Use a funded Signet session to inspect the security headers on any public URL and get a normalized hardening score with findings for CSP, HSTS, CORS, cookie flags, and related controls.
Headers Audit checks whether a public URL is sending the main browser-facing security headers you would expect on a hardened deployment. It is designed for quick reviews, automation, and agent workflows that need structured findings instead of manual header inspection.
Raw response headers are easy for humans to read once, but they are not a great automation primitive. This endpoint turns a live header fetch into a compact security posture summary that is easier to compare, alert on, or feed into a broader domain review workflow.
Use a funded token from the Fund page. The endpoint is also documented in /openapi.json for agents and wrappers.
For broader platform usage, see the main docs and the live catalog.