payment-ready until 2026-09-11
imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed
One HEAD request against a URL, returning its parsed HTTP security headers as JSON: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, plus advisory warnings and any disclosed Server or X-Powered-By. $0.01 per call on Base. Operated by x402 Atlas.
Part of the x402 Atlas operator hub
Pay from $0.01 per request in USDC on Arbitrum One / Base / Polygon / Solana, settled onchain via the x402 protocol, no signup, no API key needed.
VERDICT
ranking generation 3solid 89/100 #135 of 265 in Data by measured score
What the score read on this service: status online, 99.6% uptime 30d, 2589ms response p95, x402 compliance 14 of 14, $0.01 price against the category. Each of those is measured, and each is published in full below.
The score comes from our own monitoring, never from reviews, operator claims, or a language model: reliability, x402 compliance, price against the category, a deterministic risk flag, and a small on-chain traction term, weighted by ranking generation 3. It is not placement anyone can buy: the paid verify tier is reported beside it and is not one of its inputs. Every component below stays published and read-only.
It is a score inside Data, and only there: price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, which here means 265 listings, this one among them. That set is wider than the 265 the position above is counted against, because a listing we have measured too little of to rank still sits in the field the price and the speed are normalized over. The same service in a different field would read differently. The same engine answers GET /api/v1/best, and asked for a different pool (the whole directory, or another filter) it returns a different number for this service under this same ranking generation. Neither is more correct: they answer different questions, and the methodology states which is which.
Bands on the 0 to 100 measured score: strong at 93 and above, solid from 75, mixed from 55, weak below 55. Price and speed are scored against the whole category field, every listing in it that carries no danger flag, the scored service included, so the score places a service in its own field.
ALTERNATIVES IN DATA
Other Data services in this directory, ordered by the same measured score. The figures are ours: 30-day uptime from our own probes, 30-day settlement volume read on-chain (a conservative undercount, and null where we cannot measure it, never a zero).
| SERVICE | BAND | SCORE | UPTIME 30D | VOL 30D |
|---|---|---|---|---|
| AgentFund US Economic, SEC & On-Chain Data | strong | 99 | 100% | --- |
| API Acre | strong | 99 | 99.7% | --- |
| ThirdMade Shelf | strong | 99 | 100% | --- |
| WebberSites x402 Data API | strong | 98 | 100% | --- |
| ForgeMesh Utility APIs | strong | 98 | 100% | --- |
ASSESSMENT
updated 2m agoThe parts the verdict above is computed from, each with its proof. Click any chip. Measured values stay read-only; unknown is honest, and an unknown is never counted as a zero.
reliability 99.6%
- uptime 24h
- 100%
- uptime 7d
- 100%
- uptime 30d
- 99.6%
- uptime 90d
- 99.7%
- response p95
- 2589ms
- avg response
- 1044ms
- total checks
- 2,673
Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.
compliance A (14/14)
14 of 14 x402 conformance checks pass. Full checklist below.
price $0.01 (p59 in Data)
- price (min)
- $0.01
- category percentile (min)
- p59 in Data
- endpoints / prices
- 1 / 1
- model
- flat
- stability
- 100%
risk clean
No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.
- domain age
- 319d
- registrar
- Amazon Registrar, Inc.
- hosting
- custom
- domain created
- 2025-10-17
Identity facts, not a risk score.
traction ---
This service settles on a network x402-list does not measure yet, so on-chain volume is not counted here. Shown as unmeasured, not zero.
CHANGES
10 in 30dPayout, price, and schema changes detected on this service's x402 wire. A payout rotation at an unchanged price shows up here even when nothing else moves. Full feed at /changes.
changes schema changed 10d ago (10 in 30d)
schema changed · 10d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"D6ZhtNQ5nT9ZnTHUbqXZsTx5MH2rPFiBBggX4hY1WePM","merchant":"x402Atlas","tier":"standard"}
schema changed · 10d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"Hc3sdEAsCGQcpgfivywog9uwtk8gUBUZgsxdME1EJy88","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema changed · 10d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"Hc3sdEAsCGQcpgfivywog9uwtk8gUBUZgsxdME1EJy88","merchant":"x402Atlas","tier":"standard"}
schema changed · 11d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema changed · 11d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"Hc3sdEAsCGQcpgfivywog9uwtk8gUBUZgsxdME1EJy88","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP","merchant":"x402Atlas","tier":"standard"}
schema changed · 12d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BFK9TLC3edb13K6v4YyH3DwPb5DSUpkWvb7XnqCL9b4F","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"Hc3sdEAsCGQcpgfivywog9uwtk8gUBUZgsxdME1EJy88","merchant":"x402Atlas","tier":"standard"}
schema changed · 12d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BFK9TLC3edb13K6v4YyH3DwPb5DSUpkWvb7XnqCL9b4F","merchant":"x402Atlas","tier":"standard"}
schema changed · 12d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema changed · 12d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP","merchant":"x402Atlas","tier":"standard"}
schema changed · 18d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BFK9TLC3edb13K6v4YyH3DwPb5DSUpkWvb7XnqCL9b4F","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
WHAT IT DOES
ai-derivedNo AI synthesis has been produced for this service yet.
