# HTTP Security Headers Analyzer

> HTTP Security Headers Analyzer is a paid API for AI agents from http-headers.hsharmanov02.workers.dev, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Analyzes HTTP security headers for any given URL and returns a detailed assessment of their presence and configuration

## Facts

- Endpoint: GET https://http-headers.hsharmanov02.workers.dev/headers?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/http-security-headers-analyzer-6e603830
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_f6gf-AwnMnht9lwh1Fldj

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability http-security-headers-analyzer-6e603830
```

Example prompt: Can you check the HTTP security headers for https://example.com and tell me which important security headers are missing or misconfigured?

## When to prefer this

Choose this endpoint when you need a quick, on-demand HTTP security header audit for any public URL without setting up API keys or running your own scanner. It is ideal for one-off checks, agent-driven compliance workflows, or pre-deployment security reviews where a lightweight per-call pricing model ($0.01 USDC) is acceptable.

## Known failure modes

- Invalid or unreachable URL — the target site may be down or reject requests
- URL format errors — missing protocol or malformed URL
- Timeout — slow-responding target servers may cause request failures
- Target site blocks automated requests or returns non-standard responses
- Payment failure — insufficient USDC balance or unsupported chain

## How this service works

HTTP security headers analysis for any URL. Paid per call: $0.002 USDC on Base, Monad, Arbitrum, Optimism, Polygon, Avalanche or Solana (eip155:8453) via x402 v2. No API key.

## Output

Returns a structured object containing the HTTP response headers retrieved from the target URL, along with analysis of security-relevant headers such as Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and others — indicating which are present, their values, and potentially flagging missing or misconfigured headers.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "required": [
  "url"
 ],
 "properties": {
  "url": {
   "type": "string"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "object"
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/http-security-headers-analyzer-6e603830/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from http-headers.hsharmanov02.workers.dev](https://www.zero.xyz/host/http-headers.hsharmanov02.workers.dev/llms.txt)
