-content-type-options: nosniff timing-allow-origin: * access-control-allow-origin: https://dashboard.stripe.com content-length: 2885 X-Firefox-Spdy: h2