--- layout: default ---

Signature

IANA permanent request RFC 9421 reached by regulation 2 spellings

Declared by 25 providers across 278 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Spelled 2 ways

HTTP field names are case-insensitive (RFC 9110 §5.1), so every spelling below is the same header on the wire. A contract is not the wire: generated clients key off the string, and a developer reading two of these sees two different headers.

Signaturesignature

Reached by regulation

Basis: mandated. The law, or a technical standard the law makes binding, names this header. Only a credentialed caller can observe it in flight — the catalog can see a contract declare it, not a deployment honour it.

psd2

Carried by the http-message-signatures standard.

The registry

Statuspermanent
ReferenceRFC 9421, Section 4.2: HTTP Message Signatures
Structured typeDictionary (RFC 9651)

Providers declaring it (25)

accountable activitypub appcharge brightback coinsph doku fintecture healthie huma mailerlite moengage paytabs paytm pixlee plansource salt-edge shufti-pro smart-pension specterops tribe-payments triodos-bank-uk upvest weavr wordline zero-hash

Explore

All headers Integrity & Signing Guidance on headers.apievangelist.com