{"uid":"cap_XlqbHEQesTJ952BGUkKzb","slug":"sitesignal-security-txt-policy-snapshot-789215b7","name":"SiteSignal Security.txt Policy Snapshot","description":"Discover and parse a public RFC 9116 security.txt policy into contacts, expiry, policy, encryption, canonical, hiring, extension, HTTP, and hash evidence.","url":"https://phases-prot-shine-royal.trycloudflare.com/x402/security-txt","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","format":"uri"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_IDilnSyqPueK_bwPdcyaq","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches and parses a public RFC 9116 security.txt file from any URL, extracting contacts, expiry, policy, encryption, canonical, hiring, extension, HTTP, and hash evidence.","exampleAgentPrompt":"Can you fetch and parse the security.txt policy for https://example.com — I want to see the security contacts, expiry date, encryption key, and any policy or hiring URLs listed there.","exampleUseCases":[{"title":"Bug bounty contact lookup","prompt":"Pull the security.txt for https://stripe.com and tell me who to contact to report a vulnerability, including any PGP encryption key and the policy URL."},{"title":"Security policy expiry audit","prompt":"Check the security.txt at https://github.com and let me know when their security policy expires and whether it's still valid."},{"title":"Responsible disclosure setup check","prompt":"Fetch the security.txt from https://mozilla.org and show me all the details — contacts, canonical URL, hiring info, and any extensions listed in the file."}],"resultDescription":"A structured snapshot of the parsed security.txt file including: security contact addresses (email, URL), policy expiration timestamp, linked security policy URL, PGP encryption key or URL, canonical URL for the security.txt itself, hiring/acknowledgment URLs, any extension fields, raw HTTP response evidence, and hash verification data — all sourced and linked back to the original document.","failureModes":["Target site does not host a security.txt file — returns empty or not-found result","security.txt exists but is malformed or non-RFC-9116-compliant — partial parse with available fields","URL is unreachable or returns non-200 HTTP status — fetch error with HTTP status code","Security.txt is expired — parsed but flagged as expired policy","Redirects or non-standard locations may cause the file to be missed"],"whenToPreferThis":"Use this endpoint when you need to programmatically discover responsible disclosure contacts, encryption keys, or policy details for a public website by parsing its RFC 9116 security.txt. Prefer this over manual DNS lookups or generic scrapers when you specifically need structured security policy data including expiry, contacts, and hash evidence in a single call.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T09:27:06.236Z","isFirstParty":false}