HTTP Header Checker

37 tools

Read the response headers a URL returns.

Free to use with no account. JSON, passwords, hashes, 2FA and text tools run entirely in your browser.

HTTP Header Checker

Read the response headers a URL returns.

Free

About

Enter a public URL and read what the server sent back above the body. The request is made from our server rather than your browser, which removes your cookies, your extensions, and your location from the picture.

How to use

Paste a full URL including https://. The response headers come back as a list. Nothing on the page is rendered and no JavaScript from it runs.

A request without your browser attached

Debugging cache behaviour in your own browser is awkward, because your browser is a participant. It has cookies from previous visits, extensions that rewrite requests, and an IP that may put you in a different CDN region from your users. Requesting from elsewhere gives a clean reading, and comparing the two is often how a caching bug becomes obvious.

The fields worth reading first

Cache-control and age explain why an update has not appeared. Location tells you where a redirect actually points, which is frequently not where the site says it points. Content-type explains a download that should have rendered, or the reverse. Strict-transport-security and the content security policy matter when they are missing from a response you assumed carried them.

CDNs rewrite what you are reading

A response passing through a CDN is not the response the origin produced. Headers get added, cache directives get rewritten, and vendor specific fields appear that describe the edge rather than your application. Before concluding that your server is misconfigured, work out which machine actually answered, because the answer usually was not yours.

A missing security header is not a vulnerability

Header scanners hand out grades, and the grade is easy to over-read. A response without a content security policy is a response without that particular defence, which matters on a page rendering user content and matters far less on a static asset. Treat an absent header as a question to ask about that endpoint, not as a finding on its own.

FAQ

How is this different from the network tab in my browser?

Your browser carries cookies, an extension or two, and your geography. This request carries none of that, so the two can legitimately disagree about caching and redirects.

Which hop am I seeing on a redirect?

The response that was actually received. Where a chain of redirects collapses to a final answer, the intermediate hops are not shown separately.

Can I check a page behind a login?

No, and you should not try. There is no session to send, so the answer would describe the login page rather than the page you meant.

Does it show the certificate?

No. Certificate fields come from the TLS handshake rather than the HTTP response, and the SSL certificate checker reads those.

Related tools

HTTP Header Checker - View Response Headers for a URL