HTTP Header Inspector
Score pasted HTTP response headers on five security headers and summarize CORS and caching headers such as Access-Control-Allow-Origin and ETag.
HTTP Header Inspector
Output
Working…What this tool does
Paste raw HTTP response headers and the inspector grades the security posture (which of five key security headers are present and which are missing), then summarizes CORS and caching behavior — entirely in your browser. Grab headers with curl -sD - -o /dev/null <url> and paste the output. A response can be perfectly functional and still ship none of the security headers browsers act on.
Updated . Provided as is. Check the output before you rely on it in production.
How to use HTTP Header Inspector
- 1
Get the response headers
Run curl -sD - -o /dev/null https://example.com and copy the headers.
- 2
Paste them
Paste the headers, one per line, or load the sample.
- 3
Read the grade
The security score covers five headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy. Missing ones are listed.
- 4
Check CORS and caching
The report shows Access-Control-Allow-Origin and -Methods, Cache-Control and ETag, so you can spot an open CORS policy or an uncached API.
Questions and answers
Which headers are graded?
Does it request the URL?
Use it as an API
HTTP Header Inspector is also callable as a free HTTP JSON API at
https://aidevhub.io/api/http-header-inspector/ — GET with query
parameters or POST with a JSON body, no authentication, CORS enabled, fair use
(abusive traffic is throttled at the edge; there is no per-request quota header). Responses return
{ ok, tool, result, meta }.
curl -s -X POST https://aidevhub.io/api/http-header-inspector/ \
-H "Content-Type: application/json" \
-d '{"headers":"content-type: text/html\nstrict-transport-security: max-age=31536000\ncache-control: public, max-age=60"}' Machine-readable contract: /api/tool/http-header-inspector.json All API endpoints: /agents/ LLM site index: /llms.txt
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Dedicated API endpoint
Deterministic outputs, machine-safe contracts, and production-ready examples.
Dedicated API
https://aidevhub.io/api/http-header-inspector/ OpenAPI: https://aidevhub.io/api/openapi.yaml
Unified Runtime API
https://aidevhub.io/api/tools/run/?toolId=http-header-inspector&a=content-type%3A%20text%2Fhtml%0Astrict-transport-security%3A%20max-age%3D3
GET and POST are supported at /api/tools/run/ with identical validation and limits.
Limit: 10 req / 60s, input max 512 KB.
How do I check which security headers a website response is missing?
Fetch the headers from your terminal, then paste them here. The inspector parses each name: value line (case-insensitive), checks five security headers, and reports a score with the exact missing list — plus the CORS and cache-control posture in the same pass.
Get response headers with curl
curl -sD - -o /dev/null https://example.com
-sD - dumps the response headers to stdout and -o /dev/null discards the body, so this works even on servers that reject HEAD requests (plain curl -I can behave differently for that reason). Copy everything after the status line and paste it into the inspector.
The five security headers this inspector grades
| Header | What it protects against |
|---|---|
| strict-transport-security | Protocol-downgrade and cookie-hijack attacks: tells browsers to use HTTPS only for future visits (HSTS). |
| content-security-policy | Cross-site scripting and injection: restricts which sources may load scripts, styles, and other resources. |
| x-frame-options | Clickjacking: controls whether the page may be embedded in a frame or iframe on another site. |
| x-content-type-options | MIME-sniffing: nosniff stops browsers reinterpreting responses as a different content type. |
| referrer-policy | URL leakage: controls how much of the current URL is sent in the Referer header on outbound navigation. |
The five headers this inspector's score counts, each worth 20 points; a fuller review also covers headers like Permissions-Policy. CORS (allow-origin, allow-methods) and caching (cache-control, ETag) are reported alongside the score.
What does access-control-allow-origin: * mean?
The wildcard lets any origin read the response cross-origin — correct for public assets and open APIs, wrong for anything behind cookies or authorization headers. Per the Fetch specification, the wildcard is not accepted for credentialed requests, so an authenticated API needs an explicit origin plus access-control-allow-credentials instead.
Why check cache-control on an API response?
A missing cache-control leaves caching to heuristics, which can put per-user API responses into shared caches. For private data, no-store is the safe answer; for public content, an explicit max-age with an etag gives caches something correct to work with. The inspector shows both fields so silent-default cases are visible.
Do pasted headers leave the browser?
No. Parsing and grading run entirely client-side; nothing is fetched or transmitted by this page. Response headers can contain session cookies, internal hostnames, and infrastructure fingerprints, so strip set-cookie lines before sharing output anywhere — pasting them here stays on your machine either way.