Before you start
What you need
Raw HTTP response or request header lines copied from an authorized source.
Developer & Data
Parse pasted HTTP headers and review common delivery, cache, and browser-policy controls.
No black box
The parser normalizes names, preserves values, and reports the presence of common security and delivery controls without making a request.
Before you start
Raw HTTP response or request header lines copied from an authorized source.
What you get
A JSON inventory, common-control presence checks, cache facts, and content type.
Keep in mind
Header presence is not proof that a policy is correct. Values must be reviewed for the specific route, browser, proxy, and threat model.
Practical uses
Verified data boundary
The published contract marks these tools as client-only processing. Nirmion uses the API only to confirm that this workspace is enabled in MySQL; source values and results are not sent to Flask.