HTTP Header Analyser — Security, Validation
← Tinker
HTTP Header Analyser
Paste headers · get security score · understand every field Dev Tools

Paste raw HTTP response headers into the HTTP Header Analyser to instantly evaluate your site's security posture. It checks for HSTS, CSP, X-Frame-Options, and other essential protections.

Try:
HTTP Response / Headers Paste the full HTTP response or just the headers block
Paste an HTTP response or click a sample above

Advertisement

Advertisement

How to use

  1. Open the tool and enter your data or select options.
  2. Adjust settings to see real-time updates.
  3. Copy the generated result to your clipboard.

Frequently Asked Questions

What are security headers?
Security headers are HTTP response headers that instruct the browser on how to behave when handling your site's content, preventing common attacks like XSS or clickjacking.
Why is Content-Security-Policy (CSP) important?
CSP prevents Cross-Site Scripting (XSS) by explicitly declaring which dynamic resources are allowed to load and execute.
Does this send my headers to a server?
No, all analysis is performed locally in your browser using JavaScript.

Did you know?

Related tools

HTTP Status Code Lookup JWT Decoder

© 2026, Tinker - tools · calculators · practice games