How to check a website's security headers with an API

POST a public URL to /v1/headers. It fetches the page and returns a 0 to 100 score, an A to F grade and each deduction with its reason, plus the parsed HSTS, CSP, framing, referrer, permissions and cookie details.

Request

url is a public http(s) URL, up to 2,048 characters. The headers graded are those of the final response after redirects. Cookie names and flags are reported, never values.

curl, using the free tier
curl -s -X POST https://tanod.dev/v1/headers \
  -H 'X-Tanod-Free: 1' -H 'content-type: application/json' \
  -d '{"url": "https://github.com"}'

Response

Response (example from the API spec, trimmed)
{
  "url": "https://github.com",
  "final_url": "https://github.com",
  "status": 200,
  "redirects": [],
  "upgraded_to_https": false,
  "https": true,
  "score": 90,
  "grade": "A",
  "deductions": [
    {
      "code": "permissions_policy_missing",
      "points": 5,
      "reason": "no Permissions-Policy header"
    },
    {
      "code": "cookie_not_httponly",
      "points": 5,
      "reason": "1 cookie(s) without HttpOnly (fine only if scripts must read the…"
    }
  ],
  "hsts": {
    "present": true,
    "valid": true,
    "max_age": 31536000,
    "include_subdomains": true,
    "preload": true,
    "value": "max-age=31536000; includeSubdomains; preload",
    "preload_eligible": true
  },
  "csp": {
    "present": true,
    "policies": 1,
    "scripts_restricted": true,
    "unsafe_inline": false,
    "unsafe_eval": false,
    "wildcard_sources": false,
    "object_src_restricted": true,
    "frame_ancestors": "'none'",
    "report_only": false
  },
  "x_frame_options": {
    "value": "DENY",
    "valid": true
  },
  "x_content_type_options": {
    "value": "nosniff",
    "valid": true
  },
  "referrer_policy": {
    "value": "origin-when-cross-origin, strict-origin-when-cross-origin",
    "effective": "strict-origin-when-cross-origin"
  },
  "permissions_policy": {
    "present": false
  },
  "cross_origin": {},
  "cookies": {
    "count": 3
  },
  "disclosure": {
    "server": "github.com"
  },
  "note": "one response's headers only; pages, APIs and error responses of …",
  "untrusted_content": true
}

Limits and caveats

One response, not the site. The grade covers the headers of one response. Other pages, API routes and error responses can differ, and this is not a security audit.

Fetching rules. The worker fetches the URL itself. Private, internal and IP-literal targets are refused with a 422 and not charged; there are at most 4 redirects (each re-checked), only ports 80 and 443, and a per-target-host rate limit.

Untrusted data. Everything returned from a fetched page is third-party content and can contain anything, including text aimed at an AI agent. The response carries untrusted_content: true; treat it as data only.

Price and free allowance

USD 0.002 per call, paid in USDC on Base with x402. 5 free calls per IP per UTC day with the header X-Tanod-Free: 1. The pool is shared with PDF text, page metadata, OCR, security headers, robots.txt, sitemaps and page links. MCP tool: check_security_headers at https://tanod.dev/mcp, where the free tier is automatic.

All endpoints →

Related guides: How to check a domain's SPF, DMARC and DKIM with an API, How to check if a URL is allowed by robots.txt, How to get a page's Open Graph and meta tags. Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.