HTTP Headers
Every HTTP header declared across the APIs.io network, assembled from the IANA HTTP Field Name Registry and from every in: header parameter and headers: mapping key in 119030 published specification files across all 26641 providers.
Authentication 44
Headers that carry who the caller is — credentials, tokens, keys, signatures of identity. The most declared category in the catalog and the most inconsistently spelled.
Authorization 1176 x-api-key 667 X-Amz-Date 98 X-Amz-Content-Sha256 97 X-Amz-Security-Token 97 X-Amz-Credential 96 X-Amz-SignedHeaders 96 X-Amz-Signature 96 X-Amz-Algorithm 96 api-key 92 x-fapi-auth-date 88 apikey 83 x-client-id 46 key 44 X-AUTH-TOKEN 41 api_key 40 token 38 Set-Cookie 37 Ocp-Apim-Subscription-Key 34 WWW-Authenticate 24 Cookie 7 x-fapi-customer-last-logged-time 3 Lock-Token Include-Referred-Token-Binding-ID Hobareg DPoP DPoP-Nonce CTA-Common-Access-Token Cookie2 Concealed-Auth-Export Client-Cert Client-Cert-Chain Cert-Not-Before Cert-Not-After Authentication-Info Authentication-Control Security-Scheme Sec-Token-Binding Proxy-Authorization Proxy-Authentication-Info Proxy-Authenticate OSCORE Optional-WWW-Authenticate Set-Cookie2Authorization & Scope 2
Headers that carry what the caller is permitted to do, once identity is settled: scope, tenancy, delegated consent, acting-on-behalf-of.
x-cds-client-headers 61 x-fapi-financial-id 5Caching 16
Headers that tell an intermediary what it may store and for how long. The oldest, best-specified corner of HTTP, and the one API providers most routinely ignore.
Cache-Control 109 Expires 20 Pragma 17 Vary 12 Surrogate-Control 1 Age 1 Cache-Groups Cache-Group-Invalidation Surrogate-Capability Refresh Meter Memento-Datetime CDN-Cache-Control Cache-Status AMP-Cache-Transform WarningConditional Requests & Concurrency 13
Headers that make a request conditional on the state of a resource — the difference between a safe update and a lost one.
ETag 125 If-Match 76 If-None-Match 76 If-Modified-Since 52 Last-Modified 29 If-Unmodified-Since 10 Isolation If-Schedule-Tag-Match If-Range OData-Isolation Schedule-Tag Set-Txn IfContent Negotiation 27
Headers through which client and server agree on representation: media type, language, encoding, character set.
Accept 183 Accept-Language 69 Accept-Encoding 29 Accept-Charset 2 Accept-Datetime 1 IM GetProfile EDIINT-Features Differential-ID Dictionary-ID Derived-From Delta-Base Available-Dictionary Alternates Accept-Signature Accept-Query Accept-Post Accept-Patch Accept-Features A-IM Use-As-Dictionary TCN SetProfile Negotiate Accept-CH Accept-Additions Variant-VaryRepresentation Metadata 33
Headers describing the payload itself — its type, length, encoding, disposition, location.
Content-Type 353 Location 272 Link 98 Content-Disposition 96 Content-Length 62 X-WP-Total 55 X-WP-TotalPages 55 X-Total-Count 40 Content-Encoding 39 Range 36 Date 35 Content-Range 17 Content-Language 16 Content-MD5 11 Server 10 Allow 6 Accept-Ranges 6 OData-EntityId 4 Label 3 SLUG 1 Position 1 ProfileObject Schedule-Reply Content-ID URI Content-Base CalDAV-Timezones Cal-Managed-ID Default-Style Content-Style-Type Content-Script-Type Ordering-Type Link-TemplateConnection & Transport 57
Headers about the connection rather than the resource: hosts, upgrades, proxies, forwarding, keep-alive.
X-Amz-Target 61 Connection 21 Transfer-Encoding 16 Upgrade 7 Sec-WebSocket-Protocol 7 Host 6 Priority 5 SoapAction 3 Alt-Svc 2 Sec-WebSocket-Key 2 Expect 1 Sec-WebSocket-Accept 1 Urgency 1 TE 1 TTL 1 Via 1 Topic 1 Sec-WebSocket-Version 1 Sec-WebSocket-Extensions 1 Forwarded Ext Early-Data Destination Depth DAV ALPN Configuration-Context Close CDN-Loop Capsule-Protocol C-PEP C-PEP-Info C-Opt C-Man C-Ext Apply-To-Redirect-Ref Alt-Used Trailer Timeout Redirect-Ref Proxy-Status Proxy-Instruction Proxy-Features Protocol Protocol-Request Protocol-Query Protocol-Info PEP PEP-Info Overwrite Opt Max-Forwards Man Keep-Alive Incremental HTTP2-Settings DASLCORS 13
The cross-origin negotiation. A small, closed set of headers that decide whether a browser is allowed to see a response it already received.
