field Provisional
Verified 2026-09-18 · registry updated 2026-08-28

Timing-Allow-Origin

Allows selected origins to read detailed cross-origin Resource Timing data.

Use a narrow origin allowlist when exposing timing information; timing data can reveal resource behavior and endpoints.

httpheadercorsprivacy

Reference (http)

Timing-Allow-Origin: https://app.example.com

Use a narrow origin allowlist when exposing timing information; timing data can reveal resource behavior and endpoints.

Editorial status: this registry value is provisional. Review compatibility before deploying it and do not present it as a current default.

Common mistakes

  • Assuming CORS response access automatically exposes Resource Timing details.

IANA registry: http-fields/field-names

Registry reference: Resource Timing Level 1

Permalink: https://merginit.com/reference/http/field-timing-allow-origin