application/xml

All MIME types
Application · Standards tree · RFC 7303.xml .xsl .xsd .rng

Media type / application

application/xml

XML documents intended for machine processing — the type to prefer over text/xml.

Served inline: Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.

Browser behaviour

Renders inertly

Charset

charset required

Compression

Compress in transit

Send it like this

Content-Type: application/xml; charset=utf-8

Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.

Handling verdict

InlineRenders inertly

Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.

Charsetcharset required

Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.

CompressionCompress in transit

The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.

NameStandards tree

Registered with IANA through a public review process, so the name is stable and every implementation can rely on it meaning the same thing.

Anatomy of the name

RFC 6838

Top-level type

application

Application

Subtype

xml

Registered in the standards tree.

Structured syntax

none

No suffix, so the payload format is defined entirely by the subtype itself.

Parameters

charset

Beyond the charset rule above, this type defines no parameters of its own.

What trips people up

1 note
  • When the charset parameter is absent, the XML declaration inside the document decides the encoding.

Response headers

Content-Type: application/xml; charset=utf-8
X-Content-Type-Options: nosniff
Content-Disposition: inline
Vary: Accept-Encoding

nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Serving it inline is safe here because the browser renders it without granting it script access.

Server configuration

extension mapping

nginx

types {
    application/xml  xml xsl xsd rng;
}

Apache

AddType application/xml .xml .xsl .xsd .rng
AddCharset UTF-8 .xml .xsl .xsd .rng

Caddy

@type path *.xml *.xsl *.xsd *.rng
header @type Content-Type "application/xml; charset=utf-8"

Extensions and other spellings

with signature

File extensions

.xml.xsl.xsd.rng

File signature

3C 3F 78 6D 6C

Check these bytes rather than the client-supplied Content-Type when validating an upload. The header is a claim; the signature is evidence.

Related media types

8
Familyapplication
Treestandards
Suffix
Inlinepassive