> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Headers and network

> Configure CORS, Host and static headers, compression, methods, WebSockets, gRPC, and rate limiting.

## Request and response headers

| Control | Use |
| - | - |
| CORS | Send `Access-Control-Allow-Origin` for all origins, listed origins, or reflected origins |
| Custom Host header | Send a fixed Host value or forward the visitor's Host header |
| Static request headers | Add fixed headers before the request reaches the origin |
| Static response headers | Add fixed headers to edge responses; `always` includes error responses |
| Response header policy | Hide all except a list, or show all except a list |

Do not place secrets in static request headers when console users without secret-handling responsibility can read distribution configuration.

## Compression

* Gzip compresses eligible content for compatible clients.
* Brotli requires a MIME type list and, in this platform configuration, Origin Shield.
* Pull pre-compressed content retrieves prebuilt compressed variants from the origin.

Brotli cannot be combined with pull pre-compressed content. When Brotli is enabled, include `text/html` in its MIME type list.

## Protocols and methods

Explicitly enable allowed HTTP methods. GET, HEAD, and OPTIONS cover most delivery workloads. Enable write methods only when the origin and cache policy are designed for them.

WebSocket support permits connection upgrades. gRPC passthrough permits gRPC traffic where the origin and hostname configuration support it.

## Bandwidth limiting

Static limits use configured speed and buffer values. Dynamic limits derive behavior from query parameters. Validate that a client cannot bypass or amplify a dynamic policy by modifying the URL.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.