HTTP Header Parser

Paste raw HTTP headers, or a whole request or response, and this HTTP header parser lays them out in a table with what each one does, splits structured values, and flags duplicates and lines a server would reject.

Parsed in your browser. The headers you paste are not uploaded.

Paste the lines as your browser's network panel or curl -i shows them. A status or request line at the top is read too; anything after the first blank line is treated as the body.

Parses as you type.

How to use the HTTP Header Parser

  1. Copy headers from the Network tab of your browser's developer tools (use the raw view), from curl -i or curl -v, or from a log.
  2. Paste them into the box. A status line such as HTTP/1.1 200 OK or a request line such as GET /path HTTP/1.1 at the top is recognised.
  3. Read the table. Values with several parts are broken out under the meaning, one part per line.
  4. Check Problems found for anything a server or cache would treat differently from what you expect.

How it works

Each line up to the first blank line is split at its first colon into a name and a value. Anything after the blank line is the message body and is only counted. Names may contain letters, digits, and a short list of symbols; a name with a space or a space before the colon is reported, because RFC 9112 tells servers to reject such a line.

A line that starts with a space or tab continues the header above it. That is called obsolete line folding. The parser joins the line, as old clients did, and warns that current servers refuse it.

Some headers may legally appear several times, such as Set-Cookie, Link, and Vary. Any other name that repeats is flagged, because servers disagree on which copy wins.

Examples

  • Cache-Control: public, max-age=3600, stale-while-revalidate=60 becomes three rows: shared caches may store it, it is fresh for 3600 seconds (1 hour), and it may be served stale for 60 more seconds while a fresh copy is fetched.
  • Accept: text/html;q=0.5, application/json is sorted by weight, so application/json (weight 1) comes before text/html (weight 0.5).
  • A response with both Content-Length and Transfer-Encoding is marked as an error, since a proxy and a server can read such a body differently. That gap is how request smuggling attacks work.
  • Pragma: no-cache next to Cache-Control gets a note that only HTTP/1.0 caches read it.

Limitations

  • Only HTTP/1.x text is read. HTTP/2 and HTTP/3 send headers in a binary form; browser tools show them as text with lowercase names, and that text parses fine.
  • Pseudo-headers such as :authority and :path from HTTP/2 views are reported as malformed lines.
  • The meanings cover common standard headers. A custom header (often starting with X- or a product name) is listed without one.
  • Nothing is fetched. To see the headers a live site sends, use the HTTP Headers checker.

Frequently asked questions

Where do I find raw headers in Chrome or Firefox?

Open the developer tools, select the Network tab, click a request, and in the Headers panel turn on Raw. Copy the request or response block from there.

Are header names case-sensitive?

No. Content-Type and content-type are the same header. HTTP/2 even requires lowercase names on the wire.

Is anything I paste sent to a server?

No. Parsing happens in your browser, so you can paste headers that include cookies or tokens. Still, remove secrets before sharing a screenshot.

Why is X-XSS-Protection marked obsolete?

Chrome, Edge, and Safari removed the XSS filter it controlled, and Firefox never had one. A Content-Security-Policy is the current way to limit scripts.

Often used together with HTTP Header Parser.

  • HTTP HeadersNetwork Tools

    Status, final URL, and response headers from one GET.

  • cURL Command Builder

    Builds copy-ready cURL commands with headers, auth, and a body, quoted for your shell.

  • HTTP Request Tester

    Online HTTP client for any method with query, headers, and body, plus a matching cURL command.