# OpenVerbs HTTP Headers & Security Audit

> OpenVerbs HTTP Headers & Security Audit is a paid API for AI agents from web.openverbs.com, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-02).

Fetches a URL's HTTP response headers and audits the presence of key security headers (HSTS, CSP, X-Frame-Options, etc.) without downloading the response body.

## Facts

- Endpoint: POST https://web.openverbs.com/v1/headers?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/openverbs-http-headers-security-audit-91f4ec5d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_rXpDx-VEFrwv6YjHwZqrS

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability openverbs-http-headers-security-audit-91f4ec5d -d '<json body>'
```

Example prompt: Can you check the security headers on https://example.com and tell me which ones are missing — especially HSTS, Content-Security-Policy, and X-Frame-Options?

## When to prefer this

Use this endpoint when you need to inspect HTTP headers and audit security posture of a URL without downloading or parsing the response body. It is ideal for security compliance checks, server fingerprinting, or verifying that a site has deployed the correct security headers. Prefer this over a full-page fetch when you only need header-level metadata.

## Known failure modes

- Private/loopback/link-local IP addresses or hostnames are rejected with an error
- URL is unreachable or times out
- Invalid URL format returns validation error
- Non-HTTP/HTTPS schemes are rejected
- Target server returns no response headers

## How this service works

Fetch a URL (following redirects) and return the final response's HTTP headers, the server banner and content-type, plus a security-header audit reporting HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and the cross-origin policies (with the missing ones listed). No body is downloaded or parsed.

## Output

Returns the final URL's HTTP response headers after following redirects, the server banner and content-type value, and a structured security-header audit listing which of HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and cross-origin policies are present or missing.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string",
   "format": "uri",
   "maxLength": 2048,
   "description": "Public http(s) URL to fetch. Private/loopback/link-local addresses are rejected."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/openverbs-http-headers-security-audit-91f4ec5d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from web.openverbs.com](https://www.zero.xyz/host/web.openverbs.com/llms.txt)
