🔍 HTTP Headers Inspector

Inspect HTTP response headers for any URL. Check status code, cache-control, security headers, and content type. Free online HTTP header checker tool — no signup.

How to Use

1

Paste your headers

Copy HTTP response headers from your browser DevTools (Network tab → Response Headers) and paste them here.

2

Inspect the results

Click Inspect to categorize headers: Security, Caching, CORS, Content-Type, and more.

3

Read the descriptions

Each header row includes a description explaining what it does and why it matters for web performance and security.

Frequently Asked Questions

Where do I find HTTP headers to paste? +
In Chrome/Firefox DevTools (F12) → Network tab → click any request → Headers tab. Or use curl -v https://example.com and copy the response headers (lines after < that start with a header name).
What are the most important security headers? +
Key security headers include: Strict-Transport-Security (HSTS — forces HTTPS), Content-Security-Policy (prevents XSS), X-Content-Type-Options: nosniff (prevents MIME sniffing), X-Frame-Options (prevents clickjacking), and Referrer-Policy.
What does Cache-Control: max-age mean? +
max-age=N tells the browser to cache the response for N seconds. For example max-age=3600 caches for 1 hour. Combined with public or private, it controls whether CDNs and proxies can also cache the response.
What are CORS headers? +
CORS (Cross-Origin Resource Sharing) headers like Access-Control-Allow-Origin control which websites can make cross-origin requests to your server. They are required for browser-based API calls from a different domain.
What is the Vary header used for? +
The Vary header tells caches which request headers affect the response. Vary: Accept-Encoding means different cached versions exist for gzip vs non-gzip responses. Vary: Accept-Language creates separate caches per language.


Guide : Inspecteur d'En-têtes HTTP

Qu'est-ce que c'est ?

L'Inspecteur d'En-têtes HTTP envoie une requête à n'importe quelle URL et affiche les en-têtes de réponse : codes de statut, cache, sécurité, CORS et plus encore.

C'est essentiel pour déboguer la configuration du serveur, les politiques de cache et les directives de sécurité.

Comment utiliser

  1. Entrez l'URL cible dans le champ d'entrée.
  2. Sélectionnez la méthode HTTP (GET, POST, HEAD…).
  3. Cliquez sur Inspect pour envoyer la requête.
  4. Consultez les en-têtes de réponse détaillés dans le panneau de résultats.

Conseils professionnels

🧰 50+ Tools