This header lets a server whitelist headers that browsers are allowed to access.

For example: X-My-Custom-Header, X-Another-Custom-Header
This allows the X-My-Custom-Header and X-Another-Custom-Header headers to be exposed to the browser.