Header Analyzer - Free Online HTTP Security Header Tool | IconVault
Paste raw HTTP response headers or fetch a URL to check security headers like HSTS, CSP and X-Frame-Options. Free, runs fully in your browser.
Header Analyzer
Paste raw response headers, get a security audit in seconds
Raw response headers
Security audit your headers
Paste raw response headers to get a clean table plus flags for missing HSTS, CSP, X-Frame-Options and more.
About this tool
IconVault's Header Analyzer turns raw HTTP response headers into a clean, readable table plus an automatic security header audit. Paste a captured header block, or fetch a URL and inspect the headers the browser actually exposes. Parsing and analysis are 100% client-side.
It flags the headers that matter for web security: Strict-Transport-Security (HSTS), Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and cookie flags like Secure, HttpOnly and SameSite. It is free with no signup and nothing leaves your device. Honest note: the browser only exposes headers that CORS allows, so a cross-origin fetch may show fewer headers than a full raw paste from DevTools or curl.
Frequently asked questions
Popular searches
More tools
AES Encryptor
AES-256-GCM text encryption in your browser
HMAC Generator
HMAC-SHA signatures in hex or Base64, with tag verify mode
JWT Builder
Sign and verify HS256/HS384/HS512 tokens
Breach Check
Check passwords against HaveIBeenPwned, safely
Coming soon
CLI
Coming soon
Figma plugin
Coming soon
VS Code extension
Coming soon
Chrome extension
Coming soon
AI icon generator
Coming soon
Team workspaces
Coming soon