HTTP headers + security analysis · Http Headers

by HTTP headers + security analysis

POSTBaseSolanaArbitrumPolygonMonadAvalancheeip155:1329OptimismFraxtaleip155:42220stellar:pubnetalgorand:wGHE2Pwdvd7S12BL5FaOP20EGYesN73ktiC1qzkkit8=

$0.003

per call · USD Coin on Base

Fetch a URL and return every response header plus a security analysis: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP/CORP/COEP. Scores 0–100 by presence, flags weak HSTS, and warns on Server/X-Powered-By identity leaks. SSRF-protected.

Endpoint

POST https://agent402.tools/api/http-headers

4

Calls / 30d

1

Unique payers / 30d

Aug 31

Last called

exact

Payment scheme

Call this service

TypeScript · @x402/fetch
import { wrapFetchWithPayment } from "@x402/fetch";
import { privateKeyToAccount } from "viem/accounts";

const account = privateKeyToAccount(process.env.PRIVATE_KEY);
const fetchWithPay = wrapFetchWithPayment(fetch, account);

const res = await fetchWithPay("https://agent402.tools/api/http-headers", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "url": "https://example.com"
  }),
});
const data = await res.json();
cURL
curl -X POST \
  "https://agent402.tools/api/http-headers" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com"}' \
  -H "X-PAYMENT: <signed x402 payment>"

Example response

{
  "fetchedAt": "2026-06-19T22:00:00.000Z",
  "finalUrl": "https://example.com/",
  "headers": {
    "content-type": "text/html; charset=UTF-8",
    "server": "ECAcc (nyd/D17C)"
  },
  "httpVersion": null,
  "redirected": false,
  "security": {
    "findings": [
      {
        "header": "HSTS",
        "present": false,
        "value": null
      }
    ],
    "score": 0,
    "warnings": [
      "Server header leaks identity: ECAcc (nyd/D17C)"
    ]
  },
  "status": 200,
  "statusText": "OK",
  "url": "https://example.com/"
}

Payment details

Pay to0xabf4fabd7c416fb67202e5f9002389fc75e2a9d0
AssetUSD Coin · 0x833589fcd6edb6e08f4c7c32d4f71b54bda02913
NetworksBase, Solana, Arbitrum, Polygon, Monad, Avalanche, eip155:1329, Optimism, Fraxtal, eip155:42220, stellar:pubnet, algorand:wGHE2Pwdvd7S12BL5FaOP20EGYesN73ktiC1qzkkit8=
Schemesexact, upto

Is this your API?

Pin it to the top of Developer Tools and the homepage with a featured placement.

Get featured →

More from HTTP headers + security analysis & similar services