FETCH402
← Protocol index

Resource / 269

healthy

HTTP Security Headers Check.

Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.

Eligibility
probeable
Failures
0
Last quote
2026-08-12 22:00:02 UTC
Last probe
2026-08-12 22:00:02 UTC
Payment requirements / accepts[] 4 options
State Network Scheme Atomic amount Asset payTo / untrusted
active eip155:8453 exact 10000 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c
active eip155:137 exact 10000 0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359 0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c
active eip155:42161 exact 10000 0xaf88d065e77c8cC2239327C5EDb3A432268e5831 0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c
active solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp exact 10000 EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ

All advertised payment options are stored. Base (`eip155:8453`) is the operational network for ranking and canaries; non-Base options remain visible for transparency.

Probe evidence 1 recent
healthy 2026-08-12 22:00:02 UTC GET · HTTP 402 · 4ms · accepts 4 · base 1 ok
Request
GET https://headers.use.x402atlas.com/
Robots
error
Note
robots_error:{:robots_http_status, 404};http_402;accepts=4;base=1
Accepts fingerprint
23df52d0080e1b8556807cb11a31ce4d19fe90ae505f731e23f278b0595a48f3

Accepts snapshot

[
  {
    "amount": "10000",
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "assetTransferMethod": null,
    "extra": {
      "merchant": "x402Atlas",
      "name": "USD Coin",
      "tier": "standard",
      "version": "2"
    },
    "maxTimeoutSeconds": 300,
    "network": "eip155:8453",
    "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
    "paymentFlow": null,
    "raw": {
      "amount": "10000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "max_timeout_seconds": 300,
      "network": "eip155:8453",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "pay_to": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    "scheme": "exact"
  },
  {
    "amount": "10000",
    "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
    "assetTransferMethod": null,
    "extra": {
      "merchant": "x402Atlas",
      "name": "USD Coin",
      "tier": "standard",
      "version": "2"
    },
    "maxTimeoutSeconds": 300,
    "network": "eip155:137",
    "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
    "paymentFlow": null,
    "raw": {
      "amount": "10000",
      "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "max_timeout_seconds": 300,
      "network": "eip155:137",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "pay_to": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    "scheme": "exact"
  },
  {
    "amount": "10000",
    "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
    "assetTransferMethod": null,
    "extra": {
      "merchant": "x402Atlas",
      "name": "USD Coin",
      "tier": "standard",
      "version": "2"
    },
    "maxTimeoutSeconds": 300,
    "network": "eip155:42161",
    "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
    "paymentFlow": null,
    "raw": {
      "amount": "10000",
      "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "max_timeout_seconds": 300,
      "network": "eip155:42161",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "pay_to": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    "scheme": "exact"
  },
  {
    "amount": "10000",
    "asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
    "assetTransferMethod": null,
    "extra": {
      "feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
      "merchant": "x402Atlas",
      "tier": "standard"
    },
    "maxTimeoutSeconds": 300,
    "network": "solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp",
    "payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
    "paymentFlow": null,
    "raw": {
      "amount": "10000",
      "asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
      "extra": {
        "feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
        "merchant": "x402Atlas",
        "tier": "standard"
      },
      "maxTimeoutSeconds": 300,
      "max_timeout_seconds": 300,
      "network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
      "payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
      "pay_to": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
      "scheme": "exact"
    },
    "scheme": "exact"
  }
]

