HTTP Headers

Every HTTP header declared across the APIs.io network, assembled from the IANA HTTP Field Name Registry and from every in: header parameter and headers: mapping key in 119030 published specification files across all 26641 providers.

302 headers catalogued
5074 distinct names observed
67 used by 25+ providers
33 reached by regulation
83 spelled more than one way
A header earns a page when it is registered with IANA, reached by a regulation, or declared by at least 25 distinct providers. The other 4933 observed names are real but are almost entirely one-off vendor fields. Counts are what a published contract declares, not what a deployment sends. Written guidance for each header lives on headers.apievangelist.com.

Authentication 44

Headers that carry who the caller is — credentials, tokens, keys, signatures of identity. The most declared category in the catalog and the most inconsistently spelled.

Authorization 1176 x-api-key 667 X-Amz-Date 98 X-Amz-Content-Sha256 97 X-Amz-Security-Token 97 X-Amz-Credential 96 X-Amz-SignedHeaders 96 X-Amz-Signature 96 X-Amz-Algorithm 96 api-key 92 x-fapi-auth-date 88 apikey 83 x-client-id 46 key 44 X-AUTH-TOKEN 41 api_key 40 token 38 Set-Cookie 37 Ocp-Apim-Subscription-Key 34 WWW-Authenticate 24 Cookie 7 x-fapi-customer-last-logged-time 3 Lock-Token Include-Referred-Token-Binding-ID Hobareg DPoP DPoP-Nonce CTA-Common-Access-Token Cookie2 Concealed-Auth-Export Client-Cert Client-Cert-Chain Cert-Not-Before Cert-Not-After Authentication-Info Authentication-Control Security-Scheme Sec-Token-Binding Proxy-Authorization Proxy-Authentication-Info Proxy-Authenticate OSCORE Optional-WWW-Authenticate Set-Cookie2

Authorization & Scope 2

Headers that carry what the caller is permitted to do, once identity is settled: scope, tenancy, delegated consent, acting-on-behalf-of.

x-cds-client-headers 61 x-fapi-financial-id 5

Caching 16

Headers that tell an intermediary what it may store and for how long. The oldest, best-specified corner of HTTP, and the one API providers most routinely ignore.

Cache-Control 109 Expires 20 Pragma 17 Vary 12 Surrogate-Control 1 Age 1 Cache-Groups Cache-Group-Invalidation Surrogate-Capability Refresh Meter Memento-Datetime CDN-Cache-Control Cache-Status AMP-Cache-Transform Warning

Conditional Requests & Concurrency 13

Headers that make a request conditional on the state of a resource — the difference between a safe update and a lost one.

ETag 125 If-Match 76 If-None-Match 76 If-Modified-Since 52 Last-Modified 29 If-Unmodified-Since 10 Isolation If-Schedule-Tag-Match If-Range OData-Isolation Schedule-Tag Set-Txn If

Content Negotiation 27

Headers through which client and server agree on representation: media type, language, encoding, character set.

Accept 183 Accept-Language 69 Accept-Encoding 29 Accept-Charset 2 Accept-Datetime 1 IM GetProfile EDIINT-Features Differential-ID Dictionary-ID Derived-From Delta-Base Available-Dictionary Alternates Accept-Signature Accept-Query Accept-Post Accept-Patch Accept-Features A-IM Use-As-Dictionary TCN SetProfile Negotiate Accept-CH Accept-Additions Variant-Vary

Representation Metadata 33

Headers describing the payload itself — its type, length, encoding, disposition, location.

Content-Type 353 Location 272 Link 98 Content-Disposition 96 Content-Length 62 X-WP-Total 55 X-WP-TotalPages 55 X-Total-Count 40 Content-Encoding 39 Range 36 Date 35 Content-Range 17 Content-Language 16 Content-MD5 11 Server 10 Allow 6 Accept-Ranges 6 OData-EntityId 4 Label 3 SLUG 1 Position 1 ProfileObject Schedule-Reply Content-ID URI Content-Base CalDAV-Timezones Cal-Managed-ID Default-Style Content-Style-Type Content-Script-Type Ordering-Type Link-Template

Connection & Transport 57

Headers about the connection rather than the resource: hosts, upgrades, proxies, forwarding, keep-alive.

