# Security Headers Analyzer — REST API endpoint `security-headers-analyzer`

Grade a set of HTTP response headers for security: returns a 0-100 score, a letter grade (A+ to F), a pass/fail/warning summary, and a per-header finding with a recommendation for CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin-* headers. Pass the headers you already have; this tool does not fetch the URL.

- Category: network
- MCP server: https://mcp.findutils.com/ (Streamable HTTP, no API keys, 120 req/min per IP)
- REST endpoint: POST https://api.findutils.com/api/tools/security-headers-analyzer/execute (no API keys, 60 req/min per IP)
- Reference page: https://findutils.com/api/security-headers-analyzer/
- Same tool on the other surface: https://findutils.com/mcp/security-headers-analyzer/

## Call the endpoint (verified example)

```bash
curl -X POST https://api.findutils.com/api/tools/security-headers-analyzer/execute \
  -H "Content-Type: application/json" \
  -d '{
    "headers": {
      "content-security-policy": "default-src '\''self'\''",
      "strict-transport-security": "max-age=31536000",
      "x-content-type-options": "nosniff",
      "x-frame-options": "DENY"
    },
    "url": "https://example.com"
  }'

# Parameter schema
curl https://api.findutils.com/api/tools/security-headers-analyzer
```

## Input schema

| Argument | Type | Required | Description |
|---|---|---|---|
| `headers` | object | yes | Response headers as an object of header name → value (case-insensitive), e.g. {"content-security-policy": "default-src 'self'"}. A raw "Name: value" block string (one header per line, as copied from curl -I) is also accepted. |
| `url` | string | no | Optional URL the headers came from. Echoed in the result only. |

Example arguments (verified):

```json
{
  "headers": {
    "content-security-policy": "default-src 'self'",
    "strict-transport-security": "max-age=31536000",
    "x-content-type-options": "nosniff",
    "x-frame-options": "DENY"
  },
  "url": "https://example.com"
}
```

OpenAPI 3.1 spec: https://findutils.com/api/openapi.json · Interactive docs: https://findutils.com/api/docs/

## Also an MCP tool

```bash
claude mcp add findutils --transport http https://mcp.findutils.com/
```

Then ask the client to call `findutils:security_headers_analyzer`. Full MCP reference: https://findutils.com/mcp/security-headers-analyzer/

---
Full catalog: GET https://api.findutils.com/api/tools · https://findutils.com/api/ · https://findutils.com/llms.txt
