How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

x-fapi-customer-ip-address

Privacy & Consent de facto — unregistered request reached by regulation

A reference entry. The registry facts and catalog measurements below are complete; the written guidance for this header has not been authored yet.

The x-fapi-customer-ip-address HTTP header — privacy & consent, declared by 92 providers in the API Evangelist catalog.

x-fapi-customer-ip-address is privacy & consent — Headers carrying a person’s preference or a legal consent artifact. The smallest category in the catalog by adoption and the largest by regulatory consequence.

The registry

Not registered with IANA. It is a de facto or vendor field — real, widely used, and governed by nothing but convention.

In the catalog

Declared by 92 providers across 2,307 published specification files in the API Evangelist catalog, where it appears as a request header — sent by the client.

Reached by regulation

This header is mandated: the law, or a technical standard the law makes binding, names it directly. Only a credentialed caller can watch it in flight. The catalog can see that a contract declares it; it cannot see that a deployment honours it, and this site never claims otherwise.

A header whose whole purpose is to pass an end user’s IP address to a third party. Mandated by the open-banking regimes and squarely inside GDPR’s definition of personal data — worth reading next to [[gdpr]] rather than only next to the security profile that requires it.

Reached by these regulations

Catalogued at regulations.apievangelist.com, with the basis of each connection recorded rather than implied.

Governed by these rules

Machine-enforceable governance rules from rules.apievangelist.com that apply to this header when it appears in an OpenAPI.

OpenAPI Components Headers Error error

Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses

Guidance: Rate Limits →
OpenAPI Components Headers Info info

Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses

Guidance: Rate Limits →
OpenAPI Headers Hyphenated Pascal Case error

HTTP headers should follow Hyphenated-Pascal-Case naming convention for consistency and readability, such as Content-Type, X-Request-Id, or Accept-Language.

Guidance: Naming →