Skip to content
We use cookies to improve the site and measure traffic. See our Cookie Policy. You can accept or reject non-essential cookies.
  • Free
  • No signup
  • Fast
  • Privacy-friendly

Back to Category

Security Headers Analyzer

Score CSP, HSTS, XFO, and related HTTP security headers on a live URL.

Waiting for bot check… this usually takes a second.

What next?

Keep going with Security Headers Analyzer

Finish this check in the browser, then pick the path that matches how you work — another related tool, REST for apps, or MCP for agents.

  1. 1. Related check

    After this result, run CSP policy evaluator for the next signal.

    CSP policy evaluator
  2. 2. Automate with API

    Same job from your server with X-Api-Key. Free tier includes 500 credits/month.

    Create free account
  3. 3. Hand off to an agent

    Connect MCP and run playbook ship-gate, then verify until pass.

    ship gate

What is Security Headers Analyzer?

Fetch a public URL and score security response headers (CSP, HSTS, X-Frame-Options, and related). Author CSP text with the CSP Policy Evaluator, then verify live with this tool. Agents include this check in ship-gate and web-security-audit playbooks, then verify until the gate passes — see <a href="/developers/ship-gate">ship gate</a> and <a href="/developers/security-audit">security audit</a>. REST/MCP on one credit quota.

What are common questions about Security Headers Analyzer?

What does Security Headers Analyzer do?

Score CSP, HSTS, XFO, and related HTTP security headers on a live URL.

Is this available via API and MCP?

Yes. Same route under /api/v1/security-apis/{slug} with one ToolYour API key.

What are the key features of Security Headers Analyzer?

Merged header checklist

One page for CSP/HSTS/frame/MIME/referrer/permissions/COOP instead of thin single-header tools.

Score and grade

Weighted score from pass/warn/fail so agents and dashboards can sort results.

API and MCP

GET with url query or POST with body.url — same credit-backed path agents use.

How do you use Security Headers Analyzer?

Paste a public HTTPS URL

Use the live page you care about (homepage, login, or app shell).

Run the analyzer

Complete the bot check; we fetch headers and score each control.

Fix fails first

Prioritize missing CSP and HSTS, then frame and MIME sniffing controls.

When teams use security headers checks

Pre-launch hardening, vendor reviews, and CI smoke checks after CDN or reverse-proxy changes. Pair with TLS certificate and cookie flag tools in this category.

Free · API · MCPToolYour platform

Use Security Headers Analyzer three ways

The free Security Headers Analyzer on this page works in your browser. The same workflow is available via REST API for apps and via the remote MCP server for Cursor, Claude, and other agents — one API key, one plan, one quota. This tool is part of the security-apis module under Security Tools.

Agents close the full job with run_playbook ship-gate, then verify until pass — see ship gate.

  1. 1Create a free accountGet an API key for REST and MCP — 500 credits/month on the free tier.
  2. 2Connect or callPaste the MCP URL into Cursor/Claude, or call REST with X-Api-Key.
  3. 3Same key & creditsBrowser smoke-checks stay free; API-backed runs share one monthly credit quota.

Which web-hardening tools sit in this cluster?

Where does this job fit on ToolYour?

Which SEO or privacy tools pair with this security check?

Where do you browse more security tools tools?

Which toolkits include Security Headers Analyzer?