A MIME type (media type) tells the receiver what a sequence of bytes is: type/subtype, optionally with parameters, as in text/html; charset=utf-8. Browsers act on the Content-Type response header, not on the file extension, so a misconfigured server can stop a script from loading. In HTML you write MIME types in type on <source> and <link>, accept on file inputs and enctype on forms. IANA keeps the official registry.
| Extension | MIME type | Extension | MIME type |
|---|---|---|---|
| .html | text/html | .png | image/png |
| .css | text/css | .jpg .jpeg | image/jpeg |
| .js .mjs | text/javascript | .webp | image/webp |
| .json | application/json | .avif | image/avif |
| .webmanifest | application/manifest+json | .svg | image/svg+xml |
| .wasm | application/wasm | .woff2 | font/woff2 |
| .txt | text/plain | .mp4 .webm | video/mp4 video/webm |
| application/pdf | .mp3 | audio/mpeg | |
| Unknown binary | application/octet-stream | .zip | application/zip |
| HTML form, default | application/x-www-form-urlencoded | Form with files | multipart/form-data |
Since RFC 9239 (2022), text/javascript is the correct type for JavaScript; application/javascript is an obsolete alias. Browsers are strict where a wrong type is dangerous: a module script with a non-JavaScript type is refused, WebAssembly.instantiateStreaming() expects application/wasm, and X-Content-Type-Options: nosniff stops the browser from sniffing (guessing a type from the bytes), so an uploaded text/plain file never runs as script.