Skip to content
We use cookies to improve the site and measure traffic. See our Cookie Policy. You can accept or reject non-essential cookies.
  • Free
  • No signup
  • Fast
  • Privacy-friendly

Back to Category

Security.txt Checker

Discover and parse RFC 9116 security.txt (/.well-known/security.txt) including Contact and Expires.

Waiting for bot check… this usually takes a second.

What next?

Keep going with Security.txt Checker

Finish this check in the browser, then pick the path that matches how you work — another related tool, REST for apps, or MCP for agents.

  1. 1. Related check

    After this result, run Security headers analyzer for the next signal.

    Security headers analyzer
  2. 2. Automate with API

    Same job from your server with X-Api-Key. Free tier includes 500 credits/month.

    Create free account
  3. 3. Hand off to an agent

    Connect MCP and run playbook security-audit, then verify until pass.

    security audit

What is Security.txt Checker?

Fetches /.well-known/security.txt and /security.txt, parses Contact/Expires and related fields. Helps verify vulnerability disclosure contact points. Agents include this in full-security-audit playbooks and verify after publishing updates — see <a href="/developers/security-audit">security audit</a>.

What are common questions about Security.txt Checker?

What does Security.txt Checker do?

Discover and parse RFC 9116 security.txt (/.well-known/security.txt) including Contact and Expires.

Is this available via API and MCP?

Yes. Same route under /api/v1/security-apis/{slug} with one ToolYour API key and shared credits.

What are the key features of Security.txt Checker?

Browser + API

Run in the browser or via REST/MCP.

Structured report

JSON-friendly output for agents and dashboards.

How do you use Security.txt Checker?

Open the tool

Use the Security Tools category page.

Provide input

URL, domain, or pasted text as required.

Review findings

Fix high-severity items first.
Free · API · MCPToolYour platform

Use Security.txt Checker three ways

The free Security.txt Checker on this page works in your browser. The same workflow is available via REST API for apps and via the remote MCP server for Cursor, Claude, and other agents — one API key, one plan, one quota. This tool is part of the security-apis module under Security Tools.

Agents close the full job with run_playbook security-audit, then verify until pass — see security audit.

  1. 1Create a free accountGet an API key for REST and MCP — 500 credits/month on the free tier.
  2. 2Connect or callPaste the MCP URL into Cursor/Claude, or call REST with X-Api-Key.
  3. 3Same key & creditsBrowser smoke-checks stay free; API-backed runs share one monthly credit quota.