text/javascript

All MIME types
Text · Standards tree · RFC 9239.js .mjs .cjs

Media type / text

text/javascript

The correct, current media type for JavaScript. RFC 9239 made every other spelling obsolete, including application/javascript.

Served inline: Rendered inline, this type executes script in the origin that served it. Never serve untrusted content under it from an origin that holds sessions — use a separate origin, or force a download with Content-Disposition: attachment.

Browser behaviour

Executes in the page

Charset

charset required

Compression

Compress in transit

Send it like this

Content-Type: text/javascript; charset=utf-8

Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.

Handling verdict

InlineExecutes in the page

Rendered inline, this type executes script in the origin that served it. Never serve untrusted content under it from an origin that holds sessions — use a separate origin, or force a download with Content-Disposition: attachment.

Charsetcharset required

Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.

CompressionCompress in transit

The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.

NameStandards tree

Registered with IANA through a public review process, so the name is stable and every implementation can rely on it meaning the same thing.

Anatomy of the name

RFC 6838

Top-level type

text

Text

Subtype

javascript

Registered in the standards tree.

Structured syntax

none

No suffix, so the payload format is defined entirely by the subtype itself.

Parameters

charset

Beyond the charset rule above, this type defines no parameters of its own.

What trips people up

2 notes
  • ES modules are enforced strictly: a module script served under a non-JavaScript type is blocked outright, not merely warned about.
  • The obsolete application/javascript still works everywhere; new configuration should use text/javascript.

Response headers

Content-Type: text/javascript; charset=utf-8
X-Content-Type-Options: nosniff
Content-Disposition: inline
Content-Security-Policy: sandbox; default-src 'none'
Vary: Accept-Encoding

nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. The sandbox directive is the belt-and-braces option when the content is not fully under your control.

Server configuration

extension mapping

nginx

types {
    text/javascript  js mjs cjs;
}

Apache

AddType text/javascript .js .mjs .cjs
AddCharset UTF-8 .js .mjs .cjs

Caddy

@type path *.js *.mjs *.cjs
header @type Content-Type "text/javascript; charset=utf-8"

Extensions and other spellings

declared

File extensions

Also written as

application/javascriptapplication/x-javascripttext/ecmascriptapplication/ecmascript

These reach the same handler in practice. Accept them on input; send text/javascript on output.

File signature

No fixed signature — this format has no reliable magic number, so identify it by parsing rather than by the first few bytes.

Related media types

8
Familytext
Treestandards
Suffix
Inlineactive