HTTP Header Inspector & Compare
Inspect HTTP header blocks, preserve repeated fields, compare two captures, mask credential-like values and export a readable report locally.
Settings
Comparison headers · optional, last block used
Try the example or enter your own settings.
Paste headers only. No URLs are fetched or requests replayed. Masking applies to results, not the input box. Ad scripts on this page can technically access page input; use redacted examples for confidential captures.
Using HTTP Header Inspector & Compare
Inspect HTTP header blocks, preserve repeated fields, compare two captures, mask credential-like values and export a readable report locally.
- Copy request or response headers from your browser developer tools, or open a UTF-8 text file.
- Select a header block and masking preference. Optionally paste a second capture for a case-insensitive name comparison.
- Inspect repeated fields and notes. Copy or download the complete JSON report, or export the visible parsed rows as CSV.
Example
Try the included editable example. Select a header block and masking preference. Optionally paste a second capture for a case-insensitive name comparison.
Questions & answers
Does it check a live website?
No. It parses supplied text locally and never fetches a URL or replays requests.
Can it read HTTP/2 pseudo-headers?
Yes, colon-prefixed names such as :status and :method are recognized. HTTP/1.x start lines and multiple blank-line-separated blocks are also supported.
What happens to repeated Set-Cookie fields?
They remain separate rows in the JSON and CSV report. The tool does not combine cookies with commas.
How are differences compared?
Names compare case-insensitively; values and duplicate order compare exactly. The chosen first block is compared with the last block of the optional second input.
Is masking complete anonymization?
No. Credential-like header names are masked in results; other custom fields, URLs and input text may still be sensitive. Review before sharing.
Does a security header prove the site is secure?
No. Explanations and selected consistency notes are observations, not a security audit or full protocol validator. Input is limited to 100,000 characters, 20 blocks and 500 fields per block.
Help improve this tool
Report a problem or suggest an improvement
Describe the issue without pasting private tool input. Feedback goes to our admin inbox.
