description:Pass custom HTTP headers through TRAWL to the target URL across all execution tiers.
---
# Custom Headers
Both `/v1` and `/scrape` accept an optional `headers` object. Headers are forwarded to the target URL across all four execution tiers.
## Usage
**`/v1` (FlareSolverr-compat)**
```json
{
"url":"https://example.com",
"headers":{
"Authorization":"Bearer my-token",
"Referer":"https://parent-site.com"
}
}
```
**`/scrape` (native API)**
```json
{
"url":"https://example.com",
"headers":{
"X-API-Key":"secret",
"Origin":"https://trusted-site.com"
}
}
```
Custom headers are merged **after** browser defaults, so they take precedence over anything like `User-Agent` or `Cache-Control` that TRAWL sets internally.
For browser tiers, route interception is scoped to the **exact target URL**. Subresources (JS, CSS, images, fonts, third-party CDNs) and Cloudflare challenge endpoints (`cdn-cgi/*`) are never intercepted — your `Authorization` header does not leak to third parties, and CF challenge solving is unaffected.
## CF challenge + custom headers flow
When a page requires both challenge bypass and custom headers, the sequence is:
Passing a `Cookie` header appends to any cookies the browser already holds (CF clearance, cached session cookies). It does not replace them.
:::
::: warning Headers and CF-protected pages
Pages that require custom auth headers are rarely also behind CF JS challenges — CF challenges are for public sites needing bot/DDoS protection, while auth headers imply a private/restricted resource. If you hit both, TRAWL handles it correctly as described above.