--- layout: default ---

X-Content-Type-Options

IANA permanent response 2 spellings

Declared by 33 providers across 2753 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Spelled 2 ways

HTTP field names are case-insensitive (RFC 9110 §5.1), so every spelling below is the same header on the wire. A contract is not the wire: generated clients key off the string, and a developer reading two of these sees two different headers.

X-Content-Type-Optionsx-content-type-options

The registry

Statuspermanent
ReferenceFetch

Providers declaring it (33)

aib-group-uk aldermore bank-of-ireland-uk bank-of-scotland co-operative-bank coventry-building-society coveo dow-jones extreme-networks first-direct gb-bank halifax leeds-building-society listrak lloyds-banking-group metro-bank mettle monument-bank nationwide-building-society open-banking-uk paragon-bank principality-building-society recognise-bank salesforce santander-uk secure-trust-bank shawbrook-bank shyft skipton-building-society starling-bank tsb-bank virgin-money-uk weatherbys-bank

Explore

All headers Security Policy Guidance on headers.apievangelist.com