{"uid":"cap_kapjkvrSC9Nrd0GEjwZ0S","slug":"security-headers-check-8b3da15e","name":"security-headers-check","description":"HTTP security headers check for a website: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, plus server and content-type headers, status and final URL. Web security audit, compliance checks and hardening reports. $0.01 per URL.","url":"https://intel.rallylive.ca/http-headers","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_sAGGLvkLgI5p0QdjQ1-I8","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a website's HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) and returns server/content-type headers, HTTP status, and final URL.","exampleAgentPrompt":"Can you check what HTTP security headers https://www.example.com is sending — specifically whether HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy are set?","exampleUseCases":[{"title":"Pre-launch security header audit","prompt":"Before we go live, can you audit the security headers on https://staging.myapp.com and tell me which ones like HSTS, CSP, and X-Frame-Options are missing or misconfigured?"},{"title":"Compliance check for client website","prompt":"I need to verify that https://www.clientsite.com has all the required security headers for our compliance report — check for HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy."},{"title":"Monitoring competitor security posture","prompt":"Can you look up what HTTP security headers https://www.competitor.com has configured, including their server header and final URL after any redirects?"}],"resultDescription":"A JSON object containing the presence and values of key HTTP security headers (HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy), plus the server and content-type response headers, the HTTP status code, and the final resolved URL after any redirects.","failureModes":["URL is unreachable or times out — endpoint may return an error or empty headers","Invalid URL format provided — request may fail validation","Website blocks automated requests — headers may be incomplete or absent","Non-HTTP/HTTPS schemes not supported","Target server uses non-standard header casing — some headers may not be detected"],"whenToPreferThis":"Choose this endpoint when you need a quick, structured snapshot of a website's HTTP security header configuration for auditing, compliance reporting, or hardening recommendations. It is purpose-built for security header analysis and returns all the major headers in one call, unlike a general URL status checker or a full vulnerability scanner.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:55:34.760Z","isFirstParty":false}