Access-Control-Allow-Origin 30 Access-Control-Allow-Methods 16 Access-Control-Allow-Headers 16 Origin 14 Access-Control-Allow-Credentials 11 Access-Control-Expose-Headers 4 Access-Control-Max-Age 1 Method-Check Method-Check-Expires Access-Control Access-Control-Request-Method Access-Control-Request-Headers Timing-Allow-OriginSecurity Policy 26
Response headers instructing the client to constrain itself — transport security, framing, script sources, sniffing, referrer leakage.
Strict-Transport-Security 33 X-Content-Type-Options 33 X-Frame-Options 30 Content-Security-Policy 4 Expect-CT 3 NEL 2 Referrer-Policy 2 Public 1 PICS-Label Permissions-Policy Origin-Agent-Cluster Cross-Origin-Resource-Policy Cross-Origin-Opener-Policy Cross-Origin-Opener-Policy-Report-Only Cross-Origin-Embedder-Policy Cross-Origin-Embedder-Policy-Report-Only Sec-Fetch-User Sec-Fetch-Storage-Access Sec-Fetch-Site Sec-Fetch-Mode Sec-Fetch-Dest Reporting-Endpoints Public-Key-Pins Public-Key-Pins-Report-Only Content-Security-Policy-Report-Only Clear-Site-DataPrivacy & Consent 7
Headers carrying a person's preference or a legal consent artifact. The smallest category in the catalog by adoption and the largest by regulatory consequence.
x-fapi-customer-ip-address 92 PSU-IP-Address 3 Consent-ID 3 psu-id 1 Sec-GPC P3P Activate-Storage-AccessRate Limiting & Quota 9
Headers that tell a caller where it stands against a limit. Documented limits give you the ceiling; these tell you your altitude.
Retry-After 229 X-RateLimit-Remaining 96 X-RateLimit-Limit 95 X-RateLimit-Reset 76 RateLimit 33 RateLimit-Policy 27 RateLimit-Limit 27 RateLimit-Remaining 26 RateLimit-Reset 25Tracing & Correlation 12
Headers that let one call be followed across many systems — request ids, correlation ids, trace context.
x-fapi-interaction-id 95 X-Request-Id 68 id 28 Traceparent 6 Tracestate 2 Server-Timing CMCD-Object CMSD-Static CMSD-Dynamic CMCD-Status CMCD-Session CMCD-RequestIdempotency & Reliability 7
Headers that make a retry safe. Almost entirely a payments-industry invention that the rest of the API economy has not adopted.
Idempotency-Key 127 x-idempotency-key 45 Repeatability-Result 1 Repeatability-Request-ID 1 Repeatability-First-Sent 1 Safe Repeatability-Client-IDVersioning & Lifecycle 9
Headers that carry version, deprecation and end-of-life. The category the catalog shows to be almost entirely unused, which is a finding rather than a gap in the data.
x-v 61 x-min-v 61 Sunset 6 Deprecation 3 OData-Version 3 OData-MaxVersion 1 MIME-Version OSLC-Core-Version Content-VersionIntegrity & Signing 14
Headers carrying a digest or a signature over the message, so a recipient can prove it arrived as it was sent.
x-jws-signature 32 Signature 25 Digest 8 Signature-Input 2 Replay-Nonce 2 Tpp-Signature-Certificate 2 Content-Digest 1 Want-Repr-Digest Want-Unencoded-Digest Repr-Digest Detached-JWS Want-Digest Want-Content-Digest Unencoded-DigestAsync & Long-Running 5
Headers for work that does not finish inside the request: preference for async handling, polling locations, progress, retry timing.
Prefer 29 Content-Location 11 Last-Event-ID 7 Preference-Applied 3 Status-URI 1Agent & Bot Identity 8
Headers by which an automated caller identifies itself, and by which a server decides what to serve it. The newest category, and the one with the least settled vocabulary.
User-Agent 71 x-customer-user-agent 30 Referer 9 From 4 Referer-Root Ping-To Ping-From Sec-Purpose