Media type / application
application/yaml
YAML documents. Registered only in 2024 — before that everyone shipped the unregistered text/yaml or application/x-yaml.
Served inline: Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.
Browser behaviour
Downloads
Charset
charset required
Compression
Compress in transit
Send it like this
Content-Type: application/yaml; charset=utf-8Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.
Handling verdict
Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.
Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.
The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.
Registered with IANA through a public review process, so the name is stable and every implementation can rely on it meaning the same thing.
Anatomy of the name
RFC 6838Top-level type
application
Application
Subtype
yaml
Registered in the standards tree.
Structured syntax
none
No suffix, so the payload format is defined entirely by the subtype itself.
Parameters
charset
Beyond the charset rule above, this type defines no parameters of its own.
What trips people up
1 note- Loading untrusted YAML with a non-safe loader can construct arbitrary objects — a documented remote code execution path in several languages.
Response headers
Content-Type: application/yaml; charset=utf-8
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="example.yaml"
Vary: Accept-Encodingnosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Content-Disposition: attachment names the saved file and removes any doubt about rendering.
Server configuration
extension mappingnginx
types {
application/yaml yaml yml;
}Apache
AddType application/yaml .yaml .yml
AddCharset UTF-8 .yaml .ymlCaddy
@type path *.yaml *.yml
header @type Content-Type "application/yaml; charset=utf-8"Extensions and other spellings
declaredFile extensions
Also written as
These reach the same handler in practice. Accept them on input; send application/yaml on output.
File signature
No fixed signature — this format has no reliable magic number, so identify it by parsing rather than by the first few bytes.