{"uid":"cap_hLKfQI0gODSbOoe_Wphyw","slug":"api-x402node-dev-d4feec06","name":"HTTP Security Headers Audit","description":"Fetch URL and return all HTTP response headers plus security audit (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy). Returns security_score 0-100 and missing headers list. Built for security agents and compliance audits. Use url param Accepts payment on Base or Solana — either network works.","url":"https://api.x402node.dev/web/headers","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"url":{"type":"string","description":"Target URL (optional)"}}}},"additionalProperties":false}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.008","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.008/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_yjj5-D3Ej3m8T2SGMW45h","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.008","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches HTTP response headers for a given URL and returns a security audit including HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, along with a security score (0–100) and list of missing headers.","exampleAgentPrompt":"Can you audit the security headers for https://example.com and tell me the security score, which headers are missing, and whether HSTS and CSP are properly configured?","exampleUseCases":null,"resultDescription":"Returns all HTTP response headers from the target URL, a security_score between 0 and 100, and a list of missing security headers from the standard set: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.","failureModes":["Invalid or unreachable URL returns an error with no headers or score","Timeout if the target server is slow to respond","Non-HTTPS URLs may lack HSTS by design, reflected in low score","Redirects may result in headers from the final destination, not the original URL"],"whenToPreferThis":"Use this endpoint when you need a quick, automated security header audit for any public URL, especially for compliance checks, security reviews, or when building dashboards that track header hygiene across multiple sites. Prefer this over manual browser inspection or full vulnerability scanners when you only need header-level analysis.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:57:07.372Z","isFirstParty":false}