X-Amz-Target 61 Connection 21 Transfer-Encoding 16 Upgrade 7 Sec-WebSocket-Protocol 7 Host 6 Priority 5 SoapAction 3 Alt-Svc 2 Sec-WebSocket-Key 2 Expect 1 Sec-WebSocket-Accept 1 Urgency 1 TE 1 TTL 1 Via 1 Topic 1 Sec-WebSocket-Version 1 Sec-WebSocket-Extensions 1 Forwarded Ext Early-Data Destination Depth DAV ALPN Configuration-Context Close CDN-Loop Capsule-Protocol C-PEP C-PEP-Info C-Opt C-Man C-Ext Apply-To-Redirect-Ref Alt-Used Trailer Timeout Redirect-Ref Proxy-Status Proxy-Instruction Proxy-Features Protocol Protocol-Request Protocol-Query Protocol-Info PEP PEP-Info Overwrite Opt Max-Forwards Man Keep-Alive Incremental HTTP2-Settings DASL

CORS 13

The cross-origin negotiation. A small, closed set of headers that decide whether a browser is allowed to see a response it already received.

Access-Control-Allow-Origin 30 Access-Control-Allow-Methods 16 Access-Control-Allow-Headers 16 Origin 14 Access-Control-Allow-Credentials 11 Access-Control-Expose-Headers 4 Access-Control-Max-Age 1 Method-Check Method-Check-Expires Access-Control Access-Control-Request-Method Access-Control-Request-Headers Timing-Allow-Origin

Security Policy 26

Response headers instructing the client to constrain itself — transport security, framing, script sources, sniffing, referrer leakage.

Strict-Transport-Security 33 X-Content-Type-Options 33 X-Frame-Options 30 Content-Security-Policy 4 Expect-CT 3 NEL 2 Referrer-Policy 2 Public 1 PICS-Label Permissions-Policy Origin-Agent-Cluster Cross-Origin-Resource-Policy Cross-Origin-Opener-Policy Cross-Origin-Opener-Policy-Report-Only Cross-Origin-Embedder-Policy Cross-Origin-Embedder-Policy-Report-Only Sec-Fetch-User Sec-Fetch-Storage-Access Sec-Fetch-Site Sec-Fetch-Mode Sec-Fetch-Dest Reporting-Endpoints Public-Key-Pins Public-Key-Pins-Report-Only Content-Security-Policy-Report-Only Clear-Site-Data

Privacy & Consent 7

Headers carrying a person's preference or a legal consent artifact. The smallest category in the catalog by adoption and the largest by regulatory consequence.

x-fapi-customer-ip-address 92 PSU-IP-Address 3 Consent-ID 3 psu-id 1 Sec-GPC P3P Activate-Storage-Access

Rate Limiting & Quota 9

Headers that tell a caller where it stands against a limit. Documented limits give you the ceiling; these tell you your altitude.

Retry-After 229 X-RateLimit-Remaining 96 X-RateLimit-Limit 95 X-RateLimit-Reset 76 RateLimit 33 RateLimit-Policy 27 RateLimit-Limit 27 RateLimit-Remaining 26 RateLimit-Reset 25

Tracing & Correlation 12

Headers that let one call be followed across many systems — request ids, correlation ids, trace context.

x-fapi-interaction-id 95 X-Request-Id 68 id 28 Traceparent 6 Tracestate 2 Server-Timing CMCD-Object CMSD-Static CMSD-Dynamic CMCD-Status CMCD-Session CMCD-Request

Idempotency & Reliability 7

Headers that make a retry safe. Almost entirely a payments-industry invention that the rest of the API economy has not adopted.

Idempotency-Key 127 x-idempotency-key 45 Repeatability-Result 1 Repeatability-Request-ID 1 Repeatability-First-Sent 1 Safe Repeatability-Client-ID

Versioning & Lifecycle 9

Headers that carry version, deprecation and end-of-life. The category the catalog shows to be almost entirely unused, which is a finding rather than a gap in the data.

x-v 61 x-min-v 61 Sunset 6 Deprecation 3 OData-Version 3 OData-MaxVersion 1 MIME-Version OSLC-Core-Version Content-Version

Integrity & Signing 14

Headers carrying a digest or a signature over the message, so a recipient can prove it arrived as it was sent.

x-jws-signature 32 Signature 25 Digest 8 Signature-Input 2 Replay-Nonce 2 Tpp-Signature-Certificate 2 Content-Digest 1 Want-Repr-Digest Want-Unencoded-Digest Repr-Digest Detached-JWS Want-Digest Want-Content-Digest Unencoded-Digest

Async & Long-Running 5

Headers for work that does not finish inside the request: preference for async handling, polling locations, progress, retry timing.

Prefer 29 Content-Location 11 Last-Event-ID 7 Preference-Applied 3 Status-URI 1

Agent & Bot Identity 8

Headers by which an automated caller identifies itself, and by which a server decides what to serve it. The newest category, and the one with the least settled vocabulary.

User-Agent 71 x-customer-user-agent 30 Referer 9 From 4 Referer-Root Ping-To Ping-From Sec-Purpose