# GET /http/security-headers: $0.003 per call

Security audit of a website's HTTP headers, graded A–F with a fix per finding: HTTPS and the http→https redirect, HSTS, Content-Security-Policy strength, clickjacking, nosniff, Referrer- and Permissions-Policy, cookie flags, version leaks, CORS. Pass ?url=https://example.com. Based on OWASP Secure Headers guidance.

- **Price:** $0.003 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** yes, 20 free calls a day from Claude, Cursor or any MCP client ([set-up](/mcp/setup)).
- **Answers cached for:** 10 min
- **Data sources:** the page itself (one request, robots.txt respected)
- **Lane:** Developer toolkit ([OpenAPI](/openapi/devkit.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/security-headers](/sample/security-headers). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/security-headers"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i "https://aayatai.com/http/security-headers?url=https%3A%2F%2Fexample.org"
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/http/security-headers?url=https%3A%2F%2Fexample.org");
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("security-headers", {"url":"https://example.org"});
```

## Inputs

- `url` **(required)** (string): Page to check, e.g. https://example.com (https:// assumed if left out).

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

Example only: the shape of an answer, with placeholder addresses and made-up figures. It is not data about any real token or wallet; call the service (or its free sample) for real results.

```json
{
  "url": "https://example.org",
  "finalUrl": "https://example.org/",
  "status": 200,
  "https": true,
  "httpsRedirect": true,
  "grade": "D",
  "score": 44,
  "checks": [
    {
      "id": "https",
      "level": "pass",
      "header": null,
      "value": null,
      "finding": "Served over HTTPS with a certificate our fetcher trusts.",
      "fix": null
    },
    {
      "id": "hsts",
      "level": "fail",
      "header": "strict-transport-security",
      "value": null,
      "finding": "No HSTS: browsers may still try plain HTTP first.",
      "fix": "Strict-Transport-Security: max-age=31536000; includeSubDomains"
    }
  ],
  "headers": {
    "content-type": "text/html"
  },
  "note": "One request to the page as a browser-less client; headers can differ by page, cookie or country. Certificate expiry is not checked. Cookie values are never shown."
}
```

## Related

- [POST /convert/csv-json](/services/csv-json) ($0.001): Convert CSV to JSON or JSON to CSV.

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).