{"uid":"cap_PjvnWslDVwfu8SmxggUCB","slug":"http-security-policy-inspector-3563b1e1","name":"HTTP Security Policy Inspector","description":"Inspect one bounded public HTTP response for cache directives, CORS headers, and redacted cookie security attributes.","url":"https://holder-victor-nova-mag.trycloudflare.com/x402/http-policy","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","format":"uri"},"origin":{"type":"string","format":"uri","description":"Optional HTTP(S) Origin header to send during the bounded GET."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_0mctnYeKxiTbaLWtMS-oY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a bounded public HTTP response and inspects its cache directives, CORS headers, and redacted cookie security attributes.","exampleAgentPrompt":"Can you check https://api.example.com/data for its CORS headers, cache directives, and any cookie security flags — use a GET request and simulate the origin https://myapp.example.com?","exampleUseCases":null,"resultDescription":"A structured report detailing the cache-control directives, CORS response headers (e.g. Access-Control-Allow-Origin, Access-Control-Allow-Methods), and redacted cookie security attributes (e.g. Secure, HttpOnly, SameSite) observed in the bounded HTTP response from the specified public URL.","failureModes":["URL is not publicly accessible or requires authentication — returns error","URL is not valid HTTP/HTTPS — validation error on input","Target server does not respond within bounded time limit — timeout error","URL returns a non-200 status — response may still be analyzed but flagged","Origin header ignored by target server — CORS fields may be absent in result"],"whenToPreferThis":"Use this endpoint when you need a quick, bounded inspection of HTTP-level security policy signals — specifically cache directives, CORS configuration, and cookie security attributes — for a single public URL without triggering side effects. Prefer this over general HTTP probing endpoints when the specific goal is security/policy header analysis rather than content extraction or redirect tracing.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:25:44.158Z","isFirstParty":false}