Resource / 269
healthyHTTP Security Headers Check.
Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.
| State | Network | Scheme | Atomic amount | Asset | payTo / untrusted |
|---|---|---|---|---|---|
| active | eip155:8453 | exact | 10000 | 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 | 0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c |
| active | eip155:137 | exact | 10000 | 0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359 | 0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c |
| active | eip155:42161 | exact | 10000 | 0xaf88d065e77c8cC2239327C5EDb3A432268e5831 | 0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c |
| active | solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp | exact | 10000 | EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v | ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ |
All advertised payment options are stored. Base (`eip155:8453`) is the operational network for ranking and canaries; non-Base options remain visible for transparency.
healthy 2026-08-12 22:00:02 UTC GET · HTTP 402 · 4ms · accepts 4 · base 1 ok
Accepts snapshot
[
{
"amount": "10000",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"assetTransferMethod": null,
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:8453",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"paymentFlow": null,
"raw": {
"amount": "10000",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"max_timeout_seconds": 300,
"network": "eip155:8453",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"pay_to": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
"scheme": "exact"
},
{
"amount": "10000",
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"assetTransferMethod": null,
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:137",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"paymentFlow": null,
"raw": {
"amount": "10000",
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"max_timeout_seconds": 300,
"network": "eip155:137",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"pay_to": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
"scheme": "exact"
},
{
"amount": "10000",
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"assetTransferMethod": null,
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:42161",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"paymentFlow": null,
"raw": {
"amount": "10000",
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"max_timeout_seconds": 300,
"network": "eip155:42161",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"pay_to": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
"scheme": "exact"
},
{
"amount": "10000",
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"assetTransferMethod": null,
"extra": {
"feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
