# Security headers applied to every route, served by Cloudflare Pages.
/*
  X-Content-Type-Options: nosniff
  X-Frame-Options: SAMEORIGIN
  Referrer-Policy: strict-origin-when-cross-origin
  Permissions-Policy: geolocation=(), microphone=(), camera=()
  # Agent discovery (RFC 8288 / RFC 8631): point agents at the API reference.
  Link: </api-reference/>; rel="service-doc"; type="text/html"
