HTTP Header Analyzer
Processed Client SidePaste a raw block of HTTP request or response headers and get them parsed into a clean table, with plain-English explanations for common headers.
Bookmark this tool now — skip the search next time you need it.
About HTTP Header Analyzer
This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.
Paste a raw block of HTTP request or response headers and get them parsed into a readable table with a plain-English explanation of what each one does. Headers are where most confusing web behaviour is actually decided — why a response is cached, why a cookie is not being set, why a cross-origin call is blocked, why a browser refuses to frame your page — but they arrive as an undifferentiated wall of text. This tool separates the start line from the headers, lists each name and value cleanly, and annotates around thirty of the most common headers so you do not have to look up what Vary or Strict-Transport-Security is doing.
Key features
- Parses a raw header block copied straight from a terminal, a browser network panel, or a log
- Recognises and separates the start line, whether it is a request line or a response status line
- Plain-English explanations for roughly thirty common headers
- Covers caching (Cache-Control, ETag, Expires, Last-Modified, Vary) and content negotiation (Accept, Content-Type, Content-Encoding)
- Covers the CORS family (Access-Control-Allow-Origin, -Credentials, -Methods) and Origin
- Covers security headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options
- Handles cookies, authentication headers, and the standard request metadata headers
- Tolerates the formatting variations you get from different sources, including the leading status line
- Runs entirely in your browser — pasted headers containing session cookies are never uploaded
How to use it
- Copy a raw header block — from curl -i, from the Headers tab of your browser network panel, or from a server log.
- Paste it into the input pane.
- Read the parsed table of header names and values.
- Check the explanation beside any header whose behaviour you are trying to understand.
Tips & common mistakes
- Pasted headers routinely contain session cookies and bearer tokens. Nothing here is uploaded, but scrub them before pasting the same block into a ticket or a chat.
- For a CORS failure, read the response headers rather than the request. The browser blocks the call because Access-Control-Allow-Origin is missing or does not match, and the error in the console rarely says which.
- Vary is the most commonly misunderstood caching header: it tells caches which request headers change the response. Omitting Vary: Accept-Encoding is a classic way to serve gzipped content to a client that cannot read it.
- Cache-Control beats Expires wherever both are present. If caching behaviour surprises you, check for a Cache-Control you did not know was being set by a proxy or CDN.
- A Set-Cookie that the browser ignores is usually failing on its attributes rather than its value — Secure over plain HTTP, or SameSite=None without Secure, are both silently dropped.
- Get a header block quickly with curl -I for response headers only, or curl -i to see the headers followed by the body.