Skip to content
Shrake DevTools
  • JSON FormatterData & Format
  • JSON ValidatorData & Format
  • JSON MinifierData & Format
  • JSON ↔ YAML ConverterData & Format
  • XML FormatterData & Format
  • Base64 Encoder / DecoderData & Format
  • URL Encoder / DecoderData & Format
  • JWT InspectorData & Format
↑ ↓ to navigate↵ to openEsc to close

HTTP Header Analyzer

Runs locally in your browser. Your input is not uploaded.Free, no sign-up

Headers

Paste headers to see what each one does and how the security settings look, or click Sample.

Paste raw HTTP headers to see what each one does and its security implications.

How to use the HTTP Header Analyzer

  1. Get the headers: curl -I https://example.com (add -L to follow redirects), or copy them from the Network tab in your browser's DevTools.
  2. Paste them, or click Sample. Request and response headers are both understood.
  3. Read the findings, then each header's explanation below them.

What's checked

  • Security headers: HSTS and its max-age, Content-Security-Policy (unsafe-inline, unsafe-eval, wildcard sources), X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy.
  • Information leaks: server versions and X-Powered-By.
  • Cookies: Secure, HttpOnly and SameSite on every Set-Cookie.
  • CORS: the invalid * plus credentials combination, and missing Vary: Origin.
  • Caching in plain words, and headers set twice.

Frequently asked questions

Does this contact the site?

No. It only reads the headers you paste, so it works for internal and staging servers too, and nothing leaves your browser. Remove cookies or tokens first if you plan to share a screenshot.

How do I add these headers in Spring Boot?

Spring Security sets X-Content-Type-Options, X-Frame-Options and, over HTTPS, HSTS by default. Add a CSP with http.headers(h -> h.contentSecurityPolicy(c -> c.policyDirectives("default-src 'self'"))).