--- layout: default ---

X-AUTH-TOKEN

de facto — unregistered request 3 spellings

Declared by 41 providers across 1720 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Spelled 3 ways

HTTP field names are case-insensitive (RFC 9110 §5.1), so every spelling below is the same header on the wire. A contract is not the wire: generated clients key off the string, and a developer reading two of these sees two different headers.

X-AUTH-TOKENX-Auth-Tokenx-auth-token

Providers declaring it (41)

alianza altinity atrato axway bigcommerce blues-wireless cisco-hardware commusoft coram-ai currencycloud d-wave dell-servers docuseal equinix getresponse hakuna hanko howler juniper juniper-networks langwatch national-cancer-institute nestcoin neuvector nevercode open-loyalty openbmc openstack packet-host preauth-instacash prewave prophecyio pure-storage rackspace-technology reverb sage-hr scaleway super-micro-computer tribe-payments uc-davis vertiv

Explore

All headers Authentication Guidance on headers.apievangelist.com