The WWW-Authenticate HTTP header — authentication, RFC 9110, declared by 24 providers in the API Evangelist catalog.
WWW-Authenticate
Authentication IANA permanent response 3 spellings
A reference entry. The registry facts and catalog measurements below are complete; the written guidance for this header has not been authored yet.
WWW-Authenticate is authentication — Headers that carry who the caller is — credentials, tokens, keys, signatures of identity. The most declared category in the catalog and the most inconsistently spelled.
The registry
Listed in the IANA HTTP Field Name Registry as a permanent entry. Defined in RFC 9110, Section 11.6.1: HTTP Semantics.
In the catalog
Declared by 24 providers across 1,152 published specification files in the API Evangelist catalog, where it appears as a response header — sent by the server.
It is spelled 3 different ways across those contracts — WWW-Authenticate, www-authenticate, Www-Authenticate. HTTP field names are case-insensitive (RFC 9110, §5.1), so every one of these is the same header. They are not the same string, which is why generated clients disagree about it.
Governed by these rules
Machine-enforceable governance rules from rules.apievangelist.com that apply to this header when it appears in an OpenAPI.
OpenAPI Components Headers Error error
Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses
Guidance: Rate Limits →OpenAPI Components Headers Info info
Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses
Guidance: Rate Limits →OpenAPI Headers Hyphenated Pascal Case error
HTTP headers should follow Hyphenated-Pascal-Case naming convention for consistency and readability, such as Content-Type, X-Request-Id, or Accept-Language.
Guidance: Naming →OpenAPI Security Schemes API Keys In Header Error error
Having components security schemes which possesses an api-key property that allows to configure how API keys are applied to operations have a in of header set.
Guidance: Security →OpenAPI Security Schemes API Keys Info info
Having components security schemes which possesses an api-key property that allows to configure how API keys are applied to operations.
Guidance: Security →