apyhub
Back
▣ SECURITY & PRIVACY · SEO

Security Headers Audit API

What it does

The security headers API checks which browser security headers a webpage sends. Send a page url (http or https) and get back a letter score, a true or false flag for each header, and a details map with the raw value of every header it found, or Missing when one is absent.

It covers the five headers most security reviews start with: Content-Security-Policy (has_csp), Strict-Transport-Security (has_hsts), X-Frame-Options (has_x_frame_options), X-Content-Type-Options (has_x_content_type) and Referrer-Policy (has_referrer_policy). The raw values let you go past presence and check the settings themselves, such as an HSTS max-age or a DENY frame policy.

Use the security headers API as a CI gate that fails a deploy when a header disappears, run a scheduled security headers check across login pages and customer portals, collect evidence for SOC 2 and ISO 27001 reviews, and flag weak headers when onboarding a vendor or reviewing a client site.

For TLS, cookie flags and exposure checks in one report, use the Website Security Audit API. To add meta tags, performance and broken links to the same scan, use the Website Audit API. For certificate expiry and issuer, the Domain Availability API includes an SSL check.

POST
Security Headers Audit
https://api.eu.apyhub.com/chisleroff/security-headers-audit

QUICKSTART

GUIDE

Quickstart

Send the webpage URL you want audited in a JSON body.

curl -X POST "https://api.eu.apyhub.com/chisleroff/security-headers-audit" \
  -H "apy-token: $APY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://apyhub.com"}'

What you'll get back

Returns a JSON object with these top-level fields:

  • score (string)
  • details (object with string values)
  • has_csp (boolean)
  • has_hsts (boolean)
  • has_x_content_type (boolean)
  • has_referrer_policy (boolean)
  • has_x_frame_options (boolean)

Example response:

{
  "has_hsts": true,
  "has_csp": false,
  "has_x_frame_options": true,
  "has_x_content_type": true,
  "has_referrer_policy": true,
  "score": "B",
  "details": {
    "strict-transport-security": "max-age=31536000; includeSubDomains; preload",
    "content-security-policy": "Missing",
    "x-frame-options": "DENY",
    "x-content-type-options": "nosniff",
    "referrer-policy": "no-referrer-when-downgrade"
  }
}
TRY ITLIVE · 100 ATOMS
Loading your default key…
The full key is used to call the gateway and stays in this tab — never sent to orbit or saved.
body*
URL of the webpage to extract, audit, or validate content from (http/https only).

About this endpoint

What it does

Audits the security headers present on the webpage at the given URL and returns a JSON object describing the audit result. The response includes a score, a details object, and booleans indicating whether specific headers were found.

Request Body

ParameterTypeDescription
urlStringURL of the webpage to extract, audit, or validate content from. Must be an http or https URI.

Response

Returns a JSON object with a score string, a details object whose values are strings, and boolean flags for the presence of specific security headers.

ParameterTypeDescription
scoreStringAudit score returned by the service.
detailsObjectA string-to-string map with audit details.
has_cspBooleanWhether a Content Security Policy header is present.
has_hstsBooleanWhether an HSTS header is present.
has_x_content_typeBooleanWhether an X-Content-Type-Options header is present.
has_referrer_policyBooleanWhether a Referrer-Policy header is present.
has_x_frame_optionsBooleanWhether an X-Frame-Options header is present.
▣ COMMON ERRORS

Errors any endpoint can return

400bad_request

Required parameter missing or malformed body.

401unauthorized

API key missing, revoked, or not authorized for this service.

429rate_limited

Your plan's per-second rate exceeded. Retry with exponential backoff.

503upstream_busy

Backend temporarily unavailable. Try again in a few seconds.