🔍

HTTP Header Analyzer — Security & CORS Audit

Parse and analyze HTTP request or response headers. Identifies categories, explains each header, flags missing security headers, and detects duplicates or suspicious values — entirely in your browser.

Developer ToolsDevOps & Infrastructure
Loading tool...

How to Use HTTP Header Analyzer — Security & CORS Audit

How to Use the HTTP Header Analyzer

Step 1: Paste Your Headers

Paste raw HTTP headers (one Header-Name: value per line) into the input field. You can paste:

  • Request headers copied from browser DevTools → Network → Headers tab
  • Response headers from curl output (curl -I https://example.com)
  • Headers from API testing tools like Postman or Insomnia
  • Any Key: Value block of header lines

Step 2: Review the Results

The analyzer immediately shows:

  • Parsed table — header name, category badge (authentication, content, caching, security, CORS, forwarding, custom), and value
  • Header explanations — each known header includes a plain-English description
  • Security check — lists any recommended security headers not found in the input
  • Warnings — flags duplicate headers, missing cookie security attributes, exposed server versions, and wildcard CORS origins

Step 3: Export Results

Click Copy as JSON to copy the parsed headers as a JSON array, or Download JSON to save a full audit report including missing headers and summary statistics.

Header Categories

  • Authentication — Authorization, Cookie, Set-Cookie, WWW-Authenticate
  • Content — Content-Type, Accept, User-Agent, Host, Location
  • Caching — Cache-Control, ETag, Vary, Expires, Age
  • Security — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy
  • CORS — Access-Control-Allow-Origin, Access-Control-Allow-Methods, Origin
  • Forwarding — X-Forwarded-For, X-Forwarded-Proto, X-Real-IP
  • Custom — Non-standard headers (X-Request-ID, X-API-Version, etc.)

Recommended Security Headers Checked

  1. Strict-Transport-Security — forces HTTPS within the max-age window (HSTS)
  2. Content-Security-Policy — restricts resource sources to prevent XSS
  3. X-Frame-Options — prevents clickjacking by blocking iframe embedding
  4. X-Content-Type-Options — stops MIME-type sniffing
  5. Referrer-Policy — controls how much referrer information is shared
  6. Permissions-Policy — restricts browser feature access (camera, mic, geolocation)

Frequently Asked Questions

Most Viewed Tools

🔐

TOTP Code Generator — 2FA Testing Tool

3,143 views

Generate time-based one-time passwords from a TOTP secret key. Enter your base32 secret, choose a period and digit length, and get the current and next codes with a live countdown timer. Useful for testing and debugging 2FA integrations.

Use Tool →
{ }

JSON to Zod — Schema Generator

3,106 views

Generate Zod validation schema code from a JSON sample object. Infers z.string(), z.number(), z.boolean(), z.array(), z.object(), and z.null() types automatically. Handles nested objects, arrays of objects with optional field detection, and outputs copy-ready TypeScript with import and z.infer type alias.

Use Tool →
{}

JSONL Formatter — Line-by-Line Validator

3,042 views

Format, validate, and inspect JSON Lines (JSONL) and NDJSON files. Validates each line individually, reports parse errors by line number, outputs compact JSONL or a pretty-print preview, and lets you download the cleaned file.

Use Tool →
🔐

TLS Cipher Suite Checker — Strength Analyzer

2,706 views

Check TLS protocol version compatibility and cipher suite strength ratings against current best practices. Supports IANA and OpenSSL cipher names — rates each suite as Strong, Weak, or Deprecated and explains why.

Use Tool →
🔑

Password Entropy Calculator — Crack Time Estimator

2,670 views

Calculate the information-theoretic bit entropy of any password or API key. Detects character set pools automatically, shows the total number of possible combinations, and estimates crack time across five attack scenarios from rate-limited web logins to GPU cracking clusters.

Use Tool →
🔍

Secret Scanner — API Key & Credential Detector

2,655 views

Scan pasted text, code, or config files for accidentally exposed API keys, tokens, passwords, and private keys. Detects 50+ secret types across AWS, GitHub, Stripe, OpenAI, and more — all client-side, nothing leaves your browser.

Use Tool →
📺

Screen Size Converter — Diagonal Dimension Tool

2,444 views

Calculate screen width and height from diagonal size and aspect ratio. Convert between inches and centimeters for displays, TVs, and monitors with instant dimension calculations.

Use Tool →

TOML Config Validator — Syntax Error Finder

2,379 views

Validate TOML configuration file syntax and report errors with line numbers. Paste any TOML content — Cargo.toml, pyproject.toml, config.toml — and instantly see a green checkmark with key counts and structure stats, or a precise error message pointing to the exact line. Includes a collapsible JSON structure preview to confirm what was parsed.

Use Tool →

Related DevOps & Infrastructure Tools

🗺️

IP Subnet Calculator — IPv4 Network Mask & Range Splitter

Enter any IPv4 CIDR to see full subnet details (network address, broadcast, usable hosts, subnet mask, wildcard) and optionally split the network into N equal subnets. Outputs a complete table of subnet ranges for VLAN planning, cloud VPC design, and network segmentation.

Use Tool →
☸️

Kubernetes YAML Validator — K8s Manifest Schema & Security Audit

Validate Kubernetes YAML manifests for syntax errors and required field completeness. Checks Deployments, Services, Ingress, ConfigMaps, Secrets, PVCs, HPAs, CronJobs, and more — with per-document results and fix hints.

Use Tool →
🐙

Docker Compose Validator — Multi-Container YAML Syntax & Logic Check

Validate docker-compose.yml syntax, service definitions, networks, volumes, and environment variables. Catches YAML errors, broken depends_on references, missing image/build, invalid restart policies, and more — with context-aware hints.

Use Tool →
🔌

Port Number Lookup — Common TCP/UDP Service & Protocol Database

Searchable reference for 80+ well-known TCP and UDP ports. Look up any port number or service name to see the official protocol, service description, port range (well-known/registered), and security recommendations for risky ports.

Use Tool →
🤖

Robots.txt Generator — Crawler Control Tool

Generate robots.txt file to control search engine crawlers. Create user-agent rules, allow/disallow paths, set crawl delays, and add sitemap URLs. Perfect for managing bot access to your website.

Use Tool →
🐋

Dockerfile Linter — Optimize & Secure Your Container Builds

Lint Dockerfile instructions for best practices, security issues, and layer optimization. Flags unpinned base images, root user, ADD vs COPY, apt-get mistakes, shell-form CMD, and more — with fix guidance for each issue.

Use Tool →
⚙️

GitHub Actions Validator — Workflow Syntax & CI/CD Security Audit

Validate GitHub Actions workflow YAML for syntax errors, missing required fields, deprecated commands, mutable action refs, outdated action versions, and broken job dependencies. Get per-job results with fix hints in real time.

Use Tool →
📄

MIME Type Finder — File Extension Lookup

Find MIME type for file extensions instantly. Look up media types for images, videos, documents, and more.

Use Tool →

Share Your Feedback

Help us improve this tool by sharing your experience

We will only use this to follow up on your feedback