{"uid":"cap_rXpDx-VEFrwv6YjHwZqrS","slug":"openverbs-http-headers-security-audit-91f4ec5d","name":"OpenVerbs HTTP Headers & Security Audit","description":"Fetch a URL (following redirects) and return the final response's HTTP headers, the server banner and content-type, plus a security-header audit reporting HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and the cross-origin policies (with the missing ones listed). No body is downloaded or parsed.","url":"https://web.openverbs.com/v1/headers?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","format":"uri","maxLength":2048,"description":"Public http(s) URL to fetch. Private/loopback/link-local addresses are rejected."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_7IPJ6tUfOZhuZW-uAkWCI","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a URL's HTTP response headers and audits the presence of key security headers (HSTS, CSP, X-Frame-Options, etc.) without downloading the response body.","exampleAgentPrompt":"Can you check the security headers on https://example.com and tell me which ones are missing — especially HSTS, Content-Security-Policy, and X-Frame-Options?","exampleUseCases":[{"title":"Security audit before site launch","prompt":"Before we go live, can you audit https://staging.mycompany.com for missing security headers? I specifically want to know if HSTS, CSP, and X-Frame-Options are all configured correctly."},{"title":"Vendor security compliance check","prompt":"We need to verify that our payment processor at https://checkout.vendorname.com has proper security headers set — can you check what they have and flag anything missing?"},{"title":"Competitor server fingerprinting","prompt":"Can you fetch the headers from https://competitor.io and tell me what server software they're running and what their content-type is?"}],"resultDescription":"Returns the final URL's HTTP response headers after following redirects, the server banner and content-type value, and a structured security-header audit listing which of HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and cross-origin policies are present or missing.","failureModes":["Private/loopback/link-local IP addresses or hostnames are rejected with an error","URL is unreachable or times out","Invalid URL format returns validation error","Non-HTTP/HTTPS schemes are rejected","Target server returns no response headers"],"whenToPreferThis":"Use this endpoint when you need to inspect HTTP headers and audit security posture of a URL without downloading or parsing the response body. It is ideal for security compliance checks, server fingerprinting, or verifying that a site has deployed the correct security headers. Prefer this over a full-page fetch when you only need header-level metadata.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T03:15:01.294Z","isFirstParty":false,"canonicalSlug":"openverbs-http-headers-security-audit-91f4ec5d"}