Headerharbor
Audit HTTP response headers offline, explain CSP and CORS interactions, and build a precise hardening plan without sending URLs away.
Focused field tools
Apply origins checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply cors checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply csp checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply hsts checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply cookies checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Apply permissions policy checks to the recorded evidence, document assumptions, and retain a concrete verification result before changing a live system.
Headerharbor reviews recorded headers and request context; browsers, caches, redirects, service workers, proxies, and origin rules may alter behavior. Confirm findings in supported browsers and on the final response path.