--- layout: default ---

Content-Security-Policy

IANA permanent response reached by regulation

Declared by 4 providers across 675 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Reached by regulation

Basis: evidentiary. No law names this header; it is the deployed control for an obligation that regulation does impose. Observable at the edge, without credentials.

nis2 eu-cyber-resilience-act

The registry

Statuspermanent
ReferenceContent Security Policy Level 3

Providers declaring it (4)

coveo listrak optus salesforce

Explore

All headers Security Policy Guidance on headers.apievangelist.com