apyhub
Back
▣ SEO

Full Site Audit API

What it does

The website audit API checks a single webpage and returns a structured health report in one call. Send a page url (http or https) and get back its meta tags, performance, broken links, security headers, detected tech stack and a mobile-friendly flag.

meta_tags covers the title, description, canonical URL, Open Graph title, description and image, and the Twitter card. performance returns load_time_ms, num_requests and page size. broken_links lists the links on the page that fail. security_headers reports HSTS, CSP, X-Frame-Options, X-Content-Type-Options and Referrer-Policy, with the raw header values and a letter score. is_mobile_friendly and tech_stack complete the report.

Use the website audit API to check pages before and after a release, catch missing meta descriptions or Open Graph images when a CMS publishes new content, run a broken link checker across key landing pages on a schedule, and give clients a quick technical snapshot of their homepage during a sales call.

Each call audits one URL. To crawl a whole site and track SEO issues across every page, use the SEO Site Audit API. For a deeper look at browser security settings, use the Security Headers API, and for the stack alone, the Tech Stack API.

POST
Full Site Audit
https://api.eu.apyhub.com/chisleroff/full-site-audit

QUICKSTART

GUIDE

Quickstart

Check a webpage and get back its audit details in one request.

curl -X POST "https://api.eu.apyhub.com/chisleroff/full-site-audit" \
  -H "apy-token: $APY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://apyhub.com"}'

What you'll get back

Returns a JSON object with fields such as url, meta_tags, source_url, tech_stack, performance, broken_links, security_headers, and is_mobile_friendly, depending on what the audit finds.

{
  "url": "https://apyhub.com",
  "meta_tags": {
    "title": "API Marketplace for Teams, Developers, and AI Agents",
    "description": "ApyHub: The API marketplace for developers and AI agents to discover, consume secure, compliant APIs. Simplify integration and accelerate development.",
    "canonical": "https://apyhub.com",
    "og_title": "API Marketplace for Teams, Developers, and AI Agents",
    "og_description": "ApyHub: The API marketplace for developers and AI agents to discover, consume secure, compliant APIs. Simplify integration and accelerate development.",
    "og_image": "https://apyhub.com/meta-apyhub-new.png",
    "twitter_card": "summary_large_image"
  },
  "tech_stack": [
    "Next.js",
    "Tailwind CSS",
    "Google Tag Manager",
    "Google Analytics"
  ],
  "security_headers": {
    "has_hsts": true,
    "has_csp": false,
    "has_x_frame_options": true,
    "has_x_content_type": true,
    "has_referrer_policy": true,
    "score": "B",
    "details": {
      "strict-transport-security": "max-age=31536000; includeSubDomains; preload",
      "content-security-policy": "Missing",
      "x-frame-options": "DENY",
      "x-content-type-options": "nosniff",
      "referrer-policy": "no-referrer-when-downgrade"
    }
  },
  "performance": {
    "page_size_bytes": 141736,
    "page_size_readable": "138.4 KB",
    "load_time_ms": 722,
    "num_requests": 60
  },
  "broken_links": [],
  "is_mobile_friendly": true,
  "source_url": "https://apyhub.com"
}
TRY ITLIVE · 100 ATOMS
Loading your default key…
The full key is used to call the gateway and stays in this tab — never sent to orbit or saved.
body*
URL of the webpage to extract, audit, or validate content from (http/https only).

About this endpoint

What it does

Audits a webpage from the provided URL and returns a structured report with metadata, detected tech stack, performance metrics, broken links, security header presence, and a mobile-friendly flag.

Request Body

ParameterTypeDescription
urlStringURL of the webpage to extract, audit, or validate content from (http/https only). Format: URI.

Response

Returns a JSON object with these top-level fields: url string, meta_tags object, source_url string, tech_stack array of strings, performance object, broken_links array of URI strings, security_headers object, and is_mobile_friendly boolean.

ParameterTypeDescription
urlStringURI of the audited page.
meta_tagsObjectPage metadata fields. Includes title string, og_image URI string, og_title string, canonical URI string, description string, twitter_card string, and og_description string.
meta_tags.titleStringPage title.
meta_tags.og_imageStringOpen Graph image URI.
meta_tags.og_titleStringOpen Graph title.
meta_tags.canonicalStringCanonical URI.
meta_tags.descriptionStringMeta description.
meta_tags.twitter_cardStringTwitter card value.
meta_tags.og_descriptionStringOpen Graph description.
source_urlStringURI for the source page used in the audit.
tech_stackString ArrayDetected technology stack items.
performanceObjectPerformance metrics. Includes load_time_ms integer, num_requests integer, page_size_bytes integer, and page_size_readable string.
performance.load_time_msIntegerPage load time in milliseconds.
performance.num_requestsIntegerNumber of requests made.
performance.page_size_bytesIntegerPage size in bytes.
performance.page_size_readableStringHuman-readable page size.
broken_linksString ArrayBroken link URIs found on the page.
security_headersObjectSecurity header audit data. Includes score string, details object, has_csp boolean, has_hsts boolean, has_x_content_type boolean, has_referrer_policy boolean, and has_x_frame_options boolean.
security_headers.scoreStringSecurity headers score.
security_headers.detailsObjectAdditional security header details as key-value string pairs.
security_headers.has_cspBooleanWhether a Content Security Policy header is present.
security_headers.has_hstsBooleanWhether an HSTS header is present.
security_headers.has_x_content_typeBooleanWhether an X-Content-Type-Options header is present.
security_headers.has_referrer_policyBooleanWhether a Referrer-Policy header is present.
security_headers.has_x_frame_optionsBooleanWhether an X-Frame-Options header is present.
is_mobile_friendlyBooleanWhether the page is mobile friendly.
▣ COMMON ERRORS

Errors any endpoint can return

400bad_request

Required parameter missing or malformed body.

401unauthorized

API key missing, revoked, or not authorized for this service.

429rate_limited

Your plan's per-second rate exceeded. Retry with exponential backoff.

503upstream_busy

Backend temporarily unavailable. Try again in a few seconds.