How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Authentication

Headers that carry who the caller is — credentials, tokens, keys, signatures of identity. The most declared category in the catalog and the most inconsistently spelled.

44 headers, ordered by how many providers in the catalog declare them.

Authorization 1176 providers 3 spellings

The header that carries who you are. The most-declared header in the entire catalog, and the one most often declared in the wrong place.

x-api-key 667 providers 7 spellings

The most fragmented header in the catalog — 667 providers, seven different spellings, no standard, no registry entry.

X-Amz-Date 98 providers 2 spellings

The X-Amz-Date HTTP header — authentication, declared by 98 providers in the API Evangelist catalog.

X-Amz-Security-Token 97 providers 2 spellings

The X-Amz-Security-Token HTTP header — authentication, declared by 97 providers in the API Evangelist catalog.

X-Amz-Content-Sha256 97 providers 2 spellings

The X-Amz-Content-Sha256 HTTP header — authentication, declared by 97 providers in the API Evangelist catalog.

X-Amz-SignedHeaders 96 providers

The X-Amz-SignedHeaders HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.

X-Amz-Signature 96 providers

The X-Amz-Signature HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.

X-Amz-Credential 96 providers

The X-Amz-Credential HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.

X-Amz-Algorithm 96 providers

The X-Amz-Algorithm HTTP header — authentication, declared by 96 providers in the API Evangelist catalog.

api-key 92 providers 5 spellings

The api-key HTTP header — authentication, declared by 92 providers in the API Evangelist catalog.

x-fapi-auth-date 88 providers regulated

The x-fapi-auth-date HTTP header — authentication, declared by 88 providers in the API Evangelist catalog.

apikey 83 providers 6 spellings

The apikey HTTP header — authentication, declared by 83 providers in the API Evangelist catalog.

x-client-id 46 providers 4 spellings

The x-client-id HTTP header — authentication, declared by 46 providers in the API Evangelist catalog.

key 44 providers 3 spellings

The key HTTP header — authentication, declared by 44 providers in the API Evangelist catalog.

X-AUTH-TOKEN 41 providers 3 spellings

The X-AUTH-TOKEN HTTP header — authentication, declared by 41 providers in the API Evangelist catalog.

api_key 40 providers 2 spellings

The api_key HTTP header — authentication, declared by 40 providers in the API Evangelist catalog.

token 38 providers 3 spellings

The token HTTP header — authentication, declared by 38 providers in the API Evangelist catalog.

Set-Cookie 37 providers regulated

The header ePrivacy is actually about, and the one place consent violations are visible from outside.

Ocp-Apim-Subscription-Key 34 providers 2 spellings

The Ocp-Apim-Subscription-Key HTTP header — authentication, declared by 34 providers in the API Evangelist catalog.

WWW-Authenticate 24 providers 3 spellings

The WWW-Authenticate HTTP header — authentication, RFC 9110, declared by 24 providers in the API Evangelist catalog.

Cookie 7 providers 2 spellings

The Cookie HTTP header — authentication, declared by 7 providers in the API Evangelist catalog.

x-fapi-customer-last-logged-time 3 providers regulated

The x-fapi-customer-last-logged-time HTTP header — authentication, declared by 3 providers in the API Evangelist catalog.

Set-Cookie2

The Set-Cookie2 HTTP header — authentication, RFC 2965, not observed in the catalog.

Security-Scheme

The Security-Scheme HTTP header — authentication, RFC 2660, not observed in the catalog.

Sec-Token-Binding

The Sec-Token-Binding HTTP header — authentication, RFC 8473, not observed in the catalog.

Proxy-Authorization

The Proxy-Authorization HTTP header — authentication, RFC 9110, not observed in the catalog.

Proxy-Authentication-Info

The Proxy-Authentication-Info HTTP header — authentication, RFC 9110, not observed in the catalog.

Proxy-Authenticate

The Proxy-Authenticate HTTP header — authentication, RFC 9110, not observed in the catalog.

OSCORE

The OSCORE HTTP header — authentication, RFC 8613, not observed in the catalog.

Optional-WWW-Authenticate

The Optional-WWW-Authenticate HTTP header — authentication, RFC 8053, not observed in the catalog.

Lock-Token

The Lock-Token HTTP header — authentication, RFC 4918, not observed in the catalog.

Include-Referred-Token-Binding-ID

The Include-Referred-Token-Binding-ID HTTP header — authentication, RFC 8473, not observed in the catalog.

Hobareg

The Hobareg HTTP header — authentication, RFC 7486, not observed in the catalog.

DPoP regulated

Binds a token to the client that holds it. Zero providers in the catalog declare it.

DPoP-Nonce

The DPoP-Nonce HTTP header — authentication, RFC 9449, not observed in the catalog.

CTA-Common-Access-Token

The CTA-Common-Access-Token HTTP header — authentication, not observed in the catalog.

Cookie2

The Cookie2 HTTP header — authentication, RFC 2965, not observed in the catalog.

Concealed-Auth-Export

The Concealed-Auth-Export HTTP header — authentication, RFC 9729, not observed in the catalog.

Client-Cert

The Client-Cert HTTP header — authentication, RFC 9440, not observed in the catalog.

Client-Cert-Chain

The Client-Cert-Chain HTTP header — authentication, RFC 9440, not observed in the catalog.

Cert-Not-Before

The Cert-Not-Before HTTP header — authentication, RFC 8739, not observed in the catalog.

Cert-Not-After

The Cert-Not-After HTTP header — authentication, RFC 8739, not observed in the catalog.

Authentication-Info

The Authentication-Info HTTP header — authentication, RFC 9110, not observed in the catalog.

Authentication-Control

The Authentication-Control HTTP header — authentication, RFC 8053, not observed in the catalog.