{"uid":"cap_m0LvUrGDLon55YL6JNUjU","slug":"pennyrail-http-header-security-analysis-1d0b7f28","name":"PennyRail HTTP Header Security Analysis","description":"Machine-readable settlement service","url":"https://pennyrail.vercel.app/api/p/network/web.http-headers--header-security-analysis","method":"POST","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object"}}},"responseSchema":{"type":"object","additionalProperties":true},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_AxPWmlgro4g_s06kFMPvQ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes HTTP response headers for security vulnerabilities and best-practice compliance","exampleAgentPrompt":"Can you run a security header analysis on my site's HTTP response headers — I want to know which security headers are missing or misconfigured, like CSP, HSTS, X-Frame-Options, and Referrer-Policy?","exampleUseCases":[{"title":"Pre-launch security header audit","prompt":"Before we go live, can you analyze the HTTP response headers from our staging environment and tell me which security headers are missing or set incorrectly — especially CSP, HSTS, and X-Content-Type-Options?"},{"title":"Compliance check for web app","prompt":"I need to verify our web app's HTTP headers meet basic security best practices — can you check for issues with headers like Permissions-Policy, X-Frame-Options, and Referrer-Policy and give me a report?"},{"title":"Identify header misconfigurations after deploy","prompt":"We just deployed a new version of our site and I want to make sure we didn't accidentally break any security headers — can you analyze our HTTP headers and flag anything that looks vulnerable or misconfigured?"}],"resultDescription":"Returns a structured security analysis of the provided HTTP headers, including which security headers are present, missing, or misconfigured, along with severity ratings and recommendations for remediation.","failureModes":["Missing or empty input headers result in an error or empty analysis","Malformed header values may cause incomplete analysis","Unrecognized header formats may be skipped without warning","Network or upstream service errors may return 5xx responses","Payment not included or invalid x402 payment token causes 402 rejection"],"whenToPreferThis":"Choose this endpoint when you need automated, machine-readable analysis of HTTP security headers — especially in CI/CD pipelines, security audits, or compliance checks where you want structured output rather than a manual browser tool. Prefer it over browser DevTools or manual inspection when integrating header security checks into an agent workflow.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:57:43.429Z","isFirstParty":false}