The max-age value is counted in seconds.

highlighted = computed this step

max-age is a count of seconds

The directive row parses the name, and the seconds row parses the number.

max-age seconds=60\text{max-age seconds}=60
Max-age valueThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Max-age value - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

The pinned value is sixty seconds

The exact integer is 60 seconds.

seconds=60\text{seconds}=60
Max-age valueThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Max-age value - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

The value comes from the response

The request does not choose this number in the toy example.

response header value\text{response header value}
Max-age valueThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Max-age value - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

Summary

The HSTS max-age value gives the remembered-rule duration.

duration checked\text{duration checked}
Max-age valueThe request host, HSTS response header, remembered rule, empty body, and checks are recomputed from pinned bytes.Max-age value - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty