Skip to content
We use cookies to improve the site and measure traffic. See our Cookie Policy. You can accept or reject non-essential cookies.
  • Free
  • No signup
  • Fast
Back to Toolkits

Security Toolkit

HTTP security headers, TLS, cookies, CORS, redirects, DNS, secrets, JWT, passwords, hashes, HMAC, bcrypt, security.txt, SRI, and email auth — plus agent playbooks for full audits and ship gates.

About the Security Toolkit toolkit

Use the Security Toolkit when you need to harden a site or debug auth — security headers, TLS, cookies, CORS, redirects, DNS, secret leak scans, JWT decode, password tools, hashes, HMAC, bcrypt, security.txt, subresource integrity, and SPF/DKIM/DMARC. Open any tool in the browser with no signup. API-backed via REST and MCP on one API key. Agents can run web-security-audit, ship-gate, and related playbooks, then verify until gates pass (or stop). Not a penetration test, malware scanner, or breach monitor.

Frequently asked questions

What jobs does the Security Toolkit cover?

Web response hardening, developer crypto helpers, DNS lookup, and email authentication DNS. It is not antivirus, port scanning, a penetration test, or a breach database.

Do I need an account?

No for browser use. Create a developer account only for REST or MCP access (500 free credits/month shared).

Can agents run a full security audit?

Yes — use MCP playbooks such as web-security-audit and ship-gate, then verify until pass or stop. See security audit.