HTTP Header Parser

Parse raw HTTP request or response headers into a structured table. Extract status line, headers, cookies, and content type information instantly.

Auto-Detect Type Cookie Extraction Content-Type Analysis

How to Use HTTP Header Parser

1

Paste Headers

Copy raw HTTP headers from browser DevTools (Network tab) or any source and paste them into the input area.

2

Auto-Parse

Headers are parsed instantly into a structured table, automatically detecting whether it is a request or response.

3

Inspect Details

Review the status line, individual headers, extracted cookies, and content-type breakdown.

What are HTTP Headers?

HTTP headers are key-value pairs sent between a client and server in HTTP requests and responses. They carry metadata about the request or response, such as content type, caching rules, authentication tokens, and cookie information. Understanding headers is essential for debugging web applications, optimizing performance, and ensuring security.

Request Headers

Sent by the client to the server, including Host, User-Agent, Accept, Authorization, and Cookie headers.

Response Headers

Sent by the server back to the client, including Content-Type, Set-Cookie, Cache-Control, and X-Request-Id headers.

Security Headers

Headers like Content-Security-Policy, Strict-Transport-Security, and X-Frame-Options that enhance security.

Frequently Asked Questions

Does it parse both request and response headers?

Yes. The parser auto-detects whether the input is an HTTP request or response based on the first line and parses accordingly. Request lines start with an HTTP method (GET, POST, etc.) while response lines start with HTTP/version.

Can it extract cookies from Set-Cookie headers?

Yes. Set-Cookie headers are parsed into individual cookies showing name, value, and all flags such as HttpOnly, Secure, SameSite, Path, Domain, and Max-Age.

What header formats are accepted?

Standard HTTP/1.1 and HTTP/2 header format with one header per line in the format "Name: Value". You can copy headers directly from browser developer tools.

Which HTTP headers show up most often?

Requests typically carry host, user-agent, accept, accept-encoding, and cookie; responses answer with content-type, content-length, cache-control, set-cookie, and date. API traffic adds authorization and content-type: application/json on the way in, and rate-limit headers on the way out. RFC 9110 (HTTP semantics, 2022) is the modern reference that defines them all.

What is the difference between request and response headers?

Request headers (host, authorization, accept-*) describe what the client wants; response headers (location, set-cookie, retry-after) describe what came back. Some fields appear in both directions (cache-control, content-type), and a few govern the connection itself (connection: keep-alive) rather than the message content. This parser annotates which side each header belongs to.

How are duplicate HTTP headers treated?

Per RFC 9110, most repeated fields combine into one comma-separated list - two cache-control lines and one line reading no-cache, no-store are equivalent. Set-Cookie is the documented exception: it can never be comma-merged because Expires dates contain commas, so proxies must forward each Set-Cookie separately. That exception is a classic source of proxy bugs.

What changed with headers in HTTP/2 and HTTP/3?

Field names became lowercase and travel as HPACK or QPACK-compressed binary frames; each request opens its own stream, and per-connection headers like Host were replaced by the :authority pseudo-header alongside :method, :scheme, and :path. Semantically the fields still follow RFC 9110 - the wire format changed, not the vocabulary.

Which header syntax is actually invalid?

Whitespace between the field name and the colon (Header : value) - HTTP/1.1 parsing and the HTTP/2 specification both reject it to prevent request smuggling. Also invalid: spaces or non-ASCII bytes inside the field name, control characters in values, and obs-fold (a header continued by an indented line), which RFC 9110 marks deprecated - replace it with a single line or a list value.

{-- * External Resources Component(#18 Phase 3b 内容佐证工程) * 工具页「权威引用」区块:RFC / W3C / WHATWG / ECMA / IANA / 官方规范站 / Wikipedia。 * * - 接受 :slug 属性 → 经 config/tool-sources.php 家族矩阵渲染该工具的权威引用 * - slug 未命中映射时不渲染(无权威来源的工具静默跳过) * - 链接 title 保持英文(引用源专名);description 经 * common.resources.descriptions.{key} 本地化,lang 未命中回退英文(线上不裸奔) * - 链接保持 dofollow(rel="noopener noreferrer") * * @param string|null $slug --}}