How HTTP Works

Response header

< Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"

Reporting-Endpoints Header: Reporting API Setup

Reporting-Endpoints names the URLs where browsers send CSP, COOP, deprecation and crash reports. Syntax, the default endpoint, and replacing Report-To.

Reviewed 2 min readadvanced4 sourcesTry itMarkdown
Direction
Response
Category
Security
Spec
Reporting API
On this page

TL;DR: Reporting-Endpoints declares named URLs for the browser Reporting API: Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports". CSP’s report-to csp-endpoint, COOP, deprecation and crash reports then deliver there. It replaces the deprecated Report-To header for declaring endpoints.

Syntax

Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports", coop-endpoint="https://example.com/coop-reports"

Each entry is name="url". URLs must be quoted and HTTPS; non-secure endpoints are ignored. The names are arbitrary tokens that other headers reference.

The name default is special. It receives reports from features with no endpoint name of their own, such as Permissions-Policy violations, and reports with no associated header at all, such as deprecation reports:

Reporting-Endpoints: default="https://example.com/reports"

Who uses it

CSP, through the report-to directive:

Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"
Content-Security-Policy: default-src 'self'; report-to csp-endpoint

Also Cross-Origin-Opener-Policy reports (see COOP), Integrity-Policy violations, deprecation reports, and crash and intervention reports. For CSP rollout with this header, read CSP Report-Only.

What the browser sends

A POST with Content-Type: application/reports+json and a JSON array of reports:

[
  {
    "type": "deprecation",
    "age": 10,
    "url": "https://example.com/",
    "user_agent": "Mozilla/5.0 ...",
    "body": { "id": "ExampleFeature", "message": "..." }
  }
]

Reports are queued and delivered asynchronously, often batched, so expect a delay rather than an immediate request.

Moving off Report-To

Report-To carries a JSON value with a group, a max_age and a list of endpoints:

Report-To: { "group": "csp-endpoints", "max_age": 10886400, "endpoints": [{ "url": "https://example.com/reports" }] }

Migration: add Reporting-Endpoints with the same URL under a name and point report-to at that name. While you support browsers you have not tested, send both headers. There is no max_age in the new header, so send it on every HTML response rather than once.

NEL still names a group

Network Error Logging has its own header whose report_to field names a reporting group:

NEL: { "report_to": "network-errors", "max_age": 2592000 }
Report-To: { "group": "network-errors", "max_age": 2592000, "endpoints": [{ "url": "https://example.com/nel" }] }

That pairing is how NEL is documented, so a site using NEL keeps its Report-To header for it even after moving CSP and COOP to Reporting-Endpoints.

Gotchas

  • Send the header on the response for the document or worker whose reports you want. Putting it only on API responses does nothing for the page.
  • Reports are POSTed by browsers on behalf of arbitrary visitors. Treat the bodies as untrusted data, and rate-limit the collector.
  • A mistyped name in report-to fails silently. Compare it with the header key character by character.

Verify

curl -sI https://example.com | grep -i -E 'reporting-endpoints|report-to|content-security-policy'

Then trigger a violation in DevTools. Chromium’s Application panel has a Reporting API section listing queued reports and their delivery status.

Frequently asked questions

What is the Reporting-Endpoints header?

A response header that maps endpoint names to URLs, for example csp-endpoint="https://example.com/csp-reports". Other headers and browser features then refer to an endpoint by name, such as a CSP report-to directive, and the browser POSTs reports there.

What is the difference between Reporting-Endpoints and Report-To?

Report-To is the earlier design: a JSON header with group, max_age and endpoints that the browser cached. Reporting-Endpoints is a simpler name-to-URL mapping. MDN marks Report-To deprecated, says to avoid it in new projects, and says Reporting-Endpoints should be used in preference.

Which browsers support Reporting-Endpoints?

MDN lists it as Baseline 2024, newly available since September 2024, with some parts of the feature varying by browser. Check the specific report types you need, since support can differ between CSP, COOP, deprecation and crash reports.

Does Network Error Logging use Reporting-Endpoints?

MDN documents the NEL header with a report_to field that names a reporting group, which is the Report-To concept, and its NEL page does not describe Reporting-Endpoints support. Until you have tested your target browsers, keep sending Report-To for NEL and use Reporting-Endpoints for the other report types.

Why do my reports never arrive?

Usual causes are an HTTP endpoint URL (non-secure endpoints are ignored), a report-to name that does not match any key in the header, the header missing from the actual document response, or a collector that rejects the application/reports+json content type the browser sends.

Sources

  1. MDN Web Docs: Reporting-Endpointsdeveloper.mozilla.org
  2. MDN Web Docs: Report-To (deprecated)developer.mozilla.org
  3. MDN Web Docs: NELdeveloper.mozilla.org
  4. W3C Reporting APIw3.org

Keep going

Browse /search