Security Policy
Response headers instructing the client to constrain itself — transport security, framing, script sources, sniffing, referrer leakage.
26 headers, ordered by how many providers in the catalog declare them.
X-Content-Type-Options
33 providers
2 spellings
The X-Content-Type-Options HTTP header — security policy, declared by 33 providers in the API Evangelist catalog.
Strict-Transport-Security
33 providers
regulated
No law names this header. Several require encryption in transit, and this is what that instruction looks like on the wire.
X-Frame-Options
30 providers
The X-Frame-Options HTTP header — security policy, declared by 30 providers in the API Evangelist catalog.
Content-Security-Policy
4 providers
regulated
Constrains what the client may execute. Four providers declare it, because almost nobody documents edge headers in a contract.
Expect-CT
3 providers
The Expect-CT HTTP header — security policy, RFC 9163, declared by 3 providers in the API Evangelist catalog.
Referrer-Policy
2 providers
The Referrer-Policy HTTP header — security policy, declared by 2 providers in the API Evangelist catalog.
NEL
2 providers
The NEL HTTP header — security policy, declared by 2 providers in the API Evangelist catalog.
Public
1 providers
The Public HTTP header — security policy, RFC 2068, declared by 1 providers in the API Evangelist catalog.
Sec-Fetch-User
The Sec-Fetch-User HTTP header — security policy, not observed in the catalog.
Sec-Fetch-Storage-Access
The Sec-Fetch-Storage-Access HTTP header — security policy, not observed in the catalog.
Sec-Fetch-Site
The Sec-Fetch-Site HTTP header — security policy, not observed in the catalog.
Sec-Fetch-Mode
The Sec-Fetch-Mode HTTP header — security policy, not observed in the catalog.
Sec-Fetch-Dest
The Sec-Fetch-Dest HTTP header — security policy, not observed in the catalog.
Reporting-Endpoints
The Reporting-Endpoints HTTP header — security policy, not observed in the catalog.
Public-Key-Pins
The Public-Key-Pins HTTP header — security policy, RFC 7469, not observed in the catalog.
Public-Key-Pins-Report-Only
The Public-Key-Pins-Report-Only HTTP header — security policy, RFC 7469, not observed in the catalog.
PICS-Label
The PICS-Label HTTP header — security policy, not observed in the catalog.
Permissions-Policy
regulated
The Permissions-Policy HTTP header — security policy, not observed in the catalog.
Origin-Agent-Cluster
The Origin-Agent-Cluster HTTP header — security policy, not observed in the catalog.
Cross-Origin-Resource-Policy
The Cross-Origin-Resource-Policy HTTP header — security policy, not observed in the catalog.
Cross-Origin-Opener-Policy
The Cross-Origin-Opener-Policy HTTP header — security policy, not observed in the catalog.
Cross-Origin-Opener-Policy-Report-Only
The Cross-Origin-Opener-Policy-Report-Only HTTP header — security policy, not observed in the catalog.
Cross-Origin-Embedder-Policy
The Cross-Origin-Embedder-Policy HTTP header — security policy, not observed in the catalog.
Cross-Origin-Embedder-Policy-Report-Only
The Cross-Origin-Embedder-Policy-Report-Only HTTP header — security policy, not observed in the catalog.
Content-Security-Policy-Report-Only
The Content-Security-Policy-Report-Only HTTP header — security policy, not observed in the catalog.
Clear-Site-Data
regulated
Erasure carried out at the client boundary. Nobody in the catalog declares it.