Media type / application
application/jose
JSON Object Signing and Encryption in compact serialisation — the transport form behind JWS and JWE.
Served inline: Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.
Browser behaviour
Downloads
Charset
no charset
Compression
Already compressed
Send it like this
Content-Type: application/joseA binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
Handling verdict
Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.
A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
The format compresses internally. Another transport encoding costs CPU on both ends and typically changes the size by less than a percent — sometimes upward.
Registered with IANA through a public review process, so the name is stable and every implementation can rely on it meaning the same thing.
Anatomy of the name
RFC 6838Top-level type
application
Application
Subtype
jose
Registered in the standards tree.
Structured syntax
none
No suffix, so the payload format is defined entirely by the subtype itself.
Parameters
none
Beyond the charset rule above, this type defines no parameters of its own.
Response headers
Content-Type: application/jose
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="example"nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Content-Disposition: attachment names the saved file and removes any doubt about rendering.
Server configuration
route headernginx
# application/jose has no file extension — set it on the route instead
add_header Content-Type "application/jose";Apache
# application/jose has no file extension — set it on the handler instead
Header set Content-Type "application/jose"Caddy
header Content-Type "application/jose"Extensions and other spellings
declaredFile extensions
None. This type exists only as a header value, so no extension-to-type mapping on a server will ever produce it — the application has to set it explicitly.
Also written as
These reach the same handler in practice. Accept them on input; send application/jose on output.
File signature
No fixed signature — this format has no reliable magic number, so identify it by parsing rather than by the first few bytes.