{"uid":"cap_0oFNbhC-Trcp0oB7hExbf","slug":"website-trust-report-0df4db2f","name":"Website Trust Report","description":"website trust report from a direct HTTPS fetch: status, response headers, HSTS, CSP and clickjacking protection signals.","url":"https://relay402.georgespring.workers.dev/api/web-website-trust-report","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["domain"],"properties":{"domain":{"type":"string","pattern":"^[a-z0-9]([a-z0-9.-]{2,251})[a-z0-9]$"}},"additionalProperties":false}},"additionalProperties":false}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_sJlMS4NVo2SkIlhNx2BF-","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a domain's HTTPS response and returns security posture signals including HTTP status, response headers, HSTS, CSP, and clickjacking protection.","exampleAgentPrompt":"Can you run a trust report on stripe.com and tell me whether it has HSTS, a Content Security Policy, and clickjacking protection set up correctly?","exampleUseCases":[{"title":"Vetting a vendor website before integration","prompt":"Before we integrate with acmepayments.io, can you check their website's security headers — specifically whether they have HSTS and CSP configured, and if there's any clickjacking risk?"},{"title":"Pre-send domain check for outreach campaigns","prompt":"I'm about to send a batch of emails linking to partnerbrand.com — can you pull a trust report on that domain and tell me if it looks properly secured with HTTPS headers?"},{"title":"Security audit of client website","prompt":"My client just launched clientsite.net — can you fetch a trust report and flag any missing security headers like HSTS or Content Security Policy that I should tell them to fix?"}],"resultDescription":"Returns HTTP status code, full response headers, HSTS policy presence and configuration, Content Security Policy (CSP) header details, and clickjacking protection signals (X-Frame-Options or frame-ancestors CSP directive) obtained via a live HTTPS fetch to the target domain.","failureModes":["Invalid or malformed domain name returns a validation error","Domain is unreachable or times out — no response headers returned","Domain uses HTTP only (no HTTPS) — HSTS and related signals will be absent or negative","Rate limits or payment failures result in a 402 or 429 error","Domains with non-standard ports or paths may not be supported by the domain-only input schema"],"whenToPreferThis":"Choose this endpoint when you need a live, real-time HTTPS fetch of a domain's security headers — especially HSTS, CSP, and clickjacking signals — rather than passive DNS or certificate checks. It complements sibling endpoints like SSL certificate info (CT-based) and domain threat report (DNS-based) by providing direct HTTP-layer evidence of security posture.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:46:55.151Z","isFirstParty":false}