# Response headers

> The headers the Product Management API sets on its responses, and what each one tells you.
{/* generated:versioned-pages - edit _pm-authored, not this file */}

Beyond the response body, the Product Management API carries information in a handful of response headers - which version served your request, whether a field was withheld, where a created resource lives. This page lists them and what each one means.

All of them are exposed to browser JavaScript via CORS, so you can read them from a front-end client as well as from a server.

## Versioning

### `Flowkiwi-Api-Version`

The version that actually served the request. You select a version by sending the same header on the request - see [API versions & support](/api/product-management/versions/) - and the response echoes back what was used.

Compare the two when in doubt: if the value differs from what you asked for, you were served something else.

### `Sunset`

Present when the version you used has a retirement date, formatted per RFC 7231:

```
Sunset: Sat, 01 Aug 2026 00:00:00 GMT
```

Past that date the version stops being accepted and requests using it are rejected. Migrate to a newer version before then - the [versions table](/api/product-management/versions/) lists what's available.

> **Worth logging**
>
> `Sunset` is the API telling you about work you'll otherwise discover as a breakage. Surfacing it in your logs turns a future outage into a scheduled migration.

## Permissions

### `Flowkiwi-Missing-Scopes`

Comma-separated scopes your token lacks. The properties they gate were returned **empty** rather than the request being refused, so a blank field is ambiguous without this header.

See [Permissions](/authentication/#permissions) for the full behaviour, including the `403` returned when an entire operation is denied.

## Writes

### `Location`

The IRI of the resource a write just created - the same value as the `@id` in the response body.

Writes return the resource's identity rather than the full record; see [Write responses](/authentication/#write-responses-return-the-resource).

## Downloads

### `Content-Disposition`

On endpoints that return a file rather than JSON, carries the generated filename:

```
Content-Disposition: attachment; filename="products-sample.csv"
```

Today that is [Download an example file](/api/product-management/imports/sample/). Use the name it gives you rather than deriving one from the URL.

## Diagnostics

### `X-App-Version`

The build of the service that handled the request, set on every response. It identifies nothing about your account and affects no behaviour - quote it when reporting a problem so support knows which build you hit.
