100% local and secure
Your data stays on your device and is never sent to our servers.
Inspect a set of HTTP headers and get a readable report covering security directives, caching, CORS, and detected cookie settings.
Paste HTTP response lines, with or without the status line.
Analyze HTTP headers and receive a report about security, caching, CORS, and cookies.
Your data stays on your device and is never sent to our servers.
Generate, convert, or validate technical data with purpose-built controls.
Technical formats and syntaxes suited to each generator, converter, or validator.
Get a clean, ready-to-use result in seconds without installing software or configuring a complex workflow.
Fonctionnement
The analyzer converts raw header lines into a normalized structure and checks common protections such as CSP, HSTS, Referrer-Policy, and X-Content-Type-Options. It also reviews caching, compression, CORS, and cookie flags before calculating an indicative score.
Quickly identify missing or incomplete HTTP protections.
Review caching, compression, and proxy-added headers.
Detect Secure, HttpOnly, and SameSite attributes.
Guide
Fill in the fields or paste the information required for the operation.
Choose the options, formats, or algorithms that fit your use case.
Generate and copy the locally produced report, code, or value.
No. Processing runs locally in your browser and the entered information is not transmitted.
Yes. Every generated output can be copied directly for reuse in code or documentation.
Processing is local, but production secrets should still be avoided on shared or untrusted devices.
Understand HSTS, CSP, X-Content-Type-Options, Referrer-Policy and Permissions-Policy and how to verify the headers actually returned.
Understand the layers that protect a website: HTTPS, HTTP security headers, CSP, SRI, authentication, passwords and integrity.
Learn why covering text is not enough, how secure PDF redaction removes sensitive information and why sanitization matters before sharing.
Learn how to introduce a CSP progressively, understand its main directives, Report-Only mode, nonces and common mistakes.
Recommended workflow
Discover tools that naturally fit before, after, or alongside this one.
Generate a complete cURL command from an HTTP request.
Build custom HTTP headers and get output ready to use in your requests.
Build a complete HTTP API request with method, URL, parameters, headers, and body.