Skip to content
TabBench

Content-Type Header Checker

Find the Content-Type to send for JSON, forms, uploads and downloads, check a header value for mistakes, or drop a file to detect its real type from its contents.

Runs in your browser. Nothing you add is uploaded.

What the Content-Type Header Checker does

The Content-Type header tells the receiver how to read a message body, and getting it wrong is behind a long list of mystery failures: a JSON API that returns 415, an upload that arrives empty because the multipart boundary was set by hand, a script the browser refuses to run because it was served as text/plain. This tool helps three ways: it lists what to send for common jobs, checks a header value for mistakes, and reads a dropped file's first bytes to find out what it really is.

How to choose or check a Content-Type

  1. On “What should I send?”, find your job, such as JSON API, file upload or server-sent events, and copy the header with its explanatory note.
  2. On “Check a header”, paste a Content-Type value to see its type, subtype, parameters and any problems.
  3. On “Identify a file”, drop a file. Only its first few kilobytes are read, in your browser.
  4. Compare the type from the extension, from your browser and from the contents. A mismatch is flagged.
  5. Copy the Content-Type header suggested for serving that file.

The Content-Type Header Checker runs entirely in your browser — nothing you enter is uploaded, stored, or logged.

When to use it

Fixing a 415 Unsupported Media Type

If an API rejects your request, the Content-Type is usually missing or wrong. Check the recipe for JSON, forms or multipart and compare it with what you send.

Serving user uploads safely

Detect the real type of an uploaded file from its bytes rather than trusting the file name, and serve it with a matching header plus nosniff.

Debugging a blocked script or stylesheet

Browsers refuse module scripts and strict-mode stylesheets with the wrong type. The recipes show the exact header each needs.

Good to know

  • For multipart/form-data let the client set the header. It must include the boundary it actually used.
  • text/event-stream must not have a charset parameter.
  • JSON does not need charset=utf-8, but text types do.
  • Serve SVG as image/svg+xml and enable compression for it.
  • Combine Content-Type with X-Content-Type-Options: nosniff for files users can upload.

Frequently asked questions

Do I set Content-Type on a multipart upload myself?

No. Let the browser or HTTP library set it. It must contain the boundary string used in the body, and setting the header by hand without the matching boundary breaks the upload.

Does application/json need charset=utf-8?

No. JSON is always UTF-8, so the parameter is redundant. Text types such as text/html and text/plain should include a charset.

How does file detection work?

Most formats start with a fixed byte pattern (“magic number”), for example PNG files begin with the bytes 89 50 4E 47. The tool reads the first few kilobytes of the file in your browser and matches them; nothing is uploaded.

What is the difference between application/json and text/json?

application/json is the registered type. text/json is not registered and some clients do not treat it as JSON. Always use application/json.

What does +json mean in application/vnd.api+json?

It is a structured-syntax suffix: the content is JSON, with extra rules from the vnd.api format. Tools can treat any +json type as JSON.

How reliable is file-signature detection?

Very reliable for formats with a fixed header such as PNG, JPEG, PDF, ZIP and MP4. Plain-text formats like CSV have no signature, so they are guessed from the content and labelled as a guess. Office files are ZIP containers, so the tool also uses the extension to tell them apart.