HTTP Header Inspector
Paste raw response headers and get a plain-English explanation of every one
About this tool
The HTTP Header Inspector takes a block of raw response headers — copy-pasted from curl -v, browser DevTools' Network tab, or a Response object's headers — and explains what each one actually does in plain English, covering caching (Cache-Control, ETag, Vary), CORS (Access-Control-Allow-*), security (CSP, HSTS, X-Frame-Options), and general HTTP mechanics (Content-Type, Transfer-Encoding, Connection). Unlike the Security Headers Checker, which scores a fixed checklist of security-relevant headers against best practices, this tool explains any header it recognizes — the goal here is understanding what you're looking at, not auditing for a specific set of best practices.
When to use it
- →Understanding an unfamiliar header in a curl -v or DevTools output without searching for each one individually
- →Debugging a caching issue by understanding exactly what Cache-Control, ETag, and Vary are each doing
- →Reviewing a CORS configuration by seeing what each Access-Control-* header actually permits
- →Learning what a security header (CSP, HSTS, X-Frame-Options) does before deciding whether to add it
Tips
- ◆Paste the full raw header block, including an optional leading HTTP/1.1 200 OK status line — it's automatically skipped, not misread as a header.
- ◆Use the category filter chips (Security, Caching, CORS, General) above the results to jump straight to the headers you're actually debugging in a large dump.
- ◆Set-Cookie can legitimately appear multiple times (once per cookie) — paste every occurrence on its own line to see each one explained.
- ◆If a header shows no explanation, it's likely a custom or application-specific header (X-Request-Id, X-Correlation-Id) rather than one defined by an HTTP or web-platform spec.
Frequently asked questions
How is this different from the Security Headers Checker?
The Security Headers Checker scores a fixed set of ~9 security-relevant headers (HSTS, CSP, X-Frame-Options, etc.) against best-practice recommendations, with a pass/fail-style result. This tool explains any header it recognizes, security-relevant or not — it's for understanding what a header does, not auditing whether your configuration follows best practices.
Does this tool distinguish between request and response headers?
No — it explains whatever header name it sees, and a few entries in its reference dictionary (like Authorization and Cookie) are actually request headers, included because raw header dumps from tools like curl -v often mix both directions together in one block.