{"uid":"cap_ljusay-klgHF8j4sNnOeA","slug":"api-strale-io-8c4e4dbf","name":"HTTP Security Headers Checker","description":"Check HTTP response headers for security best practices: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. Returns grade A-F.","url":"https://api.strale.io/x402/header-security-check","method":"GET","headers":{},"bodySchema":{"type":"object","required":["url"],"properties":{"url":{"type":"string"}}},"responseSchema":{"grade":{"type":"string"},"score":{"type":"integer"},"missing":{"type":"array"},"present":{"type":"array"}},"example":{"request":{"url":"https://www.example.com"},"response":{"url":"https://www.example.com","cors":null,"_meta":{"payment":{"method":"x402","price_usd":0.054000000000000006,"settlement_id":"0x66862407ce6871d4bed5905373d293debf7600aee73774445dd849e13fd6553c"},"capability":"header-security-check","latency_ms":21,"provenance":{"source":"http-headers","fetched_at":"2026-06-16T01:20:19.296Z"}},"grade":"F","score":10,"server":"cloudflare","missing":[{"header":"strict-transport-security","severity":"high","recommendation":"Add: Strict-Transport-Security: max-age=31536000; includeSubDomains"},{"header":"content-security-policy","severity":"high","recommendation":"Add Content-Security-Policy to prevent XSS and injection attacks"},{"header":"x-frame-options","severity":"medium","recommendation":"Add: X-Frame-Options: DENY (or SAMEORIGIN) to prevent clickjacking"},{"header":"x-content-type-options","severity":"medium","recommendation":"Add: X-Content-Type-Options: nosniff to prevent MIME sniffing"},{"header":"referrer-policy","severity":"medium","recommendation":"Add: Referrer-Policy: strict-origin-when-cross-origin"},{"header":"permissions-policy","severity":"medium","recommendation":"Add Permissions-Policy to restrict browser features (camera, microphone, etc.)"}],"present":[],"response_status":200}},"exampleRequest":{"url":"https://www.example.com"},"tags":["x402"],"displayCostAmount":"0.054001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.054001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.054","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.054","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm__y5svTvLpLaCRXShxo1kl","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.054","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a URL's HTTP response headers for security best practices (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) and returns a letter grade A–F.","exampleAgentPrompt":"Can you check the security headers on https://myapp.example.com and tell me what grade it gets — specifically whether it has HSTS, CSP, and X-Frame-Options set correctly?","exampleUseCases":null,"resultDescription":"Returns a security grade from A to F and a breakdown of whether each key security header (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) is present and correctly configured on the given URL.","failureModes":["Invalid or unreachable URL returns an error or failed check result","URL uses a non-HTTP scheme (e.g. ftp://) — may not be supported","Rate limiting or upstream timeout if the target server is slow","Missing required 'url' query parameter returns a validation error"],"whenToPreferThis":"Use this endpoint when you need a quick, structured security header audit for a given URL with a clear letter grade and per-header breakdown. Prefer this over a full SEO or accessibility audit when the specific concern is HTTP security posture, particularly for HSTS, CSP, clickjacking protection, and MIME-type sniffing prevention.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:01:40.060Z","isFirstParty":false}