Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use IANA’s live Transport Layer Security (TLS) Extensions registry as the authoritative TLS extension codepoint list. It tells you a registered extension’s numeric value, name, TLS 1.3 handshake contexts, DTLS-only designation, recommendation status, reference, and comments. It also marks values as assigned, reserved, or unassigned. For wire format and protocol behavior, follow the RFC named in the reference column; the registry is an index and allocation record, not a replacement for that specification.

The registry page reports “Last Updated: 2026-08-11.” Assignments and annotations can change, so check the live entry when implementing or documenting a protocol.

What the TLS extension registry contains

IANA groups several TLS-related namespaces on one page. Start by selecting TLS ExtensionType Values, not a neighboring table. The page also contains TLS Certificate Types, TLS Certificate Status Types, TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs, TLS CachedInformationType Values, and TLS Certificate Compression Algorithm IDs. A number from one of those registries is not automatically a TLS ExtensionType codepoint.

Column How to use it
Value The numeric ExtensionType codepoint. The table includes named assignments plus ranges marked Reserved or Unassigned.
Extension Name IANA’s registered name. Preserve a rename note when it affects your documentation.
TLS 1.3 Handshake-message contexts in which the registry records use, such as CH, SH, EE, CT, CR, NST, and HRR.
DTLS-Only Whether the entry is designated specifically for DTLS. Confirm the meaning in the cited specification.
Recommended A registry designation such as Y, N, or D. “D” means discouraged in the registry’s procedure terminology; it is not a blanket security verdict.
Reference The RFC or other document that governs the extension.
Comment Additional qualifications, including version or transport notes.

How to look up a TLS extension number and name

  1. Open the IANA TLS Extensions registry.
  2. Locate the TLS ExtensionType Values table. Do not use the ALPN or certificate tables for an ExtensionType lookup.
  3. Search the page for the decimal value or the registered extension name. For a value such as 123, inspect the complete row rather than assuming that the number is active.
  4. Record the value, exact name, TLS 1.3 context labels, DTLS-only field, recommendation status, reference, and comments.
  5. Open the referenced RFC before implementing the extension. Verify payload encoding, legal handshake locations, version constraints, and negotiation rules there.
  6. Record the date you checked the registry when publishing an interoperability note, because the live table can gain assignments or annotations.

Assigned, reserved, and unassigned values

Assigned entries

An assigned row has a registered name and a governing reference. That establishes the registry allocation, not that every TLS or DTLS implementation supports it. Support and behavior come from the relevant specification and implementation documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reserved values

A Reserved range is intentionally set aside by the registry. Treat it as unavailable for a private or public extension unless the applicable specification explicitly defines a permitted use. Do not describe a reserved number as an undocumented extension.

Unassigned values

Unassigned means the registry currently has no assignment for that value. It is different from Reserved: an unassigned value has no registered extension, while a reserved value is held out by registry policy. Neither status proves that a packet using the number is valid.

Reading TLS 1.3 context labels

The TLS 1.3 column uses compact handshake-message labels:

  • CH: ClientHello
  • SH: ServerHello
  • EE: EncryptedExtensions
  • CT: Certificate
  • CR: CertificateRequest
  • NST: NewSessionTicket
  • HRR: HelloRetryRequest

These labels identify registry-recorded contexts; they are not a complete description of wire behavior. An entry listed for ClientHello, for example, still requires its RFC to determine the extension’s structure, whether it is echoed, and what a peer must do when it is absent or malformed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DTLS-only and post-RFC 9851 entries

Read the DTLS-Only column together with the cited RFC. A designation there is a registry qualification, not a substitute for checking whether the extension is defined for a particular DTLS version or handshake message.

The registry notes: “Any TLS entry added after the IESG approves publication of [RFC 9851] is intended for TLS 1.3 or later, and makes no similar requirement on DTLS.” This conditional statement applies to entries added after that approval; it does not reclassify every historical entry or create a general DTLS requirement.

Recommendation status: Y, N, and D

The Recommended column is part of IANA’s registration and procedure framework. Y, N, and D describe registry status and process. Do not translate N into “broken,” and do not treat D as a universal security judgment. For implementation advice, read the referenced specification and any comments, then consider the protocol version and transport you actually support.