ENDPOINTS
| METHOD | PATH | DESCRIPTION | PRICE | NETWORK | ASSET | 402 CHANNEL |
|---|---|---|---|---|---|---|
| GET | / | $0.01 | Arbitrum One/Base/Polygon/Solana | USDC | header |
REQUEST / RESPONSE EXAMPLE
An unpaid request to GET / returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.
curl -i 'https://headers.use.x402atlas.com/'
// 402 response (captured by monitor) · 1 payload · click to expand
[
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
},
{
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:137",
"maxTimeoutSeconds": 300
},
{
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:42161",
"maxTimeoutSeconds": 300
},
{
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"extra": {
"tier": "standard",
"feePayer": "D6ZhtNQ5nT9ZnTHUbqXZsTx5MH2rPFiBBggX4hY1WePM",
"merchant": "x402Atlas"
},
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"amount": "10000",
"scheme": "exact",
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://headers.use.x402atlas.com/",
"tags": [
"http",
"headers",
"security",
"hsts",
"csp",
"x-frame-options",
"posture"
],
"mimeType": "application/json",
"description": "Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.",
"serviceName": "HTTP Security Headers Check"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"type": "http",
"method": "GET",
"queryParams": {
"url": "https://example.com/"
}
},
"output": {
"type": "json",
"example": {
"url": "https://example.com/",
"headers": {
"server": null,
"x_powered_by": null,
"referrer_policy": "strict-origin-when-cross-origin",
"x_frame_options": "DENY",
"permissions_policy": null,
"x_content_type_options": "nosniff",
"content_security_policy": "default-src 'self'",
"strict_transport_security": {
"value": "max-age=31536000; includeSubDomains",
"max_age": 31536000,
"preload": false,
"include_subdomains": true
}
},
"warnings": [
"no Permissions-Policy header (powerful browser features are not restricted)"
],
"queried_at": "2026-07-03T12:00:00Z",
"status_code": 200
}
}
},
"tags": [
"http",
"headers",
"security",
"hsts",
"csp",
"x-frame-options",
"posture"
],
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method"
],
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"GET"
],
"type": "string"
},
"queryParams": {
"type": "object",
"required": [
"url"
],
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Absolute http/https URL to audit. Host must be a hostname (not an IP literal), not \"localhost\", and not under a reserved suffix (.local, .internal, .localdomain, .lan, .test). Non-default ports must be allowlisted. Redirects are not followed."
}
}
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"required": [
"url",
"status_code",
"queried_at",
"headers",
"warnings"
],
"properties": {
"url": {
"type": "string",
"description": "The audited URL, exactly as given"
},
"headers": {
"type": "object",
"properties": {
"server": {
"type": [
"string",
"null"
],
"description": "Server header value, if disclosed by the target"
},
"x_powered_by": {
"type": [
"string",
"null"
],
"description": "X-Powered-By header value, if disclosed by the target"
},
"referrer_policy": {
"type": [
"string",
"null"
]
},
"x_frame_options": {
"type": [
"string",
"null"
]
},
"permissions_policy": {
"type": [
"string",
"null"
]
},
"x_content_type_options": {
"type": [
"string",
"null"
]
},
"content_security_policy": {
"type": [
"string",
"null"
]
},
"strict_transport_security": {
"type": [
"object",
"null"
],
"properties": {
"value": {
"type": "string",
"description": "Raw Strict-Transport-Security header value"
},
"max_age": {
"type": [
"integer",
"null"
],
"description": "Parsed max-age in seconds; null if absent or unparseable"
},
"preload": {
"type": "boolean"
},
"include_subdomains": {
"type": "boolean"
}
}
}
},
"description": "Graded, normalized security headers. Each field is null when the header is absent from the response"
},
"warnings": {
"type": "array",
"items": {
"type": "string"
},
"description": "Human-readable posture advisories, e.g. missing or weak headers"
},
"queried_at": {
"type": "string",
"format": "date-time",
"description": "UTC timestamp the audit was performed"
},
"status_code": {
"type": "integer",
"description": "HTTP status code returned by the target for the HEAD request"
}
}
}
}
}
}
},
"category": "domain-intelligence"
}
},
"x402Version": 2
}
] OVER TIME
All charts use the 30d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/http-security-headers-check/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.
checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression
Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.
COMPLIANCE
14/14 checks pass · grade Alast 402 captured 2026-08-25 · last up 2026-09-04
- 402 payload captured
- accepts[] array present
- payTo address recoverable
- payTo at accepts[0].payTo (conformant shape)
- payTo is a valid on-chain address
- atomic price declared
- atomic price in a sane range
- asset (token) address declared
- network resolves to CAIP-2
- payment scheme declared
- served over HTTPS
- declares the current x402 version (2)
- EIP-712 domain parameters present on every EVM entry
- x402 v2 envelope delivered in the payment-required header
SITE PILLARS
- homepage reachable
- openapi doc
- pricing page
- llms.txt
- robots.txt
- terms page
recent checks (18) live · click to expand
EMBED THIS BADGE
<a href="https://x402-list.com/services/http-security-headers-check?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/http-security-headers-check.svg" alt="HTTP Security Headers Check listed on x402-list" height="28"> </a>
[](https://x402-list.com/services/http-security-headers-check?utm_source=badge&utm_medium=referral&utm_campaign=embed)
<a href="https://x402-list.com/services/http-security-headers-check?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/http-security-headers-check.svg?data=uptime" alt="HTTP Security Headers Check uptime on x402-list" height="28"> </a>