Khipu Security Headers AuditGET /v1/security-headers · x402 API by Khipu
Security headers audit for any URL: HSTS, CSP, clickjacking, cookie flags, info leaks, HTTPS redirect. Score 0-100 with findings and fixes. $0.10 USDC on Base.
What does this x402 API do?
Khipu Security Headers Audit. This is an x402-gated GET API resource from Khipu. TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-08-05. No normalized USD price is recorded; the listing names Base. No settled paid call has been verified.
- Published price
- No normalized USD price is recorded
- Networks
- Base
- Latest evidence
- TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-08-05
- Resource ID
- 9ca47b304b1bb78f0398999b
Start with a quote-only recipe. Payment signing stays in your project.
const response = await fetch("https://khipu-x402.khipu-agency.workers.dev/v1/security-headers", {
method: "GET",
});
console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));
// A valid 402 is a quote, not a completed paid call.This sends no payment. Inspect the 402 response before adding a wallet-enabled client.
- Observed in 402-index
Discovered through self-registered.
- Live 402 quote confirmed
GET returned a protocol-valid 402 quote (402). No payment was made.
- Origin reachable
HEAD https://khipu-x402.khipu-agency.workers.dev/ returned 302.
- Registry record checked
Registry health: healthy.
What evidence supports this listing?
Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →
Which networks and payment options does it accept?
The normalized listing price is No normalized USD price is recorded. Raw protocol requirements remain visible below for implementation and audit use.