// reference
MIME Type Lookup.
Reverse-lookup MIME types. Find the right Content-Type header value for a file extension or vice-versa.
What is a MIME type?
A MIME type (Multipurpose Internet Mail Extensions) tells a browser, server, or operating system what kind of data a file contains. The MIME type application/json means the content is JSON; image/png means it's a PNG image. MIME types are used in HTTP headers (Content-Type), HTML forms (enctype), email attachments, and operating system file associations.
Every MIME type has two parts: a type (application, image, text, video, audio, font, multipart) and a subtype (json, png, html). Some subtypes include a suffix like +json or +xml to indicate the underlying format: application/vnd.api+json is a JSON:API response.
Why correct MIME types matter.
Security. Serving a file with the wrong MIME type can bypass content security policies. If an attacker uploads an HTML file with a .txt extension but the server serves it as text/plain, the browser won't execute embedded scripts. But if the server serves it as text/html, scripts will run. Always set the correct Content-Type header.
API design. REST APIs use Content-Type to tell clients how to parse the response. An API returning application/json expects the client to parse JSON. If you accidentally return text/plain, some clients may not parse the response correctly.
File uploads. When uploading files, the browser sends the file's MIME type in the request. If your server validates MIME types for security (rejecting executable types), an incorrect MIME type can cause legitimate uploads to fail or malicious uploads to pass validation.
Common MIME types.
Web: text/html, text/css, application/javascript, application/json, image/svg+xml. Documents: application/pdf, application/zip, text/csv. Media: image/png, image/jpeg, video/mp4, audio/mpeg. Fonts: font/woff2, font/ttf. This tool contains over 100 MIME types organized by category, searchable by extension or type.
Content-Type headers explained.
The Content-Type HTTP header tells the receiving end how to interpret the message body. A server sends Content-Type: application/json to indicate the response is JSON. A browser sends Content-Type: application/x-www-form-urlencoded for standard form submissions, or multipart/form-data when uploading files. Getting this header right is critical — if it doesn't match the actual content, browsers may misinterpret data, APIs may reject requests, and security vulnerabilities can arise.
Some content types include a charset parameter, such as text/html; charset=UTF-8, which specifies the character encoding. Without this, browsers may render text incorrectly, especially for non-ASCII characters. Modern web standards default to UTF-8, but explicitly declaring the charset avoids ambiguity. The charset parameter is separate from the MIME type itself — it's metadata about how the bytes should be decoded.
MIME type detection and sniffing.
Browsers sometimes ignore the declared MIME type and "sniff" the content to guess what it is. This was historically useful but created security issues — for example, a file served as text/plain might actually contain HTML with scripts. To prevent this, servers can send the X-Content-Type-Options: nosniff header, which tells the browser to trust only the declared Content-Type. Modern browsers enforce this by default for JavaScript, CSS, and JSON responses.
File extensions are a loose mapping to MIME types. A .json file is typically application/json, but a server might serve it as text/plain or application/octet-stream. Never rely on file extension alone for type detection — always verify with the Content-Type header. This tool helps you find the correct MIME type by extension so you can configure your server accurately.
Configuring MIME types in web servers.
Every web server has a MIME type configuration. Nginx uses the mime.types file, Apache uses mod_mime, and Node.js frameworks like Express use the mime package. When deploying a new file type — such as WebP images (image/webp), WOFF2 fonts (font/woff2), or WebAssembly modules (application/wasm) — you may need to add the MIME type to your server configuration. Serving an unknown type may cause browsers to refuse to load the resource or handle it incorrectly.
This tool includes over 100 MIME types organized by category. Use it to quickly look up the correct type for any file extension, whether you are configuring Nginx, writing an Express route, setting HTTP headers in a CDN, or debugging why a file isn't loading in the browser.
FAQ
How do I find the MIME type for a file extension in Node.js?
`mime-types` package: `mime.lookup('file.pdf')` returns `'application/pdf'`; or `mime.getType('json')` returns `'application/json'` (mime v3+).
Why is `application/octet-stream` returned for unknown file types?
It's the default catch-all MIME type meaning 'binary data of unknown type' — browsers will force-download it. Always set proper Content-Type headers when serving files.
What is the correct MIME type for JSON, XML, YAML?
JSON: `application/json`; XML: `application/xml` or `text/xml`; YAML: there is NO official IANA MIME type, but `application/yaml` or `text/yaml` are commonly used.
How do I find the MIME type of a file from its content (not extension)?
Use `file --mime-type file.bin` (Linux/macOS) or `multer`/`file-type` (Node.js) which read magic bytes; extension-based detection is unreliable for security.
What is the difference between `text/javascript` and `application/javascript`?
Both are valid, but `text/javascript` is now preferred per RFC 9239; older browsers required `application/javascript`. For ES modules use `text/javascript` with `type='module'`.