{"uid":"cap_Dmf7RccbV7Dl_oSGAHAwx","slug":"sitesignal-http-cache-cors-cookie-policy-inspector-5d843d16","name":"SiteSignal HTTP Cache CORS Cookie Policy Inspector","description":"Inspect one bounded public HTTP response for cache directives, CORS headers, and redacted cookie security attributes.","url":"https://obtain-incentive-exceptions-speakers.trycloudflare.com/x402/http-policy","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","format":"uri"},"origin":{"type":"string","format":"uri","description":"Optional HTTP(S) Origin header to send during the bounded GET."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_EO6zEKlJJUWVBsOTvXMq1","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Inspects a public HTTP URL's response for cache-control directives, CORS headers, and redacted cookie security attributes in a single bounded GET request.","exampleAgentPrompt":"Check the cache headers, CORS policy, and cookie security attributes on https://example.com — do a GET with origin https://myapp.com so I can see if cross-origin requests are allowed and whether any cookies have secure flags.","exampleUseCases":[{"title":"Audit third-party API endpoint security","prompt":"I'm integrating a third-party API at https://api.partner.com/data — can you check their cache-control headers, CORS settings, and cookie flags to make sure they're secure and won't cause issues with my cross-origin requests?"},{"title":"Verify CDN cache policies before migration","prompt":"We're thinking about switching to a new CDN. Can you inspect https://cdn.example.net/assets and tell me what cache directives and CORS policies are in place, plus whether their cookies have the secure and HttpOnly flags set?"},{"title":"Security compliance check for client domains","prompt":"Our compliance team needs me to audit a list of client-facing endpoints. Start with https://client-app.company.com/api — check their cache headers, CORS configuration, and cookie security attributes to document what we're inheriting."}],"resultDescription":"Returns parsed cache-control directives (e.g. max-age, no-store), CORS response headers (Access-Control-Allow-Origin, etc.), and redacted cookie security attribute flags (Secure, HttpOnly, SameSite) observed in the HTTP response from the target URL.","failureModes":["Target URL is unreachable or times out — returns error with connectivity details","URL points to a non-public or authenticated resource — response may lack expected headers","Malformed URL input — returns validation error","Target server returns no cache or CORS headers — result set will be empty for those fields","Rate limiting or blocking by the target server — may return incomplete data"],"whenToPreferThis":"Use this endpoint when you need to audit a specific public URL's HTTP-level security posture around caching, cross-origin resource sharing, and cookie hygiene in a single lightweight call. Prefer it over full site crawlers when you only need response-header policy data for one URL, not content or DNS records.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T15:26:35.463Z","isFirstParty":false}