Skip to main content
Develop Tools

HTTP header analysis/security confirmation tool

Deconstructs request/response headers for security, CORS, caching, cookies, and sensitive information.

HTTP header to parse

Paste the headers you copied from DevTools, curl, HTTP logs, etc.

Parse with Ctrl/Command + Enter

Please enter the HTTP headers or open the sample.

About this tool

See syntax, sensitive values, and typical security settings before sharing HTTP headers with third parties or exposing server settings.

Features

  • HTTP/1.x, HTTP/2/HTTP/3 format, pseudo header, multiple responses
  • CSP, HSTS, clickjacking, MIME sniffing measures
  • CORS, cache, Content-Type, cookie attributes, product information disclosure
  • Sensitive value masking such as authorization, cookies, API keys, etc.

How to use

  1. Paste the HTTP header or open a text file.
  2. Specify the input format and judgment criteria URL as necessary.
  3. Run the analysis and review the list and diagnostic reasons by severity.
  4. Copy and save masked plastic surgery results or diagnostic reports.

Limitations

Privacy: HTTP headers, files, criteria URLs, and analysis results are processed only within the browser and are not sent or saved to the Develop Tools server.