The Expect-CT HTTP header — security policy, RFC 9163, declared by 3 providers in the API Evangelist catalog.
Expect-CT
Security Policy deprecated response
A reference entry. The registry facts and catalog measurements below are complete; the written guidance for this header has not been authored yet.
Expect-CT is security policy — Response headers instructing the client to constrain itself — transport security, framing, script sources, sniffing, referrer leakage.
The registry
Listed in the IANA HTTP Field Name Registry as marked deprecated in the registry. Defined in RFC 9163: Expect-CT Extension for HTTP.
In the catalog
Declared by 3 providers across 136 published specification files in the API Evangelist catalog, where it appears as a response header — sent by the server.
Governed by these rules
Machine-enforceable governance rules from rules.apievangelist.com that apply to this header when it appears in an OpenAPI.
OpenAPI Components Headers Error error
Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses
Guidance: Rate Limits →OpenAPI Components Headers Info info
Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses
Guidance: Rate Limits →OpenAPI Headers Hyphenated Pascal Case error
HTTP headers should follow Hyphenated-Pascal-Case naming convention for consistency and readability, such as Content-Type, X-Request-Id, or Accept-Language.
Guidance: Naming →