Grade a set of HTTP response headers for security: returns a 0-100 score, a letter grade (A+ to F), a pass/fail/warning summary, and a per-header finding with a recommendation for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin-* headers. Pass the headers you already have; this tool does not fetch the URL.
This page documents the HTTP endpoint POST /api/tools/security-headers-analyzer/execute. See the MCP reference →
Call it over REST
POST https://api.findutils.com/api/tools/security-headers-analyzer/execute · no API keys · 60 requests/min per IP
Execute — verified arguments
curl -X POST https://api.findutils.com/api/tools/security-headers-analyzer/execute \
-H "Content-Type: application/json" \
-d '{
"headers": {
"content-security-policy": "default-src '\''self'\''",
"strict-transport-security": "max-age=31536000",
"x-content-type-options": "nosniff",
"x-frame-options": "DENY"
},
"url": "https://example.com"
}' Parameter schema for this endpoint
curl https://api.findutils.com/api/tools/security-headers-analyzer Input schema
| Argument | Type | Required | Description |
|---|---|---|---|
| headers | object | yes | Response headers as an object of header name → value (case-insensitive), e.g. {"content-security-policy": "default-src 'self'"}. A raw "Name: value" block string (one header per line, as copied from curl -I) is also accepted. |
| url | string | no | Optional URL the headers came from. Echoed in the result only. |
Example arguments (verified)
{
"headers": {
"content-security-policy": "default-src 'self'",
"strict-transport-security": "max-age=31536000",
"x-content-type-options": "nosniff",
"x-frame-options": "DENY"
},
"url": "https://example.com"
} Also an MCP tool
Claude, Cursor, and any MCP client can call this tool as
findutils:security_headers_analyzer after one connect command.
Connect once
claude mcp add findutils --transport http https://mcp.findutils.com/ More Network tools
Cidr Calculate
Compute network / broadcast / first-last host / subnet mask / hosts count for a CIDR (e.g.
Cookie Analyzer
Analyze Set-Cookie header strings and return a per-cookie list of security issues, an overall 0-100 score, and recommendations.
Curl To Code
Returns source code that performs the same HTTP request as a cURL command, in JavaScript (fetch), Python (requests), PHP (cURL), Go (net/htt
Dns Lookup
Return the DNS records of a domain for one record type (A, AAAA, CNAME, MX, TXT, NS or SOA).
Dns Security Scanner
Return a DNS security report for a domain: SPF, DMARC, MX and CAA records with issues, a 0-100 score, a letter grade and recommendations.
Email Security Checker
Return an email-security report for the domain of an email address: MX, SPF, DKIM (common selectors), DMARC, MTA-STS, TLS-RPT and BIMI check
Har To Curl
Convert a HAR (HTTP Archive) file into curl commands, one per recorded request, and return them as a script plus a per-request list.
Http Status Code Lookup
Return the meaning, typical use case and fix for HTTP status codes.