"merchant": "x402Atlas",
"tier": "standard"
},
"maxTimeoutSeconds": 300,
"network": "solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp",
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"paymentFlow": null,
"raw": {
"amount": "10000",
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"extra": {
"feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
"merchant": "x402Atlas",
"tier": "standard"
},
"maxTimeoutSeconds": 300,
"max_timeout_seconds": 300,
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"pay_to": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"scheme": "exact"
},
"scheme": "exact"
}
]
PaymentRequired raw
{
"accepts": [
{
"amount": "10000",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:8453",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
{
"amount": "10000",
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:137",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
{
"amount": "10000",
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:42161",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
{
"amount": "10000",
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"extra": {
"feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
"merchant": "x402Atlas",
"tier": "standard"
},
"maxTimeoutSeconds": 300,
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"scheme": "exact"
}
],
"error": "Payment required",
"extensions": {
"bazaar": {
"category": "domain-intelligence",
"info": {
"input": {
"method": "GET",
"queryParams": {
"url": "https://example.com/"
},
"type": "http"
},
"output": {
"example": {
"headers": {
"content_security_policy": "default-src 'self'",
"permissions_policy": null,
"referrer_policy": "strict-origin-when-cross-origin",
"server": null,
"strict_transport_security": {
"include_subdomains": true,
"max_age": 31536000,
"preload": false,
"value": "max-age=31536000; includeSubDomains"
},
"x_content_type_options": "nosniff",
"x_frame_options": "DENY",
"x_powered_by": null
},
"queried_at": "2026-07-03T12:00:00Z",
"status_code": 200,
"url": "https://example.com/",
"warnings": [
"no Permissions-Policy header (powerful browser features are not restricted)"
]
},
"type": "json"
}
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"method": {
"enum": [
"GET"
],
"type": "string"
},
"queryParams": {
"properties": {
"url": {
"description": "Absolute http/https URL to audit. Host must be a hostname (not an IP literal), not \"localhost\", and not under a reserved suffix (.local, .internal, .localdomain, .lan, .test). Non-default ports must be allowlisted. Redirects are not followed.",
"format": "uri",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"properties": {
"headers": {
"description": "Graded, normalized security headers. Each field is null when the header is absent from the response",
