{"uid":"cap_KyBH0nnaUviJFNAcFCGoB","slug":"sentinel-security-header-inspector-299aeac2","name":"Sentinel Security Header Inspector","description":"Response headers and security-header report for a URL","url":"https://sentinel.rootstuff.io/x402/headers","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","description":"The http(s) URL to request. Public hosts only."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_IfPAhTpXS7IqdvNLa3IJU","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches response headers from a URL and reports on the presence and quality of HTTP security headers","exampleAgentPrompt":"Can you pull the response headers for https://example.com and tell me which security headers like Content-Security-Policy, Strict-Transport-Security, and X-Frame-Options are missing or misconfigured?","exampleUseCases":[{"title":"Security audit before launch","prompt":"Before we go live, can you check the security headers on https://staging.myapp.com and tell me which important ones like CSP, HSTS, and X-Content-Type-Options are missing?"},{"title":"Compliance check for partner API","prompt":"I need to verify that our partner's API at https://api.partner-service.com returns the right security headers — can you fetch and report on what they're sending?"},{"title":"Spot-check competitor website headers","prompt":"What security headers is https://www.competitorsite.com returning? I want to see if they have Content-Security-Policy and HSTS configured."}],"resultDescription":"Returns the full set of HTTP response headers received from the target URL, along with a security-focused report highlighting which security headers (e.g. Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) are present, absent, or misconfigured.","failureModes":["Private or non-public hosts rejected — only public HTTP/HTTPS URLs are supported","Target URL is unreachable or returns a network error — endpoint may return an error or empty header set","URL is malformed or missing scheme — input validation failure","Target returns a redirect that resolves to a non-public host — may be blocked","Rate limiting if called excessively against the same host"],"whenToPreferThis":"Choose this endpoint when you need a quick, paid-per-call security header inspection of a specific URL without setting up your own HTTP client — especially useful in agent workflows that need to audit web properties, verify compliance, or report on header posture as part of a broader security check. Prefer over manual fetching when you want a structured report on security headers specifically, not just raw header values.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:47:00.755Z","isFirstParty":false}