# Security Headers in Ember.js Application

**URL:** <https://discuss.emberjs.com/t/security-headers-in-ember-js-application/16680>\
**Category:** Questions\
**Created:** [June 17, 2019, 3:07am UTC](https://discuss.emberjs.com/t/security-headers-in-ember-js-application/16680 "2019-06-17T03:07:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wishwa14](https://avatars.discourse-cdn.com/v4/letter/w/b5a626/32.png) [@Wishwa14](https://discuss.emberjs.com/u/Wishwa14)\
**Post date:** [June 17, 2019, 3:07am UTC](https://discuss.emberjs.com/t/security-headers-in-ember-js-application/16680/1 "2019-06-17T03:07:13Z")

</div>

Does anyone know how can I set security headers in an ember.js application with the following response headers?

‘X-XSS-Protection’

‘X-Frame-Options’, ‘deny’

‘X-Content-Type-Options’

‘Content-Security-Policy’

‘Public-Key-Pins’

---

<div class="post-metadata">

**Author:** ![ef4](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/ef4/32/13470_2.png) [@ef4](https://discuss.emberjs.com/u/ef4)\
**Post date:** [June 17, 2019, 1:45pm UTC](https://discuss.emberjs.com/t/security-headers-in-ember-js-application/16680/2 "2019-06-17T13:45:03Z")

</div>

Hi @Wishwa14, that depends entirely on what webserver you are using. It’s not something Ember itself can control, since Ember doesn’t run on the webserver (unless you’re using Fastboot, in which case you _could_ [add headers from inside Ember](http://ember-fastboot.com/docs/user-guide#response-headers)).
