/

HTTP Header Analyzer

Processed Client Side

Paste a raw block of HTTP request or response headers and get them parsed into a clean table, with plain-English explanations for common headers.

Raw headers
Length: 316Lines: 9Size: 316 BytesCursor: 1:1
8 headers
8 parsed · 8 known
Start lineHTTP/1.1 200 OK
Content-Type
application/json; charset=utf-8
Media type (and charset) of the body, e.g. application/json.
Cache-Control
max-age=3600, public
Directives for caching in browsers and shared caches (max-age, no-cache, public/private).
Content-Encoding
gzip
Compression applied to the body (gzip, br, deflate) — must be decoded before use.
Strict-Transport-Security
max-age=63072000; includeSubDomains
HSTS: forces HTTPS for the domain for the given max-age.
X-Frame-Options
DENY
Controls whether the page may be framed — a clickjacking defense (DENY, SAMEORIGIN).
Set-Cookie
session=abc123; HttpOnly; Secure; SameSite=Lax
Instructs the client to store a cookie. Check for HttpOnly, Secure, and SameSite flags.
Access-Control-Allow-Origin
*
CORS: which origins may read the response. "*" allows any.
Server
nginx/1.25.3
Software and version handling the request — often trimmed for security.

Bookmark this tool now — skip the search next time you need it.

About HTTP Header Analyzer

This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.

Paste a raw block of HTTP request or response headers and get them parsed into a readable table with a plain-English explanation of what each one does. Headers are where most confusing web behaviour is actually decided — why a response is cached, why a cookie is not being set, why a cross-origin call is blocked, why a browser refuses to frame your page — but they arrive as an undifferentiated wall of text. This tool separates the start line from the headers, lists each name and value cleanly, and annotates around thirty of the most common headers so you do not have to look up what Vary or Strict-Transport-Security is doing.

Key features

  • Parses a raw header block copied straight from a terminal, a browser network panel, or a log
  • Recognises and separates the start line, whether it is a request line or a response status line
  • Plain-English explanations for roughly thirty common headers
  • Covers caching (Cache-Control, ETag, Expires, Last-Modified, Vary) and content negotiation (Accept, Content-Type, Content-Encoding)
  • Covers the CORS family (Access-Control-Allow-Origin, -Credentials, -Methods) and Origin
  • Covers security headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options
  • Handles cookies, authentication headers, and the standard request metadata headers
  • Tolerates the formatting variations you get from different sources, including the leading status line
  • Runs entirely in your browser — pasted headers containing session cookies are never uploaded

How to use it

  1. Copy a raw header block — from curl -i, from the Headers tab of your browser network panel, or from a server log.
  2. Paste it into the input pane.
  3. Read the parsed table of header names and values.
  4. Check the explanation beside any header whose behaviour you are trying to understand.

Tips & common mistakes

  • Pasted headers routinely contain session cookies and bearer tokens. Nothing here is uploaded, but scrub them before pasting the same block into a ticket or a chat.
  • For a CORS failure, read the response headers rather than the request. The browser blocks the call because Access-Control-Allow-Origin is missing or does not match, and the error in the console rarely says which.
  • Vary is the most commonly misunderstood caching header: it tells caches which request headers change the response. Omitting Vary: Accept-Encoding is a classic way to serve gzipped content to a client that cannot read it.
  • Cache-Control beats Expires wherever both are present. If caching behaviour surprises you, check for a Cache-Control you did not know was being set by a proxy or CDN.
  • A Set-Cookie that the browser ignores is usually failing on its attributes rather than its value — Secure over plain HTTP, or SameSite=None without Secure, are both silently dropped.
  • Get a header block quickly with curl -I for response headers only, or curl -i to see the headers followed by the body.

Related tools

Browse all 9 Web / API tools

Frequently asked questions

9

Paste a block of request or response headers, one per line, into the input pane. Each header is parsed into a table row showing its name, value, and — for common headers — a plain-English description.

Over 30 common request and response headers are documented, including Content-Type, Cache-Control, Set-Cookie, the CORS Access-Control-* headers, and security headers like Strict-Transport-Security and Content-Security-Policy.

Yes — it makes it easy to spot missing security headers (HSTS, CSP, X-Frame-Options) and cookies set without HttpOnly, Secure, or SameSite flags, which are frequent audit findings.

Use curl -I for response headers only, or curl -i to see headers followed by the body. In a browser, the Headers tab of the network panel has a raw view you can copy.

Check the response headers, not the request. The browser blocks the call when Access-Control-Allow-Origin is missing or does not match your origin, and the console error rarely says which of the two it is.

It tells caches which request headers change the response. Omitting Vary: Accept-Encoding is a classic bug — a cache can then serve a gzipped response to a client that did not ask for one.

Almost always its attributes rather than its value. A Secure cookie sent over plain HTTP is dropped, and SameSite=None without Secure is dropped too.

Parsing happens entirely in your browser and nothing is uploaded. Do scrub cookies and tokens before pasting the same block anywhere else, such as a bug report.

Cache-Control takes precedence. If caching behaviour is surprising you, look for a Cache-Control being added by a proxy or CDN that you did not set yourself.