HTTP Header Analyzer
Paste raw HTTP request or response headers to inspect security, caching, CORS, content, and auth metadata. Descriptions for 88 headers, with hints. Runs in your browser.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Example: Response with security headers
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Content-Security-Policy: default-src 'self'; script-src 'self'
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Cache-Control: no-store
Set-Cookie: session=abc123; HttpOnly; Secure; SameSite=Strict; Path=/
The analyzer groups Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, and Referrer-Policy under Security. Cache-Control lands in Caching, Content-Type in Content, and Set-Cookie in Cookie. Each card includes a one-line description and any hints — for example, a Set-Cookie without HttpOnly triggers a warning.
Example: CORS preflight
OPTIONS /api/v1/orders HTTP/1.1
Host: api.example.com
Origin: https://app.example.com
Access-Control-Request-Method: POST
Access-Control-Request-Headers: Authorization, Content-Type
This is recognized as a request. The Access-Control-Request-* pair indicates a preflight; the analyzer surfaces the Origin and lists the requested method and headers. Use it alongside the response side to debug CORS handshakes end-to-end.
Categories at a glance
- Status — the first line (status line or method line).
- Security — HSTS, CSP, X-Frame-Options, COOP/COEP/CORP, Permissions-Policy, fetch metadata.
- Caching — Cache-Control, ETag, Vary, Expires, Last-Modified, conditional headers.
- Content — Content-Type, Content-Encoding, Accept-*, Content-Disposition.
- CORS — Access-Control-* and Origin.
- Auth — Authorization, WWW-Authenticate, Proxy-Authenticate.
- Cookie — Cookie and Set-Cookie.
- Transport / Range / Proxy / General / Custom — the rest, with X-* unknown headers in Custom.
Compliance hints
Hints are conservative — they highlight obvious misconfiguration, not subjective style. Examples:
- HSTS max-age below 1 year, or missing includeSubDomains / preload directives.
- CSP containing
‘unsafe-inline’or‘unsafe-eval’. - Set-Cookie without HttpOnly or Secure flags.
- Access-Control-Allow-Credentials: true paired with a wildcard origin (spec-illegal).
- Cache-Control combining no-store with max-age (dead weight).
Example: a response with problems
Pasting the following response, copied from an HTTP/2 site, produces the hints listed under it. The hint texts are quoted from the tool’s output.
HTTP/2 200
content-type: text/html; charset=utf-8
strict-transport-security: max-age=86400
content-security-policy: script-src 'self' 'unsafe-inline'
access-control-allow-origin: *
access-control-allow-credentials: true
set-cookie: sid=31d4d96e407aad42; Path=/
cache-control: no-store, max-age=600
server: nginx
- strict-transport-security: Warning “max-age < 1 year (31536000s). Many preload lists require ≥ 1 year.”, plus notes to add includeSubDomains and preload. One day (86400 s) is far below the one year that hstspreload.org requires.
- content-security-policy: Warning “‘unsafe-inline’ defeats most XSS protection. Use nonces or hashes instead.” and a note that there is no
default-src. - access-control-allow-credentials: Warning “Credentialed CORS requires explicit Allow-Origin (no wildcard).” The Fetch Standard does not let a browser expose a credentialed response when the origin is
*. The warning disappears when the pasted headers contain a specific origin such ashttps://app.example.com. - set-cookie: Warnings for missing HttpOnly and Secure, and a note for the missing SameSite attribute: Chrome treats such a cookie as
SameSite=Lax, while Firefox and Safari do not (MDN browser compatibility data), so the behaviour differs between browsers. - cache-control: Warning that
no-storemakesmax-age=600pointless. - server: A note that the software name helps fingerprinting.
The summary bar shows the message type (response), the status line, the number of headers and how many fall in the Security group. A response with no security headers at all gets a warning in the summary instead.
Where to copy headers from
- curl:
curl -sS -D - -o /dev/null https://example.com/prints the response headers of a normal GET.curl -Isends a HEAD request, which some servers answer with different headers. - Chrome or Edge DevTools: Network panel → select the request → Headers → turn on Raw next to Response Headers or Request Headers, then copy.
- Firefox DevTools: Network panel → select the request → Headers → turn on the Raw switch.
If you need the full request list with timings and bodies, export a HAR file and open it in the HAR analyzer below instead.
Limitations
- The descriptions and hint texts are in English on every language version of this page. 88 headers have a description; any other header is listed under Custom / Other without one.
- HTTP/2 and HTTP/3 pseudo-headers such as
:statusand:path, which browser developer tools copy as the first lines, are listed in their own group with a short description (RFC 9113 §8.3, RFC 8441 for:protocol). Without a status line,:statusmarks the input as a response and:methodas a request. - The first line is recognized as a request only for GET, POST, PUT, DELETE, PATCH, OPTIONS, HEAD, TRACE and CONNECT.
- Hints look at one header at a time, except the CORS credentials check above. The tool does not evaluate a full CSP (use the CSP Header Generator) and does not check cookie attributes beyond HttpOnly, Secure and SameSite.
- The JSON view uses lowercase names, because header names are case-insensitive (RFC 9110 section 5.1), and puts repeated headers into arrays.
- Nothing is fetched: the tool cannot see redirects or headers you did not paste. Because pasted headers often contain cookies and tokens, this page does not load Google Analytics or AdSense, and the input is not saved.
Related tools on ZeroTool
- Cookie Parser & Decoder — break Set-Cookie or Cookie strings into names, values and attributes, and see whether a browser keeps each cookie.
- CSP Header Generator — build a strict Content-Security-Policy from scratch.
- HAR Analyzer & Viewer — visualize the full request waterfall from DevTools.
- HTTP Status Codes — searchable reference for 1xx–5xx.
FAQ
Does this tool send my headers to a server?
No. Parsing and analysis run in your browser via inline JavaScript. Nothing is uploaded. Paste sensitive Authorization tokens, Set-Cookie strings, or production headers without worry.
Can it fetch headers from a URL?
No — by design. URL fetching requires a backend and opens the door to abuse. Paste headers from curl -i, curl -v, browser DevTools Network panel, or any HTTP client instead. The analyzer is the second step; capture is the first.
How does it detect request vs response?
It reads the first line. HTTP/x.x followed by a status code is a response. A method (GET, POST, …) followed by a path and HTTP/x.x is a request. If neither matches, the input is treated as header-only and all lines are parsed as headers.
What security headers does it check?
It flags presence and configuration of Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Set-Cookie flags, the Cross-Origin-* family, and CORS Allow-Origin / Allow-Credentials combinations.
How does it handle duplicate headers and folded lines?
Duplicate header names are kept as separate entries in the categorized view and collapsed into JSON arrays in the JSON view. HTTP/1.1 obs-fold lines (those starting with whitespace) are merged into the previous header per RFC 7230.
Can I export the parsed result?
Yes. Click Copy JSON to copy a normalized object. Single-value headers become string values; repeated headers become arrays preserving order. The status line is included under the key _status.