{"slug":"headers-use-x402atlas-com-6c150e","title":"Audit a URL's HTTP security headers over a single body-free (HEAD) request","host":"headers.use.x402atlas.com","method":"GET","resource":"https://headers.use.x402atlas.com/","category":"code","description":"Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values","price_listed":0.01,"price_asked":0.01,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":624,"reported_calls_30d":23,"reported_payers_30d":9,"networks":["eip155:137","eip155:42161","eip155:8453","solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"url":"https://example.com/"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET"],"type":"string"},"queryParams":{"properties":{"url":{"description":"Absolute http/https URL to audit. Host must be a hostname (not an IP literal), not \"localhost\", and not under a reserved suffix (.local, .internal, .localdomain, .lan, .test). Non-default ports must be allowlisted. Redirects are not followed.","format":"uri","type":"string"}},"required":["url"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"headers":{"description":"Graded, normalized security headers. Each field is null when the header is absent from the response","properties":{"content_security_policy":{"type":["string","null"]},"permissions_policy":{"type":["string","null"]},"referrer_policy":{"type":["string","null"]},"server":{"description":"Server header value, if disclosed by the target","type":["string","null"]},"strict_transport_security":{"properties":{"include_subdomains":{"type":"boolean"},"max_age":{"description":"Parsed max-age in seconds; null if absent or unparseable","type":["integer","null"]},"preload":{"type":"boolean"},"value":{"description":"Raw Strict-Transport-Security header value","type":"string"}},"type":["object","null"]},"x_content_type_options":{"type":["string","null"]},"x_frame_options":{"type":["string","null"]},"x_powered_by":{"description":"X-Powered-By header value, if disclosed by the target","type":["string","null"]}},"type":"object"},"queried_at":{"description":"UTC timestamp the audit was performed","format":"date-time","type":"string"},"status_code":{"description":"HTTP status code returned by the target for the HEAD request","type":"integer"},"url":{"description":"The audited URL, exactly as given","type":"string"},"warnings":{"description":"Human-readable posture advisories, e.g. missing or weak headers","items":{"type":"string"},"type":"array"}},"required":["url","status_code","queried_at","headers","warnings"],"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.01,"price_match":true,"latency_ms":624,"error":null}],"description_full":"Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.","last_updated":"2026-09-24T02:14:15.051Z","schemes":["exact"]}