Developer Toolbox

application/zip

application/zip is the registered type for ZIP archives. It looks simple, but uploads arrive under several names, and many other file formats are ZIP archives inside.

Open in cURL Builder A request with this type is filled in.

Header

Content-Type: application/zip

At a glance

Extensions
.zip
Kind
Binary
Parameters
None
In a browser
Downloads the file.

With curl

curl -o export.zip -H 'Accept: application/zip' https://api.example.com/exports/42

With fetch

const res = await fetch('https://api.example.com/exports/42', { headers: { Accept: 'application/zip' } });
const blob = await res.blob();

Common mistakes

  • Uploads arrive under other names

    Browsers on Windows often label ZIP uploads application/x-zip-compressed, and some send application/octet-stream. Accept those too, and check the first bytes of the file (PK\x03\x04).

  • Office files are ZIPs

    .docx, .xlsx, .pptx and .jar files are ZIP archives with types of their own, and their first bytes cannot tell them apart. EPUB and OpenDocument files can be told apart: they store an uncompressed mimetype entry first.

  • Zip bombs and paths

    A small archive can unpack to gigabytes, and an entry named ../../etc/passwd can write outside the target folder (Zip Slip). Limit the unpacked size and reject entries whose path leaves the folder.