HTTP Response Headers Inspector

Check HTTP status codes (200, 301, 404), server technologies, compression, and security headers (CSP, HSTS).

📑

HTTP Response for upwork.com

HTTP/1.1 403 Forbidden
Header Field Value
Status HTTP/1.1 403 Forbidden
Date Tue, 06 Oct 2026 21:11:16 GMT
Content-Type text/html; charset=UTF-8
Content-Length 344322
Connection close
Accept-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cf-Mitigated challenge
X-Frame-Options SAMEORIGIN
Server cloudflare
Critical-Ch Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
Cross-Origin-Embedder-Policy require-corp
Cross-Origin-Opener-Policy same-origin
Cross-Origin-Resource-Policy same-origin
Origin-Agent-Cluster ?1
Permissions-Policy accelerometer=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=(),xr-spatial-tracking=*
Referrer-Policy same-origin
Server-Timing chlray;desc="a467a8599be1052e"
X-Content-Type-Options nosniff
Strict-Transport-Security max-age=31536000; includeSubDomains; preload
set-cookie __cf_bm=5QP.9XQGL9Y6a4VywVMak1fqib72bpjHuJcQkKYevAQ-1791321076.732064-1.0.1.1-7PbzzrQYchwJonX.Y1vd00zivjrH85cdZ5XoMBFWEusz1PZNMRmotxmHMYt9W7VD9aepFuByPKeN3t3fpx_wbeNWLndkeH9OJONaOSg3Gn_30Qd6FHGsUaDoDCNezboz; HttpOnly; SameSite=None; Secure; Path=/; Domain=upwork.com; Expires=Tue, 06 Oct 2026 21:41:16 GMT
CF-RAY a467a8599be1052e-DEL
alt-svc h3=":443"; ma=86400