http-security-headers-mcp
Generate recommended security headers configuration for Apache HTTP servers.
Generate recommended security headers configuration for Cloudflare deployments.
Generate recommended security headers configuration for Express.js applications.
Generate recommended security headers configuration for Next.js applications.
Generate recommended security headers configuration for NGINX web servers.
Generate recommended security headers configuration for Vercel deployments.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@http-security-headers-mcpscan https://example.com for security headers"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
http-security-headers-mcp
Analyze and score HTTP security headers (CSP, HSTS, CORS, cookies) with actionable fix recommendations for web applications.
Tools
Tool | Description |
| Fetch a URL and analyze all security headers. Returns A+ to F grade with findings. |
| Score a set of headers you provide. Returns grade and per-header breakdown. |
| Deep analysis of a Content-Security-Policy header. Detects unsafe sources and bypass risks. |
| Generate recommended security headers config for Express, Next.js, nginx, Apache, Cloudflare, or Vercel. |
Related MCP server: PostureCheck MCP
Quick Start
Install from MCPize (Recommended)
npx -y mcpize connect @shakiltousif/http-security-headers-mcp --client claudeOr visit: mcpize.com/mcp/http-security-headers-mcp
Per-client install
Claude: claude mcp add --transport http http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp
Cursor: cursor mcp add http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcp
Windsurf: windsurf mcp add http-security-headers-mcp https://http-security-headers-mcp.mcpize.run/mcpJSON Config (manual setup)
{
"mcpServers": {
"http-security-headers-mcp": {
"url": "https://http-security-headers-mcp.mcpize.run/mcp"
}
}
}Run Locally
npm install
mcpize dev # Start dev server with hot reload
mcpize dev --playground # Interactive testing in your browserServer runs at http://localhost:3000/mcp
Development
mcpize dev # Development mode (port 3000, hot reload, loads .env)
npm run build # Compile TypeScript
npm test # Run unit tests (26 tests)
bash test-mcp.sh # MCP protocol smoke test (14 checks)
npm start # Run compiled server (port 8080)Deploy
mcpize login # Authenticate (opens browser)
mcpize deploy # Ship it!Project Structure
src/
index.ts # Express + MCP server setup, tool registration
tools.ts # Pure business logic (header analysis, scoring, CSP parsing)
tests/
tools.test.ts # Unit tests (vitest)
test-mcp.sh # MCP protocol smoke test
mcpize.yaml # MCPize deployment config
Dockerfile # Production container buildLicense
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
MDN HTTP Observatory — grade any website's HTTP security headers and get the specific fixes, from…
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
DNS resolution, HTTP security headers, and SPF/DMARC email hygiene audits.
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Related MCP Servers
- AlicenseAqualityDmaintenanceAudit any website for privacy, security, accessibility, and performance issues — with scores, grades, and actionable fix instructions. No account required.34 npmMIT
- AlicenseAqualityCmaintenancePerforms domain security posture checks including SPF, DKIM, DMARC, TLS, and HTTP security headers.36 npmMIT
- AlicenseNot gradedqualityCmaintenanceEnables users to analyze HTTP response headers of any URL for security and configuration, returning a 0-100 security score, HSTS/CSP and header checks, server detection, caching details, and recommendations. Supports pay-per-call access via x402 micropayments.MIT
- AlicenseAqualityCmaintenanceEnables Claude to scan a website's HTTP security headers and receive an A–F grade against OWASP best practices, including per-header pass/warn/fail results and copy-paste fixes for missing headers.1MIT