font/woff2

All MIME types
Font · Standards tree · W3C WOFF2.woff2

Media type / font

font/woff2

The webfont format to ship: Brotli-compressed OpenType, supported by every browser in current use.

Served inline: Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Browser behaviour

Downloads

Charset

no charset

Compression

Already compressed

Send it like this

Content-Type: font/woff2

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

Handling verdict

InlineDownloads

Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Charsetno charset

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

CompressionAlready compressed

The format compresses internally. Another transport encoding costs CPU on both ends and typically changes the size by less than a percent — sometimes upward.

NameStandards tree

Registered with IANA through a public review process, so the name is stable and every implementation can rely on it meaning the same thing.

Anatomy of the name

RFC 6838

Top-level type

font

Font

Subtype

woff2

Registered in the standards tree.

Structured syntax

none

No suffix, so the payload format is defined entirely by the subtype itself.

Parameters

none

Beyond the charset rule above, this type defines no parameters of its own.

What trips people up

2 notes
  • Already Brotli-compressed inside, so compressing it again in transit is wasted CPU.
  • Fonts are fetched in CORS mode even from the same origin, so a CDN must send Access-Control-Allow-Origin or text renders in the fallback face.

Response headers

Content-Type: font/woff2
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="example.woff2"
Access-Control-Allow-Origin: *

nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Content-Disposition: attachment names the saved file and removes any doubt about rendering.

Server configuration

extension mapping

nginx

types {
    font/woff2  woff2;
}

Apache

AddType font/woff2 .woff2

Caddy

@type path *.woff2
header @type Content-Type "font/woff2"

Extensions and other spellings

with signature

File extensions

File signature

77 4F 46 32 (wOF2)

Check these bytes rather than the client-supplied Content-Type when validating an upload. The header is a claim; the signature is evidence.

Related media types

4
Familyfont
Treestandards
Suffix
Inlinedownload