"properties": {
"content_security_policy": {
"type": [
"string",
"null"
]
},
"permissions_policy": {
"type": [
"string",
"null"
]
},
"referrer_policy": {
"type": [
"string",
"null"
]
},
"server": {
"description": "Server header value, if disclosed by the target",
"type": [
"string",
"null"
]
},
"strict_transport_security": {
"properties": {
"include_subdomains": {
"type": "boolean"
},
"max_age": {
"description": "Parsed max-age in seconds; null if absent or unparseable",
"type": [
"integer",
"null"
]
},
"preload": {
"type": "boolean"
},
"value": {
"description": "Raw Strict-Transport-Security header value",
"type": "string"
}
},
"type": [
"object",
"null"
]
},
"x_content_type_options": {
"type": [
"string",
"null"
]
},
"x_frame_options": {
"type": [
"string",
"null"
]
},
"x_powered_by": {
"description": "X-Powered-By header value, if disclosed by the target",
"type": [
"string",
"null"
]
}
},
"type": "object"
},
"queried_at": {
"description": "UTC timestamp the audit was performed",
"format": "date-time",
"type": "string"
},
"status_code": {
"description": "HTTP status code returned by the target for the HEAD request",
"type": "integer"
},
"url": {
"description": "The audited URL, exactly as given",
"type": "string"
},
"warnings": {
"description": "Human-readable posture advisories, e.g. missing or weak headers",
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"url",
"status_code",
"queried_at",
"headers",
"warnings"
],
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
},
"tags": [
"http",
"headers",
"security",
"hsts",
"csp",
"x-frame-options",
"posture"
]
}
},
"resource": {
"description": "Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.",
"mimeType": "application/json",
"serviceName": "HTTP Security Headers Check",
"tags": [
"http",
"headers",
"security",
"hsts",
"csp",
"x-frame-options",
"posture"
],
"url": "https://headers.use.x402atlas.com/"
},
"x402Version": 2
}
Response headers
{
"alt-svc": "h3=\":443\"; ma=2592000",
"content-length": "2243",
"content-type": "application/json",
"date": "Wed, 12 Aug 2026 22:00:02 GMT",
"payment-required": "eyJ4NDAyVmVyc2lvbiI6MiwiZXJyb3IiOiJQYXltZW50IHJlcXVpcmVkIiwicmVzb3VyY2UiOnsidXJsIjoiaHR0cHM6Ly9oZWFkZXJzLnVzZS54NDAyYXRsYXMuY29tLyIsImRlc2NyaXB0aW9uIjoiQXVkaXQgYSBVUkwncyBIVFRQIHNlY3VyaXR5IGhlYWRlcnMgb3ZlciBhIHNpbmdsZSBib2R5LWZyZWUgKEhFQUQpIHJlcXVlc3QuIEdyYWRlcyBTdHJpY3QtVHJhbnNwb3J0LVNlY3VyaXR5LCBDb250ZW50LVNlY3VyaXR5LVBvbGljeSwgWC1GcmFtZS1PcHRpb25zLCBYLUNvbnRlbnQtVHlwZS1PcHRpb25zLCBSZWZlcnJlci1Qb2xpY3kgYW5kIFBlcm1pc3Npb25zLVBvbGljeSwgZmxhZ3MgaW5mb3JtYXRpb24tbGVhayBoZWFkZXJzIChTZXJ2ZXIsIFgtUG93ZXJlZC1CeSksIGFuZCByZXR1cm5zIHRoZSBwYXJzZWQgdmFsdWVzIHBsdXMgYWR2aXNvcnkgd2FybmluZ3MuIENsZWFuIEpTT04gZm9yIHNlY3VyaXR5IGFuZCBwZW50ZXN0IGF1dG9tYXRpb24uIiwibWltZVR5cGUiOiJhcHBsaWNhdGlvbi9qc29uIiwic2VydmljZU5hbWUiOiJIVFRQIFNlY3VyaXR5IEhlYWRlcnMgQ2hlY2siLCJ0YWdzIjpbImh0dHAiLCJoZWFkZXJzIiwic2VjdXJpdHkiLCJoc3RzIiwiY3NwIiwieC1mcmFtZS1vcHRpb25zIiwicG9zdHVyZSJdfSwiYWNjZXB0cyI6W3sic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoiZWlwMTU1Ojg0NTMiLCJhc3NldCI6IjB4ODMzNTg5ZkNENmVEYjZFMDhmNGM3QzMyRDRmNzFiNTRiZEEwMjkxMyIsImFtb3VudCI6IjEwMDAwIiwicGF5VG8iOiIweDdmODA0M2M0MDA3OTk2NDNiY2I2MkI0MUI4NGIyOTdhOEVjYjdiOWMiLCJtYXhUaW1lb3V0U2Vjb25kcyI6MzAwLCJleHRyYSI6eyJtZXJjaGFudCI6Ing0MDJBdGxhcyIsIm5hbWUiOiJVU0QgQ29pbiIsInRpZXIiOiJzdGFuZGFyZCIsInZlcnNpb24iOiIyIn19LHsic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoiZWlwMTU1OjEzNyIsImFzc2V0IjoiMHgzYzQ5OWM1NDJjRUY1RTM4MTFlMTE5MmNlNzBkOGNDMDNkNWMzMzU5IiwiYW1vdW50IjoiMTAwMDAiLCJwYXlUbyI6IjB4N2Y4MDQzYzQwMDc5OTY0M2JjYjYyQjQxQjg0YjI5N2E4RWNiN2I5YyIsIm1heFRpbWVvdXRTZWNvbmRzIjozMDAsImV4dHJhIjp7Im1lcmNoYW50IjoieDQwMkF0bGFzIiwibmFtZSI6IlVTRCBDb2luIiwidGllciI6InN0YW5kYXJkIiwidmVyc2lvbiI6IjIifX0seyJzY2hlbWUiOiJleGFjdCIsIm5ldHdvcmsiOiJlaXAxNTU6NDIxNjEiLCJhc3NldCI6IjB4YWY4OGQwNjVlNzdjOGNDMjIzOTMyN0M1RURiM0E0MzIyNjhlNTgzMSIsImFtb3VudCI6IjEwMDAwIiwicGF5VG8iOiIweDdmODA0M2M0MDA3OTk2NDNiY2I2MkI0MUI4NGIyOTdhOEVjYjdiOWMiLCJtYXhUaW1lb3V0U2Vjb25kcyI6MzAwLCJleHRyYSI6eyJtZXJjaGFudCI6Ing0MDJBdGxhcyIsIm5hbWUiOiJVU0QgQ29pbiIsInRpZXIiOiJzdGFuZGFyZCIsInZlcnNpb24iOiIyIn19LHsic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoic29sYW5hOjVleWt0NFVzRnY4UDhOSmRUUkVwWTF2enFLcVpLdmRwIiwiYXNzZXQiOiJFUGpGV2RkNUF1ZnFTU3FlTTJxTjF4enliYXBDOEc0d0VHR2tad3lURHQxdiIsImFtb3VudCI6IjEwMDAwIiwicGF5VG8iOiJBU3Q2eHZSeVE3bnRFUnNtY1lWTWRMcVp2ejFHRU44RnpleHpxNjJ0WHJOUSIsIm1heFRpbWVvdXRTZWNvbmRzIjozMDAsImV4dHJhIjp7ImZlZVBheWVyIjoiQkVOckxvVWJuZHhvTk1VUzVKWEFwR010TnlrTGpGWFhpeE10cER3RFI5U1AiLCJtZXJjaGFudCI6Ing0MDJBdGxhcyIsInRpZXIiOiJzdGFuZGFyZCJ9fV0sImV4dGVuc2lvbnMiOnsiYmF6YWFyIjp7ImNhdGVnb3J5IjoiZG9tYWluLWludGVsbGlnZW5jZSIsImluZm8iOnsiaW5wdXQiOnsibWV0aG9kIjoiR0VUIiwicXVlcnlQYXJhbXMiOnsidXJsIjoiaHR0cHM6Ly9leGFtcGxlLmNvbS8ifSwidHlwZSI6Imh0dHAifSwib3V0cHV0Ijp7ImV4YW1wbGUiOnsiaGVhZGVycyI6eyJjb250ZW50X3NlY3VyaXR5X3BvbGljeSI6ImRlZmF1bHQtc3JjICdzZWxmJyIsInBlcm1pc3Npb25zX3BvbGljeSI6bnVsbCwicmVmZXJyZXJfcG9saWN5Ijoic3RyaWN0LW9yaWdpbi13aGVuLWNyb3NzLW9yaWdpbiIsInNlcnZlciI6bnVsbCwic3RyaWN0X3RyYW5zcG9ydF9zZWN1cml0eSI6eyJpbmNsdWRlX3N1YmRvbWFpbnMiOnRydWUsIm1heF9hZ2UiOjMxNTM2MDAwLCJwcmVsb2FkIjpmYWxzZSwidmFsdWUiOiJtYXgtYWdlPTMxNTM2MDAwOyBpbmNsdWRlU3ViRG9tYWlucyJ9LCJ4X2NvbnRlbnRfdHlwZV9vcHRpb25zIjoibm9zbmlmZiIsInhfZnJhbWVfb3B0aW9ucyI6IkRFTlkiLCJ4X3Bvd2VyZWRfYnkiOm51bGx9LCJxdWVyaWVkX2F0IjoiMjAyNi0wNy0wM1QxMjowMDowMFoiLCJzdGF0dXNfY29kZSI6MjAwLCJ1cmwiOiJodHRwczovL2V4YW1wbGUuY29tLyIsIndhcm5pbmdzIjpbIm5vIFBlcm1pc3Npb25zLVBvbGljeSBoZWFkZXIgKHBvd2VyZnVsIGJyb3dzZXIgZmVhdHVyZXMgYXJlIG5vdCByZXN0cmljdGVkKSJdfSwidHlwZSI6Impzb24ifX0sInNjaGVtYSI6eyIkc2NoZW1hIjoiaHR0cHM6Ly9qc29uLXNjaGVtYS5vcmcvZHJhZnQvMjAyMC0xMi9zY2hlbWEiLCJwcm9wZXJ0aWVzIjp7ImlucHV0Ijp7ImFkZGl0aW9uYWxQcm9wZXJ0aWVzIjpmYWxzZSwicHJvcGVydGllcyI6eyJtZXRob2QiOnsiZW51bSI6WyJHRVQiXSwidHlwZSI6InN0cmluZyJ9LCJxdWVyeVBhcmFtcyI6eyJwcm9wZXJ0aWVzIjp7InVybCI6eyJkZXNjcmlwdGlvbiI6IkFic29sdXRlIGh0dHAvaHR0cHMgVVJMIHRvIGF1ZGl0LiBIb3N0IG11c3QgYmUgYSBob3N0bmFtZSAobm90IGFuIElQIGxpdGVyYWwpLCBub3QgXCJsb2NhbGhvc3RcIiwgYW5kIG5vdCB1bmRlciBhIHJlc2VydmVkIHN1ZmZpeCAoLmxvY2FsLCAuaW50ZXJuYWwsIC5sb2NhbGRvbWFpbiwgLmxhbiwgLnRlc3QpLiBOb24tZGVmYXVsdCBwb3J0cyBtdXN0IGJlIGFsbG93bGlzdGVkLiBSZWRpcmVjdHMgYXJlIG5vdCBmb2xsb3dlZC4iLCJmb3JtYXQiOiJ1cmkiLCJ0eXBlIjoic3RyaW5nIn19LCJyZXF1aXJlZCI6WyJ1cmwiXSwidHlwZSI6Im9iamVjdCJ9LCJ0eXBlIjp7ImNvbnN0IjoiaHR0cCIsInR5cGUiOiJzdHJpbmcifX0sInJlcXVpcmVkIjpbInR5cGUiLCJtZXRob2QiXSwidHlwZSI6Im9iamVjdCJ9LCJvdXRwdXQiOnsicHJvcGVydGllcyI6eyJleGFtcGxlIjp7InByb3BlcnRpZXMiOnsiaGVhZGVycyI6eyJkZXNjcmlwdGlvbiI6IkdyYWRlZCwgbm9ybWFsaXplZCBzZWN1cml0eSBoZWFkZXJzLiBFYWNoIGZpZWxkIGlzIG51bGwgd2hlbiB0aGUgaGVhZGVyIGlzIGFic2VudCBmcm9tIHRoZSByZXNwb25zZSIsInByb3BlcnRpZXMiOnsiY29udGVudF9zZWN1cml0eV9wb2xpY3kiOnsidHlwZSI6WyJzdHJpbmciLCJudWxsIl19LCJwZXJtaXNzaW9uc19wb2xpY3kiOnsidHlwZSI6WyJzdHJpbmciLCJudWxsIl19LCJyZWZlcnJlcl9wb2xpY3kiOnsidHlwZSI6WyJzdHJpbmciLCJudWxsIl19LCJzZXJ2ZXIiOnsiZGVzY3JpcHRpb24iOiJTZXJ2ZXIgaGVhZGVyIHZhbHVlLCBpZiBkaXNjbG9zZWQgYnkgdGhlIHRhcmdldCIsInR5cGUiOlsic3RyaW5nIiwibnVsbCJdfSwic3RyaWN0X3RyYW5zcG9ydF9zZWN1cml0eSI6eyJwcm9wZXJ0aWVzIjp7ImluY2x1ZGVfc3ViZG9tYWlucyI6eyJ0eXBlIjoiYm9vbGVhbiJ9LCJtYXhfYWdlIjp7ImRlc2NyaXB0aW9uIjoiUGFyc2VkIG1heC1hZ2UgaW4gc2Vjb25kczsgbnVsbCBpZiBhYnNlbnQgb3IgdW5wYXJzZWFibGUiLCJ0eXBlIjpbImludGVnZXIiLCJudWxsIl19LCJwcmVsb2FkIjp7InR5cGUiOiJib29sZWFuIn0sInZhbHVlIjp7ImRlc2NyaXB0aW9uIjoiUmF3IFN0cmljdC1UcmFuc3BvcnQtU2VjdXJpdHkgaGVhZGVyIHZhbHVlIiwidHlwZSI6InN0cmluZyJ9fSwidHlwZSI6WyJvYmplY3QiLCJudWxsIl19LCJ4X2NvbnRlbnRfdHlwZV9vcHRpb25zIjp7InR5cGUiOlsic3RyaW5nIiwibnVsbCJdfSwieF9mcmFtZV9vcHRpb25zIjp7InR5cGUiOlsic3RyaW5nIiwibnVsbCJdfSwieF9wb3dlcmVkX2J5Ijp7ImRlc2NyaXB0aW9uIjoiWC1Qb3dlcmVkLUJ5IGhlYWRlciB2YWx1ZSwgaWYgZGlzY2xvc2VkIGJ5IHRoZSB0YXJnZXQiLCJ0eXBlIjpbInN0cmluZyIsIm51bGwiXX19LCJ0eXBlIjoib2JqZWN0In0sInF1ZXJpZWRfYXQiOnsiZGVzY3JpcHRpb24iOiJVVEMgdGltZXN0YW1wIHRoZSBhdWRpdCB3YXMgcGVyZm9ybWVkIiwiZm9ybWF0IjoiZGF0ZS10aW1lIiwidHlwZSI6InN0cmluZyJ9LCJzdGF0dXNfY29kZSI6eyJkZXNjcmlwdGlvbiI6IkhUVFAgc3RhdHVzIGNvZGUgcmV0dXJuZWQgYnkgdGhlIHRhcmdldCBmb3IgdGhlIEhFQUQgcmVxdWVzdCIsInR5cGUiOiJpbnRlZ2VyIn0sInVybCI6eyJkZXNjcmlwdGlvbiI6IlRoZSBhdWRpdGVkIFVSTCwgZXhhY3RseSBhcyBnaXZlbiIsInR5cGUiOiJzdHJpbmcifSwid2FybmluZ3MiOnsiZGVzY3JpcHRpb24iOiJIdW1hbi1yZWFkYWJsZSBwb3N0dXJlIGFkdmlzb3JpZXMsIGUuZy4gbWlzc2luZyBvciB3ZWFrIGhlYWRlcnMiLCJpdGVtcyI6eyJ0eXBlIjoic3RyaW5nIn0sInR5cGUiOiJhcnJheSJ9fSwicmVxdWlyZWQiOlsidXJsIiwic3RhdHVzX2NvZGUiLCJxdWVyaWVkX2F0IiwiaGVhZGVycyIsIndhcm5pbmdzIl0sInR5cGUiOiJvYmplY3QifSwidHlwZSI6eyJ0eXBlIjoic3RyaW5nIn19LCJyZXF1aXJlZCI6WyJ0eXBlIl0sInR5cGUiOiJvYmplY3QifX0sInJlcXVpcmVkIjpbImlucHV0Il0sInR5cGUiOiJvYmplY3QifSwidGFncyI6WyJodHRwIiwiaGVhZGVycyIsInNlY3VyaXR5IiwiaHN0cyIsImNzcCIsIngtZnJhbWUtb3B0aW9ucyIsInBvc3R1cmUiXX19fQ==",
