80trust / 100

Security Http Headers

by CodePulse Agentic API in Security & trust

x402 APIPassing, checked 5 h ago

Queries target URL headers to score security configurations (HSTS, CSP, X-Frame-Options).

POST https://codepulse-api.hahavoid0.workers.dev/security/http-headers

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
156 ms typical, 156 ms slowest 5%
Last check
5 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X POST "https://codepulse-api.hahavoid0.workers.dev/security/http-headers" \
  -H "content-type: application/json" \
  -d '{"url":"https://google.com"}'
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fcodepulse-api.hahavoid0.workers.dev%2Fsecurity%2Fhttp-headers
const res = await pay("https://codepulse-api.hahavoid0.workers.dev/security/http-headers", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({"url":"https://google.com"}),
});
console.log(await res.json());

Example input

{
  "url": "https://google.com"
}

Example output

{
  "confidence": "high",
  "data_as_of": "2026-06",
  "disclaimer": "Informational support only. Not legal, tax, medical, veterinary, or financial advice. Verify with the cited official source or a qualified professional before acting.",
  "result": {
    "headers": {
      "csp": false,
      "hsts": true
    },
    "score": 80
  },
  "supported": true,
  "warnings": []
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
5 h agoPassed402156 ms$0.01