Static ReadonlyHEADERName of the header carrying the request id between Workers.
StaticofBuilds the correlation header for an outbound call.
OptionalrequestId: string
The id to propagate. Omit or pass a blank value to send nothing.
The header as a spreadable object, empty when there is no id.
Returns a plain object rather than a Headers, so it spreads into the
headers a caller was already building instead of replacing them:
headers: { 'content-type': 'application/json', ...RequestCorrelation.of(requestId) }
An absent id yields an empty object. A hop with nothing to propagate should send no header at all rather than an empty one, which the far end would read as an id and correlate against.
The one header that carries a request id from one Worker to the next.
Remarks
Cloudflare gives every request that arrives from the internet a
CF-Ray, andCloudflareRequestMetadatareads it as the request id — the id the dashboard's own logs are keyed by, so a line here and a line there can be joined without inventing anything.A subrequest gets no new one. When a Worker calls another over a Service Binding, or reaches an external API, the far end sees whatever headers the caller built and nothing the edge added. Without a header of its own the trail stops at each hop, and a failure three Workers deep cannot be walked back to the request that caused it.
This is that header. The caller stamps its request id on the way out, the callee prefers an inbound value over minting a fresh one, and one id spans the whole fan-out.
It is correlation, and only correlation
The value is attacker-controlled: anyone may send
X-Request-Id. That is acceptable for joining log lines and unacceptable for anything else. It must never gate access, identify a caller, or stand in for a credential — the API key check inSecurityMiddlewareis what decides who may call, and it reads none of this. The worst a forged value can do is put two unrelated requests under one id in a log query.Example
Author
Bayu Dwiyan Satria
Version
1.2.0
Since
1.2.0