"via": "1.1 Caddy",
"x-request-id": "f10a0d85-97da-47d7-82ec-dc7d9e42941c"
}
Response body
{
"accepts": [
{
"amount": "10000",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:8453",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
{
"amount": "10000",
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:137",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
{
"amount": "10000",
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"extra": {
"merchant": "x402Atlas",
"name": "USD Coin",
"tier": "standard",
"version": "2"
},
"maxTimeoutSeconds": 300,
"network": "eip155:42161",
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"scheme": "exact"
},
{
"amount": "10000",
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"extra": {
"feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
"merchant": "x402Atlas",
"tier": "standard"
},
"maxTimeoutSeconds": 300,
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"scheme": "exact"
}
],
"contact": {
"email": "support@x402atlas.com"
},
"documentation": "https://headers.use.x402atlas.com/docs",
"error": "payment_required",
"hint": "This endpoint requires x402 payment. The price and payment options are in the PAYMENT-REQUIRED response header (x402 v2). Pay with an x402 client, then retry to receive the data.",
"llms": "https://headers.use.x402atlas.com/llms.txt",
"method": "GET",
"openapi": "https://headers.use.x402atlas.com/openapi.json",
"price": "$0.01 per call",
"resource": {
"description": "Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.",
"mimeType": "application/json",
"serviceName": "HTTP Security Headers Check",
"tags": [
"http",
"headers",
"security",
"hsts",
"csp",
"x-frame-options",
"posture"
],
"url": "https://headers.use.x402atlas.com/"
},
"x402Version": 2
}
Request headers
{
"accept": "*/*",
"user-agent": "Fetch402Bot/0.1 (+https://fetch402.com/crawler; contact: crawler@fetch402.com)"
}
Machine contract
Schemas.
{
"method": "GET",
"queryParams": {
"url": "https://example.com/"
},
"type": "http"
}
{
"example": {
"headers": {
"content_security_policy": "default-src 'self'",
"permissions_policy": null,
"referrer_policy": "strict-origin-when-cross-origin",
"server": null,
"strict_transport_security": {
"include_subdomains": true,
"max_age": 31536000,
"preload": false,
"value": "max-age=31536000; includeSubDomains"
},
"x_content_type_options": "nosniff",
"x_frame_options": "DENY",
"x_powered_by": null
},
"queried_at": "2026-07-03T12:00:00Z",
"status_code": 200,
"url": "https://example.com/",
"warnings": [
"no Permissions-Policy header (powerful browser features are not restricted)"
]
},
"type": "json"
}