← All tools

HTTP Header Inspector: Request & Response Fields

Inspect pasted HTTP header blocks, retain field order and duplicate values, and create a masked report without sending a request.

Enabling local controls…

1. Paste a header block

Page-memory only; no requests. Limits: 1 MiB UTF-8, 502 lines, 500 fields, 16,384 characters per line; report: 2 MiB. One HTTP/1.0 or 1.1 textual block, LF/CRLF. No body, multiple blocks, obsolete folding, HTTP/2 wire or pseudo headers.

Without a start line, select Request or Response explicitly. Duplicate fields retain their order; Set-Cookie is never merged.

All values (including custom fields) and start lines are masked by default. Hidden after 15 s, paste, inspection or leaving the tab. Copied/downloaded reports always redact every value; field names may still be private, so review before sharing. This is not a security audit.

2. Line diagnostics and redacted report

Paste a block or load a sample, then inspect.

How to use this tool

Paste a header block, choose its request or response context and inspect line diagnostics and duplicate fields. Reveal values deliberately; use the masked report for sharing.

When not to use it

This is not a remote endpoint tester or a full HTTP wire parser. A pasted block cannot establish authenticity, transport security or what a browser actually received.

Read the guide →