HTTP Header Analyzer
Runs locally in your browser. Your input is not uploaded.Free, no sign-up
Headers
Paste headers to see what each one does and how the security settings look, or click Sample.
Paste raw HTTP headers to see what each one does and its security implications.
How to use the HTTP Header Analyzer
- Get the headers:
curl -I https://example.com(add-Lto follow redirects), or copy them from the Network tab in your browser's DevTools. - Paste them, or click Sample. Request and response headers are both understood.
- Read the findings, then each header's explanation below them.
What's checked
- Security headers: HSTS and its max-age, Content-Security-Policy (unsafe-inline, unsafe-eval, wildcard sources), X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy.
- Information leaks: server versions and
X-Powered-By. - Cookies: Secure, HttpOnly and SameSite on every
Set-Cookie. - CORS: the invalid
*plus credentials combination, and missingVary: Origin. - Caching in plain words, and headers set twice.
Frequently asked questions
Does this contact the site?
No. It only reads the headers you paste, so it works for internal and staging servers too, and nothing leaves your browser. Remove cookies or tokens first if you plan to share a screenshot.
How do I add these headers in Spring Boot?
Spring Security sets X-Content-Type-Options, X-Frame-Options and, over HTTPS, HSTS by default. Add a CSP with http.headers(h -> h.contentSecurityPolicy(c -> c.policyDirectives("default-src 'self'"))).
Related tools
All tools- HTTP Status Code LookupLook up HTTP status codes with clear descriptions and typical causes.
- CORS Header GeneratorGenerate CORS configuration for Spring Boot, Nginx, Express and Apache.
- URL ParserBreak a URL into protocol, credentials, host, port, path, query and fragment.
- Query String ParserTurn query strings into key/value tables and JSON into query strings.
- cURL GeneratorBuild cURL commands from a method, URL, headers, body and authentication.