HTTP Security Header Analyzer
Inspect pasted HTTP response headers for selected security-header syntax and context notes, entirely in your browser.
This tool handles input and primary processing in your browser and is designed not to send the input to QuickKit’s server.
Avoid live production secrets; use dummy or masked data where possible. Data handling details
Parsed headers
Observations
How it works
Paste a response header block to inspect its syntax locally. The tool covers HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, COEP, CORP, CSP frame-ancestors, X-Frame-Options, and the legacy X-XSS-Protection header. Repeated Content-Security-Policy fields and comma-separated policy lists are treated as multiple independently enforced policies, not as a duplicate header. It does not fetch a URL, verify HTTPS delivery, browser behavior, deployment configuration, or assign a security score. Header blocks can contain credentials or cookies, so they are never uploaded, stored, or put into the URL.