DEVELOPER WORKBENCH

HTTP Header Inspector & Compare

Inspect HTTP header blocks, preserve repeated fields, compare two captures, mask credential-like values and export a readable report locally.

Local processingEditable exampleCopy + file exports

Settings

Comparison headers · optional, last block used

Try the example or enter your own settings.

Paste headers only. No URLs are fetched or requests replayed. Masking applies to results, not the input box. Ad scripts on this page can technically access page input; use redacted examples for confidential captures.

Using HTTP Header Inspector & Compare

Inspect HTTP header blocks, preserve repeated fields, compare two captures, mask credential-like values and export a readable report locally.

  1. Copy request or response headers from your browser developer tools, or open a UTF-8 text file.
  2. Select a header block and masking preference. Optionally paste a second capture for a case-insensitive name comparison.
  3. Inspect repeated fields and notes. Copy or download the complete JSON report, or export the visible parsed rows as CSV.

Example

Try the included editable example.
Select a header block and masking preference. Optionally paste a second capture for a case-insensitive name comparison.

Questions & answers

Does it check a live website?

No. It parses supplied text locally and never fetches a URL or replays requests.

Can it read HTTP/2 pseudo-headers?

Yes, colon-prefixed names such as :status and :method are recognized. HTTP/1.x start lines and multiple blank-line-separated blocks are also supported.

What happens to repeated Set-Cookie fields?

They remain separate rows in the JSON and CSV report. The tool does not combine cookies with commas.

How are differences compared?

Names compare case-insensitively; values and duplicate order compare exactly. The chosen first block is compared with the last block of the optional second input.

Is masking complete anonymization?

No. Credential-like header names are masked in results; other custom fields, URLs and input text may still be sensitive. Review before sharing.

Does a security header prove the site is secure?

No. Explanations and selected consistency notes are observations, not a security audit or full protocol validator. Input is limited to 100,000 characters, 20 blocks and 500 fields per block.

Help improve this tool

Report a problem or suggest an improvement

Describe the issue without pasting private tool input. Feedback goes to our admin inbox.

Find another tool · Read practical guides