---
sourceDocument: Brazil ServiceNow AI Platform Capabilities
sourceDocumentLink: https://www.servicenow.com/docs/r/servicenow-platform

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# HTTP Response Headers

# HTTP Response Headers {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of HTTP Response Headers

HTTP response headers are name-value pairs included in HTTP responses to convey additional information about page content or instruct clients on how to handle that content.
In the ServiceNow AI Platform, you can configure HTTP response headers globally or for specific page types such as Service Portal, UI Pages, or UX applications.
This capability enables browsers and other clients to perform special handling of page content, improving security and functionality.
Show full answer Show less  

## Configuring HTTP Response Headers

You can define HTTP response headers by specifying their name-value pairs according to the HTTP header standards. It is important to refer to the official HTTP header definitions to understand how the client will process these headers. For example, configuring a **Content-Security-Policy: frame-ancestors** header controls which URLs are permitted to embed your pages in frames.

Once configured, you can verify the headers in browsers like Chrome using Developer Tools under the Response Headers section.

**Security caution:** When using custom name-value pairs or URLs in headers, proceed carefully because improper configurations can introduce security risks or override ServiceNow AI Platform's signed security assurances.

If you want to disable all custom HTTP response header configurations, set the system property `glide.http.headersconfig.enabled` to `false`. This disables use of header configurations defined in the `sysresponseheader` table.

## Special Handling of Content-Security-Policy and Frame-Ancestors Header

By default, the ServiceNow AI Platform includes the **X-Frame-Options: SAMEORIGIN** header to restrict framing to the same origin, controlled by the `glide.setxframeoptions` global property (enabled by default).

If you configure a **Content-Security-Policy: frame-ancestors 'self' URL1 URL2** header, the platform will automatically omit the `X-Frame-Options: SAMEORIGIN` header to avoid conflicts since the frame-ancestors directive already enforces similar framing restrictions.

## Internet Explorer Compatibility

Internet Explorer does not support the **Content-Security-Policy: frame-ancestors** header. Instead, it only supports the **X-Frame-Options: ALLOW-FROM URL** directive, which allows framing from a single URL.

When a frame-ancestors header with multiple URLs is configured and the client is Internet Explorer, the ServiceNow AI Platform automatically substitutes `X-Frame-Options: ALLOW-FROM URL` as follows:

* If the IE request includes a referrer URL, the platform attempts to match it against the configured URLs (including wildcard hostnames) and uses the matching URL.
* If no referrer is present, it uses the first non-wildcard URL from the frame-ancestors list.

**Configuration note:** When specifying URLs in the frame-ancestors header, do not include a trailing slash, as this can cause the special handling to fail. For example, use `https://microsoft.com` rather than `https://microsoft.com/`.

## Practical Benefits for ServiceNow Customers

* Enable precise control over how browsers and clients handle your pages, improving security and compliance with content policies.
* Support embedding pages securely in frames from specified trusted domains, with automatic adjustments for Internet Explorer compatibility.
* Maintain control over HTTP response headers centrally, with the option to disable custom headers if needed to preserve platform security guarantees.
* Diagnose and verify header behavior easily using browser developer tools.  
A response header is a simple name-value pair used in an HTTP response to provide
additional information about page content or how the client should process it.

You can configure HTTP response headers for all, or specific types of pages, which include Service Portal, UI Page, or UX applications. The ability to configure and pass
response headers enables special handling of the page content by a client, most typically a
browser.

To learn more about what an HTTP header is, and about configuring the name-value pair for
specific HTTP response headers, see:<https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers>  
When configuring response headers, you must look at the definition for the HTTP header to determine how the client would handle the page content.

* For example, you configure an HTTP header for a specific page or all the pages with a Content-Security-Policy: frame-ancestors 'self' https://www.servicenow.com.
* When you invoke the page in a browser such as Chrome, you can review it in the Response Headers section of Chrome Developer Tools.

{#http-response-header__ul_pfr_cn2_14b}

To learn more about how browsers handle a page with frame-ancestors, see <https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors>.  
Warning:  
When using URLs with custom name-value pairs, proceed with caution because there is a potential security risk when doing so. The signed security amendment to the ServiceNow AI Platform contract has implied security. You may potentially or accidentally override it when you use custom name-value pairs in the resulting URLs.

* If you want to entirely disable HTTP response header configuration functions, set the glide.http.headers_config.enabled property to false.
* Once you set it to false, ServiceNow AI Platform does not use any of the header configurations you defined in the sys_response_header table.
{#http-response-header__ul_njb_pbm_14b}

## Special handling of the Content-Security-Policy: frame-ancestor header {#http-response-header__section_my5_351_14b}

Normally, the ServiceNow AI Platform automatically includes the X-Frame-Options: SAMEORIGIN header.

* It supports use of this header in all types of browsers, based on the setting of the glide.set_x_frame_options global property, which is enabled by default.
* When you configure a page with a Content-Security-Policy: frame-ancestor 'self' URL1 URL2 header, the ServiceNow AI Platform does not automatically include the X-Frame-Options: SAMEORIGIN header. Excluding it prevents the browser from being confused, because Content-Security-Policy: frame-ancestor 'self' already has a similar effect.
{#http-response-header__ul_e1f_lbm_14b}

## Special handling of Content-Security-Policy: frame-ancestor header for Internet
Explorer {#http-response-header__section_ny5_351_14b}

Using the Content-Security-Policy: frame-ancestor 'self' URL1 URL2 header enables you to configure multiple URL sources to include the page from within an iFrame rendered from a third-party site. However, Internet Explorer does not support this type of header.

* Instead, the Internet Explorer only supports the X-Frame-Options: ALLOW-FROM URL (ALLOW-FROM) directive in this header, although the restriction is for a single host URL.
* If you configure the frame-ancestor 'self' URL1 URL2 header, and Internet Explorer is in use, the ServiceNow AI Platform automatically uses the X-Frame-Options: ALLOW-FROM URL (ALLOW-FROM) header instead.
{#http-response-header__ul_ykg_xk2_14b}  
If the Internet Explorer request includes the referrer URL header:

* It attempts to match it with the host URLs (full or wildcard http://\*.example.com type URL format only) configured in the Content-Security-Policy: frame-ancestor 'self' URL1 URL2 header.
* If there is a match, include the matched URL as X-Frame-Options: ALLOW-FROM URL1.
* If there is no referrer header, it uses the first non-wildcard based host URLs configured in the Content-Security-Policy: frame-ancestor 'self' URL1 URL2 header.

{#http-response-header__ul_qf5_2l2_14b}  
Note:  
When configuring URLs, do not include a forward slash at the end of the URL.

* This example of an incorrect configuration that may not work properly with this special handling:
  * Name: Content-Security-Policy
  * Value: frame-ancestors 'self' https://microsoft.com/
  {#http-response-header__ul_bgt_53r_nsb}
* Use this correct syntax instead:
  * Name: Content-Security-Policy
  * Value: frame-ancestors 'self' https://microsoft.com
  {#http-response-header__ul_s32_x3r_nsb}
{#http-response-header__ul_wdh_ntg_14b}
**Related topics**   

* [Control request and response content type](https://www.servicenow.com/docs/access?context=c_SpecifyContentType&version=brazil&pubname=brazil-api-reference&ft:locale=en-US)
* Cache-Control HTTP header value
* [Content-Security-Policy: frame-ancestor 'self' URL1 URL2](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/frame-ancestors)
* [X-Frame-Options: SAMEORIGIN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options)
* [X-Frame-Options: ALLOW-FROM URL](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options)

