{"uid":"cap_Pk44K_mKKx5zEA9Uv_RGG","slug":"sitesignal-security-txt-policy-snapshot-a4ef2129","name":"SiteSignal Security.txt Policy Snapshot","description":"Discover and parse a public RFC 9116 security.txt policy into contacts, expiry, policy, encryption, canonical, hiring, extension, HTTP, and hash evidence.","url":"https://trinity-throw-thursday-gravity.trycloudflare.com/x402/security-txt","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","format":"uri"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_KUZfpwN5HfLvvOYmJ5zN_","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches and parses the RFC 9116 security.txt file from a given public URL, extracting contacts, expiry, policy, encryption keys, canonical URLs, hiring links, extensions, HTTP metadata, and hash evidence.","exampleAgentPrompt":"Can you fetch and parse the security.txt policy for https://example.com and tell me who to contact for vulnerability disclosures, when the policy expires, and whether there's a PGP encryption key listed?","exampleUseCases":[{"title":"Vendor security contact lookup","prompt":"Before we onboard this vendor, can you pull the security.txt from https://vendor.example.com and tell me their responsible disclosure contact, policy URL, and whether their security.txt has expired?"},{"title":"Bug bounty program discovery","prompt":"I want to report a vulnerability — can you check the security.txt at https://bugbounty-target.com and find out if they have a bug bounty or disclosure policy listed, along with any encryption key I should use?"},{"title":"RFC 9116 compliance audit","prompt":"Can you inspect the security.txt at https://mycompany.io and check whether it follows RFC 9116 — specifically whether it has a valid expiry date, canonical URL, and contact field?"}],"resultDescription":"Returns a structured snapshot of the parsed security.txt file including: contact addresses (email, phone, URL), expiry timestamp, security policy URL, PGP or other encryption key references, canonical URL, hiring links, any extension fields, relevant HTTP response headers, and hash evidence for integrity verification.","failureModes":["No security.txt file found at the target URL (404 or missing well-known path)","security.txt exists but is malformed or does not conform to RFC 9116","Expired security.txt policy (past the Expires field date)","Target URL is unreachable or returns a non-200 HTTP status","Invalid or non-URI input URL causes schema validation failure","HTTPS-only requirement not met if target serves over HTTP only"],"whenToPreferThis":"Use this endpoint when you need to programmatically discover who is responsible for security disclosures at a given domain, verify RFC 9116 compliance, or extract structured security policy metadata without manually browsing to /.well-known/security.txt. Prefer this over generic web scrapers when you specifically need security.txt fields like contacts, expiry, PGP keys, and policy URLs in a structured, parsed format.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T08:28:03.017Z","isFirstParty":false}