Scan a website's HTTP security headers (HSTS, CSP, framing, COOP/CORP/COEP, cookies)
scan_headersScan the HTTP security headers of a public website. Returns a 0–100 score and A+–F grade (HTTPS 10, HSTS 15, CSP 25, framing 10, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 5, COOP 5, CORP 5, cookies 5, minus up to 5 for version-leak headers; without HTTPS the score is capped at 39), each header's status and notes, recommended fix headers, and a link to the full report with copy-paste snippets for nginx, Apache, Cloudflare, Netlify, Vercel and Express. Read-only: it sends ordinary GET requests to the site (following up to 10 redirects, each safety-checked) and never reads page bodies. Same engine and scoring as the HeaderGuard JSON API (GET /api/scan).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | URL or bare domain to scan, e.g. example.com or https://example.com/login. A bare domain is scanned as https://<domain>/ (plain HTTP if HTTPS does not answer). | |
| include_raw | No | Also return the full /api/scan JSON (redirect chain, all response headers with cookie values redacted, per-platform fix snippets) in structuredContent.raw. Larger output. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| raw | No | Full /api/scan response (only when include_raw is true) | |
| url | Yes | Normalized URL that was scanned | |
| plan | Yes | ||
| fixes | Yes | ||
| grade | No | Omitted when the grade is withheld | |
| notes | No | ||
| score | No | Omitted when the grade is withheld | |
| apiUrl | No | ||
| cached | No | ||
| version | No | ||
| finalUrl | Yes | ||
| findings | Yes | ||
| reportUrl | Yes | ||
| scannedAt | No | ||
| finalStatus | No | ||
| reliability | Yes | ||
| gradeWithheld | Yes | true when the site blocked, rate-limited or challenged the scanner | |
| redirectCount | No | ||
| gradeWithheldReason | No |