Content-Security-Policy
IANA permanent
response
reached by regulation
Declared by 4 providers across 725 published specification files in the APIs.io network.
A count here is providers whose published contract declares this header — not
providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low
number can measure documentation practice rather than deployment.
Reached by regulation
Basis: evidentiary.
No law names this header; it is the deployed control for an obligation that regulation does impose.
Observable at the edge, without credentials.
The registry
| Status | permanent |
|---|---|
| Reference | Content Security Policy Level 3 |
Providers declaring it (4)
coveo listrak optus salesforce
Explore
All headers Security Policy Guidance on headers.apievangelist.com
Work with this as data
Every header here is available over the APIs.io API and to AI agents over MCP. HTTP Headers is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.