# Security Headers Auditor

> Security Headers Auditor is a paid API for AI agents from agentshelf.syntexa.ch, paid per call via x402, $0.004/call, status unknown (last checked 2026-10-01).

Audits a public URL for the presence and configuration of CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy HTTP security headers

## Facts

- Endpoint: POST https://agentshelf.syntexa.ch/v1/security-headers?utm_source=zero.xyz
- Price: $0.004/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/security-headers-auditor-58c2853d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_8jtRszIQl63dvoyXX6sws

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability security-headers-auditor-58c2853d -d '<json body>'
```

Example prompt: Can you audit the security headers on https://example.com — I want to know if CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy are all properly configured?

## When to prefer this

Use this endpoint when you need a quick, SSRF-safe audit of HTTP security headers on a publicly accessible URL without setting up your own scanning infrastructure. It is preferable when you need results for a single URL on-demand, want a deterministic machine-readable breakdown of exactly the five major security headers, and are operating in an agentic workflow where paying $0.004 USDC per call is acceptable. Try the free POST /v1/sandbox/security-headers endpoint first if cost is a concern.

## Known failure modes

- URL points to a private/internal network address (SSRF protection blocks it)
- URL is unreachable or returns a non-200 response
- URL scheme not supported (non-HTTP/HTTPS)
- URL exceeds maximum length of 2048 characters
- URL shorter than minimum 8 characters
- Payment not processed — 402 response if unpaid path used

## How this service works

Call when an agent needs CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy audited on a public URL (SSRF-safe). Exact $0.004 USDC. Prefer unpaid POST /v1/sandbox/security-headers first.

## Output

A structured report detailing the presence, value, and configuration status of each security header (CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy) for the submitted URL, typically including whether each header is present, its current value, and any notable issues or misconfigurations.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string",
   "examples": [
    "https://example.com/"
   ],
   "maxLength": 2048,
   "minLength": 8,
   "description": "Public http(s) URL whose CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are audited."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/security-headers-auditor-58c2853d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agentshelf.syntexa.ch](https://www.zero.xyz/host/agentshelf.syntexa.ch/llms.txt)
