Skip to main content
ToolsBay

Runs in your browser — nothing is uploaded · verify

HTTP Header Parser — free, and it runs in your browser

Parse raw HTTP headers into a readable, annotated table.

  • Takes output straight from curl -I or a browser network panel, folded lines and all.
  • Each header is explained, so you are not looking half of them up.
  • Useful for debugging caching, CORS, redirects and security policy.

Paste headers on the left to see them parsed.

  • 70 tools

    Free, with no account and no watermark

  • 0 bytes

    Of your files or text uploaded — this tool runs in the tab

  • No queue

    The work happens in this tab, not in a line behind other users

Three steps, nothing to install

HTTP Header Parser in three steps

  1. HEADERS123456Paste it in — it never leaves the tab

    Paste the raw headers

    Straight out of curl -I, a browser network panel or a log.

  2. HEADERSEvery field, broken out and checked

    Read them as a table

    Names and values are separated and each recognised header carries a short note on what it actually controls.

  3. Copy TABLE

    Take the readable version

    Copy it into a ticket or an incident write-up.

Why use HTTP Header Parser

  • Annotated, not just split

    Splitting on a colon is the easy half. Knowing that a Vary header is why your cache hit rate collapsed is the part worth having.

  • Handles real-world input

    Folded lines, duplicated header names and mixed line endings all appear in genuine captures, and all parse here rather than producing one unusable row.

  • Your text stays in the page

    What you paste is not transmitted or stored, so an API response full of customer records, a token or an internal query never leaves your machine.

Frequently asked questions

From curl -I https://example.com, or from your browser devtools: Network tab, click a request, and copy the request or response headers.

Reading an HTTP exchange

Every HTTP request and response starts with a single line — a request line like GET /path HTTP/1.1, or a status line like HTTP/1.1 200 OK — followed by headers, one per line, each a name and a value separated by a colon.

Values may legitimately contain colons, which is why only the first one separates the name from the value. Content-Type: text/html; charset=utf-8 is one header whose value happens to contain both a colon-adjacent parameter and a semicolon.

The headers worth knowing

  • Cache-Control — the single most consequential header for performance. Decides who may cache the response and for how long.
  • Content-Type — how the browser interprets the body. A wrong value here makes a page render as plain text or download instead of displaying.
  • ETag and Last-Modified — used to revalidate a cached copy without re-downloading it.
  • Strict-Transport-Security, Content-Security-Policy and X-Content-Type-Options — the security headers worth auditing on any site you run.
  • Vary — tells caches which request headers change the response. Getting it wrong causes the wrong cached variant to be served.

To pull apart the URL a request was made to, use the URL parser. To decode a bearer token from an Authorization header, use the JWT decoder.

  • URL Parser

    Break a URL into its protocol, host, path and query parameters.

  • JWT Decoder

    Decode a JSON Web Token to inspect its header, payload and expiry.

  • JSON Formatter

    Pretty-print JSON with the indentation you choose, or minify it.

  • JSON Validator

    Check whether JSON parses, and see the line and column where it stops.

  • JSON to CSV

    Flatten a JSON array of objects into CSV rows.

  • JSON to XML

    Convert JSON structures into equivalent XML markup.

More tools

70 tools, none of which want your file

Everything this tool does happens in the page you are looking at. No account, no upload, no watermark.