Authentication
Headers that carry who the caller is — credentials, tokens, keys, signatures of identity. The most declared category in the catalog and the most inconsistently spelled.
44 headers, ordered by how many providers in the catalog declare them.
Authorization
1176 providers
3 spellings
The header that carries who you are. The most-declared header in the entire catalog, and the one most often declared in the wrong place.
x-api-key
667 providers
7 spellings
The most fragmented header in the catalog — 667 providers, seven different spellings, no standard, no registry entry.
X-Amz-Date
98 providers
2 spellings
The X-Amz-Date HTTP header — authentication, declared by 98 providers in the API Evangelist catalog.
X-Amz-Security-Token
97 providers
2 spellings
The X-Amz-Security-Token HTTP header — authentication, declared by 97 providers in the API Evangelist catalog.
X-Amz-Content-Sha256
97 providers
2 spellings
The X-Amz-Content-Sha256 HTTP header — authentication, declared by 97 providers in the API Evangelist catalog.
X-Amz-SignedHeaders
96 providers
The X-Amz-SignedHeaders HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.
X-Amz-Signature
96 providers
The X-Amz-Signature HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.
X-Amz-Credential
96 providers
The X-Amz-Credential HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.
X-Amz-Algorithm
96 providers
The X-Amz-Algorithm HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.
api-key
92 providers
5 spellings
The api-key HTTP header — authentication, declared by 92 providers in the API Evangelist catalog.
x-fapi-auth-date
88 providers
regulated
The x-fapi-auth-date HTTP header — authentication, declared by 88 providers in the API Evangelist catalog.
apikey
83 providers
6 spellings
The apikey HTTP header — authentication, declared by 83 providers in the API Evangelist catalog.
x-client-id
46 providers
4 spellings
The x-client-id HTTP header — authentication, declared by 46 providers in the API Evangelist catalog.
key
44 providers
3 spellings
The key HTTP header — authentication, declared by 44 providers in the API Evangelist catalog.
X-AUTH-TOKEN
41 providers
3 spellings
The X-AUTH-TOKEN HTTP header — authentication, declared by 41 providers in the API Evangelist catalog.
api_key
40 providers
2 spellings
The api_key HTTP header — authentication, declared by 40 providers in the API Evangelist catalog.
token
38 providers
3 spellings
The token HTTP header — authentication, declared by 38 providers in the API Evangelist catalog.
Set-Cookie
37 providers
regulated
The header ePrivacy is actually about, and the one place consent violations are visible from outside.
Ocp-Apim-Subscription-Key
34 providers
2 spellings
The Ocp-Apim-Subscription-Key HTTP header — authentication, declared by 34 providers in the API Evangelist catalog.
WWW-Authenticate
24 providers
3 spellings
The WWW-Authenticate HTTP header — authentication, RFC 9110, declared by 24 providers in the API Evangelist catalog.
Cookie
7 providers
2 spellings
The Cookie HTTP header — authentication, declared by 7 providers in the API Evangelist catalog.
x-fapi-customer-last-logged-time
3 providers
regulated
The x-fapi-customer-last-logged-time HTTP header — authentication, declared by 3 providers in the API Evangelist catalog.
Set-Cookie2
The Set-Cookie2 HTTP header — authentication, RFC 2965, not observed in the catalog.
Security-Scheme
The Security-Scheme HTTP header — authentication, RFC 2660, not observed in the catalog.
Sec-Token-Binding
The Sec-Token-Binding HTTP header — authentication, RFC 8473, not observed in the catalog.
Proxy-Authorization
The Proxy-Authorization HTTP header — authentication, RFC 9110, not observed in the catalog.
Proxy-Authentication-Info
The Proxy-Authentication-Info HTTP header — authentication, RFC 9110, not observed in the catalog.
Proxy-Authenticate
The Proxy-Authenticate HTTP header — authentication, RFC 9110, not observed in the catalog.
OSCORE
The OSCORE HTTP header — authentication, RFC 8613, not observed in the catalog.
Optional-WWW-Authenticate
The Optional-WWW-Authenticate HTTP header — authentication, RFC 8053, not observed in the catalog.
Lock-Token
The Lock-Token HTTP header — authentication, RFC 4918, not observed in the catalog.
Include-Referred-Token-Binding-ID
The Include-Referred-Token-Binding-ID HTTP header — authentication, RFC 8473, not observed in the catalog.
Hobareg
The Hobareg HTTP header — authentication, RFC 7486, not observed in the catalog.
DPoP
regulated
Binds a token to the client that holds it. Zero providers in the catalog declare it.
DPoP-Nonce
The DPoP-Nonce HTTP header — authentication, RFC 9449, not observed in the catalog.
CTA-Common-Access-Token
The CTA-Common-Access-Token HTTP header — authentication, not observed in the catalog.
Cookie2
The Cookie2 HTTP header — authentication, RFC 2965, not observed in the catalog.
Concealed-Auth-Export
The Concealed-Auth-Export HTTP header — authentication, RFC 9729, not observed in the catalog.
Client-Cert
The Client-Cert HTTP header — authentication, RFC 9440, not observed in the catalog.
Client-Cert-Chain
The Client-Cert-Chain HTTP header — authentication, RFC 9440, not observed in the catalog.
Cert-Not-Before
The Cert-Not-Before HTTP header — authentication, RFC 8739, not observed in the catalog.
Cert-Not-After
The Cert-Not-After HTTP header — authentication, RFC 8739, not observed in the catalog.
Authentication-Info
The Authentication-Info HTTP header — authentication, RFC 9110, not observed in the catalog.
Authentication-Control
The Authentication-Control HTTP header — authentication, RFC 8053, not observed in the catalog.