Analyzes security headers you paste or load from a file (never via a real request), explaining each header's purpose, detecting conflicting or repeated values, and generating sample configurations by profile (static site, web app, JSON API) as a plain header list, or for Next.js, Nginx, or Apache. It never automatically enables COEP/COOP/CORP/HSTS without a warning — each one can break OAuth, iframes, or third-party Workers if not reviewed first. It never assigns a security score or calls a site "secure" based on its headers alone.
Data is processed on your device and never sent to the server. This tool never makes an HTTP request.
or upload a .txt file with the headers
The data is processed on your device and is never sent to the server.