🔍 HTTP Headers Inspector
Inspect HTTP response headers for any URL. Check status code, cache-control, security headers, and content type. Free online HTTP header checker tool — no signup.
How to Use
1
Paste your headers
Copy HTTP response headers from your browser DevTools (Network tab → Response Headers) and paste them here.
2
Inspect the results
Click Inspect to categorize headers: Security, Caching, CORS, Content-Type, and more.
3
Read the descriptions
Each header row includes a description explaining what it does and why it matters for web performance and security.
Frequently Asked Questions
Where do I find HTTP headers to paste?
In Chrome/Firefox DevTools (F12) → Network tab → click any request → Headers tab. Or use curl -v https://example.com and copy the response headers (lines after < that start with a header name).
What are the most important security headers?
Key security headers include: Strict-Transport-Security (HSTS — forces HTTPS), Content-Security-Policy (prevents XSS), X-Content-Type-Options: nosniff (prevents MIME sniffing), X-Frame-Options (prevents clickjacking), and Referrer-Policy.
What does Cache-Control: max-age mean?
max-age=N tells the browser to cache the response for N seconds. For example max-age=3600 caches for 1 hour. Combined with public or private, it controls whether CDNs and proxies can also cache the response.
What are CORS headers?
CORS (Cross-Origin Resource Sharing) headers like Access-Control-Allow-Origin control which websites can make cross-origin requests to your server. They are required for browser-based API calls from a different domain.
What is the Vary header used for?
The Vary header tells caches which request headers affect the response. Vary: Accept-Encoding means different cached versions exist for gzip vs non-gzip responses. Vary: Accept-Language creates separate caches per language.
Guide : Inspecteur d'En-têtes HTTP
Qu'est-ce que c'est ?
L'Inspecteur d'En-têtes HTTP envoie une requête à n'importe quelle URL et affiche les en-têtes de réponse : codes de statut, cache, sécurité, CORS et plus encore.
C'est essentiel pour déboguer la configuration du serveur, les politiques de cache et les directives de sécurité.
Comment utiliser
- Entrez l'URL cible dans le champ d'entrée.
- Sélectionnez la méthode HTTP (GET, POST, HEAD…).
- Cliquez sur Inspect pour envoyer la requête.
- Consultez les en-têtes de réponse détaillés dans le panneau de résultats.
Conseils professionnels
- Vérifiez
Strict-Transport-SecurityetContent-Security-Policypour votre sécurité. - Inspectez
Cache-ControletETagpour optimiser les performances de mise en cache.