--- layout: default ---

WWW-Authenticate

IANA permanent response RFC 9110 3 spellings

Declared by 24 providers across 1152 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Spelled 3 ways

HTTP field names are case-insensitive (RFC 9110 §5.1), so every spelling below is the same header on the wire. A contract is not the wire: generated clients key off the string, and a developer reading two of these sees two different headers.

WWW-Authenticatewww-authenticateWww-Authenticate

The registry

Statuspermanent
ReferenceRFC 9110, Section 11.6.1: HTTP Semantics

Providers declaring it (24)

adyen airbus-oneatlas artifactory bird bloomreach c-hoare-and-co cdr-energy dream-sports etsi expedia-group griffin holidu lucent mastercard microsoft-azure moneris nift qualtrics salesforce salesgraph shyft va-gov xquik-api zuora

Explore

All headers Authentication Guidance on headers.apievangelist.com