HTTP Header Inspector: Request & Response Fields
Inspect pasted HTTP header blocks, retain field order and duplicate values, and create a masked report without sending a request.
Enabling local controls…
1. Paste a header block
Page-memory only; no requests. Limits: 1 MiB UTF-8, 502 lines, 500 fields, 16,384 characters per line; report: 2 MiB. One HTTP/1.0 or 1.1 textual block, LF/CRLF. No body, multiple blocks, obsolete folding, HTTP/2 wire or pseudo headers.
Without a start line, select Request or Response explicitly. Duplicate fields retain their order; Set-Cookie is never merged.
All values (including custom fields) and start lines are masked by default. Hidden after 15 s, paste, inspection or leaving the tab. Copied/downloaded reports always redact every value; field names may still be private, so review before sharing. This is not a security audit.
2. Line diagnostics and redacted report
Paste a block or load a sample, then inspect.
How to use this tool
Paste a header block, choose its request or response context and inspect line diagnostics and duplicate fields. Reveal values deliberately; use the masked report for sharing.
When not to use it
This is not a remote endpoint tester or a full HTTP wire parser. A pasted block cannot establish authenticity, transport security or what a browser actually received.
Read the guide →