application/vnd.android.package-archive

All MIME types
Application · Vendor tree.apk

Media type / application

application/vnd.android.package-archive

Android application packages (APK), a signed ZIP container of compiled code and resources.

Served inline: Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Browser behaviour

Downloads

Charset

no charset

Compression

Already compressed

Send it like this

Content-Type: application/vnd.android.package-archive

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

Handling verdict

InlineDownloads

Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Charsetno charset

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

CompressionAlready compressed

The format compresses internally. Another transport encoding costs CPU on both ends and typically changes the size by less than a percent — sometimes upward.

NameVendor tree

A `vnd.` subtype belongs to a specific product or organisation. It is registered, but its meaning is defined by that vendor rather than by a standards body.

Anatomy of the name

RFC 6838

Top-level type

application

Application

Subtype

vnd.android.package-archive

Registered in the vendor tree.

Structured syntax

none

No suffix, so the payload format is defined entirely by the subtype itself.

Parameters

none

Beyond the charset rule above, this type defines no parameters of its own.

What trips people up

1 note
  • Serving APKs outside a store means users must enable installation from unknown sources, which is a meaningful security downgrade.

Response headers

Content-Type: application/vnd.android.package-archive
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="example.apk"

nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Content-Disposition: attachment names the saved file and removes any doubt about rendering.

Server configuration

extension mapping

nginx

types {
    application/vnd.android.package-archive  apk;
}

Apache

AddType application/vnd.android.package-archive .apk

Caddy

@type path *.apk
header @type Content-Type "application/vnd.android.package-archive"

Extensions and other spellings

with signature

File extensions

File signature

50 4B 03 04

Check these bytes rather than the client-supplied Content-Type when validating an upload. The header is a claim; the signature is evidence.

Related media types

8
Familyapplication
Treevendor
Suffix
Inlinedownload