payment-ready until 2026-08-20
imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed
One HEAD request against a URL, returning its parsed HTTP security headers as JSON: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, plus advisory warnings and any disclosed Server or X-Powered-By. $0.01 per call on Base. Operated by x402 Atlas.
Pay from $0.01 per request in USDC on Arbitrum One / Base / Polygon / Solana, settled onchain via the x402 protocol, no signup, no API key needed.
first settlement 2026-07-03 · $0.12 all-time · settled via coinbase, payAI
ASSESSMENT
updated 3h agoEvidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.
reliability 99.5%
- uptime 24h
- 100%
- uptime 7d
- 98%
- uptime 30d
- 99.5%
- uptime 90d
- 99.5%
- response p95
- 1764ms
- avg response
- 823ms
- total checks
- 2,085
Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.
compliance A (14/14)
14 of 14 x402 conformance checks pass. Full checklist below.
price $0.01 (p53 in Data)
- price (min)
- $0.01
- category percentile (min)
- p53 in Data
- endpoints / prices
- 1 / 1
- model
- flat
- stability
- 100%
risk clean
No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.
- domain age
- -
- registrar
- -
- hosting
- custom
- domain created
- ---
Identity facts, not a risk score.
traction $0.113 30d · 13 buyers
- volume 30d
- $0.113
- buyers 30d
- 13
- settlements 30d
- 60
- first settlement
- 2026-07-03
- last settlement
- 2026-08-13
- top buyer share
- 58% of 30d volume
- trend 7d vs 30d
- 0.93x the 30d daily rate
- networks
- eip155:137, eip155:8453, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdpKuc147dw2N9d
- volume all-time
- $0.12
- settlements all-time
- 61
- median settlement 30d
- $0.005
- max settlement 30d
- $0.01
- settled via
- coinbase ($0.34, 58 tx), payAI ($0.02, 2 tx)
Attributed pro-quota: this payout address is shared, so volume is the operator-level figure divided by the services sharing it, while buyer and transaction counts stay whole. A declared convention, not an individually observed measure, and still a conservative undercount.
Currently sharing this payout address with Apple App Store Search, Reviews & App Data, Atlas Market Data, CoinGecko Crypto Price & Data (x402 Atlas), Crypto Perp Signals, DefiLlama Data API (x402 Atlas), DNS & WHOIS Domain Lookup, Email Auth Check (SPF/DMARC/DKIM), GDELT News Search and Timeline, Google Trends SEO Keyword Data, Hyperliquid Account Intelligence, Hyperliquid Market Data, Hyperliquid Prediction Markets Data (x402 Atlas), Image Optimizer & WebP Converter, Places & Local Business Search, Twitter/X Advanced Tweet Search, URL Unwrap / Redirect Tracer, Web Search, News & Page Reader, Wikipedia Article Summary, X (Twitter) Media Downloader.
Top buyer share is a concentration signal, not part of the ranking score.
CHANGES
6 events, detecting since 2026-07-24Payout, price, and schema changes detected on this service's x402 wire. A payout rotation at an unchanged price shows up here even when nothing else moves. Full feed at /changes.
changes schema changed 2h ago (6 since 2026-07-24)
schema changed · 2h ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema changed · 3d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BENrLoUbndxoNMUS5JXApGMtNykLjFXXixMtpDwDR9SP","merchant":"x402Atlas","tier":"standard"}
schema changed · 7d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BFK9TLC3edb13K6v4YyH3DwPb5DSUpkWvb7XnqCL9b4F","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema changed · 7d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BFK9TLC3edb13K6v4YyH3DwPb5DSUpkWvb7XnqCL9b4F","merchant":"x402Atlas","tier":"standard"}
schema changed · 7d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BFK9TLC3edb13K6v4YyH3DwPb5DSUpkWvb7XnqCL9b4F","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb","merchant":"x402Atlas","tier":"standard"}
schema changed · 9d ago
schema removed GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"D6ZhtNQ5nT9ZnTHUbqXZsTx5MH2rPFiBBggX4hY1WePM","merchant":"x402Atlas","tier":"standard"}
schema added GET / exact solana:5eykt4usfv8p8njdtrepy1vzqkqzkvdp EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v USDC 2 300 {"feePayer":"BFK9TLC3edb13K6v4YyH3DwPb5DSUpkWvb7XnqCL9b4F","merchant":"x402Atlas","tier":"standard"}
WHAT IT DOES
ai-derivedNo AI synthesis has been produced for this service yet.
ENDPOINTS
| METHOD | PATH | DESCRIPTION | PRICE | NETWORK | ASSET | 402 CHANNEL |
|---|---|---|---|---|---|---|
| GET | / | $0.01 | Arbitrum One/Base/Polygon/Solana | USDC | header |
REQUEST / RESPONSE EXAMPLE
An unpaid request to GET / returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.
curl -i 'https://headers.use.x402atlas.com/'
// 402 response (captured by monitor) · 1 payload · click to expand
[
{
"error": "Payment required",
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 300
},
{
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:137",
"maxTimeoutSeconds": 300
},
{
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"extra": {
"name": "USD Coin",
"tier": "standard",
"version": "2",
"merchant": "x402Atlas"
},
"payTo": "0x7f8043c400799643bcb62B41B84b297a8Ecb7b9c",
"amount": "10000",
"scheme": "exact",
"network": "eip155:42161",
"maxTimeoutSeconds": 300
},
{
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"extra": {
"tier": "standard",
"feePayer": "GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb",
"merchant": "x402Atlas"
},
"payTo": "ASt6xvRyQ7ntERsmcYVMdLqZvz1GEN8Fzexzq62tXrNQ",
"amount": "10000",
"scheme": "exact",
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"maxTimeoutSeconds": 300
}
],
"resource": {
"url": "https://headers.use.x402atlas.com/",
"tags": [
"http",
"headers",
"security",
"hsts",
"csp",
"x-frame-options",
"posture"
],
"mimeType": "application/json",
"description": "Audit a URL's HTTP security headers over a single body-free (HEAD) request. Grades Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, flags information-leak headers (Server, X-Powered-By), and returns the parsed values plus advisory warnings. Clean JSON for security and pentest automation.",
"serviceName": "HTTP Security Headers Check"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"type": "http",
"method": "GET",
"queryParams": {
"url": "https://example.com/"
}
},
"output": {
"type": "json",
"example": {
"url": "https://example.com/",
"headers": {
"server": null,
"x_powered_by": null,
"referrer_policy": "strict-origin-when-cross-origin",
"x_frame_options": "DENY",
"permissions_policy": null,
"x_content_type_options": "nosniff",
"content_security_policy": "default-src 'self'",
"strict_transport_security": {
"value": "max-age=31536000; includeSubDomains",
"max_age": 31536000,
"preload": false,
"include_subdomains": true
}
},
"warnings": [
"no Permissions-Policy header (powerful browser features are not restricted)"
],
"queried_at": "2026-07-03T12:00:00Z",
"status_code": 200
}
}
},
"tags": [
"http",
"headers",
"security",
"hsts",
"csp",
"x-frame-options",
"posture"
],
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method"
],
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"GET"
],
"type": "string"
},
"queryParams": {
"type": "object",
"required": [
"url"
],
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Absolute http/https URL to audit. Host must be a hostname (not an IP literal), not \"localhost\", and not under a reserved suffix (.local, .internal, .localdomain, .lan, .test). Non-default ports must be allowlisted. Redirects are not followed."
}
}
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"required": [
"url",
"status_code",
"queried_at",
"headers",
"warnings"
],
"properties": {
"url": {
"type": "string",
"description": "The audited URL, exactly as given"
},
"headers": {
"type": "object",
"properties": {
"server": {
"type": [
"string",
"null"
],
"description": "Server header value, if disclosed by the target"
},
"x_powered_by": {
"type": [
"string",
"null"
],
"description": "X-Powered-By header value, if disclosed by the target"
},
"referrer_policy": {
"type": [
"string",
"null"
]
},
"x_frame_options": {
"type": [
"string",
"null"
]
},
"permissions_policy": {
"type": [
"string",
"null"
]
},
"x_content_type_options": {
"type": [
"string",
"null"
]
},
"content_security_policy": {
"type": [
"string",
"null"
]
},
"strict_transport_security": {
"type": [
"object",
"null"
],
"properties": {
"value": {
"type": "string",
"description": "Raw Strict-Transport-Security header value"
},
"max_age": {
"type": [
"integer",
"null"
],
"description": "Parsed max-age in seconds; null if absent or unparseable"
},
"preload": {
"type": "boolean"
},
"include_subdomains": {
"type": "boolean"
}
}
}
},
"description": "Graded, normalized security headers. Each field is null when the header is absent from the response"
},
"warnings": {
"type": "array",
"items": {
"type": "string"
},
"description": "Human-readable posture advisories, e.g. missing or weak headers"
},
"queried_at": {
"type": "string",
"format": "date-time",
"description": "UTC timestamp the audit was performed"
},
"status_code": {
"type": "integer",
"description": "HTTP status code returned by the target for the HEAD request"
}
}
}
}
}
}
},
"category": "domain-intelligence"
}
},
"x402Version": 2
}
] OVER TIME
All charts use the 90d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/http-security-headers-check/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.
checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression
Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.
Shared payout address (19 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 20 services sharing it: a declared convention, not an individually observed measure.
Shared payout address (19 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Per-service buyer and transaction counts are shown whole (integers), not divided; only volume is attributed pro-quota. A declared convention, not an individually observed measure.
COMPLIANCE
14/14 checks pass · grade Alast 402 captured 2026-08-13 · last up 2026-08-13
- 402 payload captured
- accepts[] array present
- payTo address recoverable
- payTo at accepts[0].payTo (conformant shape)
- payTo is a valid on-chain address
- atomic price declared
- atomic price in a sane range
- asset (token) address declared
- network resolves to CAIP-2
- payment scheme declared
- served over HTTPS
- declares the current x402 version (2)
- EIP-712 domain parameters present on every EVM entry
- x402 v2 envelope delivered in the payment-required header
SITE PILLARS
- homepage reachable
- openapi doc
- pricing page
- llms.txt
- robots.txt
- terms page
recent checks (18) live · click to expand
EMBED THIS BADGE
<a href="https://x402-list.com/services/http-security-headers-check?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/http-security-headers-check.svg" alt="HTTP Security Headers Check listed on x402-list" height="28"> </a>
[](https://x402-list.com/services/http-security-headers-check?utm_source=badge&utm_medium=referral&utm_campaign=embed)
<a href="https://x402-list.com/services/http-security-headers-check?utm_source=badge&utm_medium=referral&utm_campaign=embed"> <img src="https://x402-list.com/badge/http-security-headers-check.svg?data=uptime" alt="HTTP Security Headers Check uptime on x402-list" height="28"> </a>