{"uid":"cap_OGS1MQHadc-xPYbtbYyCo","slug":"sitesignal-http-cache-cors-cookie-policy-bcf20537","name":"SiteSignal HTTP Cache CORS Cookie Policy","description":"Inspect one bounded public HTTP response for cache directives, CORS headers, and redacted cookie security attributes.","url":"https://trinity-throw-thursday-gravity.trycloudflare.com/x402/http-policy","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","format":"uri"},"origin":{"type":"string","format":"uri","description":"Optional HTTP(S) Origin header to send during the bounded GET."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_yS-PLEyep1TiJ40uvd4EM","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Inspects a single public HTTP URL and returns its cache-control directives, CORS headers, and redacted cookie security attributes from the response.","exampleAgentPrompt":"Can you check https://api.example.com/data for its cache-control headers, CORS policy, and any cookie security attributes — do a GET request and tell me what you find?","exampleUseCases":[{"title":"Audit CORS policy before integration","prompt":"I'm about to integrate with https://api.thirdparty.com/v2/feed — can you inspect it with origin https://myapp.com and tell me what CORS headers it returns and whether cross-origin access is allowed?"},{"title":"Verify cookie security on a public page","prompt":"Check https://accounts.example.com/login and tell me what cookie security attributes it sets — I want to know if they're using HttpOnly, Secure, and SameSite correctly."},{"title":"Check caching behavior of a CDN-served asset","prompt":"Can you fetch https://cdn.mybrand.com/static/config.json and report the cache-control and related caching headers so I can tell if it's being cached properly by CDNs?"}],"resultDescription":"Returns parsed HTTP response data including cache-control directives (e.g. max-age, no-store), CORS headers (e.g. Access-Control-Allow-Origin, Access-Control-Allow-Methods), and redacted cookie security attributes (HttpOnly, Secure, SameSite) observed in the bounded GET response from the target URL.","failureModes":["Target URL is unreachable or returns a non-2xx status — may return an error or empty policy data","URL is not a valid HTTP/HTTPS URI — input validation error","Private or firewall-protected URLs will not be accessible from the inspection service","Rate limiting or bot protection on the target may block the request","CORS headers only appear if the target responds to the optional Origin header correctly"],"whenToPreferThis":"Use this endpoint when you need a quick, structured snapshot of a single public URL's HTTP-level security posture — specifically its cache policy, CORS configuration, and cookie security attributes — without needing full TLS or DNS analysis. Prefer this over general HTTP clients when you want parsed, structured output rather than raw headers.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T11:27:22.204Z","isFirstParty":false}