{"slug":"api-zfinia-com-x402-v1-security-header-diff-85b690","title":"Compare a fixed list of ten security-relevant response headers across two releas","host":"api.zfinia.com","method":"POST","resource":"https://api.zfinia.com/x402/v1/security-header-diff","category":"other","description":"Compare a fixed list of ten security-relevant response headers across two releases and name the specific reverts. Reports a header removed, added or changed, and separately a reduced Strict-Transport-Security max-age, dropped includeSubDomains, a newly permitted unsafe-inline or unsafe-eval, and a C","price_listed":0.11,"price_asked":0.11,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":2487,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"after":{"Content-Security-Policy-Report-Only":"default-src 'self'; script-src 'self' 'unsafe-inline'","Referrer-Policy":"no-referrer","Strict-Transport-Security":"max-age=600","X-Frame-Options":"SAMEORIGIN"},"after_name":"release-42","before":{"Content-Security-Policy":"default-src 'self'; script-src 'self'","Referrer-Policy":"no-referrer","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Content-Type-Options":"nosniff","X-Frame-Options":"DENY"},"before_name":"release-41"},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"additionalProperties":false,"properties":{"after":{"type":"object"},"after_name":{"maxLength":64,"type":"string"},"before":{"type":"object"},"before_name":{"maxLength":64,"type":"string"}},"required":["before","after"],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-10-04","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.11,"price_match":true,"latency_ms":2487,"error":null}],"description_full":"Compare a fixed list of ten security-relevant response headers across two releases and name the specific reverts. Reports a header removed, added or changed, and separately a reduced Strict-Transport-Security max-age, dropped includeSubDomains, a newly permitted unsafe-inline or unsafe-eval, and a Content-Security-Policy that moved from enforcing to report-only so it no longer blocks anything. Observable differences only, not an assessment of whether either configuration is adequate.","last_updated":"2026-10-04T08:18:34.078Z","schemes":["exact"]}