Http Headers X402
About
Analyze HTTP response headers -- security score, HSTS/CSP check, server detection, caching config. Score 0-100. -- x402 micropayment API + MCP server for AI agents
Details
- Author
- Br0ski777
- Downloads
- 217
- Categories
- Developer Tools
Jump to
- Security score from 0 to 100 based on headers
- Checks HSTS, CSP, X‑Frame‑Options, X‑Content‑Type‑Options
- Detects server software (e.g., nginx, Apache)
- Reports caching configuration (Cache‑Control, ETag)
- Pay‑per‑call via x402 (USDC on Base L2)
- No API key, no signup, no rate‑limit walls
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Http Headers X402Command (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Add the server URL to your MCP client configuration (Claude Desktop, Cursor, ElizaOS, etc.) using the endpoint https://http-headers.api.klymax402.com/mcp. The server exposes one tool: network_analyze_headers. To call it from an x402‑aware client (e.g., @x402/fetch, x402-agent-tools, ATXP), send a POST request to https://http-headers.api.klymax402.com/api/analyze with a JSON body containing the url parameter. The client automatically handles the 402 payment challenge, signs it, and retries the request.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"http headers x402": {
"http-headers": {
"url": "https://http-headers-production.up.railway.app/mcp",
"transport": "sse"
}
}
}
}
McpServers
{
"http-headers": {
"url": "https://http-headers-production.up.railway.app/mcp",
"transport": "sse"
}
}
HTTP Headers Analyzer API
Analyze HTTP response headers -- security score, HSTS/CSP check, server detection, caching config. Score 0-100. Pay-per-call via x402 (USDC on Base L2) -- no API key, no signup, no rate-limit wall.
Part of the klymax402 marketplace -- 100 x402 micropayment APIs for AI agents, one wallet, USDC on Base.
Quickstart -- MCP
Add to your MCP client config (Claude Desktop, Cursor, ElizaOS, etc.):
{
"mcpServers": {
"http-headers": {
"url": "https://http-headers.api.klymax402.com/mcp"
}
}
}
Quickstart -- HTTP (x402)
curl -X POST "https://http-headers.api.klymax402.com/api/analyze" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com"}'
-> 402 Payment Required, with an x402 payment challenge in the response body
Any x402-aware client (@x402/fetch, x402-agent-tools, ATXP) handles the 402 -> sign -> retry cycle automatically.
Tools
| Tool | Method | Path | Price | Description |
|---|---|---|---|---|
| network_analyze_headers | POST | /api/analyze | $0.001 | Analyze HTTP response headers for a URL |
network_analyze_headers
Use this when you need to analyze HTTP response headers of a URL for security and configuration. Returns a full header audit in JSON.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| url | string | yes | Full URL to analyze (e.g. https://example.com) |
Example response:
{"url":"https://example.com","securityScore":85,"securityHeaders":{"hsts":true,"csp":true,"xFrameOptions":true,"xContentType":true,"referrerPolicy":false},"server":"nginx","caching":{"cacheControl":"max-age=3600","etag":true},"recommendations":["Add Referrer-Policy header"]}
When to use: security audits, DevOps monitoring, compliance checks, and verifying proper header configuration after deployment.
Not for: SSL certificate check (use security_check_ssl), web scraping (use web_scrape_to_markdown), GDPR compliance (use compliance_scan_gdpr).
Example agent prompts
- "Analyze HTTP response headers of a URL for security and configuration"
Payment
- Protocol: x402 -- HTTP-native pay-per-call, no signup, no API key
- Network: Base L2 (eip155:8453)
- Asset: USDC
- Facilitator: Coinbase CDP (primary), PayAI (fallback)
- Also reachable via ATXP (OAuth-wrapped x402, RFC 9728 protected-resource metadata)
Part of klymax402
100 x402 micropayment APIs for AI agents -- one wallet, USDC on Base, zero signup.
- Catalog: https://klymax402.com/llms.txt
- Full API reference: https://klymax402.com/llms-full.txt
- Live stats: https://klymax402.com/stats
License
MIT
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





