Free Online HTTP Header Parser and Explainer
Paste a raw head from curl, a network tab or a log and get it as a table: the start line split up, every header with what it does, and the values that have structure of their own broken out. Duplicated and unknown headers are flagged, and nothing you paste leaves the page.
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
How to Parse HTTP Headers
A few steps, and nothing is uploaded.
What to Know About HTTP Headers
Including what this page will not do with your token.
Set-Cookie lines are normal and required, since cookies cannot be combined onto one line. Two Content-Length lines or two Location lines are a real problem and different proxies resolve them differently, which is the basis of request smuggling. Both cases are flagged, and the note says which is which.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About the HTTP Header Parser
Most of what a browser and a server agree about happens in the head, and it is written in a format designed to be easy for a machine to read rather than a person. A response with twenty headers is perfectly ordinary, and three or four of them will be carrying compound values with their own grammar inside a single line.
This page takes that head apart. The start line is split into its pieces, each header is listed with a sentence on what it does, and the headers whose values have internal structure are opened up: Cache-Control into its directives, Content-Type into type and parameters, Set-Cookie into its attributes, Accept into a list sorted by real preference, and a Content-Security-Policy into one row per directive.
Two decisions shaped it. Folded continuation lines are joined onto the header above, because logs and old proxies still produce them and treating them as separate headers makes nonsense of the table. And nothing is verified: a Bearer token is decoded so you can read it, but a page that asked for your signing key in order to check a signature would deserve to be closed immediately.
Frequently Asked Questions
Duplicates, folded lines, cookie attributes and Basic auth.
Set-Cookie lines are normal, because cookies cannot be combined. Multiple Accept-Encoding or Via lines are harmless and combine with commas. Two Content-Length headers, or a Content-Length together with Transfer-Encoding, is serious: different servers in a chain may disagree about where the body ends.text/html,application/xml;q=0.9,*/*;q=0.8 is a ranked list rather than a plain one. Items with no q value default to 1. The table lists them in descending order of q, which is the order a server should consider them in, and that is often different from the order they were written.