# Vextorium Website Security Headers Audit

> Vextorium Website Security Headers Audit is a paid API for AI agents from api.vextorium.com, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-01).

Audits a website's HTTP security headers (HTTPS, HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, cookies) and returns a score.

## Facts

- Endpoint: POST https://api.vextorium.com/cabeceras-seguridad-pago?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/vextorium-website-security-headers-audit-4b2c9bd9
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_oLKbvND9AQQYLFZy8ZWBY

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability vextorium-website-security-headers-audit-4b2c9bd9 -d '<json body>'
```

Example prompt: Can you audit the security headers for https://example.com and tell me which headers are missing and what score it gets?

## When to prefer this

Choose this endpoint when you need a comprehensive, scored audit of a website's HTTP security headers in a single call — covering HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and cookie flags together. Prefer it over manual header inspection tools when you want structured JSON output with explanations of missing headers, suitable for automated compliance checks or agent-driven security workflows.

## Known failure modes

- Invalid or unreachable URL returns an error or null fields
- Site with no HTTP response may timeout
- Redirected domains may return headers for the final destination URL rather than the input
- Sites blocking bots may return incomplete header data
- Malformed URL input causes validation error

## How this service works

Website security headers audit: HTTPS, HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and cookie flags, with a score.

## Output

Returns a structured object including: whether the site uses HTTPS, HTTP status code, final URL after redirects, server type, a score/grade, list of present security headers with their values, list of missing headers with explanations of their purpose, and cookie security flags.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method",
    "bodyType",
    "body"
   ],
   "properties": {
    "body": {
     "required": [
      "url"
     ],
     "properties": {
      "url": {
       "type": "string",
       "description": "Website URL or domain"
      }
     }
    },
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "POST"
     ],
     "type": "string"
    },
    "bodyType": {
     "enum": [
      "json",
      "form-data",
      "text"
     ],
     "type": "string"
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "properties": {
      "nota": {
       "type": [
        "string",
        "null"
       ]
      },
      "cookies": {
       "type": [
        "array",
        "null"
       ],
       "items": {
        "type": [
         "string",
         "number",
         "object"
        ]
       }
      },
      "servidor": {
       "type": [
        "string",
        "null"
       ]
      },
      "url_final": {
       "type": [
        "string",
        "null"
       ]
      },
      "usa_https": {
       "type": [
        "boolean",
        "null"
       ]
      },
      "puntuacion": {
       "type": [
        "string",
        "null"
       ]
      },
      "codigo_estado": {
       "type": [
        "number",
        "null"
       ]
      },
      "cabeceras_presentes": {
       "type": [
        "object",
        "null"
       ],
       "additionalProperties": {
        "type": "string"
       }
      },
      "cabeceras_que_faltan": {
       "type": [
        "array",
        "null"
       ],
       "items": {
        "type": [
         "object",
         "null"
        ],
        "properties": {
         "cabecera": {
          "type": [
           "string",
           "null"
          ]
         },
         "para_que_sirve": {
          "type": [
           "string",
           "null"
          ]
         }
        }
       }
      }
     }
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "nota": "Revision pasiva de cabeceras; no es una auditoria de seguridad completa.",
  "cookies": [],
  "servidor": "cloudflare",
  "url_final": "https://example.com/",
  "usa_https": true,
  "puntuacion": "1/7",
  "codigo_estado": 200,
  "cabeceras_presentes": {},
  "cabeceras_que_faltan": [
   {
    "cabecera": "strict-transport-security",
    "para_que_sirve": "HSTS: obliga a usar HTTPS"
   }
  ]
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/vextorium-website-security-headers-audit-4b2c9bd9/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from api.vextorium.com](https://www.zero.xyz/host/api.vextorium.com/llms.txt)
