HTTP Security Headers Check
GET headers.use.x402atlas.com
Why an agent can trust this route.
Sonar evidence is advisory. Paid delivery is shown as verified only when paid probes are available; otherwise route estimates use the unpaid handshake as a clearly labeled proxy.
Observed outcomes
Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.
Resource: headers.use.x402atlas.com
Network: eip155:8453, eip155:137, eip155:42161, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp · Asset: 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 · Pay to: 0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c
Payment methods: — · Last validation: 2026-09-14 12:26:25.382+00
{
"input": {
"type": "object",
"required": [
"type",
"method"
],
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"GET"
],
"type": "string"
},
"queryParams": {
"type": "object",
"required": [
"url"
],
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Absolute http/https URL to audit. Host must be a hostname (not an IP literal), not \"localhost\", and not under a reserved suffix (.local, .internal, .localdomain, .lan, .test). Non-default ports must be allowlisted. Redirects are not followed."
}
}
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"required": [
"url",
"status_code",
"queried_at",
"headers",
"warnings"
],
"properties": {
"url": {
"type": "string",
"description": "The audited URL, exactly as given"
},
"headers": {
"type": "object",
"properties": {
"server": {
"type": [
"string",
"null"
],
"description": "Server header value, if disclosed by the target"
},
"x_powered_by": {
"type": [
"string",
"null"
],
"description": "X-Powered-By header value, if disclosed by the target"
},
"referrer_policy": {
"type": [
"string",
"null"
]
},
"x_frame_options": {
"type": [
"string",
"null"
]
},
"permissions_policy": {
"type": [
"string",
"null"
]
},
"x_content_type_options": {
"type": [
"string",
"null"
]
},
"content_security_policy": {
"type": [
"string",
"null"
]
},
"strict_transport_security": {
"type": [
"object",
"null"
],
"properties": {
"value": {
"type": "string",
"description": "Raw Strict-Transport-Security header value"
},
"max_age": {
"type": [
"integer",
"null"
],
"description": "Parsed max-age in seconds; null if absent or unparseable"
},
"preload": {
"type": "boolean"
},
"include_subdomains": {
"type": "boolean"
}
}
}
},
"description": "Graded, normalized security headers. Each field is null when the header is absent from the response"
},
"warnings": {
"type": "array",
"items": {
"type": "string"
},
"description": "Human-readable posture advisories, e.g. missing or weak headers"
},
"queried_at": {
"type": "string",
"format": "date-time",
"description": "UTC timestamp the audit was performed"
},
"status_code": {
"type": "integer",
"description": "HTTP status code returned by the target for the HEAD request"
}
}
}
}
},
"paymentRequirements": [
{
"raw": {
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
},
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact",
"network": "eip155:8453",
"amountAtomic": "10000"
},
{
"raw": {
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:137",
"maxTimeoutSeconds": 300
},
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact",
"network": "eip155:137",
"amountAtomic": "10000"
},
{
"raw": {
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:42161",
"maxTimeoutSeconds": 300
},
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact",
"network": "eip155:42161",
"amountAtomic": "10000"
},
{
"raw": {
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"extra": {
"tier": "standard",
"feePayer": "D6ZhtNQ5nT9ZnTHUbqXZsTx5MH2rPFiBBggX4hY1WePM",
"merchant": "x402Atlas"
},
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"amount": "10000",
"scheme": "exact",
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"maxTimeoutSeconds": 300
},
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"scheme": "exact",
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"amountAtomic": "10000"
}
]
}Source catalog records are retained separately from live endpoint observations. Sonar score, uptime, and latency are advisory metrics. CDP indexing is not inferred from validation.