Reporting-Endpoints header

Baseline 2024
Newly available

Since September 2024, this feature works across the latest devices and browser versions. This feature might not work in older devices or browsers.

The HTTP Reporting-Endpoints response header allows website administrators to specify one or more endpoints that can be sent reports generated by the Reporting API.

The endpoints can be used, for example, as targets for sending crash reports, deprecation reports, Content Security Policy (CSP) violation reports, Cross-Origin-Opener-Policy reports, and so on.

Note: This header replaces Report-To for declaring endpoints, and should be used in preference.

Header type Response header
CORS-safelisted response header No

Syntax

http
Reporting-Endpoints: <endpoint>
Reporting-Endpoints: <endpoint>, …, <endpointN>
<endpoint>

A reporting endpoint in the format <endpoint-name>="<URL>". The endpoints must have valid URIs in quoted strings (e.g., my-endpoint="https://example.com/reports") and non-secure endpoints are ignored. A comma-separated list of endpoints may be provided.

Description

The Reporting-Endpoints header defines the mapping between an endpoint name and a URL.

This name can be used to identify the reporting endpoint for policy violations in some HTTP headers. For example, the Content-Security-Policy allows you to specify the reporting endpoint name in its report-to directive, while the endpoints key serves the same purpose for Integrity-Policy violations.

Default reporting endpoint

The default reporting endpoint is just a report with the name "default", as shown:

http
Reporting-Endpoints: default="https://example.com/reports"

This may be used as the reporting endpoint for cases where the HTTP header that triggers a report does not have mechanism for reporting the endpoint, such as the Permissions-Policy header. It may also be used as the endpoint for reports where there is no associated HTTP header at all, such as for deprecation reports.

Examples

Setting a CSP violation report endpoint

The following example shows how the Reporting-Endpoints response header is used in conjunction with the Content-Security-Policy header to indicate where CSP violation reports are sent:

http
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports"
Content-Security-Policy: default-src 'self'; report-to csp-endpoint

Specifying multiple reporting endpoints

It's possible to specify multiple endpoints that can be used for different types of violation reports.

http
Reporting-Endpoints: csp-endpoint="https://example.com/csp-reports",
                     permissions-endpoint="https://example.com/permissions-policy-reports"

Specifications

Specification
Reporting API
# header-field-registration

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
Reporting-Endpoints
Chrome – Full support
Chrome 96 (Release date: 2021-11-15)
footnote Full support
Edge – Full support
Edge 96 (Release date: 2021-11-19)
footnote Full support
Firefox – Full support
Firefox 130 (Release date: 2024-09-03)
footnote Full support
Opera – Full support
Opera 82 (Release date: 2021-12-02)
footnote Full support
Safari – Full support
Safari 16.4 (Release date: 2023-03-27)
footnote Full support
Chrome Android – Full support
Chrome Android 96 (Release date: 2021-11-15)
footnote Full support
Firefox for Android – Full support
Firefox for Android 130 (Release date: 2024-09-03)
footnote Full support
Opera Android – Full support
Opera Android 67 (Release date: 2022-01-31)
footnote Full support
Safari on iOS – Full support
Safari on iOS 16.4 (Release date: 2023-03-27)
footnote Full support
Samsung Internet – Full support
Samsung Internet 17 (Release date: 2022-05-04)
footnote Full support
WebView Android – Full support
WebView Android 96 (Release date: 2021-11-15)
footnote Full support
WebView on iOS – Full support
WebView on iOS 16.4 (Release date: 2023-03-27)
footnote Full support
crash-reporting endpoint name
Experimental
Chrome – Full support
Chrome 139 (Release date: 2025-08-05)
footnote Full support
Edge – Full support
Edge 139 (Release date: 2025-08-07)
footnote Full support
Firefox – No support
Firefox
footnote No support
Opera – Full support
Opera 123 (Release date: 2025-10-28)
footnote Full support
Safari – No support
Safari
footnote No support
Chrome Android – Full support
Chrome Android 139 (Release date: 2025-08-05)
footnote Full support
Firefox for Android – No support
Firefox for Android
footnote No support
Opera Android – Full support
Opera Android 91 (Release date: 2025-08-19)
footnote Full support
Safari on iOS – No support
Safari on iOS
footnote No support
Samsung Internet – No support
Samsung Internet
footnote No support
WebView Android – Full support
WebView Android 139 (Release date: 2025-08-05)
footnote Full support
WebView on iOS – No support
WebView on iOS
footnote No support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support
Experimental. Expect behavior to change in the future.

See also