HTTP Header Analyzer
Paste request or response headers from curl, DevTools or logs. Each header is explained, security and caching problems are flagged, and cookies and CORS are checked.
Runs in your browser. Nothing you add is uploaded.
What the HTTP Header Analyzer does
HTTP headers carry the instructions that decide how a page is cached, secured and shared across sites, yet they are hard to read in a wall of text. Paste the headers from curl, your browser's Network tab or a server log, and this viewer explains each one, groups the problems it finds, and shows how long a response can be cached. It is a quick way to check a site's security headers, debug a caching problem or understand why a cross-origin request is blocked, without sending your headers to anyone.
How to check HTTP headers
- Get the headers: run curl -I https://example.com in a terminal, or open your browser's developer tools, choose the Network tab, select a request and copy its headers.
- Paste them into the box. A status line (HTTP/2 200) or a request line (GET /path HTTP/1.1) is optional.
- Read the summary: the number of headers, problems and, for responses, how many of the six key security headers are set.
- Open the findings to see each problem with an explanation, then select a header in the list for its meaning and a breakdown of its value.
- Fix the issues on your server with the HTTP Header Generator, then paste the new headers to confirm.
The HTTP Header Analyzer runs entirely in your browser — nothing you enter is uploaded, stored, or logged.
When to use it
Checking a site's security headers
After a deploy, confirm that HSTS, Content-Security-Policy, X-Content-Type-Options and framing protection are really being sent, and that values such as unsafe-inline or a short HSTS lifetime have not crept in.
Debugging caching
If a CDN keeps serving an old file or never caches a new one, the Cache-Control, Vary and ETag headers usually explain why. The viewer translates them into what a browser and a CDN will actually do.
Understanding a CORS error
Paste the response headers of the failing request and the viewer shows whether Access-Control-Allow-Origin is present, whether it conflicts with credentials and whether Vary: Origin is missing.
Good to know
- curl -sIL https://example.com shows the headers of every hop in a redirect chain; paste the whole output and switch between responses.
- Header names are case-insensitive. HTTP/2 requires lower case, which is why Chrome shows them that way.
- Set-Cookie can appear several times in one response. Each cookie is checked on its own.
- Remove Authorization and Cookie values before pasting into a bug report or screenshot.
- A missing header is not always a problem: Strict-Transport-Security only matters on HTTPS.
Frequently asked questions
Can this tool fetch the headers of a website for me?
Are the headers I paste sent anywhere?
What does the security checklist mean?
Which security headers matter most?
Why does the viewer say X-XSS-Protection is obsolete?
What does Vary: Cookie do to caching?
Related tools
URL Parser
Break a URL into scheme, host, port, path, query and fragment.
Query String Parser
Turn a query string into a table or JSON, decoded.
Query String Builder
Build a correctly encoded query string from rows or JSON.