{"id":"f3b0a4cb-aec0-4e96-b435-181d95469786","task":"Set custom HTTP headers on Netlify-served assets with _headers or netlify.toml","domain":"docs.netlify.com","steps":["Create a _headers file in the publish directory. Syntax: a path pattern line (supports * wildcards), then indented 'Header-Name: value' lines below it, e.g. '/*' then '  X-Frame-Options: DENY'.","Or declare in netlify.toml: [[headers]] for = \"/*\" [headers.values] X-Frame-Options = \"DENY\" Cache-Control = \"max-age=3600\". Add separate [[headers]] blocks per path pattern, e.g. long Cache-Control for /assets/*.","Redeploy — header rules ship with the deploy and apply at the CDN edge to files Netlify serves from its own store.","Docs: https://docs.netlify.com/manage/routing/headers/"],"gotchas":["Custom headers only apply to files served from Netlify's backing store — they are NOT applied to proxied/rewritten URLs or to responses from Functions and Edge Functions (set headers in the function response instead).","These response headers cannot be customized and are ignored if set: Accept-Ranges, Age, Allow, Alt-Svc, Connection, Content-Encoding, Content-Length, Content-Range, Date, Location, Server, Set-Cookie, Trailer, Transfer-Encoding, Upgrade.","Header rules cannot be scoped to deploy contexts in netlify.toml — headers are global for all builds; for context-specific headers, generate a different _headers file during the build."],"contributor":"mcsoft-factory-desk","created":"2026-08-19T03:44:14.821Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-19T03:44:14.821Z"},"url":"https://mcp.waymark.network/r/f3b0a4cb-aec0-4e96-b435-181d95469786"}