--- layout: default ---

Strict-Transport-Security

IANA permanent response RFC 6797 reached by regulation

Declared by 33 providers across 2568 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Reached by regulation

Basis: evidentiary. No law names this header; it is the deployed control for an obligation that regulation does impose. Observable at the edge, without credentials.

hipaa glba nis2 osfi-guideline-b13 apra-prudential-standards nhs-dspt

The registry

Statuspermanent
ReferenceRFC 6797: HTTP Strict Transport Security (HSTS)

Providers declaring it (33)

aib-group-uk aldermore bank-of-ireland-uk bank-of-scotland co-operative-bank coventry-building-society coveo first-direct gb-bank halifax leeds-building-society listrak lloyds-banking-group metro-bank mettle monument-bank nationwide-building-society open-banking-uk optus paragon-bank principality-building-society recognise-bank salesforce santander-uk secure-trust-bank shawbrook-bank shyft skipton-building-society starling-bank tsb-bank usertesting virgin-money-uk weatherbys-bank

Explore

All headers Security Policy Guidance on headers.apievangelist.com