HTTP Header Inspector
Analyze HTTP headers in seconds. Paste a raw header block and get a categorized report — security, caching, cookies and CORS findings with before-state honesty, computed entirely in your browser.
About this tool
- What is it?
- DataFormatter HTTP Header Inspector is a free online tool that analyzes a pasted raw header block and reports cache control, cookies, CORS, HSTS and security headers with honest ok/warn/error notes.
- Who is it for?
- Developers and security reviewers checking response headers for caching behavior and missing security protections.
- What makes DataFormatter's tool different?
- Analysis runs locally — header blocks are never uploaded — so it is safe to inspect real production responses.
HTTP headers
Paste a header block from a request or response. Inspection runs locally — headers never leave the browser.
Findings
- content-typeinfoContentBody is declared as "text/html".
- cache-controlinfoCachingmax-age=0 (0s)
- strict-transport-securityokSecurityHSTS pinned: 2y.
- x-frame-optionsokSecurityFraming policy is "DENY". (CSP frame-ancestors is the modern replacement.)
- x-content-type-optionsokSecurityMIME sniffing is disabled.
- set-cookieokSessionCookie is marked HttpOnly and Secure.
- access-control-allow-originerrorCORSAccess-Control-Allow-Origin: * combined with allow-credentials is rejected by browsers (cannot be a wildcard).
- access-control-allow-credentialsinfoCORSBrowser credentials are allowed on CORS requests.
Unrecognized: cross-origin-opener-policy
Quick start
- Copy headers from DevTools (Network → Headers) or curl -i output.
- Paste them into the box, one header per line.
- Review the findings: errors first, then warnings, then info.
- Use the filter to isolate a topic like cache, cookie or CORS.
What header inspection checks
- Cache-Control semantics — privately-cacheable vs public and revalidation flags.
- Cookie markers — HttpOnly, Secure, SameSite strictness and Domain/Path scope.
- CORS coherence — a wildcard Access-Control-Allow-Origin never pairs with credentials.
- Transport settings — HSTS max-age, upgrade-insecure-requests, redirection hints.
- Security headers — X-Frame-Options, X-Content-Type-Options, CSP presence and permissions policy.
- Credential hygiene — plumbing headers like Authorization, token names and shared secrets usage flags.
How to analyze headers online
- Paste a complete block to avoid false gaps — partial header sets yield partial advice.
- Sort by severity: nickname errors clearly; worth flagging, not required for small internal tools.
- Filter by category to audit one concern (optimize caching, harden cookies).
- Copy Report or Download to share the inspection with a teammate or attach to an issue.
access-control-allow-origin: *
access-control-allow-credentials: true[error] CORS · access-control-allow-credentials
Browsers reject requests when credentials ship with a wildcard origin.Who inspects headers — and when
Before shipping a new endpoint
Paste the response headers of an API before go-live and catch the CORS-with-credentials or missing-SameSite mistake early.
Auditing an inherited service
You inherited a server with no docs. A quick paste of its response headers tells you how cookies, caching and transport are actually configured.
Debugging unexpected browser behavior
Cached responses, silently dropped cross-site cookies, blocked frames — the header block usually reveals which.
When the report looks odd
Nothing parsedWhy: The paste doesn't contain Name: Value lines — common when you copy the entire DevTools Headers section including its HTML table.
Fix: Switch to the raw/copy view in DevTools, or paste the plain response text from curl -i.
Header shown as unrecognizedWhy: A custom or less common header this tool doesn't have a rule for.
Fix: Count it as informational; the exact value is preserved so you can read it yourself. Report gaps via GitHub issues.
A website scores fine here but elsewhere warns about missing headersWhy: Different tools demand different baselines — this inspector only judges what you paste.
Fix: If you pasted a complete block and care about hardening, add the headers the warn findings mention.
Pro tips
- Paste response headers for EC-site audits and request headers when debugging CORS preflights.
- Download a report before and after a change to see the delta over time.
- Combine with the cURL to Code tool to build a request that reproduces the exact header set you're inspecting.
Frequently asked questions
What does the header inspector understand?
It parses any raw header block (one header per line, like a request or response printed by curl -i or the DevTools Headers tab) and analyzes the security, caching, cookie and CORS relevant headers it recognizes. Everything else is listed as unrecognized rather than guessed at.
How are findings categorized?
Each finding has a tone — ok, warn, info or error — plus a category (Security, Caching, Cookie, CORS, Transport, Protocol). Errors are definite problems like a CORS wildcard paired with credentials; warnings are observations that usually warrant a look.
Does it claim a header is missing?
No. The inspector treats headers as optional unless a spec demands them, and you haven't necessarily pasted the complete set. It reports observations about the headers you supply, not demands about ones you didn't.
Is my header block uploaded?
No. Parsing and analysis run entirely in your browser, so copies of real Set-Cookie or Authorization values that include a header block never leave the page.
How do I actually get a header block to paste?
Use curl -i https://example.com, or open DevTools → Network, click a request, and copy the headers under the Request Headers/Response Headers section. Both produce the line-per-header format this tool reads.
What's the difference between info and ok findings?
ok confirms a header has a recommended value (e.g. nosniff set correctly). info just describes behavior — like an HSTS max-age or a SameSite cookie setting — without passing judgment.