HTTP Headers Viewer for www.facebook.com

View all HTTP response headers returned by any URL.

Results for www.facebook.com
Checked: Aug 25, 2026 at 01:55 UTC
{ "success": true, "url": "https:\/\/www.facebook.com", "status": 200, "headers": { "vary": "Accept-Encoding", "set-cookie": "sb=BfaMajbMFqRsEYZOhHkp14ab; expires=Wed, 29-Sep-2027 01:55:17 GMT; Max-Age=34560000; path=\/; domain=.facebook.com; secure; httponly", "accept-ch-lifetime": "4838400", "accept-ch": "viewport-width,dpr,Sec-CH-Prefers-Color-Scheme,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Model", "reporting-endpoints": "coop_report=\"https:\/\/www.facebook.com\/browser_reporting\/coop\/?minimize=0\", default=\"https:\/\/www.facebook.com\/ajax\/browser_error_reports\/?device_level=unknown&brsid=7677781967077667904&cpp=C3&cv=1045929245&st=1787622917572\", permissions_policy=\"https:\/\/www.facebook.com\/ajax\/browser_error_reports\/\"", "report-to": "{\"max_age\":2592000,\"endpoints\":[{\"url\":\"https:\\\/\\\/www.facebook.com\\\/browser_reporting\\\/coop\\\/?minimize=0\"}],\"group\":\"coop_report\",\"include_subdomains\":true}, {\"max_age\":259200,\"endpoints\":[{\"url\":\"https:\\\/\\\/www.facebook.com\\\/ajax\\\/browser_error_reports\\\/?device_level=unknown&brsid=7677781967077667904&cpp=C3&cv=1045929245&st=1787622917572\"}]}, {\"max_age\":21600,\"endpoints\":[{\"url\":\"https:\\\/\\\/www.facebook.com\\\/ajax\\\/browser_error_reports\\\/\"}],\"group\":\"permissions_policy\"}", "content-security-policy": "default-src blob: 'self' https:\/\/*.fbsbx.com *.facebook.com *.fbcdn.net *.facebook.net *.whatsapp.com *.whatsapp.net;script-src *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* 'nonce-B6ay5EDJ' blob: 'self' connect.facebook.net 'unsafe-eval' https:\/\/accounts.google.com https:\/\/*.google-analytics.com *.google.com;style-src *.fbcdn.net data: *.facebook.com 'unsafe-inline' https:\/\/accounts.google.com https:\/\/fonts.googleapis.com;connect-src *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss:\/\/*.facebook.com:* wss:\/\/*.whatsapp.com:* wss:\/\/*.fbcdn.net attachment.fbsbx.com ws:\/\/localhost:* blob: *.cdninstagram.com 'self' http:\/\/localhost:3103 wss:\/\/gateway.facebook.com wss:\/\/edge-chat.facebook.com wss:\/\/snaptu-d.facebook.com wss:\/\/kaios-d.facebook.com\/ v.whatsapp.net *.fbsbx.com *.fb.com *.instagram.com *.ipification.com https:\/\/accounts.google.com https:\/\/*.google-analytics.com;font-src data: *.facebook.com *.fbcdn.net *.fbsbx.com https:\/\/fonts.gstatic.com;img-src *.fbcdn.net *.facebook.com data: https:\/\/*.fbsbx.com facebook.com *.cdninstagram.com fbsbx.com fbcdn.net connect.facebook.net blob: android-webview-video-poster: *.whatsapp.net *.fb.com *.oculuscdn.com *.tenor.co *.tenor.com *.giphy.com https:\/\/trustly.one\/ https:\/\/*.trustly.one\/ https:\/\/paywithmybank.com\/ https:\/\/*.paywithmybank.com\/ https:\/\/www.googleadservices.com https:\/\/googleads.g.doubleclick.net https:\/\/*.google-analytics.com;media-src *.cdninstagram.com blob: *.fbcdn.net *.fbsbx.com www.facebook.com *.facebook.com data: *.tenor.co *.tenor.com https:\/\/*.giphy.com;child-src data: blob: 'self' https:\/\/*.fbsbx.com *.facebook.com *.fbcdn.net;frame-src *.facebook.com *.fbsbx.com fbsbx.com data: www.instagram.com *.fbcdn.net accounts.meta.com *.accounts.meta.com *.fbthirdpartypixel.com *.ipification.com https:\/\/trustly.one\/ https:\/\/*.trustly.one\/ https:\/\/paywithmybank.com\/ https:\/\/*.paywithmybank.com\/ https:\/\/www.googleadservices.com https:\/\/googleads.g.doubleclick.net https:\/\/www.google.com https:\/\/td.doubleclick.net *.google.com *.doubleclick.net;manifest-src data: blob: 'self' https:\/\/*.fbsbx.com *.facebook.com *.fbcdn.net;object-src data: blob: 'self' https:\/\/*.fbsbx.com *.facebook.com *.fbcdn.net;worker-src blob: *.facebook.com data:;block-all-mixed-content;upgrade-insecure-requests;", "x-frame-options": "DENY", "document-policy": "include-js-call-stacks-in-crash-reports", "permissions-policy": "accelerometer=(), attribution-reporting=(self), autoplay=(), bluetooth=(), browsing-topics=(self), camera=(self \"https:\/\/www.fbsbx.com\"), ch-device-memory=(), ch-downlink=(), ch-dpr=(), ch-ect=(), ch-rtt=(), ch-save-data=(), ch-ua-arch=(), ch-ua-bitness=(), ch-viewport-height=(), ch-viewport-width=(), ch-width=(), clipboard-read=(self), clipboard-write=(self), compute-pressure=(), display-capture=(self), encrypted-media=(self), fullscreen=(self), gamepad=*, geolocation=(self), gyroscope=(), hid=(), idle-detection=(), interest-cohort=(self), keyboard-map=(), local-fonts=(), magnetometer=(), microphone=(self), midi=(), otp-credentials=(), payment=(), picture-in-picture=(self), private-state-token-issuance=(), publickey-credentials-get=(self), screen-wake-lock=(), serial=(), shared-storage=(), shared-storage-select-url=(), private-state-token-redemption=(), usb=(), unload=(self), window-management=(), xr-spatial-tracking=(self);report-to=\"permissions_policy\"", "cross-origin-resource-policy": "same-origin", "cross-origin-opener-policy": "unsafe-none", "pragma": "no-cache", "cache-control": "private, no-cache, no-store, must-revalidate", "expires": "Sat, 01 Jan 2000 00:00:00 GMT", "x-content-type-options": "nosniff", "x-xss-protection": "0", "origin-agent-cluster": "?1", "strict-transport-security": "max-age=15552000; preload", "content-type": "text\/html; charset=\"utf-8\"", "x-fb-debug": "GIEhE4ps0JVZ2DnpsoS+gqucnDo3I0BUq2fIOMOatZ5B39kOhvrOi1fAu1sx8Lgc4ciSbCZ34mjYj9l8NEThvg==", "date": "Tue, 25 Aug 2026 01:55:17 GMT", "x-fb-connection-quality": "EXCELLENT; q=0.9, rtt=5, rtx=0, c=10, mss=1380, tbw=3803, tp=-1, tpl=-1, uplat=166, ullat=0", "alt-svc": "h3=\":443\"; ma=86400", "server-timing": "slb_crtt;dur=5,slb_srtt;dur=-1,slb_req_start;dur=1787622917527617,slb_srv_hdr_rcvd;dur=166126,slb_cli_body_rcvd_first;dur=-1,slb_cli_body_rcvd_last;dur=-1,slb_conn_lat;dur=0,slb_ssl;dur=26,slb_rule_lat;dur=0" } }

