Skip to content
ToolSuite

HTTP Header Parser

Parse raw HTTP headers into a readable table and flag missing security headers.

Processed in your browser

Your result will appear here as soon as you add some input.

How to use it

  1. 1Paste your input into the input box, or type it directly.
  2. 2Adjust the options if you need something other than the defaults.
  3. 3The result updates as you type.
  4. 4Copy the result to your clipboard or download it as a file.

About the HTTP Header Parser

Paste the output of `curl -I`, a browser network panel copy, or a raw request. A start line is detected if present, and obsolete line folding is joined back onto the previous header.

For a response, four security headers are checked: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options and Referrer-Policy. Their absence is reported with what each one would have prevented.

Questions people ask

Is your code uploaded to a server?

No. This tool runs entirely in your browser using standard web APIs, so your code never leaves your device. You can confirm it by opening your browser's network panel while the tool runs, or by disconnecting from the internet after the page has loaded.

Is it free, and do I need an account?

Yes, it is free, and there is no account, no sign-up and no watermark on the result. The project is funded by optional donations.