Use IANA’s live Transport Layer Security (TLS) Extensions registry as the authoritative TLS extension codepoint list. It tells you a registered extension’s numeric value, name, TLS 1.3 handshake contexts, DTLS-only designation, recommendation status, reference, and comments. It also marks values as assigned, reserved, or unassigned. For wire format and protocol behavior, follow the RFC named in the reference column; the registry is an index and allocation record, not a replacement for that specification.
The registry page reports “Last Updated: 2026-08-11.” Assignments and annotations can change, so check the live entry when implementing or documenting a protocol.
What the TLS extension registry contains
IANA groups several TLS-related namespaces on one page. Start by selecting TLS ExtensionType Values, not a neighboring table. The page also contains TLS Certificate Types, TLS Certificate Status Types, TLS Application-Layer Protocol Negotiation (ALPN) Protocol IDs, TLS CachedInformationType Values, and TLS Certificate Compression Algorithm IDs. A number from one of those registries is not automatically a TLS ExtensionType codepoint.
| Column | How to use it |
|---|---|
| Value | The numeric ExtensionType codepoint. The table includes named assignments plus ranges marked Reserved or Unassigned. |
| Extension Name | IANA’s registered name. Preserve a rename note when it affects your documentation. |
| TLS 1.3 | Handshake-message contexts in which the registry records use, such as CH, SH, EE, CT, CR, NST, and HRR. |
| DTLS-Only | Whether the entry is designated specifically for DTLS. Confirm the meaning in the cited specification. |
| Recommended | A registry designation such as Y, N, or D. “D” means discouraged in the registry’s procedure terminology; it is not a blanket security verdict. |
| Reference | The RFC or other document that governs the extension. |
| Comment | Additional qualifications, including version or transport notes. |
How to look up a TLS extension number and name
- Open the IANA TLS Extensions registry.
- Locate the TLS ExtensionType Values table. Do not use the ALPN or certificate tables for an ExtensionType lookup.
- Search the page for the decimal value or the registered extension name. For a value such as 123, inspect the complete row rather than assuming that the number is active.
- Record the value, exact name, TLS 1.3 context labels, DTLS-only field, recommendation status, reference, and comments.
- Open the referenced RFC before implementing the extension. Verify payload encoding, legal handshake locations, version constraints, and negotiation rules there.
- Record the date you checked the registry when publishing an interoperability note, because the live table can gain assignments or annotations.
Assigned, reserved, and unassigned values
Assigned entries
An assigned row has a registered name and a governing reference. That establishes the registry allocation, not that every TLS or DTLS implementation supports it. Support and behavior come from the relevant specification and implementation documentation.
#1 Best Overall
Reserved values
A Reserved range is intentionally set aside by the registry. Treat it as unavailable for a private or public extension unless the applicable specification explicitly defines a permitted use. Do not describe a reserved number as an undocumented extension.
Unassigned values
Unassigned means the registry currently has no assignment for that value. It is different from Reserved: an unassigned value has no registered extension, while a reserved value is held out by registry policy. Neither status proves that a packet using the number is valid.
Reading TLS 1.3 context labels
The TLS 1.3 column uses compact handshake-message labels:
- CH: ClientHello
- SH: ServerHello
- EE: EncryptedExtensions
- CT: Certificate
- CR: CertificateRequest
- NST: NewSessionTicket
- HRR: HelloRetryRequest
These labels identify registry-recorded contexts; they are not a complete description of wire behavior. An entry listed for ClientHello, for example, still requires its RFC to determine the extension’s structure, whether it is echoed, and what a peer must do when it is absent or malformed.
Recommended Free Tools
DTLS-only and post-RFC 9851 entries
Read the DTLS-Only column together with the cited RFC. A designation there is a registry qualification, not a substitute for checking whether the extension is defined for a particular DTLS version or handshake message.
The registry notes: “Any TLS entry added after the IESG approves publication of [RFC 9851] is intended for TLS 1.3 or later, and makes no similar requirement on DTLS.” This conditional statement applies to entries added after that approval; it does not reclassify every historical entry or create a general DTLS requirement.
Recommendation status: Y, N, and D
The Recommended column is part of IANA’s registration and procedure framework. Y, N, and D describe registry status and process. Do not translate N into “broken,” and do not treat D as a universal security judgment. For implementation advice, read the referenced specification and any comments, then consider the protocol version and transport you actually support.
