Here it is for the autosave call that works. General:
Request URL: https://mydomain.com/wp-json/wp/v2/pages/440/autosaves?_locale=user
Request Method: POST
Status Code: 200
Remote Address: my.ip.addr:443
Referrer Policy: strict-origin-when-cross-origin
Response Headers:
access-control-allow-credentials: true
access-control-allow-headers: Authorization, Content-Type
access-control-allow-methods: OPTIONS, GET, POST, PUT, PATCH, DELETE
access-control-allow-origin: https://mydomain.com
access-control-expose-headers: X-WP-Total, X-WP-TotalPages
age: 2
allow: GET, POST
cache-control: no-cache, must-revalidate, max-age=0
content-security-policy: upgrade-insecure-requests;
content-type: application/json; charset=UTF-8
date: Tue, 18 Dec 2018 22:17:37 GMT
expires: Wed, 11 Jan 1984 05:00:00 GMT
link: <https://mydomain.com/wp-json/>; rel="https://api.w.org/"
server: nginx
status: 200
strict-transport-security: max-age=300
vary: Origin
via: http/1.1 obfustacated.secureserver.net (ApacheTrafficServer/7.1.2 [uSc sSf pSeN:tOc i p sS])
x-content-type-options: nosniff
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-port: port_10645
x-robots-tag: noindex
x-sucuri-id: 11018
x-wp-nonce: 20464aac7b
x-xss-protection: 1; mode=block