field Provisional
Verified 2026-09-18 · registry updated 2026-08-28

Reporting-Endpoints

Defines named endpoints for browser Reporting API reports.

Use Reporting-Endpoints with CSP, integrity, or network reporting only after the endpoint is authenticated, rate-limited, and safe for untrusted reports.

httpheadersecuritymonitoring

Reference (http)

Reporting-Endpoints: default="https://reports.example.com/reports"

Use Reporting-Endpoints with CSP, integrity, or network reporting only after the endpoint is authenticated, rate-limited, and safe for untrusted reports.

Editorial status: this registry value is provisional. Review compatibility before deploying it and do not present it as a current default.

Common mistakes

  • Logging arbitrary report payloads without size limits or privacy review.

IANA registry: http-fields/field-names

Registry reference: Reporting API

Permalink: https://merginit.com/reference/http/field-reporting-endpoints