application/x-www-form-urlencoded

All MIME types
Application · Unregistered tree · WHATWG URLheader only

Media type / application

application/x-www-form-urlencoded

The default encoding of an HTML form POST: percent-encoded key=value pairs joined by ampersands, with spaces as plus signs.

Served inline: Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Browser behaviour

Downloads

Charset

no charset

Compression

Compress in transit

Send it like this

Content-Type: application/x-www-form-urlencoded

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

Handling verdict

InlineDownloads

Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Charsetno charset

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

CompressionCompress in transit

The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.

NameUnregistered tree

An `x-` prefix marks a type that was never registered. RFC 6838 discourages new ones, but several — like application/x-www-form-urlencoded — are now too widespread to change.

Anatomy of the name

RFC 6838

Top-level type

application

Application

Subtype

x-www-form-urlencoded

Registered in the unregistered tree.

Structured syntax

none

No suffix, so the payload format is defined entirely by the subtype itself.

Parameters

none

Beyond the charset rule above, this type defines no parameters of its own.

What trips people up

2 notes
  • It cannot carry file uploads — a form with <input type="file"> must use multipart/form-data instead.
  • Because it is a CORS-safelisted request type, a cross-origin POST with it triggers no preflight, which is why CSRF defences matter here.

Response headers

Content-Type: application/x-www-form-urlencoded
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="example"
Vary: Accept-Encoding

nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Content-Disposition: attachment names the saved file and removes any doubt about rendering.

Server configuration

route header

nginx

# application/x-www-form-urlencoded has no file extension — set it on the route instead
add_header Content-Type "application/x-www-form-urlencoded";

Apache

# application/x-www-form-urlencoded has no file extension — set it on the handler instead
Header set Content-Type "application/x-www-form-urlencoded"

Caddy

header Content-Type "application/x-www-form-urlencoded"

Related media types

8
Familyapplication
Treeunregistered
Suffix
Inlinedownload