Headers

Headers

Name Value Status
Status 302 No
Content-Type application/binary Yes
Vary Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site Yes
Cache-Control no-cache, no-store, max-age=0, must-revalidate Yes
Pragma no-cache Yes
Expires Mon, 01 Jan 1990 00:00:00 GMT Yes
Date Fri, 07 Aug 2026 10:32:49 GMT Yes
Location https://accounts.google.com/ServiceLogin?passive=1209600&osid=1&continue=https://docs.google.com/&followup=https://docs.google.com/&emr=1 Yes
P3p CP="This is not a P3P policy! See g.co/p3phelp for more info." Yes
Strict-Transport-Security max-age=31536000 Yes
Cross-Origin-Resource-Policy same-site Yes
Accept-Ch Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version Yes
Cross-Origin-Opener-Policy same-origin Yes
Permissions-Policy ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=* Yes
Content-Security-Policy script-src 'report-sample' 'nonce-yVddnpX0PKa_fUhe43KKTQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DocsHomeRedirectHttp/cspreport;worker-src 'self' Yes
Content-Security-Policy script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DocsHomeRedirectHttp/cspreport/allowlist Yes
Content-Security-Policy require-trusted-types-for 'script';report-uri /_/DocsHomeRedirectHttp/cspreport Yes
Server ESF Yes
Content-Length 0 Yes
X-Xss-Protection 0 Yes
X-Frame-Options SAMEORIGIN Yes
X-Content-Type-Options nosniff Yes
Set-Cookie NID=[redacted]; expires=Sat, 06-Feb-2027 10:32:49 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none Yes
Alt-Svc h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Yes

Test Another Page

This page temporarily (302) redirects. See below for the new Location.

Raw Headers

HTTP/2 302 
content-type: application/binary
vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site
cache-control: no-cache, no-store, max-age=0, must-revalidate
pragma: no-cache
expires: Mon, 01 Jan 1990 00:00:00 GMT
date: Fri, 07 Aug 2026 10:32:49 GMT
location: https://accounts.google.com/ServiceLogin?passive=1209600&osid=1&continue=https://docs.google.com/&followup=https://docs.google.com/&emr=1
p3p: CP="This is not a P3P policy! See g.co/p3phelp for more info."
strict-transport-security: max-age=31536000
cross-origin-resource-policy: same-site
accept-ch: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
cross-origin-opener-policy: same-origin
permissions-policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
content-security-policy: script-src 'report-sample' 'nonce-yVddnpX0PKa_fUhe43KKTQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DocsHomeRedirectHttp/cspreport;worker-src 'self'
content-security-policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DocsHomeRedirectHttp/cspreport/allowlist
content-security-policy: require-trusted-types-for 'script';report-uri /_/DocsHomeRedirectHttp/cspreport
server: ESF
content-length: 0
x-xss-protection: 0
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
Set-Cookie: NID=[redacted]; expires=Sat, 06-Feb-2027 10:32:49 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
alt-svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000