{"uid":"cap_NDCf0BIXqmMx0t_1nHuRV","slug":"papacasper-security-headers-audit-a8810735","name":"PapaCasper Security Headers Audit","description":"A hosted MCP server exposing utility tools any AI agent can call over HTTP — page-to-markdown, SEO audits, robots/sitemap checks, and more.","url":"https://papacasper.com/mcp/pay/security_headers_audit","method":"POST","headers":{},"bodySchema":{"type":"object","required":["url"],"properties":{"url":{"type":"string","description":"The URL to audit"}}},"responseSchema":{"type":"object"},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_RLAZQWNzk8zhuFunOngtC","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a given URL's HTTP security headers and returns a structured report of their presence, configuration, and any issues found.","exampleAgentPrompt":"Can you run a security headers audit on https://example.com and tell me which headers are missing or misconfigured?","exampleUseCases":[{"title":"Pre-launch security checklist","prompt":"Before we go live with our new site at https://myapp.io, can you audit its HTTP security headers and flag anything critical that's missing?"},{"title":"Competitor security comparison","prompt":"Run a security headers audit on https://competitor-site.com — I want to see how their header config stacks up."},{"title":"Catch CSP misconfigurations","prompt":"Check the security headers on https://staging.mycompany.com and tell me if Content-Security-Policy and X-Frame-Options are properly set."}],"resultDescription":"A structured object reporting which HTTP security headers (e.g. Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) are present or absent, their current values, and any detected misconfigurations or recommendations.","failureModes":["Invalid or unreachable URL returns an error with no audit data","Target server blocks automated requests or returns non-standard responses, leading to incomplete results","Payment failure via x402 protocol halts the request before processing","Timeout if the target URL is slow to respond","Redirects or unusual HTTP configurations may affect header detection accuracy"],"whenToPreferThis":"Use this endpoint when you need a quick, automated audit of a single URL's HTTP security headers without setting up a full security scanning pipeline. It is ideal for pre-launch checks, compliance reviews, or spot-checking competitor or third-party sites. It is more cost-effective and faster than full vulnerability scanners when you only care about header-level security posture.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:49:02.616Z","isFirstParty":false}