--- layout: default ---

x-jws-signature

de facto — unregistered response reached by regulation 2 spellings

Declared by 32 providers across 1816 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Spelled 2 ways

HTTP field names are case-insensitive (RFC 9110 §5.1), so every spelling below is the same header on the wire. A contract is not the wire: generated clients key off the string, and a developer reading two of these sees two different headers.

x-jws-signatureX-JWS-Signature

Reached by regulation

Basis: mandated. The law, or a technical standard the law makes binding, names this header. Only a credentialed caller can observe it in flight — the catalog can see a contract declare it, not a deployment honour it.

cma-open-banking-order

Carried by the uk-open-banking-standard standard.

Providers declaring it (32)

aldermore allica-bank bank-of-ireland-uk bank-of-scotland c-hoare-and-co cashplus chase-uk coutts coventry-building-society cynergy-bank first-direct gb-bank hampden-and-co investec kroo lloyds-banking-group mastercard monument-bank natwest open-banking-uk paragon-bank payments-canada recognise-bank revolut santander-uk secure-trust-bank shawbrook-bank tandem-bank vanquis-banking-group volt-io yorkshire-building-society zopa

Explore

All headers Integrity & Signing Guidance on headers.apievangelist.com