--- layout: default ---
Header category

Security Policy

Response headers instructing the client to constrain itself — transport security, framing, script sources, sniffing, referrer leakage.

26 headers
116 provider declarations
HeaderProvidersStatus
X-Content-Type-Options 35 permanent
Strict-Transport-Security 35 permanent regulated
X-Frame-Options 33 permanent
Content-Security-Policy 4 permanent regulated
NEL 3 permanent
Expect-CT 3 deprecated
Referrer-Policy 2 permanent
Public 1 obsoleted
Permissions-Policy provisional regulated
Origin-Agent-Cluster permanent
Cross-Origin-Resource-Policy permanent
Cross-Origin-Opener-Policy-Report-Only permanent
Cross-Origin-Opener-Policy permanent
Cross-Origin-Embedder-Policy-Report-Only permanent
Cross-Origin-Embedder-Policy permanent
Content-Security-Policy-Report-Only permanent
Clear-Site-Data permanent regulated
Sec-Fetch-Storage-Access provisional
Sec-Fetch-Site permanent
Sec-Fetch-Mode permanent
Sec-Fetch-Dest permanent
Reporting-Endpoints provisional
Public-Key-Pins-Report-Only permanent
Public-Key-Pins permanent
PICS-Label obsoleted
Sec-Fetch-User permanent

All categories

Authentication Authorization & Scope Caching Conditional Requests & Concurrency Content Negotiation Representation Metadata Connection & Transport CORS Security Policy Privacy & Consent Rate Limiting & Quota Tracing & Correlation Idempotency & Reliability Versioning & Lifecycle Integrity & Signing Async & Long-Running Cost & Metering Agent & Bot Identity

Work with this as data

Every header here is available over the APIs.io API and to AI agents over MCP. HTTP Headers is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for http headers

3 MCP tools reach this
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
Search the catalog
curl "https://apis.io/api/v1/search?q=security-policy&limit=10"
Everything under a tag
curl "https://apis.io/api/v1/tags/security-policy"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.