Resta saysRequest headers carry metadata: what you accept, who you are, and what you’re sending.
Headers configure the request. Accept states the format you want; Content-Type describes the body you're sending; Authorization carries credentials (e.g. Bearer <token>); User-Agent identifies the client. They're key:value pairs the server reads to decide how to handle you.
Power-ups you unlock
Accept: desired response format
Content-Type: format of your body
Authorization: credentials (Bearer token)
Headers are request metadata
The 401 Bandit attacks — common mistakes
Missing Content-Type on a JSON body
Putting secrets in the URL instead of Authorization
Forgetting Accept and getting an unexpected format
Boss battleWrite the headers for a JSON POST with a bearer token.