Developer Toolbox

application/xml

application/xml is the general type for XML documents (RFC 7303). Formats built on XML get types of their own with a +xml suffix, like image/svg+xml and application/atom+xml.

Open in cURL Builder A request with this type is filled in.

Header

Content-Type: application/xml; charset=utf-8

At a glance

Extensions
.xml
Kind
Text
Parameters
charset. When present, it wins over the encoding in the <?xml ...?> declaration.
In a browser
Shows the document as a collapsible tree, unless it links a stylesheet.

With curl

curl https://api.example.com/users \
  -H 'Content-Type: application/xml' \
  -d '<user><name>Ada</name></user>'

With fetch

await fetch('https://api.example.com/users', {
  method: 'POST',
  headers: { 'Content-Type': 'application/xml' },
  body: '<user><name>Ada</name></user>'
});

Common mistakes

  • text/xml or application/xml

    RFC 7303 treats the two alike and recommends application/xml. Under the older rules, text/xml without a charset meant US-ASCII, a source of encoding bugs that still turns up.

  • Header and declaration disagree

    A charset in the header overrides the encoding in the XML declaration. When the two differ, the parser decodes the bytes the way the header says and the text comes out garbled.

  • External entities (XXE)

    Parsing untrusted XML with external entities enabled lets a request read files from your server. Turn off DTDs or external entities in your parser; OWASP's XXE cheat sheet shows how for each language.