How HTTP Works

Glossary Term

MIME Type (Media Type)

A MIME type, or media type, is the type/subtype label in Content-Type that tells clients how to interpret a body. Covers nosniff and blocked-script errors.

Reviewed 2 min readbeginner3 sourcesMarkdown
On this page

TL;DR: A MIME type (officially a media type) is the type/subtype label in the Content-Type header, such as text/html or application/json. Browsers trust it more than the file extension.

A MIME type, called a media type in RFC 9110, is a two-part identifier of the form type/subtype, optionally followed by parameters, that tells the receiver how to interpret a message body. It is carried in Content-Type on responses and on requests with bodies, and the registry of valid values is maintained by IANA.

Anatomy

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-Content-Type-Options: nosniff
  • text is the top-level type; html is the subtype; charset=utf-8 is a parameter.
  • Suffixes such as application/ld+json and image/svg+xml mean “this is JSON-LD” and “this is XML-based”.
  • application/json defines no charset parameter, because JSON is always UTF-8.

The errors this causes

With nosniff set, Chrome refuses wrongly typed scripts and stylesheets:

Refused to execute script from 'https://example.com/app.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.
Failed to load module script: Expected a JavaScript module script but the server responded with a MIME type of "text/html". Strict MIME type checking is enforced for module scripts per HTML spec.

Module scripts are checked even without nosniff. In both cases the actual cause is almost always a 404 that the server replaced with index.html, often after a deploy removed an old hashed asset.

Non-obvious facts

  • Browsers sniff when the type is missing or wrong, which is why X-Content-Type-Options: nosniff exists. It also prevents a user-uploaded file from being interpreted as HTML or script.
  • text/plain is not a safe default for uploads. Serve user content with an explicit type and Content-Disposition: attachment where possible.
  • Requests have media types too. Sending JSON with Content-Type: text/plain or form encoding to a JSON parser yields a 415 Unsupported Media Type or an empty body in frameworks like Express.
  • The Accept header is the other half. The client lists types it can handle; the server picks one and labels it in Content-Type.

Go deeper

Frequently asked questions

What is the difference between a MIME type and a media type?

They are the same thing. RFC 9110 calls it a media type; MIME type is the older name from email, and both appear in the Content-Type header.

What is the MIME type for JSON and JavaScript?

application/json for JSON, and text/javascript for JavaScript. HTML specifies text/javascript as the one to use; application/javascript is obsolete but still recognized.

What does "strict MIME type checking is enabled" mean?

The response has X-Content-Type-Options: nosniff, so the browser refuses to run a script or apply a stylesheet whose Content-Type is not a JavaScript or CSS type.

Why does my missing JavaScript file return text/html?

A single-page app fallback rule is serving index.html for every unknown path, including a missing chunk. The browser then rejects the HTML as a script.

Sources

  1. MDN Web Docs: MIME typesdeveloper.mozilla.org
  2. RFC 9110: Media Typerfc-editor.org
  3. IANA Media Types registryiana.org

Keep going

Browse /search