field Registered
Verified 2026-09-18 · registry updated 2026-08-28

Signature

Carries one or more HTTP Message Signatures.

Use Signature with Signature-Input, a defined key-distribution mechanism, freshness controls, and replay protection.

httpheadersecurityintegrity

Reference (http)

Signature: sig1=:BASE64_SIGNATURE:

Use Signature with Signature-Input, a defined key-distribution mechanism, freshness controls, and replay protection.

Common mistakes

  • Signing fields without defining canonicalization, covered components, or key rotation.

IANA registry: http-fields/field-names · structured type: Dictionary

Registry reference: RFC 9421, Section 4.2: HTTP Message Signatures

Permalink: https://merginit.com/reference/http/field-signature