{"uid":"cap_jVLu4CAvvn5bWINADkuVa","slug":"pennyrail-security-headers-checker-f69464ab","name":"PennyRail Security Headers Checker","description":"Machine-readable settlement service","url":"https://pennyrail.vercel.app/api/p/network/web.http-headers--security-headers","method":"POST","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object"}}},"responseSchema":{"type":"object","additionalProperties":true},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_xgAJ6xs2ASENqn-iSdczH","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches and analyzes HTTP security headers for a given web resource via a paid settlement endpoint","exampleAgentPrompt":"Can you check what HTTP security headers example.com is sending back — I want to know if they have things like CSP, HSTS, and X-Frame-Options set correctly?","exampleUseCases":[{"title":"Security audit of a client website","prompt":"Run a security header check on my client's site at shop.acmecorp.com — I need to know if they're missing any important headers like Content-Security-Policy or Strict-Transport-Security before I write my audit report."},{"title":"Pre-launch compliance check","prompt":"Before we go live, can you pull the HTTP security headers for staging.myapp.io and tell me which protective headers are present and which ones are missing?"},{"title":"Competitive security benchmarking","prompt":"Check what security headers competitor.com is using — I want to compare their header setup against industry best practices for X-Frame-Options, CSP, and HSTS."}],"resultDescription":"Returns the HTTP response headers from the target web resource, with a focus on security-relevant headers such as Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, enabling analysis of the site's security posture.","failureModes":["Target URL is unreachable or times out — returns an error or empty response","Invalid or malformed URL input — may return a validation error","Target server returns no security headers — response will reflect missing headers","Payment settlement failure via x402 protocol — call is rejected before execution","Rate limiting or upstream restrictions on the target domain"],"whenToPreferThis":"Choose this endpoint when you need a quick, paid, machine-readable fetch of a web resource's HTTP security headers without running your own infrastructure. It is particularly useful in agent workflows that need to audit, compare, or validate security header configurations across multiple sites programmatically, and when a micro-payment model per call is acceptable.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T07:21:56.216Z","isFirstParty":false}