Comparing two or more extensions
When you need to compare entries, use the same axes for each one:
| Comparison axis | Question to answer |
|---|---|
| Value and name | What numeric codepoint and exact IANA name are registered? |
| TLS 1.3 context | Which handshake-message labels appear, and what does the RFC require? |
| DTLS-only | Is the row limited to DTLS, and does the specification define transport-specific behavior? |
| Recommendation | Is the status Y, N, or D, and what procedure or comment explains it? |
| Allocation state | Is the value assigned, reserved, or unassigned? |
| Reference | Which RFC or document supplies the normative definition? |
Do not call entries alternatives merely because they appear in the same table. They may serve unrelated handshake functions or different transports.
Finding the RFC that defines an extension
Use the row’s Reference link to answer “what RFC defines TLS extension [name]?” Treat the RFC as authoritative for:
- the extension-data format and field lengths;
- the handshake messages in which it may appear;
- TLS and DTLS version constraints;
- server and client processing rules;
- error handling, negotiation, and interaction with other extensions.
If the registry comment and RFC appear to differ, state the scope and date of each source instead of silently merging them. The registry records allocation and current annotations; the specification defines protocol semantics.
Registration procedure and implementation cautions
RFC authors should use the exact registry name and follow the procedure specified for the registry. IANA’s Guidance for RFC Authors: Protocol Registration explains the process, while the IANA Protocol Registries index provides broader registry context.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
The TLS page points to RFC 8126 and RFC 9847. Procedures vary with registry rules and recommendation status; there is no single allocation path that applies to every request. Where the “Specification Required” procedure applies, IANA states: “If the ‘Specification Required’ [RFC 8126] procedure applies, registration requests can be sent to iana@iana.org or submitted via IANA’s application form, per [RFC 9847].” Check the live procedure notes before submitting a request.
Practical lookup checklist
- Confirm you are in TLS ExtensionType Values.
- Copy the decimal value and exact registered name.
- Check whether the row is assigned, Reserved, or Unassigned.
- Read every TLS 1.3 context label and the DTLS-only field.
- Interpret Y, N, or D as registry status, not a standalone security rating.
- Open and cite the governing RFC for behavior and wire format.
- Check comments for transport and version qualifications.
- Note the registry date and re-check the live page before release.
Common lookup errors and fixes
Using an ALPN number as an ExtensionType
Cause: The registries are adjacent on the same page. Fix: Return to TLS ExtensionType Values and verify the column heading before copying a codepoint.
Calling an unassigned value a private extension
Cause: A number appears available, but no assignment exists. Fix: Describe it as unassigned and consult the applicable allocation procedure; do not imply interoperability.
Treating Reserved and Unassigned as synonyms
Cause: Both lack an active extension row. Fix: Preserve the registry’s exact state: Reserved is held out; Unassigned has no current assignment.
Best Value
- Used Book in Good Condition
Assuming a context label defines payload semantics
Cause: CH, SH, EE and similar labels look like complete documentation. Fix: Follow the RFC for encoding, legality, and processing.
Reading “D” as a security ban
Cause: The word “discouraged” is mistaken for a universal prohibition. Fix: Read the procedure notes, comments, and cited specification before drawing an implementation conclusion.
Or skip the browser setup
If you need a reproducible image of the live registry for a ticket, change review, or documentation, ScreenshotNeo can capture the page with one request. Cookie and consent banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and the response reports the page verdict and billing status in headers. Its MCP server lets Claude, Cursor, or another MCP client use take_screenshot, get_page_info, and capture_pdf.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://www.iana.org/assignments/tls-extensiontype-values -o tls-extensions.webp
See the ScreenshotNeo API documentation for options such as full-page capture, custom CSS, waiting for network idle, PDF output, caching, signed links, asynchronous jobs, and bulk capture. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteFrequently Asked Questions
How often should I recheck a TLS extension codepoint?
Recheck the live IANA row whenever you publish or update interoperability documentation, because assignments, comments, and recommendations can change.
Does a TLS 1.3 context label guarantee that an implementation accepts an extension there?
No. The label records the registry context; the referenced RFC and the implementation determine legal use and processing.
Where do I find the procedure for requesting a new codepoint?
Start with the TLS registry’s procedure notes, then consult IANA’s protocol-registration guidance and the RFCs it cites, including RFC 8126 and RFC 9847.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

