# Reporting-Endpoints Header: Reporting API Setup

> Reporting-Endpoints names the URLs where browsers send CSP, COOP, deprecation and crash reports. Syntax, the default endpoint, and replacing Report-To.

Source: https://howhttpworks.com/headers/reporting-endpoints
Last reviewed: 2026-10-04

> **TL;DR:** `Reporting-Endpoints` declares named URLs for the browser Reporting API: `Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"`. CSP's `report-to csp-endpoint`, COOP, deprecation and crash reports then deliver there. It replaces the deprecated `Report-To` header for declaring endpoints.

## Syntax

```http
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports", coop-endpoint="https://example.com/coop-reports"
```

Each entry is `name="url"`. URLs must be quoted and HTTPS; non-secure endpoints are ignored. The names are arbitrary tokens that other headers reference.

The name `default` is special. It receives reports from features with no endpoint name of their own, such as `Permissions-Policy` violations, and reports with no associated header at all, such as deprecation reports:

```http
Reporting-Endpoints: default="https://example.com/reports"
```

## Who uses it

CSP, through the `report-to` directive:

```http
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"
Content-Security-Policy: default-src 'self'; report-to csp-endpoint
```

Also Cross-Origin-Opener-Policy reports (see [COOP](https://howhttpworks.com/headers/cross-origin-opener-policy)), Integrity-Policy violations, deprecation reports, and crash and intervention reports. For CSP rollout with this header, read [CSP Report-Only](https://howhttpworks.com/headers/content-security-policy-report-only).

## What the browser sends

A `POST` with `Content-Type: application/reports+json` and a JSON array of reports:

```json
[
  {
    "type": "deprecation",
    "age": 10,
    "url": "https://example.com/",
    "user_agent": "Mozilla/5.0 ...",
    "body": { "id": "ExampleFeature", "message": "..." }
  }
]
```

Reports are queued and delivered asynchronously, often batched, so expect a delay rather than an immediate request.

## Moving off Report-To

`Report-To` carries a JSON value with a group, a `max_age` and a list of endpoints:

```http
Report-To: { "group": "csp-endpoints", "max_age": 10886400, "endpoints": [{ "url": "https://example.com/reports" }] }
```

Migration: add `Reporting-Endpoints` with the same URL under a name and point `report-to` at that name. While you support browsers you have not tested, send both headers. There is no `max_age` in the new header, so send it on every HTML response rather than once.

## NEL still names a group

Network Error Logging has its own header whose `report_to` field names a reporting group:

```http
NEL: { "report_to": "network-errors", "max_age": 2592000 }
Report-To: { "group": "network-errors", "max_age": 2592000, "endpoints": [{ "url": "https://example.com/nel" }] }
```

That pairing is how NEL is documented, so a site using NEL keeps its `Report-To` header for it even after moving CSP and COOP to `Reporting-Endpoints`.

## Gotchas

- Send the header on the response for the document or worker whose reports you want. Putting it only on API responses does nothing for the page.
- Reports are POSTed by browsers on behalf of arbitrary visitors. Treat the bodies as untrusted data, and rate-limit the collector.
- A mistyped name in `report-to` fails silently. Compare it with the header key character by character.

## Verify

```bash
curl -sI https://example.com | grep -i -E 'reporting-endpoints|report-to|content-security-policy'
```

Then trigger a violation in DevTools. Chromium's Application panel has a Reporting API section listing queued reports and their delivery status.

## Related

- [Content-Security-Policy](https://howhttpworks.com/headers/content-security-policy), [CSP Report-Only](https://howhttpworks.com/headers/content-security-policy-report-only)
- [COOP](https://howhttpworks.com/headers/cross-origin-opener-policy), [COEP](https://howhttpworks.com/headers/cross-origin-embedder-policy)
