Headerharbor icon
One-time iPhone and iPad app

Headerharbor

Audit HTTP response headers offline, explain CSP and CORS interactions, and build a precise hardening plan without sending URLs away.

Focused field tools

Origins

Apply origins checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.

CORS

Apply cors checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.

CSP

Apply csp checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.

HSTS

Apply hsts checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.

Cookies

Apply cookies checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.

Permissions Policy

Apply permissions policy checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.

Headerharbor reviews recorded headers and request context; browsers, caches, redirects, service workers, proxies, and origin rules may alter behavior. Confirm findings in supported browsers and on the final response path.