{"uid":"cap__m6uxrhxW3XCwmda2hjWs","slug":"api-trustsource-cc-99e608dc","name":"TrustSource HTTP Security Headers Analyzer","description":"Audit a site's HTTP security headers before embedding, scraping, or trusting it. Returns an A+ to F grade and 0–100 score with structured analysis of HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and Cross-Origin headers, plus server-header disclosure. A defense-in-depth signal for agents reviewing a site's security posture — not a vulnerability scan.","url":"https://api.trustsource.cc/headers","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["url"],"properties":{"url":{"type":"string","description":"Full URL including scheme to audit (e.g. https://example.com). Follows up to 3 re-validated redirects."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"url":"https://example.com"}}},"response":{"url":"https://example.com/","meta":{"cached":false,"paidWith":"x402/USDC","checkedAt":"2026-06-10T04:32:21.197Z","apiVersion":"1.0"},"grade":"F","score":8,"analysis":{"csp":{"notes":["missing"],"score":0,"value":null,"present":false,"maxScore":20},"coop":{"notes":["missing"],"score":0,"value":null,"present":false,"maxScore":10},"hsts":{"notes":["missing"],"score":0,"value":null,"present":false,"maxScore":20},"xFrameOptions":{"notes":["missing"],"score":0,"value":null,"present":false,"maxScore":10},"referrerPolicy":{"notes":["missing"],"score":0,"value":null,"present":false,"maxScore":10},"serverDisclosure":{"notes":["server_disclosed"],"score":8,"value":"cloudflare","present":true,"maxScore":10},"permissionsPolicy":{"notes":["missing"],"score":0,"value":null,"present":false,"maxScore":10},"xContentTypeOptions":{"notes":["missing"],"score":0,"value":null,"present":false,"maxScore":10}},"hostname":"example.com","maxScore":100,"response":{"status":200,"redirects":0},"warnings":["missing_hsts","missing_csp","missing_xFrameOptions","missing_xContentTypeOptions","missing_referrerPolicy","missing_permissionsPolicy","missing_coop","serverDisclosure:server_disclosed"]}},"exampleRequest":{"url":"https://example.com"},"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_cA6DdeO5PeWH3V7QQ352f","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes HTTP security headers for a given URL and returns a letter grade (A+ to F), a 0–100 score, and structured findings for HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, and server header disclosure.","exampleAgentPrompt":"Can you check the HTTP security headers for https://example.com and tell me what grade it gets, whether HSTS and CSP are properly set, and if the server is leaking version info?","exampleUseCases":null,"resultDescription":"Returns a letter grade (A+ to F), a numeric score from 0 to 100, and a structured breakdown of each security header: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, and whether the server header discloses software details.","failureModes":["Invalid or unreachable URL returns an error response","URL missing scheme (http/https) may cause parsing failure","Rate limiting or payment failure results in 402 response","Target site blocking HEAD/GET requests may yield incomplete header data"],"whenToPreferThis":"Use this endpoint when you need a structured, graded audit of HTTP security response headers for a specific URL — especially useful for security posture reviews, compliance checks, or automated site audits where you want actionable findings on missing or misconfigured headers like HSTS, CSP, or X-Frame-Options.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":1,"lastUsedAt":"2026-08-12T11:20:22.660Z","lastSuccessfullyRanAt":"2026-08-12T11:20:22.660Z","lastHealthCheckAt":"2026-09-15T06:31:34.436Z","isFirstParty":false}