The x-jws-signature HTTP header — integrity & signing, declared by 32 providers in the API Evangelist catalog.
x-jws-signature
Integrity & Signing de facto — unregistered response reached by regulation 2 spellings
A reference entry. The registry facts and catalog measurements below are complete; the written guidance for this header has not been authored yet.
x-jws-signature is integrity & signing — Headers carrying a digest or a signature over the message, so a recipient can prove it arrived as it was sent.
The registry
Not registered with IANA. It is a de facto or vendor field — real, widely used, and governed by nothing but convention.
In the catalog
Declared by 32 providers across 1,816 published specification files in the API Evangelist catalog, where it appears as a response header — sent by the server.
It is spelled 2 different ways across those contracts — x-jws-signature, X-JWS-Signature. HTTP field names are case-insensitive (RFC 9110, §5.1), so every one of these is the same header. They are not the same string, which is why generated clients disagree about it.
Reached by regulation
This header is mandated: the law, or a technical standard the law makes binding, names it directly. Only a credentialed caller can watch it in flight. The catalog can see that a contract declares it; it cannot see that a deployment honours it, and this site never claims otherwise.
Reached by these regulations
Catalogued at regulations.apievangelist.com, with the basis of each connection recorded rather than implied.
Governed by these rules
Machine-enforceable governance rules from rules.apievangelist.com that apply to this header when it appears in an OpenAPI.
OpenAPI Components Headers Error error
Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses
Guidance: Rate Limits →OpenAPI Components Headers Info info
Utilizing the headers object in the centralized OpenAPI components library helps make headers reusable across API requests and responses
Guidance: Rate Limits →OpenAPI Headers Hyphenated Pascal Case error
HTTP headers should follow Hyphenated-Pascal-Case naming convention for consistency and readability, such as Content-Type, X-Request-Id, or Accept-Language.
Guidance: Naming →