{"uid":"cap_oLKbvND9AQQYLFZy8ZWBY","slug":"vextorium-website-security-headers-audit-4b2c9bd9","name":"Vextorium Website Security Headers Audit","description":"Website security headers audit: HTTPS, HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and cookie flags, with a score.","url":"https://api.vextorium.com/cabeceras-seguridad-pago?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"required":["url"],"properties":{"url":{"type":"string","description":"Website URL or domain"}}},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"nota":{"type":["string","null"]},"cookies":{"type":["array","null"],"items":{"type":["string","number","object"]}},"servidor":{"type":["string","null"]},"url_final":{"type":["string","null"]},"usa_https":{"type":["boolean","null"]},"puntuacion":{"type":["string","null"]},"codigo_estado":{"type":["number","null"]},"cabeceras_presentes":{"type":["object","null"],"additionalProperties":{"type":"string"}},"cabeceras_que_faltan":{"type":["array","null"],"items":{"type":["object","null"],"properties":{"cabecera":{"type":["string","null"]},"para_que_sirve":{"type":["string","null"]}}}}}}}}}},"responseSchema":{"type":"json","example":{"nota":"Revision pasiva de cabeceras; no es una auditoria de seguridad completa.","cookies":[],"servidor":"cloudflare","url_final":"https://example.com/","usa_https":true,"puntuacion":"1/7","codigo_estado":200,"cabeceras_presentes":{},"cabeceras_que_faltan":[{"cabecera":"strict-transport-security","para_que_sirve":"HSTS: obliga a usar HTTPS"}]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_BnNS_H1lXF0wpULYsK6Eb","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a website's HTTP security headers (HTTPS, HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, cookies) and returns a score.","exampleAgentPrompt":"Can you audit the security headers for https://example.com and tell me which headers are missing and what score it gets?","exampleUseCases":[{"title":"Pre-launch security checklist","prompt":"Before we go live, can you check if our site at https://app.mycompany.com has all the necessary security headers configured — HSTS, CSP, X-Frame-Options, the works — and give me a score?"},{"title":"Third-party vendor security review","prompt":"I need to evaluate the security posture of a vendor's website. Can you audit the HTTP security headers on https://vendor-portal.com and flag anything that's missing?"},{"title":"Ongoing compliance monitoring","prompt":"Run a security headers audit on https://checkout.mystore.com and let me know if the cookie flags and content security policy are properly set — I want to make sure we're still compliant."}],"resultDescription":"Returns a structured object including: whether the site uses HTTPS, HTTP status code, final URL after redirects, server type, a score/grade, list of present security headers with their values, list of missing headers with explanations of their purpose, and cookie security flags.","failureModes":["Invalid or unreachable URL returns an error or null fields","Site with no HTTP response may timeout","Redirected domains may return headers for the final destination URL rather than the input","Sites blocking bots may return incomplete header data","Malformed URL input causes validation error"],"whenToPreferThis":"Choose this endpoint when you need a comprehensive, scored audit of a website's HTTP security headers in a single call — covering HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and cookie flags together. Prefer it over manual header inspection tools when you want structured JSON output with explanations of missing headers, suitable for automated compliance checks or agent-driven security workflows.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:50:39.650Z","isFirstParty":false,"canonicalSlug":"vextorium-website-security-headers-audit-4b2c9bd9"}