application/xml
application/xml is the general type for XML documents (RFC 7303). Formats built on XML get types of their own with a +xml suffix, like image/svg+xml and application/atom+xml.
Open in cURL Builder A request with this type is filled in.
Header
Content-Type: application/xml; charset=utf-8At a glance
- Extensions
- .xml
- Kind
- Text
- Parameters
charset. When present, it wins over the encoding in the<?xml ...?>declaration.- In a browser
- Shows the document as a collapsible tree, unless it links a stylesheet.
With curl
curl https://api.example.com/users \ -H 'Content-Type: application/xml' \ -d '<user><name>Ada</name></user>'
With fetch
await fetch('https://api.example.com/users', {
method: 'POST',
headers: { 'Content-Type': 'application/xml' },
body: '<user><name>Ada</name></user>'
});Common mistakes
text/xmlorapplication/xmlRFC 7303 treats the two alike and recommends
application/xml. Under the older rules,text/xmlwithout a charset meant US-ASCII, a source of encoding bugs that still turns up.Header and declaration disagree
A
charsetin the header overrides the encoding in the XML declaration. When the two differ, the parser decodes the bytes the way the header says and the text comes out garbled.External entities (XXE)
Parsing untrusted XML with external entities enabled lets a request read files from your server. Turn off DTDs or external entities in your parser; OWASP's XXE cheat sheet shows how for each language.