# Website Security Headers Audit

> Website Security Headers Audit is a paid API for AI agents from twin.unykorn.org, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-01).

Audits a public website's HTTP security headers, returning an A-F grade, cookie flag analysis, and version-leak detection

## Facts

- Endpoint: POST https://twin.unykorn.org/web/headers-audit?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/website-security-headers-audit-50915a49
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_VnLeckhKDLHinzBjhGHEp

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability website-security-headers-audit-50915a49 -d '<json body>'
```

Example prompt: Can you audit the security headers for https://example.com and tell me what grade it gets, whether the cookies have the right flags set, and if it's leaking any version or server info?

## When to prefer this

Choose this endpoint when you need a quick, automated HTTP security header audit with a standardized A-F grade, cookie flag inspection, and version-leak detection for any public URL — especially useful for pre-launch checks, compliance reviews, or competitive benchmarking without needing to run your own tooling like securityheaders.com or custom curl scripts.

## Known failure modes

- Non-public or unreachable URLs return an error or timeout
- Private/intranet URLs that are inaccessible from the audit server fail with a connection error
- Malformed URLs result in a validation error
- Sites behind aggressive firewalls or WAFs may block the audit request
- HTTPS sites with invalid certificates may fail or return partial results

## How this service works

Website security-headers audit with A-F grade, cookie flags and version leaks — Genesis402 / UnyKorn Operator Network

## Output

Returns an A-F security grade for the target website's HTTP headers, a breakdown of individual security headers (present, missing, or misconfigured), an analysis of cookie flags (HttpOnly, Secure, SameSite), and detection of version or software information leaked via headers like Server or X-Powered-By.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "params": {
   "type": "object",
   "properties": {
    "url": {
     "type": "string",
     "description": "required public URL"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "ok": true,
  "type": "http-headers-audit",
  "receipt": {
   "tx_hash": "0x<64hex>",
   "amount_usd": 0.002,
   "receipt_id": "g402-<16hex>"
  },
  "sources": [
   {
    "ok": true,
    "name": "<source>"
   }
  ],
  "limitations": "<text>",
  "generated_at": "<iso time>",
  "evidence_hash": "sha256:<64hex>"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/website-security-headers-audit-50915a49/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from twin.unykorn.org](https://www.zero.xyz/host/twin.unykorn.org/llms.txt)