Comparing two or more extensions

When you need to compare entries, use the same axes for each one:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Comparison axis Question to answer
Value and name What numeric codepoint and exact IANA name are registered?
TLS 1.3 context Which handshake-message labels appear, and what does the RFC require?
DTLS-only Is the row limited to DTLS, and does the specification define transport-specific behavior?
Recommendation Is the status Y, N, or D, and what procedure or comment explains it?
Allocation state Is the value assigned, reserved, or unassigned?
Reference Which RFC or document supplies the normative definition?

Do not call entries alternatives merely because they appear in the same table. They may serve unrelated handshake functions or different transports.

Finding the RFC that defines an extension

Use the row’s Reference link to answer “what RFC defines TLS extension [name]?” Treat the RFC as authoritative for:

  • the extension-data format and field lengths;
  • the handshake messages in which it may appear;
  • TLS and DTLS version constraints;
  • server and client processing rules;
  • error handling, negotiation, and interaction with other extensions.

If the registry comment and RFC appear to differ, state the scope and date of each source instead of silently merging them. The registry records allocation and current annotations; the specification defines protocol semantics.

Registration procedure and implementation cautions

RFC authors should use the exact registry name and follow the procedure specified for the registry. IANA’s Guidance for RFC Authors: Protocol Registration explains the process, while the IANA Protocol Registries index provides broader registry context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The TLS page points to RFC 8126 and RFC 9847. Procedures vary with registry rules and recommendation status; there is no single allocation path that applies to every request. Where the “Specification Required” procedure applies, IANA states: “If the ‘Specification Required’ [RFC 8126] procedure applies, registration requests can be sent to iana@iana.org or submitted via IANA’s application form, per [RFC 9847].” Check the live procedure notes before submitting a request.

Practical lookup checklist

  • Confirm you are in TLS ExtensionType Values.
  • Copy the decimal value and exact registered name.
  • Check whether the row is assigned, Reserved, or Unassigned.
  • Read every TLS 1.3 context label and the DTLS-only field.
  • Interpret Y, N, or D as registry status, not a standalone security rating.
  • Open and cite the governing RFC for behavior and wire format.
  • Check comments for transport and version qualifications.
  • Note the registry date and re-check the live page before release.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common lookup errors and fixes

Using an ALPN number as an ExtensionType

Cause: The registries are adjacent on the same page. Fix: Return to TLS ExtensionType Values and verify the column heading before copying a codepoint.

Calling an unassigned value a private extension

Cause: A number appears available, but no assignment exists. Fix: Describe it as unassigned and consult the applicable allocation procedure; do not imply interoperability.

Treating Reserved and Unassigned as synonyms

Cause: Both lack an active extension row. Fix: Preserve the registry’s exact state: Reserved is held out; Unassigned has no current assignment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assuming a context label defines payload semantics

Cause: CH, SH, EE and similar labels look like complete documentation. Fix: Follow the RFC for encoding, legality, and processing.

Reading “D” as a security ban

Cause: The word “discouraged” is mistaken for a universal prohibition. Fix: Read the procedure notes, comments, and cited specification before drawing an implementation conclusion.

Or skip the browser setup

If you need a reproducible image of the live registry for a ticket, change review, or documentation, ScreenshotNeo can capture the page with one request. Cookie and consent banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and the response reports the page verdict and billing status in headers. Its MCP server lets Claude, Cursor, or another MCP client use take_screenshot, get_page_info, and capture_pdf.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://www.iana.org/assignments/tls-extensiontype-values -o tls-extensions.webp

See the ScreenshotNeo API documentation for options such as full-page capture, custom CSS, waiting for network idle, PDF output, caching, signed links, asynchronous jobs, and bulk capture. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

How often should I recheck a TLS extension codepoint?

Recheck the live IANA row whenever you publish or update interoperability documentation, because assignments, comments, and recommendations can change.

Does a TLS 1.3 context label guarantee that an implementation accepts an extension there?

No. The label records the registry context; the referenced RFC and the implementation determine legal use and processing.

Where do I find the procedure for requesting a new codepoint?

Start with the TLS registry’s procedure notes, then consult IANA’s protocol-registration guidance and the RFCs it cites, including RFC 8126 and RFC 9847.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.