Skip to content

Header: Reporting Endpoints

Ryan Parman edited this page Jun 11, 2024 · 3 revisions

Overview

The Reporting-Endpoints HTTP response header allows website administrators to specify one or more endpoints that are used to receive errors such as CSP violation reports, Cross-Origin-Opener-Policy reports, or other generic violations.

This header can be used in combination with the Content-Security-Policy header report-to directive. For more details on setting up CSP reporting, see the Content Security Policy (CSP) documentation.

Usage

Reporting-Endpoints: <name>="<endpoint>"
Reporting-Endpoints: <name>="<endpoint>", <name>="<endpoint>"
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports",
                     hpkp-endpoint="https://example.com/hpkp-reports"

References

Clone this wiki locally