Content-Security-Policy
IANA permanent
response
reached by regulation
Declared by 4 providers across 675 published specification files in the APIs.io network.
A count here is providers whose published contract declares this header — not
providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low
number can measure documentation practice rather than deployment.
Reached by regulation
Basis: evidentiary.
No law names this header; it is the deployed control for an obligation that regulation does impose.
Observable at the edge, without credentials.
The registry
| Status | permanent |
|---|---|
| Reference | Content Security Policy Level 3 |
Providers declaring it (4)
coveo listrak optus salesforce
Explore
All headers Security Policy Guidance on headers.apievangelist.com