PaymentRequired raw

{
  "accepts": [
    {
      "amount": "10000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "network": "eip155:8453",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    {
      "amount": "10000",
      "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "network": "eip155:137",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    {
      "amount": "10000",
      "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "network": "eip155:42161",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    {
      "amount": "10000",
      "asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
      "extra": {
        "feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
        "merchant": "x402Atlas",
        "tier": "standard"
      },
      "maxTimeoutSeconds": 300,
      "network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
      "payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
      "scheme": "exact"
    }
  ],
  "error": "Payment required",
  "extensions": {
    "bazaar": {
      "category": "domain-intelligence",
      "info": {
        "input": {
          "method": "GET",
          "queryParams": {
            "url": "https://example.com/"
          },
          "type": "http"
        },
        "output": {
          "example": {
            "headers": {
              "content_security_policy": "default-src 'self'",
              "permissions_policy": null,
              "referrer_policy": "strict-origin-when-cross-origin",
              "server": null,
              "strict_transport_security": {
                "include_subdomains": true,
                "max_age": 31536000,
                "preload": false,
                "value": "max-age=31536000; includeSubDomains"
              },
              "x_content_type_options": "nosniff",
              "x_frame_options": "DENY",
              "x_powered_by": null
            },
            "queried_at": "2026-07-03T12:00:00Z",
            "status_code": 200,
            "url": "https://example.com/",
            "warnings": [
              "no Permissions-Policy header (powerful browser features are not restricted)"
            ]
          },
          "type": "json"
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "properties": {
          "input": {
            "additionalProperties": false,
            "properties": {
              "method": {
                "enum": [
                  "GET"
                ],
                "type": "string"
              },
              "queryParams": {
                "properties": {
                  "url": {
                    "description": "Absolute http/https URL to audit. Host must be a hostname (not an IP literal), not \"localhost\", and not under a reserved suffix (.local, .internal, .localdomain, .lan, .test). Non-default ports must be allowlisted. Redirects are not followed.",
                    "format": "uri",
                    "type": "string"
                  }
                },
                "required": [
                  "url"
                ],
                "type": "object"
              },
              "type": {
                "const": "http",
                "type": "string"
              }
            },
            "required": [
              "type",
              "method"
            ],
            "type": "object"
          },
          "output": {
            "properties": {
              "example": {
                "properties": {
                  "headers": {
                    "description": "Graded, normalized security headers. Each field is null when the header is absent from the response",
                    "properties": {
                      "content_security_policy": {
                        "type": [
                          "string",
                          "null"
                        ]
                      },
                      "permissions_policy": {
                        "type": [
                          "string",
                          "null"
                        ]
                      },
                      "referrer_policy": {
                        "type": [
                          "string",
                          "null"
                        ]
                      },
                      "server": {
                        "description": "Server header value, if disclosed by the target",
                        "type": [
                          "string",
                          "null"
                        ]
                      },
                      "strict_transport_security": {
                        "properties": {
                          "include_subdomains": {
                            "type": "boolean"
                          },
                          "max_age": {
                            "description": "Parsed max-age in seconds; null if absent or unparseable",
                            "type": [
                              "integer",
                              "null"
                            ]
                          },
                          "preload": {
                            "type": "boolean"
                          },
                          "value": {
                            "description": "Raw Strict-Transport-Security header value",
                            "type": "string"
                          }
                        },
                        "type": [
                          "object",
                          "null"
                        ]
                      },
                      "x_content_type_options": {
                        "type": [
                          "string",
                          "null"
                        ]
                      },
                      "x_frame_options": {
                        "type": [
                          "string",
                          "null"
                        ]
                      },
                      "x_powered_by": {
                        "description": "X-Powered-By header value, if disclosed by the target",
                        "type": [
                          "string",
                          "null"
                        ]
                      }
                    },
                    "type": "object"
                  },
                  "queried_at": {
                    "description": "UTC timestamp the audit was performed",
                    "format": "date-time",
                    "type": "string"
                  },
                  "status_code": {
                    "description": "HTTP status code returned by the target for the HEAD request",
                    "type": "integer"
                  },
                  "url": {
                    "description": "The audited URL, exactly as given",
                    "type": "string"
                  },
                  "warnings": {
                    "description": "Human-readable posture advisories, e.g. missing or weak headers",
                    "items": {
                      "type": "string"
                    },
                    "type": "array"
                  }
                },
                "required": [
                  "url",
                  "status_code",
                  "queried_at",
                  "headers",
                  "warnings"
                ],
                "type": "object"
              },
              "type": {
                "type": "string"
              }
            },
            "required": [
              "type"
            ],
            "type": "object"
          }
        },
        "required": [
          "input"
        ],
        "type": "object"
      },
      "tags": [
        "http",
        "headers",
        "security",
        "hsts",
        "csp",
        "x-frame-options",
        "posture"
      ]
    }
  },
  "resource": {
    "description": "Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.",
    "mimeType": "application/json",
    "serviceName": "HTTP Security Headers Check",
    "tags": [
      "http",
      "headers",
      "security",
      "hsts",
      "csp",
      "x-frame-options",
      "posture"
    ],
    "url": "https://headers.use.x402atlas.com/"
  },
  "x402Version": 2
}

