HTTP Headers Inspector
Paste response headers and get them explained
Paste raw HTTP headers to see what each one does, check security and caching headers and spot common mistakes.
- HTTP
- Headers
- Security
- Cache
How to use HTTP Headers Inspector
- Copy raw headers, for example from
curl -sI https://example.comor DevTools (Network → select the request → Headers → Response Headers → Raw), and paste them into Raw headers. The status line is optional. - You can also drop a text file on the box or use Open file. Load sample fills in an example response.
- For response headers, read the Security review grade and its checks, and the Caching summary of who may store the response and for how long.
- Scroll through the Headers list: each known header is explained, and values such as
Cache-Control,Content-Security-Policy,Set-CookieandStrict-Transport-Securityare broken down directive by directive.
How it works
The text is split into lines and parsed in your browser. It understands plain curl -I output, curl -v output (lines starting with <, > and *), DevTools copies where a value sits on the line after its name, HTTP/2 pseudo headers such as :status, and obsolete folded lines. If several responses are present, as with curl -IL following redirects, the last one is shown. Lines that aren’t valid name: value headers are listed as skipped.
Each header name is looked up in a built-in list of about 95 common headers, with its category and whether it is deprecated. Request and response headers are told apart by the start line or, without one, by typical header names. Only response headers get the security review and caching summary.
The security review checks HSTS, CSP (script sources, unsafe-inline, unsafe-eval, wildcards, object-src, base-uri, frame-ancestors), X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, COOP/COEP/CORP, cookie attributes, CORS, version leaks and obsolete headers. The score starts at 100 and loses 20 points per problem and 7 per warning, which maps to a grade from A+ to F. The caching summary works out freshness from max-age, s-maxage or Expires minus Date, and reports validators, Vary, Age and common mistakes.
Limits
- Input over 512 KB is cut off and only the start is read. Files opened or dropped are limited to 10 MB.
- Headers aren’t fetched for you: paste them from curl or DevTools. The site can’t make requests to other servers.
- The grade is based on the headers alone. A CSP set in a
<meta>tag isn’t visible, and HSTS only matters over HTTPS. - Headers outside the built-in list are shown as “Custom / uncommon” without an explanation.
- Request headers are listed and explained but not graded or checked for caching.
Privacy
Headers are parsed and reviewed entirely in your browser; nothing is uploaded or stored. Cookies and tokens in the pasted headers may be sensitive, but they never leave the page. If another tool sends headers here with Send to…, they are handed over through this tab’s session storage and removed as soon as this tool reads them.
Frequently asked questions
Can it fetch the headers of a URL for me?
No. The site only talks to its own server, so it can’t request other websites. Run curl -sI https://example.com (add -L to follow redirects) or copy the response headers from your browser’s DevTools, then paste them.
How is the security grade calculated?
Every check is rated good, info, warning or problem. Starting from 100, each problem costs 20 points and each warning 7. A score of 100 is A+, 90 or more is A, 75 B, 60 C, 45 D and anything lower F.
I pasted curl -v output with both request and response. Which one is analysed?
The response. Lines starting with * are ignored, and when several responses appear (redirects), the last one is shown with a notice.
Why is there no security review for my headers?
The headers look like request headers, either because of a request line such as GET / HTTP/1.1 or because names like Host, Accept or Cookie outnumber response-only ones. The review only applies to responses.
Why does the caching summary say a cookie could be shared?
The response sets a cookie but its Cache-Control lets shared caches such as CDNs store it, so another user could receive the same cookie. Add private or don’t set cookies on cacheable responses.
More tools
- Clean Image: Inspect and remove hidden image metadata
- JWT Decoder: Decode and verify JSON Web Tokens
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- HTTP Status Codes: Look up any HTTP status code
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- JWT Generator: Create and sign test JSON Web Tokens
- Certificate Inspector: Decode PEM certificates and keys
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- .env Diff: Compare and validate .env files
- TOTP Generator: Generate and verify 2FA codes
- String Escaper: Escape and unescape strings for any language
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- Kubernetes YAML Checker: Validate and explain Kubernetes manifests
- .gitignore Generator: Build a .gitignore from presets
- CSP Builder: Build and check a Content-Security-Policy
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones