https://2s.io/api/security/http-headersGET /api/security/http-headers · x402 API by 2s.io
Fetch a URL and grade its HTTP security headers. Pass url (scheme optional — defaults to https). Returns an overall letter grade + score, the list of present/missing headers, and a per-header analysis with the live value and specific issues for: Strict-Transport-Security (HSTS max-age/includeSubDomains), Content-Security-Policy (flags 'unsafe-inline'/'unsafe-eval'/missing default-src), X-Frame-Options or CSP frame-ancestors (clickjacking), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy, and Cross-Origin-Opener/Resource-Policy. Also flags Server/X-Powered-By info disclosure. Analyzed from the target's LIVE response headers through an SSRF-guarded fetch (private/loopback targets refused) — an LLM cannot see a site's current headers. For web-app security review, vendor
What does this x402 API do?
https://2s.io/api/security/http-headers. This is an x402-gated GET API resource from 2s.io. TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21. No normalized USD price is recorded; the listing names Base and Solana. No settled paid call has been verified.
- Published price
- No normalized USD price is recorded
- Networks
- Base · Solana
- Latest evidence
- TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21
- Resource ID
- 5d282190b6051ebc5bff246c
Start with a quote-only recipe. Payment signing stays in your project.
const response = await fetch("https://2s.io/api/security/http-headers", {
method: "GET",
});
console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));
// A valid 402 is a quote, not a completed paid call.This sends no payment. Inspect the 402 response before adding a wallet-enabled client.
- Live 402 quote confirmed
GET returned a protocol-valid 402 quote (402). No payment was made.
- Origin reachable
HEAD https://2s.io/ returned 200.
- Observed in cdp-bazaar
The registry record was observed and retained with provenance.
- Observed in 402-index
Discovered through bazaar.
- Registry record checked
Registry health: healthy.
What evidence supports this listing?
Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →
Which networks and payment options does it accept?
The normalized listing price is No normalized USD price is recorded. Raw protocol requirements remain visible below for implementation and audit use.