Response headers

{
  "alt-svc": "h3=\":443\"; ma=2592000",
  "content-length": "2243",
  "content-type": "application/json",
  "date": "Wed, 12 Aug 2026 22:00:02 GMT",
  "payment-required": "eyJ4NDAyVmVyc2lvbiI6MiwiZXJyb3IiOiJQYXltZW50IHJlcXVpcmVkIiwicmVzb3VyY2UiOnsidXJsIjoiaHR0cHM6Ly9oZWFkZXJzLnVzZS54NDAyYXRsYXMuY29tLyIsImRlc2NyaXB0aW9uIjoiQXVkaXQgYSBVUkwncyBIVFRQIHNlY3VyaXR5IGhlYWRlcnMgb3ZlciBhIHNpbmdsZSBib2R5LWZyZWUgKEhFQUQpIHJlcXVlc3QuIEdyYWRlcyBTdHJpY3QtVHJhbnNwb3J0LVNlY3VyaXR5LCBDb250ZW50LVNlY3VyaXR5LVBvbGljeSwgWC1GcmFtZS1PcHRpb25zLCBYLUNvbnRlbnQtVHlwZS1PcHRpb25zLCBSZWZlcnJlci1Qb2xpY3kgYW5kIFBlcm1pc3Npb25zLVBvbGljeSwgZmxhZ3MgaW5mb3JtYXRpb24tbGVhayBoZWFkZXJzIChTZXJ2ZXIsIFgtUG93ZXJlZC1CeSksIGFuZCByZXR1cm5zIHRoZSBwYXJzZWQgdmFsdWVzIHBsdXMgYWR2aXNvcnkgd2FybmluZ3MuIENsZWFuIEpTT04gZm9yIHNlY3VyaXR5IGFuZCBwZW50ZXN0IGF1dG9tYXRpb24uIiwibWltZVR5cGUiOiJhcHBsaWNhdGlvbi9qc29uIiwic2VydmljZU5hbWUiOiJIVFRQIFNlY3VyaXR5IEhlYWRlcnMgQ2hlY2siLCJ0YWdzIjpbImh0dHAiLCJoZWFkZXJzIiwic2VjdXJpdHkiLCJoc3RzIiwiY3NwIiwieC1mcmFtZS1vcHRpb25zIiwicG9zdHVyZSJdfSwiYWNjZXB0cyI6W3sic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoiZWlwMTU1Ojg0NTMiLCJhc3NldCI6IjB4ODMzNTg5ZkNENmVEYjZFMDhmNGM3QzMyRDRmNzFiNTRiZEEwMjkxMyIsImFtb3VudCI6IjEwMDAwIiwicGF5VG8iOiIweDdmODA0M2M0MDA3OTk2NDNiY2I2MkI0MUI4NGIyOTdhOEVjYjdiOWMiLCJtYXhUaW1lb3V0U2Vjb25kcyI6MzAwLCJleHRyYSI6eyJtZXJjaGFudCI6Ing0MDJBdGxhcyIsIm5hbWUiOiJVU0QgQ29pbiIsInRpZXIiOiJzdGFuZGFyZCIsInZlcnNpb24iOiIyIn19LHsic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoiZWlwMTU1OjEzNyIsImFzc2V0IjoiMHgzYzQ5OWM1NDJjRUY1RTM4MTFlMTE5MmNlNzBkOGNDMDNkNWMzMzU5IiwiYW1vdW50IjoiMTAwMDAiLCJwYXlUbyI6IjB4N2Y4MDQzYzQwMDc5OTY0M2JjYjYyQjQxQjg0YjI5N2E4RWNiN2I5YyIsIm1heFRpbWVvdXRTZWNvbmRzIjozMDAsImV4dHJhIjp7Im1lcmNoYW50IjoieDQwMkF0bGFzIiwibmFtZSI6IlVTRCBDb2luIiwidGllciI6InN0YW5kYXJkIiwidmVyc2lvbiI6IjIifX0seyJzY2hlbWUiOiJleGFjdCIsIm5ldHdvcmsiOiJlaXAxNTU6NDIxNjEiLCJhc3NldCI6IjB4YWY4OGQwNjVlNzdjOGNDMjIzOTMyN0M1RURiM0E0MzIyNjhlNTgzMSIsImFtb3VudCI6IjEwMDAwIiwicGF5VG8iOiIweDdmODA0M2M0MDA3OTk2NDNiY2I2MkI0MUI4NGIyOTdhOEVjYjdiOWMiLCJtYXhUaW1lb3V0U2Vjb25kcyI6MzAwLCJleHRyYSI6eyJtZXJjaGFudCI6Ing0MDJBdGxhcyIsIm5hbWUiOiJVU0QgQ29pbiIsInRpZXIiOiJzdGFuZGFyZCIsInZlcnNpb24iOiIyIn19LHsic2NoZW1lIjoiZXhhY3QiLCJuZXR3b3JrIjoic29sYW5hOjVleWt0NFVzRnY4UDhOSmRUUkVwWTF2enFLcVpLdmRwIiwiYXNzZXQiOiJFUGpGV2RkNUF1ZnFTU3FlTTJxTjF4enliYXBDOEc0d0VHR2tad3lURHQxdiIsImFtb3VudCI6IjEwMDAwIiwicGF5VG8iOiJBU3Q2eHZSeVE3bnRFUnNtY1lWTWRMcVp2ejFHRU44RnpleHpxNjJ0WHJOUSIsIm1heFRpbWVvdXRTZWNvbmRzIjozMDAsImV4dHJhIjp7ImZlZVBheWVyIjoiQkVOckxvVWJuZHhvTk1VUzVKWEFwR010TnlrTGpGWFhpeE10cER3RFI5U1AiLCJtZXJjaGFudCI6Ing0MDJBdGxhcyIsInRpZXIiOiJzdGFuZGFyZCJ9fV0sImV4dGVuc2lvbnMiOnsiYmF6YWFyIjp7ImNhdGVnb3J5IjoiZG9tYWluLWludGVsbGlnZW5jZSIsImluZm8iOnsiaW5wdXQiOnsibWV0aG9kIjoiR0VUIiwicXVlcnlQYXJhbXMiOnsidXJsIjoiaHR0cHM6Ly9leGFtcGxlLmNvbS8ifSwidHlwZSI6Imh0dHAifSwib3V0cHV0Ijp7ImV4YW1wbGUiOnsiaGVhZGVycyI6eyJjb250ZW50X3NlY3VyaXR5X3BvbGljeSI6ImRlZmF1bHQtc3JjICdzZWxmJyIsInBlcm1pc3Npb25zX3BvbGljeSI6bnVsbCwicmVmZXJyZXJfcG9saWN5Ijoic3RyaWN0LW9yaWdpbi13aGVuLWNyb3NzLW9yaWdpbiIsInNlcnZlciI6bnVsbCwic3RyaWN0X3RyYW5zcG9ydF9zZWN1cml0eSI6eyJpbmNsdWRlX3N1YmRvbWFpbnMiOnRydWUsIm1heF9hZ2UiOjMxNTM2MDAwLCJwcmVsb2FkIjpmYWxzZSwidmFsdWUiOiJtYXgtYWdlPTMxNTM2MDAwOyBpbmNsdWRlU3ViRG9tYWlucyJ9LCJ4X2NvbnRlbnRfdHlwZV9vcHRpb25zIjoibm9zbmlmZiIsInhfZnJhbWVfb3B0aW9ucyI6IkRFTlkiLCJ4X3Bvd2VyZWRfYnkiOm51bGx9LCJxdWVyaWVkX2F0IjoiMjAyNi0wNy0wM1QxMjowMDowMFoiLCJzdGF0dXNfY29kZSI6MjAwLCJ1cmwiOiJodHRwczovL2V4YW1wbGUuY29tLyIsIndhcm5pbmdzIjpbIm5vIFBlcm1pc3Npb25zLVBvbGljeSBoZWFkZXIgKHBvd2VyZnVsIGJyb3dzZXIgZmVhdHVyZXMgYXJlIG5vdCByZXN0cmljdGVkKSJdfSwidHlwZSI6Impzb24ifX0sInNjaGVtYSI6eyIkc2NoZW1hIjoiaHR0cHM6Ly9qc29uLXNjaGVtYS5vcmcvZHJhZnQvMjAyMC0xMi9zY2hlbWEiLCJwcm9wZXJ0aWVzIjp7ImlucHV0Ijp7ImFkZGl0aW9uYWxQcm9wZXJ0aWVzIjpmYWxzZSwicHJvcGVydGllcyI6eyJtZXRob2QiOnsiZW51bSI6WyJHRVQiXSwidHlwZSI6InN0cmluZyJ9LCJxdWVyeVBhcmFtcyI6eyJwcm9wZXJ0aWVzIjp7InVybCI6eyJkZXNjcmlwdGlvbiI6IkFic29sdXRlIGh0dHAvaHR0cHMgVVJMIHRvIGF1ZGl0LiBIb3N0IG11c3QgYmUgYSBob3N0bmFtZSAobm90IGFuIElQIGxpdGVyYWwpLCBub3QgXCJsb2NhbGhvc3RcIiwgYW5kIG5vdCB1bmRlciBhIHJlc2VydmVkIHN1ZmZpeCAoLmxvY2FsLCAuaW50ZXJuYWwsIC5sb2NhbGRvbWFpbiwgLmxhbiwgLnRlc3QpLiBOb24tZGVmYXVsdCBwb3J0cyBtdXN0IGJlIGFsbG93bGlzdGVkLiBSZWRpcmVjdHMgYXJlIG5vdCBmb2xsb3dlZC4iLCJmb3JtYXQiOiJ1cmkiLCJ0eXBlIjoic3RyaW5nIn19LCJyZXF1aXJlZCI6WyJ1cmwiXSwidHlwZSI6Im9iamVjdCJ9LCJ0eXBlIjp7ImNvbnN0IjoiaHR0cCIsInR5cGUiOiJzdHJpbmcifX0sInJlcXVpcmVkIjpbInR5cGUiLCJtZXRob2QiXSwidHlwZSI6Im9iamVjdCJ9LCJvdXRwdXQiOnsicHJvcGVydGllcyI6eyJleGFtcGxlIjp7InByb3BlcnRpZXMiOnsiaGVhZGVycyI6eyJkZXNjcmlwdGlvbiI6IkdyYWRlZCwgbm9ybWFsaXplZCBzZWN1cml0eSBoZWFkZXJzLiBFYWNoIGZpZWxkIGlzIG51bGwgd2hlbiB0aGUgaGVhZGVyIGlzIGFic2VudCBmcm9tIHRoZSByZXNwb25zZSIsInByb3BlcnRpZXMiOnsiY29udGVudF9zZWN1cml0eV9wb2xpY3kiOnsidHlwZSI6WyJzdHJpbmciLCJudWxsIl19LCJwZXJtaXNzaW9uc19wb2xpY3kiOnsidHlwZSI6WyJzdHJpbmciLCJudWxsIl19LCJyZWZlcnJlcl9wb2xpY3kiOnsidHlwZSI6WyJzdHJpbmciLCJudWxsIl19LCJzZXJ2ZXIiOnsiZGVzY3JpcHRpb24iOiJTZXJ2ZXIgaGVhZGVyIHZhbHVlLCBpZiBkaXNjbG9zZWQgYnkgdGhlIHRhcmdldCIsInR5cGUiOlsic3RyaW5nIiwibnVsbCJdfSwic3RyaWN0X3RyYW5zcG9ydF9zZWN1cml0eSI6eyJwcm9wZXJ0aWVzIjp7ImluY