{"uid":"cap_f0ZyB-o1rOWrNJ_NFdl0d","slug":"x402-data-api-http-security-inspector-2115e70d","name":"X402 Data API – HTTP Security Inspector","description":"Paid x402 API for AI agents that audits HTTP security headers, HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and web security scan findings for a public URL.","url":"https://api.x402dataapi.com/v1/http-security","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","format":"uri","description":"Public http or https URL to inspect"}}},"responseSchema":{"type":"json","example":{"url":"https://example.com","score":80,"status":200,"missing":[]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_vbWXSE3mVufumhXW7gcCC","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes a public URL for HTTP security posture and returns a score, HTTP status, and list of missing security headers or configurations","exampleAgentPrompt":"Can you check the HTTP security posture of https://example.com and tell me its security score and what security headers or configurations it's missing?","exampleUseCases":null,"resultDescription":"Returns a JSON object containing the inspected URL, a numeric security score (0–100), the HTTP status code received, and an array of missing security headers or configurations. Example: {url: 'https://example.com', score: 80, status: 200, missing: []}.","failureModes":["URL is not publicly reachable — endpoint may return an error or low score","Malformed or non-HTTP/HTTPS URL input returns a validation error","Target server is down or returns a non-2xx status, reflected in the status field","Rate limiting or payment failure may block the request","Private or internal IPs may be rejected for security reasons"],"whenToPreferThis":"Use this endpoint when you need a quick, paid-per-request HTTP security audit of a single public URL — especially useful for AI agents that need to programmatically assess web endpoint security posture, check for missing headers like HSTS or CSP, or validate security compliance before proceeding with further actions. Prefer this over manual header inspection tools when you need a structured score and diff of missing configurations.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:35:13.680Z","isFirstParty":false}