{"uid":"cap_dshtBXv74Y6u6DSQmebnW","slug":"hergert-synthora-http-security-headers-audit-d23ef504","name":"HERGERT SYNTHORA HTTP Security Headers Audit","description":"SYNTHORA headers-audit: HTTP security headers + TLS audit for any URL — missing headers, score 0-100, cookie flags. $0.005 USDC x402 Base.","url":"https://api.hergertsynthora.com/v1/headers-audit","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"input":{"type":"string","description":"SYNTHORA headers-audit: HTTP security headers + TLS audit for any URL — missing headers, score 0-100, cookie flags. $0.005 USDC x402 Base."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_eVeE6AtAm2YTt_1SvrqFo","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a URL's HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type, Referrer-Policy, Permissions-Policy, CORS) plus cookie hygiene across 10 security checks","exampleAgentPrompt":"Can you run a full HTTP security headers audit on https://www.mycompany.com — I want to know if we're missing HSTS, CSP, X-Frame-Options, cookie hygiene issues, CORS, and the rest of the 10 security checks?","exampleUseCases":[{"title":"Pre-launch security header check","prompt":"Before we go live, can you audit the security headers on https://staging.myapp.io — I need to know if we're missing HSTS, CSP, or any cookie flags like HttpOnly and SameSite?"},{"title":"Compliance audit for client website","prompt":"My client at https://www.clientportal.com needs a security header report — run all 10 checks including X-Frame-Options, Referrer-Policy, Permissions-Policy, and CORS hygiene and tell me what's failing."},{"title":"Ongoing security posture check","prompt":"Can you check whether https://api.myservice.com has proper CORS headers and that cookies are set with Secure and SameSite attributes? I want to make sure nothing regressed after the last deploy."}],"resultDescription":"Returns a JSON object with ok status, niche identifier ('headers_audit'), a result object containing pass/fail status for each of the 10 security checks (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, CORS, and cookie Secure/HttpOnly/SameSite flags), and a payment receipt.","failureModes":["Invalid or unreachable URL returns an error with no audit results","Malformed input string causes a validation error","Target site blocks the auditor's requests resulting in incomplete header data","Payment failure or insufficient USDC balance prevents the call from completing","Timeout if the target URL responds too slowly"],"whenToPreferThis":"Choose this endpoint when you need a comprehensive, automated HTTP security headers audit covering all major security headers and cookie hygiene in a single API call, especially for web security compliance checks, pre-launch reviews, or ongoing monitoring pipelines. Prefer it over manual header inspection or generic curl-based checks when you need structured, machine-readable results across 10 standardized security checks.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:57:25.516Z","isFirstParty":false}