2x1ZGVfc3ViZG9tYWlucyI6eyJ0eXBlIjoiYm9vbGVhbiJ9LCJtYXhfYWdlIjp7ImRlc2NyaXB0aW9uIjoiUGFyc2VkIG1heC1hZ2UgaW4gc2Vjb25kczsgbnVsbCBpZiBhYnNlbnQgb3IgdW5wYXJzZWFibGUiLCJ0eXBlIjpbImludGVnZXIiLCJudWxsIl19LCJwcmVsb2FkIjp7InR5cGUiOiJib29sZWFuIn0sInZhbHVlIjp7ImRlc2NyaXB0aW9uIjoiUmF3IFN0cmljdC1UcmFuc3BvcnQtU2VjdXJpdHkgaGVhZGVyIHZhbHVlIiwidHlwZSI6InN0cmluZyJ9fSwidHlwZSI6WyJvYmplY3QiLCJudWxsIl19LCJ4X2NvbnRlbnRfdHlwZV9vcHRpb25zIjp7InR5cGUiOlsic3RyaW5nIiwibnVsbCJdfSwieF9mcmFtZV9vcHRpb25zIjp7InR5cGUiOlsic3RyaW5nIiwibnVsbCJdfSwieF9wb3dlcmVkX2J5Ijp7ImRlc2NyaXB0aW9uIjoiWC1Qb3dlcmVkLUJ5IGhlYWRlciB2YWx1ZSwgaWYgZGlzY2xvc2VkIGJ5IHRoZSB0YXJnZXQiLCJ0eXBlIjpbInN0cmluZyIsIm51bGwiXX19LCJ0eXBlIjoib2JqZWN0In0sInF1ZXJpZWRfYXQiOnsiZGVzY3JpcHRpb24iOiJVVEMgdGltZXN0YW1wIHRoZSBhdWRpdCB3YXMgcGVyZm9ybWVkIiwiZm9ybWF0IjoiZGF0ZS10aW1lIiwidHlwZSI6InN0cmluZyJ9LCJzdGF0dXNfY29kZSI6eyJkZXNjcmlwdGlvbiI6IkhUVFAgc3RhdHVzIGNvZGUgcmV0dXJuZWQgYnkgdGhlIHRhcmdldCBmb3IgdGhlIEhFQUQgcmVxdWVzdCIsInR5cGUiOiJpbnRlZ2VyIn0sInVybCI6eyJkZXNjcmlwdGlvbiI6IlRoZSBhdWRpdGVkIFVSTCwgZXhhY3RseSBhcyBnaXZlbiIsInR5cGUiOiJzdHJpbmcifSwid2FybmluZ3MiOnsiZGVzY3JpcHRpb24iOiJIdW1hbi1yZWFkYWJsZSBwb3N0dXJlIGFkdmlzb3JpZXMsIGUuZy4gbWlzc2luZyBvciB3ZWFrIGhlYWRlcnMiLCJpdGVtcyI6eyJ0eXBlIjoic3RyaW5nIn0sInR5cGUiOiJhcnJheSJ9fSwicmVxdWlyZWQiOlsidXJsIiwic3RhdHVzX2NvZGUiLCJxdWVyaWVkX2F0IiwiaGVhZGVycyIsIndhcm5pbmdzIl0sInR5cGUiOiJvYmplY3QifSwidHlwZSI6eyJ0eXBlIjoic3RyaW5nIn19LCJyZXF1aXJlZCI6WyJ0eXBlIl0sInR5cGUiOiJvYmplY3QifX0sInJlcXVpcmVkIjpbImlucHV0Il0sInR5cGUiOiJvYmplY3QifSwidGFncyI6WyJodHRwIiwiaGVhZGVycyIsInNlY3VyaXR5IiwiaHN0cyIsImNzcCIsIngtZnJhbWUtb3B0aW9ucyIsInBvc3R1cmUiXX19fQ==",
  "via": "1.1 Caddy",
  "x-request-id": "f10a0d85-97da-47d7-82ec-dc7d9e42941c"
}

