How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Security Policy

Response headers instructing the client to constrain itself — transport security, framing, script sources, sniffing, referrer leakage.

26 headers, ordered by how many providers in the catalog declare them.

X-Content-Type-Options 33 providers 2 spellings

The X-Content-Type-Options HTTP header — security policy, declared by 33 providers in the API Evangelist catalog.

Strict-Transport-Security 33 providers regulated

No law names this header. Several require encryption in transit, and this is what that instruction looks like on the wire.

X-Frame-Options 30 providers

The X-Frame-Options HTTP header — security policy, declared by 30 providers in the API Evangelist catalog.

Content-Security-Policy 4 providers regulated

Constrains what the client may execute. Four providers declare it, because almost nobody documents edge headers in a contract.

Expect-CT 3 providers

The Expect-CT HTTP header — security policy, RFC 9163, declared by 3 providers in the API Evangelist catalog.

Referrer-Policy 2 providers

The Referrer-Policy HTTP header — security policy, declared by 2 providers in the API Evangelist catalog.

NEL 2 providers

The NEL HTTP header — security policy, declared by 2 providers in the API Evangelist catalog.

Public 1 providers

The Public HTTP header — security policy, RFC 2068, declared by 1 providers in the API Evangelist catalog.

Sec-Fetch-User

The Sec-Fetch-User HTTP header — security policy, not observed in the catalog.

Sec-Fetch-Storage-Access

The Sec-Fetch-Storage-Access HTTP header — security policy, not observed in the catalog.

Sec-Fetch-Site

The Sec-Fetch-Site HTTP header — security policy, not observed in the catalog.

Sec-Fetch-Mode

The Sec-Fetch-Mode HTTP header — security policy, not observed in the catalog.

Sec-Fetch-Dest

The Sec-Fetch-Dest HTTP header — security policy, not observed in the catalog.

Reporting-Endpoints

The Reporting-Endpoints HTTP header — security policy, not observed in the catalog.

Public-Key-Pins

The Public-Key-Pins HTTP header — security policy, RFC 7469, not observed in the catalog.

Public-Key-Pins-Report-Only

The Public-Key-Pins-Report-Only HTTP header — security policy, RFC 7469, not observed in the catalog.

PICS-Label

The PICS-Label HTTP header — security policy, not observed in the catalog.

Permissions-Policy regulated

The Permissions-Policy HTTP header — security policy, not observed in the catalog.

Origin-Agent-Cluster

The Origin-Agent-Cluster HTTP header — security policy, not observed in the catalog.

Cross-Origin-Resource-Policy

The Cross-Origin-Resource-Policy HTTP header — security policy, not observed in the catalog.

Cross-Origin-Opener-Policy

The Cross-Origin-Opener-Policy HTTP header — security policy, not observed in the catalog.

Cross-Origin-Opener-Policy-Report-Only

The Cross-Origin-Opener-Policy-Report-Only HTTP header — security policy, not observed in the catalog.

Cross-Origin-Embedder-Policy

The Cross-Origin-Embedder-Policy HTTP header — security policy, not observed in the catalog.

Cross-Origin-Embedder-Policy-Report-Only

The Cross-Origin-Embedder-Policy-Report-Only HTTP header — security policy, not observed in the catalog.

Content-Security-Policy-Report-Only

The Content-Security-Policy-Report-Only HTTP header — security policy, not observed in the catalog.

Clear-Site-Data regulated

Erasure carried out at the client boundary. Nobody in the catalog declares it.