HTTP HeadersNetwork Tools
Status, final URL, and response headers from one GET.
Paste raw HTTP headers, or a whole request or response, and this HTTP header parser lays them out in a table with what each one does, splits structured values, and flags duplicates and lines a server would reject.
Paste the lines as your browser's network panel or curl -i shows them. A status or request line at the top is read too; anything after the first blank line is treated as the body.
| Line | Name | Value | Meaning |
|---|
curl -i or curl -v, or from a log.HTTP/1.1 200 OK or a request line such as GET /path HTTP/1.1 at the top is recognised.Each line up to the first blank line is split at its first colon into a name and a value. Anything after the blank line is the message body and is only counted. Names may contain letters, digits, and a short list of symbols; a name with a space or a space before the colon is reported, because RFC 9112 tells servers to reject such a line.
A line that starts with a space or tab continues the header above it. That is called obsolete line folding. The parser joins the line, as old clients did, and warns that current servers refuse it.
Some headers may legally appear several times, such as Set-Cookie, Link, and Vary. Any other name that repeats is flagged, because servers disagree on which copy wins.
Cache-Control: public, max-age=3600, stale-while-revalidate=60 becomes three rows: shared caches may store it, it is fresh for 3600 seconds (1 hour), and it may be served stale for 60 more seconds while a fresh copy is fetched.Accept: text/html;q=0.5, application/json is sorted by weight, so application/json (weight 1) comes before text/html (weight 0.5).Content-Length and Transfer-Encoding is marked as an error, since a proxy and a server can read such a body differently. That gap is how request smuggling attacks work.Pragma: no-cache next to Cache-Control gets a note that only HTTP/1.0 caches read it.:authority and :path from HTTP/2 views are reported as malformed lines.Open the developer tools, select the Network tab, click a request, and in the Headers panel turn on Raw. Copy the request or response block from there.
No. Content-Type and content-type are the same header. HTTP/2 even requires lowercase names on the wire.
No. Parsing happens in your browser, so you can paste headers that include cookies or tokens. Still, remove secrets before sharing a screenshot.
Chrome, Edge, and Safari removed the XSS filter it controlled, and Firefox never had one. A Content-Security-Policy is the current way to limit scripts.
Often used together with HTTP Header Parser.
Status, final URL, and response headers from one GET.
Builds copy-ready cURL commands with headers, auth, and a body, quoted for your shell.
Online HTTP client for any method with query, headers, and body, plus a matching cURL command.