Add gin/contrib secure middleware as an alternative: https://github.com/gin-contrib/secure The page: https://gin-gonic.com/en/docs/examples/security-headers/