field Provisional
Verified 2026-09-18 · registry updated
2026-08-28Reporting-Endpoints
Defines named endpoints for browser Reporting API reports.
Use Reporting-Endpoints with CSP, integrity, or network reporting only after the endpoint is authenticated, rate-limited, and safe for untrusted reports.
httpheadersecuritymonitoring
Reference (http)
Reporting-Endpoints: default="https://reports.example.com/reports"
Use Reporting-Endpoints with CSP, integrity, or network reporting only after the endpoint is authenticated, rate-limited, and safe for untrusted reports.
Editorial status: this registry value is provisional. Review compatibility before deploying it and do not present it as a current default.
Common mistakes
- Logging arbitrary report payloads without size limits or privacy review.
IANA registry: http-fields/field-names
Registry reference: Reporting API