ToolBuddy
In Browser

Security Headers

Audit pasted HTTP response headers for CSP, HSTS, X-Frame-Options, and related controls. No URL is fetched.

Runs in your browser. Nothing is uploaded.

0 characters · 0 lines

0 characters · 0 lines

About this tool

Audit pasted response headers for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and related COOP/CORP headers.

How to use: paste headers from DevTools, read present vs missing. No URL is fetched, so CORS is not involved.

Example: a 200 with only content-type lists the rest as missing. Related: URL parser for the request line.

Related Ops tools