DataFormatter
DebuggingAug 26, 20263 min read

HTTP Headers Every Developer Should Know

A response headers block is a diagnosis in plain text: caching freshness, CORS policy, session protections and security posture. Knowing the handful that matter turns an opaque wall into a readable story.

In brief

What is it?
HTTP response headers carry the metadata that governs caching, CORS, sessions and security (Cache-Control, ETag, Set-Cookie, HSTS, CSP), and knowing how to read them is core debugging skill.
Who is it for?
Developers reviewing production responses, debugging redirects, CORS failures or caching surprises, and auditing security headers.
How DataFormatter's tool is different
The HTTP Header Inspector categorizes a pasted header block (content, caching, CORS, session, security), flags real issues like insecure cookies or wildcard-CORS-with-credentials, and runs locally so real responses are safe to paste.

Headers are name: value pairs, one per line, sent with requests and responses. Five groups carry most of what you need day to day: security, caching, CORS, sessions and content. The Inspector reads the block, assigns each header to a category, and attaches a tone — ok, warn, info or error — so the important lines stand out.

How the block is parsed

Each non-empty line is split at its first colon: the left half is the header name, the right half the value. Response lines appear as they come from the server, so you can paste a block straight out of a browser's network panel. Metrics and values are converted to human-readable forms where it helps — Content-Length becomes '1,234 bytes', max-age becomes '1h 30m'.

Security headers

  • Strict-Transport-Security — 'HSTS pinned' with its max-age (and whether includeSubDomains is set); tells browsers to force HTTPS.
  • Content-Security-Policy — a source list of what the page may load; review the origins you trust.
  • X-Content-Type-Options: nosniff — disables MIME sniffing; anything else is only informational.
  • X-Frame-Options: DENY — blocks framing; CSP frame-ancestors is the modern replacement.
  • Referrer-Policy and Permissions-Policy — control what is leaked on navigation and what APIs the page may use.
  • X-XSS-Protection — deprecated and ignored by modern browsers; seeing it is a sign of an old config.

Caching headers

Cache-Control drives freshness with directives like no-store, no-cache and max-age=N seconds. When none of those are present the Inspector notes that caches may apply heuristic expiry — an important gap for APIs that must control freshness. ETag is the revalidation validator: quotes mean a strong ETag, a W/ prefix means a weak one, and browsers send it back as If-None-Match. Expires is the old HTTP-date freshness marker that Cache-Control supersedes when both appear.

A well-formed caching policy
Cache-Control: public, max-age=3600
ETag: "33a64df5"

CORS headers

Access-Control-Allow-Origin tells the browser which origin may read a response. A wildcard (*) works only without credentials — combine it with Access-Control-Allow-Credentials: true and browsers refuse the CORS exchange entirely, which the Inspector flags as an error. Access-Control-Max-Age says how long a preflight may be cached.

Session and credential headers

Set-Cookie is checked for the two flags that matter most: Secure (transport only) and HttpOnly (invisible to JavaScript). Missing either produces a warning, and the header is never shown in full — cookie values stay masked. Authorization is treated as a secret outright: the Inspector flags it as an error and reminds you never to log or share raw headers.

Content and encoding headers

Content-Type names the body's media type; Content-Length and Content-Encoding (gzip, br, deflate, zstd) describe size and compression; Transfer-Encoding signals chunked, streamed bodies. A body sent with both Content-Length and Transfer-Encoding is a red flag — a real length is undefined in that combination.

Headers that are mostly noise

Accept-*, Host, User-Agent, Connection and sec-fetch-* appear constantly but rarely matter for diagnosis; the Inspector collects them into a separate unknown/request list so the findings stay focused. Server introspection headers are flagged when they expose framework or version fingerprints.

Try it

Copy a response's raw headers into the HTTP Header Inspector for categorized, commented findings. For full request/response pairs, capture a HAR and drop it into the HAR Debugger instead.

Frequently asked questions

Why is X-XSS-Protection flagged as informational?

It is deprecated and ignored by modern browsers, so its presence is a clue about config age rather than a protection you can rely on.

Is a wildcard CORS origin bad?

Only in combination with credentials (Access-Control-Allow-Credentials: true) — browsers reject that pair, which the Inspector reports as an error. A wildcard with no credentials simply means any site may read non-credentialed responses.

Why should I care if a cookie lacks HttpOnly?

Without HttpOnly, page JavaScript can read the cookie via document.cookie, expanding the blast radius of any XSS bug. Secure matters when the cookie must never travel over plain HTTP.

Related articles

Try it yourself

Last reviewed Aug 26, 2026 · DataFormatter team — this article describes how the DataFormatter tool actually works, verified against its source.