What is HTTP Headers Viewer?

HTTP Headers Viewer displays all response headers returned by any URL. Headers control caching, security, content type, redirects, and more. Essential for debugging server configuration and verifying security headers are properly set.

How to use this tool

  1. Enter the URL to inspect.
  2. Click Check to send a request and capture response headers.
  3. Review each header and its value.
  4. Check for security headers like HSTS, CSP, X-Frame-Options.
  5. Verify caching headers (Cache-Control, Expires) are set correctly.

Frequently asked questions

What are the most important security headers?
Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Content-Type-Options, X-Frame-Options, and Referrer-Policy. These protect against XSS, clickjacking, and MIME-type attacks.
What does Cache-Control do?
Tells browsers and CDNs how long to cache the response. max-age=3600 means cache for one hour. no-cache means revalidate every time. Proper caching dramatically improves page speed.
What is HSTS?
HTTP Strict Transport Security forces browsers to always use HTTPS for your domain. Once set, even typing http:// loads HTTPS. Use max-age of at least 31536000 (one year).
How do I add security headers?
In Nginx: add_header directive. In Apache: Header set in .htaccess. In Caddy: header directive. Most CDNs like Cloudflare also let you set headers in their dashboard.

Recently checked

See all 14 lookups →

Related tools

Need a place to build your project?

Launch a cloud workspace with Claude Code. Your AI builds it, we host it.

Start for $5/month