Response header
< Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"Reporting-Endpoints Header: Reporting API Setup
Reporting-Endpoints names the URLs where browsers send CSP, COOP, deprecation and crash reports. Syntax, the default endpoint, and replacing Report-To.
- Direction
- Response
- Category
- Security
- Spec
- Reporting API
On this page
TL;DR:
Reporting-Endpointsdeclares named URLs for the browser Reporting API:Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports". CSP’sreport-to csp-endpoint, COOP, deprecation and crash reports then deliver there. It replaces the deprecatedReport-Toheader for declaring endpoints.
Syntax
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports", coop-endpoint="https://example.com/coop-reports"
Each entry is name="url". URLs must be quoted and HTTPS; non-secure endpoints are ignored. The names are arbitrary tokens that other headers reference.
The name default is special. It receives reports from features with no endpoint name of their own, such as Permissions-Policy violations, and reports with no associated header at all, such as deprecation reports:
Reporting-Endpoints: default="https://example.com/reports"
Who uses it
CSP, through the report-to directive:
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"
Content-Security-Policy: default-src 'self'; report-to csp-endpoint
Also Cross-Origin-Opener-Policy reports (see COOP), Integrity-Policy violations, deprecation reports, and crash and intervention reports. For CSP rollout with this header, read CSP Report-Only.
What the browser sends
A POST with Content-Type: application/reports+json and a JSON array of reports:
[
{
"type": "deprecation",
"age": 10,
"url": "https://example.com/",
"user_agent": "Mozilla/5.0 ...",
"body": { "id": "ExampleFeature", "message": "..." }
}
]
Reports are queued and delivered asynchronously, often batched, so expect a delay rather than an immediate request.
Moving off Report-To
Report-To carries a JSON value with a group, a max_age and a list of endpoints:
Report-To: { "group": "csp-endpoints", "max_age": 10886400, "endpoints": [{ "url": "https://example.com/reports" }] }
Migration: add Reporting-Endpoints with the same URL under a name and point report-to at that name. While you support browsers you have not tested, send both headers. There is no max_age in the new header, so send it on every HTML response rather than once.
NEL still names a group
Network Error Logging has its own header whose report_to field names a reporting group:
NEL: { "report_to": "network-errors", "max_age": 2592000 }
Report-To: { "group": "network-errors", "max_age": 2592000, "endpoints": [{ "url": "https://example.com/nel" }] }
That pairing is how NEL is documented, so a site using NEL keeps its Report-To header for it even after moving CSP and COOP to Reporting-Endpoints.
Gotchas
- Send the header on the response for the document or worker whose reports you want. Putting it only on API responses does nothing for the page.
- Reports are POSTed by browsers on behalf of arbitrary visitors. Treat the bodies as untrusted data, and rate-limit the collector.
- A mistyped name in
report-tofails silently. Compare it with the header key character by character.
Verify
curl -sI https://example.com | grep -i -E 'reporting-endpoints|report-to|content-security-policy'
Then trigger a violation in DevTools. Chromium’s Application panel has a Reporting API section listing queued reports and their delivery status.
Related
Frequently asked questions
What is the Reporting-Endpoints header?
A response header that maps endpoint names to URLs, for example csp-endpoint="https://example.com/csp-reports". Other headers and browser features then refer to an endpoint by name, such as a CSP report-to directive, and the browser POSTs reports there.
What is the difference between Reporting-Endpoints and Report-To?
Report-To is the earlier design: a JSON header with group, max_age and endpoints that the browser cached. Reporting-Endpoints is a simpler name-to-URL mapping. MDN marks Report-To deprecated, says to avoid it in new projects, and says Reporting-Endpoints should be used in preference.
Which browsers support Reporting-Endpoints?
MDN lists it as Baseline 2024, newly available since September 2024, with some parts of the feature varying by browser. Check the specific report types you need, since support can differ between CSP, COOP, deprecation and crash reports.
Does Network Error Logging use Reporting-Endpoints?
MDN documents the NEL header with a report_to field that names a reporting group, which is the Report-To concept, and its NEL page does not describe Reporting-Endpoints support. Until you have tested your target browsers, keep sending Report-To for NEL and use Reporting-Endpoints for the other report types.
Why do my reports never arrive?
Usual causes are an HTTP endpoint URL (non-secure endpoints are ignored), a report-to name that does not match any key in the header, the header missing from the actual document response, or a collector that rejects the application/reports+json content type the browser sends.
Sources
Related
CSP Report-Only Header: Roll Out CSP Safely
Content-Security-Policy-Report-Only tests a policy without blocking. Rollout steps, report-uri vs report-to, sample violation JSON, and cutting noise.
Content-Security-Policy Header: Directives, Nonces and Console Errors
Content-Security-Policy (CSP) limits what a page may load or run. Directives, nonces, strict-dynamic, Report-Only rollout, console errors, helmet and Next.js.
Cross-Origin-Embedder-Policy
Learn how Cross-Origin-Embedder-Policy (COEP) controls cross-origin resource loading. Required for SharedArrayBuffer and high-resolution timer access.
Cross-Origin-Opener-Policy
Learn how Cross-Origin-Opener-Policy (COOP) isolates your browsing context from cross-origin documents. Required for SharedArrayBuffer and enhanced security.