9]a[d10:20]Hello World![d42:46] [d0:9]b[d10:20]I am here[d42:46] The dictionary can either be a separate resource that is only required for Compression Dictionary Transport, or it can be a resource that the website needs anyway. For example, suppose your website uses a JavaScript library. You would typically load a specific version of the library, and might include the version name in the name of the library, like