Response body

{
  "accepts": [
    {
      "amount": "10000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "network": "eip155:8453",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    {
      "amount": "10000",
      "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "network": "eip155:137",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    {
      "amount": "10000",
      "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
      "extra": {
        "merchant": "x402Atlas",
        "name": "USD Coin",
        "tier": "standard",
        "version": "2"
      },
      "maxTimeoutSeconds": 300,
      "network": "eip155:42161",
      "payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
      "scheme": "exact"
    },
    {
      "amount": "10000",
      "asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
      "extra": {
        "feePayer": "BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP",
        "merchant": "x402Atlas",
        "tier": "standard"
      },
      "maxTimeoutSeconds": 300,
      "network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
      "payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
      "scheme": "exact"
    }
  ],
  "contact": {
    "email": "support@x402atlas.com"
  },
  "documentation": "https://headers.use.x402atlas.com/docs",
  "error": "payment_required",
  "hint": "This endpoint requires x402 payment. The price and payment options are in the PAYMENT-REQUIRED response header (x402 v2). Pay with an x402 client, then retry to receive the data.",
  "llms": "https://headers.use.x402atlas.com/llms.txt",
  "method": "GET",
  "openapi": "https://headers.use.x402atlas.com/openapi.json",
  "price": "$0.01 per call",
  "resource": {
    "description": "Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.",
    "mimeType": "application/json",
    "serviceName": "HTTP Security Headers Check",
    "tags": [
      "http",
      "headers",
      "security",
      "hsts",
      "csp",
      "x-frame-options",
      "posture"
    ],
    "url": "https://headers.use.x402atlas.com/"
  },
  "x402Version": 2
}

Request headers

{
  "accept": "*/*",
  "user-agent": "Fetch402Bot/0.1 (+https://fetch402.com/crawler; contact: crawler@fetch402.com)"
}

Machine contract

Schemas.

InputJSON
{
  "method": "GET",
  "queryParams": {
    "url": "https://example.com/"
  },
  "type": "http"
}
OutputJSON
{
  "example": {
    "headers": {
      "content_security_policy": "default-src 'self'",
      "permissions_policy": null,
      "referrer_policy": "strict-origin-when-cross-origin",
      "server": null,
      "strict_transport_security": {
        "include_subdomains": true,
        "max_age": 31536000,
        "preload": false,
        "value": "max-age=31536000; includeSubDomains"
      },
      "x_content_type_options": "nosniff",
      "x_frame_options": "DENY",
      "x_powered_by": null
    },
    "queried_at": "2026-07-03T12:00:00Z",
    "status_code": 200,
    "url": "https://example.com/",
    "warnings": [
      "no Permissions-Policy header (powerful browser features are not restricted)"
    ]
  },
  "type": "json"
}