HTTP Headers Inspector
AcceptrequestMedia types the client can handle (e.g., text/html, application/json).
Access-Control-Allow-CredentialsresponseSet to "true" to let the browser expose a cross-origin response to JavaScript when the request carried cookies or HTTP auth.
Access-Control-Allow-HeadersresponseRequest headers the server permits on the real cross-origin request; answers a preflight OPTIONS.
Access-Control-Allow-MethodsresponseHTTP methods the server permits cross-origin (e.g., GET, POST, PUT); answers a preflight OPTIONS.
Access-Control-Allow-OriginresponseOrigin allowed to read the response: a specific origin or *. Cannot be * when credentials are included.
Access-Control-Max-AgeresponseHow many seconds the browser may cache a CORS preflight result before asking again.
Accept-EncodingrequestCompression algorithms the client accepts (gzip, deflate, br).
Accept-LanguagerequestPreferred languages for the response (e.g., en-US,en;q=0.9).
AuthorizationrequestCredentials for authenticating the client (Bearer token, Basic auth, etc.).
Cache-ControlbothCaching directives (e.g., no-cache, max-age=3600, public, private).
ConnectionbothControls whether the network connection stays open (keep-alive or close).
Content-EncodingbothEncoding applied to the body (gzip, deflate, identity).
Content-LengthbothSize of the request or response body in bytes.
Content-Security-PolicyresponseRestricts where scripts, styles, images, and frames may load from — the primary defence against XSS (e.g., default-src 'self').
Content-TypebothMedia type and encoding of the request/response body (e.g., application/json; charset=utf-8).
CookierequestHTTP cookies previously set by the server, sent back with requests.
ETagresponseUnique identifier for a version of a resource, used for caching.
HostrequestDomain name and port of the server being requested. Required in HTTP/1.1.
If-Modified-SincerequestReturns the resource only if modified after the given date (conditional GET).
If-None-MatchrequestReturns the resource only if the ETag does not match (conditional GET).
Last-ModifiedresponseDate and time the resource was last changed.
LocationresponseURL to redirect the client to (used with 3xx responses).
OriginrequestOrigin of the cross-site request, used in CORS preflight requests.
RefererrequestURL of the page making the request (note: misspelling is intentional in the HTTP spec).
Retry-AfterresponseHow long to wait before making another request (used with 429 or 503).
ServerresponseInformation about the server software handling the request.
Set-CookieresponseSets a cookie in the client; may include attributes like HttpOnly, Secure, SameSite.
Strict-Transport-SecurityresponseForces HTTPS by telling browsers not to use HTTP for a given duration (HSTS).
Transfer-EncodingbothEncoding for the message body (chunked, compress, deflate, gzip, identity).
User-AgentrequestString identifying the client browser, OS, and version.
VaryresponseTells caches which request headers affect the response (e.g., Vary: Accept-Encoding).
WWW-AuthenticateresponseAuthentication method the server requires (used with 401 responses).
X-Content-Type-OptionsresponsePrevents MIME-type sniffing; value "nosniff" instructs browser to use declared content type.
X-Frame-OptionsresponseControls embedding in iframes: DENY, SAMEORIGIN, or ALLOW-FROM uri.
X-Forwarded-ForrequestOriginal IP address of the client when passing through proxies or load balancers.
X-Requested-WithrequestIndicates an AJAX request; typically set to "XMLHttpRequest" by JS libraries.
X-XSS-ProtectionresponseLegacy XSS filter directive (deprecated in modern browsers, but still sent for legacy support).
Understand HTTP Headers Inspector
A reference for the common HTTP request and response headers, plus a parser that turns a pasted raw header block into structured key/value pairs.
How it works
HTTP headers are line-oriented: a name, a colon, and a value, terminated by CRLF, with a blank line ending the block. Names are case-insensitive, which is why HTTP/2 and HTTP/3 lowercase them all on the wire. The parser here splits each line at the first colon so that values containing colons (a URL in Location, a time in Retry-After) survive intact, and the reference alongside it labels each header as request-side, response-side, or both. Everything runs locally — this tool reads headers you paste, it does not fetch them from a URL.
When to use it
- Pasting a block copied out of the DevTools Network tab or `curl -i` output to read it as a structured list
- Checking what Cache-Control directives are actually being sent before blaming the CDN for a stale response
- Looking up which security headers a response should carry (Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options) and what each value does
- Confirming whether a header you expected — Vary, ETag, Access-Control-Allow-Origin — is present at all
Watch out for
- This tool does not fetch a URL. It explains and parses headers you supply; to capture real headers, use `curl -I`, the DevTools Network tab, or the REST client.
- Repeated header names are legal and meaningful. A response can carry several Set-Cookie lines; a flat key/value view keeps only the last of a repeated name, so check the raw block when cookies go missing.
- The misspelling in "Referer" is in the original specification and is permanent. Referrer-Policy, added much later, is spelled correctly — using the wrong spelling for either one silently does nothing.
- X-XSS-Protection is dead. Modern browsers ignore or have removed it, and a nonzero value was itself exploitable; a Content-Security-Policy is the replacement.
Frequently Asked Questions
What is the Cache-Control header?
Cache-Control directs browsers and CDNs on caching behavior. Key values: no-cache (revalidate before using cache), no-store (never cache), max-age=3600 (cache for 1 hour), public (CDN-cacheable), private (browser only), immutable (never revalidate, for versioned assets).
What headers are needed for CORS?
For simple requests: Access-Control-Allow-Origin: * (or specific origin). For preflighted requests (POST/PUT/custom headers): also Access-Control-Allow-Methods, Access-Control-Allow-Headers, and optionally Access-Control-Max-Age. Credentialed requests need Access-Control-Allow-Credentials: true.
What is the Strict-Transport-Security header?
HSTS (HTTP Strict Transport Security) tells browsers to only connect via HTTPS for a set duration: Strict-Transport-Security: max-age=31536000; includeSubDomains. After one HTTPS visit, browsers refuse plain HTTP for a year. Use with care — HTTPS must work before enabling.
How to Use HTTP Headers Inspector
- Paste or type your input in the input area above.
- The tool processes your input automatically or click Run.
- Copy or download the result using the action buttons.
- Use Ctrl+Enter to run quickly from the keyboard.