How to use the API Response Diff
- Copy each response from curl -i, Postman, Insomnia or your browser's Network tab, including the status line and headers if you have them.
- Paste one response on each side, or just the bodies. Optionally give each side a name such as Production and Staging.
- Choose what to compare and which headers or body fields to ignore.
- Review the status, header and body differences, then copy or download the Markdown report for a ticket or pull request.
What does this tool do?
When an endpoint behaves differently between environments or versions, the answer is usually in one of three places: the status code, a header such as Cache-Control or Content-Type, or a field deep in the body. This tool reads raw HTTP responses — it understands the status line, header block and body, and skips interim responses such as 100 Continue or redirects in curl output — and compares each part separately.
Header names are compared case-insensitively and repeated headers are combined, as HTTP specifies. Headers that change on every request — Date, Age, ETag, request and trace IDs, rate-limit counters and similar — are ignored by default so they don't drown out real differences. JSON bodies are compared structurally with the same engine as JSON Diff; other bodies (HTML, XML, plain text) are compared line by line.
It's a comparison of responses you paste, not a live API tester: it never contacts your API, needs no key, and works offline once the page has loaded.
Why use it?
- Status, headers and body compared in one report.
- Accepts raw curl -i output, including multiple header blocks.
- Noise filters for dates, request IDs and other per-request headers.
- Markdown report ready to paste into an issue or pull request.
Use cases
- Confirm that staging returns the same response as production before a release.
- Spot breaking changes between API versions (v1 vs v2).
- Debug caching problems by comparing Cache-Control, Vary and ETag headers.
- Compare a third-party API's response today with a saved snapshot.
Example
The built-in example compares the same user endpoint on two API versions. With the default settings the report shows: Cache-Control changed from max-age=60 to no-store, X-Api-Version changed, $.user.role changed from "admin" to "editor", $.user.email removed, $.user.avatarUrl added, $.permissions[2] ("delete") removed and $.meta.cached changed. The Date and X-Request-Id headers are ignored automatically; add requestId to the body ignore list to hide $.meta.requestId as well.
Accuracy and limits
- Only what you paste is compared. Bodies that are compressed or binary must be decoded first (curl does this with --compressed).
- Status codes come from the status line; if you paste bodies only, type the codes into the Status boxes to compare them.
- Everything runs in your browser. No request is sent and nothing you paste is uploaded or stored.
Privacy
Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.
Frequently asked questions
Does this tool call my API?
No. It only compares responses you paste or open from a file. That keeps tokens and private data on your device and means it works with internal APIs that aren't reachable from the internet.
How do I copy a full response?
With curl, use curl -i https://… to include the status line and headers. In Chrome or Firefox dev tools, open the request in the Network tab, copy the response headers and the response body, and paste them with a blank line between them.
Which headers are ignored by default?
Headers that differ on every request: Date, Age, Expires, Last-Modified, ETag, Set-Cookie, Content-Length, request and trace IDs (X-Request-Id, traceparent, CF-Ray, X-Amzn-Trace-Id…), timing headers and rate-limit counters. Untick the option to compare them too.
What if a body isn't JSON?
It's compared line by line instead, and the report says why — for example, if one side is an HTML error page.
Last reviewed by the M2Toolkit team.