{"uid":"cap_3SMb9f4PZE1YHQCo2OYgv","slug":"domain-hugen-tokyo-ea0b5cdd","name":"Security Header Audit API","description":"Security header audit — 10 headers checked: CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection, CORP, COEP, COOP. Information leakage detection via Server/X-Powered-By headers. A-F security grade. Accepts USDC payments on Base and Solana","url":"https://domain.hugen.tokyo/domain/headers","method":"GET","headers":{},"bodySchema":{"properties":{"input":{"required":["method"]}}},"responseSchema":null,"example":{"request":{"domain":"example.com"},"response":{"grade":"F","domain":"example.com","status_code":200,"url_checked":"http://172.66.147.243","headers_total":10,"headers_present":0,"security_headers":{"Referrer-Policy":{"value":null,"present":false,"description":"Controls referrer information"},"X-Frame-Options":{"value":null,"present":false,"description":"Prevents clickjacking"},"X-XSS-Protection":{"value":null,"present":false,"description":"XSS filter (legacy)"},"Permissions-Policy":{"value":null,"present":false,"description":"Controls browser features"},"X-Content-Type-Options":{"value":null,"present":false,"description":"Prevents MIME type sniffing"},"Content-Security-Policy":{"value":null,"present":false,"description":"Controls resources the browser can load"},"Strict-Transport-Security":{"value":null,"present":false,"description":"Enforces HTTPS connections"},"Cross-Origin-Opener-Policy":{"value":null,"present":false,"description":"Controls cross-origin window access"},"Cross-Origin-Embedder-Policy":{"value":null,"present":false,"description":"Controls cross-origin embedding"},"Cross-Origin-Resource-Policy":{"value":null,"present":false,"description":"Controls cross-origin resource sharing"}},"information_leakage":{"server":"cloudflare"}}},"exampleRequest":{"domain":"example.com"},"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_DS7BQnZMB3GXypZ-I0Sm7","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a domain's HTTP security headers across 10 vectors and assigns an A-F security grade with information leakage detection","exampleAgentPrompt":"Can you run a full security header audit on example.com and tell me the grade it gets — especially whether it has CSP, HSTS, and X-Frame-Options set, and if the server is leaking any technology info?","exampleUseCases":null,"resultDescription":"Returns the status of 10 security headers (CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection, CORP, COEP, COOP), information leakage findings from Server and X-Powered-By headers, and an overall A-F security grade for the domain.","failureModes":["Domain does not exist or is unreachable — returns error or partial result","Domain blocks external HTTP requests — headers may not be retrievable","Payment not processed — 402 response requiring USDC payment on Base or Solana","Invalid domain format — request rejected","Timeout on slow-responding domain — partial or empty header results"],"whenToPreferThis":"Use this endpoint when you need a fast, structured audit of a single domain's HTTP security posture with a letter grade. It is ideal for security compliance checks, pre-launch audits, or monitoring header regressions. Prefer it over manual curl-based checks or full-stack scanners when you specifically want header analysis with grading and information leakage detection in a single lightweight API call.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:34:48.903Z","isFirstParty":false}