Http Headers X402

by Br0ski777

217 downloads
Not rated
GitHub

About

Analyze HTTP response headers -- security score, HSTS/CSP check, server detection, caching config. Score 0-100. -- x402 micropayment API + MCP server for AI agents

Details

Author
Br0ski777
Downloads
217
Categories
Developer Tools

- Security score from 0 to 100 based on headers
- Checks HSTS, CSP, X‑Frame‑Options, X‑Content‑Type‑Options
- Detects server software (e.g., nginx, Apache)
- Reports caching configuration (Cache‑Control, ETag)
- Pay‑per‑call via x402 (USDC on Base L2)
- No API key, no signup, no rate‑limit walls

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Http Headers X402
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Add the server URL to your MCP client configuration (Claude Desktop, Cursor, ElizaOS, etc.) using the endpoint https://http-headers.api.klymax402.com/mcp. The server exposes one tool: network_analyze_headers. To call it from an x402‑aware client (e.g., @x402/fetch, x402-agent-tools, ATXP), send a POST request to https://http-headers.api.klymax402.com/api/analyze with a JSON body containing the url parameter. The client automatically handles the 402 payment challenge, signs it, and retries the request.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "http headers x402": {
            "http-headers": {
                "url": "https://http-headers-production.up.railway.app/mcp",
                "transport": "sse"
            }
        }
    }
}

McpServers

{
    "http-headers": {
        "url": "https://http-headers-production.up.railway.app/mcp",
        "transport": "sse"
    }
}

HTTP Headers Analyzer API

MCP Server
x402
License: MIT

Analyze HTTP response headers -- security score, HSTS/CSP check, server detection, caching config. Score 0-100. Pay-per-call via x402 (USDC on Base L2) -- no API key, no signup, no rate-limit wall.

Part of the klymax402 marketplace -- 100 x402 micropayment APIs for AI agents, one wallet, USDC on Base.

Quickstart -- MCP

Add to your MCP client config (Claude Desktop, Cursor, ElizaOS, etc.):

{
  "mcpServers": {
    "http-headers": {
      "url": "https://http-headers.api.klymax402.com/mcp"
    }
  }
}

Quickstart -- HTTP (x402)

curl -X POST "https://http-headers.api.klymax402.com/api/analyze" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com"}'

-> 402 Payment Required, with an x402 payment challenge in the response body

Any x402-aware client (@x402/fetch, x402-agent-tools, ATXP) handles the 402 -> sign -> retry cycle automatically.

Tools

| Tool | Method | Path | Price | Description |
|---|---|---|---|---|
| network_analyze_headers | POST | /api/analyze | $0.001 | Analyze HTTP response headers for a URL |

network_analyze_headers

Use this when you need to analyze HTTP response headers of a URL for security and configuration. Returns a full header audit in JSON.

Parameters

| Name | Type | Required | Description |
|---|---|---|---|
| url | string | yes | Full URL to analyze (e.g. https://example.com) |

Example response:

{"url":"https://example.com","securityScore":85,"securityHeaders":{"hsts":true,"csp":true,"xFrameOptions":true,"xContentType":true,"referrerPolicy":false},"server":"nginx","caching":{"cacheControl":"max-age=3600","etag":true},"recommendations":["Add Referrer-Policy header"]}

When to use: security audits, DevOps monitoring, compliance checks, and verifying proper header configuration after deployment.

Not for: SSL certificate check (use security_check_ssl), web scraping (use web_scrape_to_markdown), GDPR compliance (use compliance_scan_gdpr).

Example agent prompts

- "Analyze HTTP response headers of a URL for security and configuration"

Payment

- Protocol: x402 -- HTTP-native pay-per-call, no signup, no API key
- Network: Base L2 (eip155:8453)
- Asset: USDC
- Facilitator: Coinbase CDP (primary), PayAI (fallback)
- Also reachable via ATXP (OAuth-wrapped x402, RFC 9728 protected-resource metadata)

Part of klymax402

100 x402 micropayment APIs for AI agents -- one wallet, USDC on Base, zero signup.

- Catalog: https://klymax402.com/llms.txt
- Full API reference: https://klymax402.com/llms-full.txt
- Live stats: https://klymax402.com/stats

License

MIT

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.