Security Headers Lookup — HSTS, CSP & Header Grade API
Pricing
from $3.00 / 1,000 successful lookups
Security Headers Lookup — HSTS, CSP & Header Grade API
Check any website's security-relevant HTTP response headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and more) and get an A-F letter grade in one request. No key, no browser, just the live headers a browser would see.
Pricing
from $3.00 / 1,000 successful lookups
Rating
0.0
(0)
Developer
Adrian Voss
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
4 days ago
Last modified
Categories
Share
Security Headers Lookup
Check any website's security-relevant HTTP response headers — HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the two Cross-Origin isolation headers — and get back a letter grade (A–F), the same manual check tools like securityheaders.com run one URL at a time. No API key, no browser rendering — this reads the raw response headers from a single HTTP request.
Features
- Full header sweep. Checks all 8 major security headers in one request: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
- Letter grade.
score/maxScoreout of 8, converted to an A–F grade based on the percentage of headers present. - Cookie flags. Reports whether
Set-Cookieuses theSecureandHttpOnlyflags. - Raw values included. Every present header's actual value is returned, not just a pass/fail flag — useful for spotting a misconfigured-but-present CSP.
- Pay only for resolved checks. URLs that don't respond cost nothing — see Pricing.
How to use Security Headers Lookup — HSTS, CSP & Header Grade API
- In the Apify Console. Open the actor page and click Start — the
itemsfield is already pre-filled with a working example. Results land in the run's dataset as soon as each item is found. - Via the API. Call it directly with a POST request — no Console needed once you have an API token:
curl "https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>" \-X POST \-H "Content-Type: application/json" \-d '{"items":["github.com"]}'
- On a schedule. Save this actor as an Apify Task with the input you want, then add a Schedule (hourly, daily, weekly) so it runs on its own — no server of your own required.
Input
{"items": ["github.com", "cloudflare.com"],"maxConcurrency": 5,"proxyConfiguration": { "useApifyProxy": true }}
items is a list of domains or full URLs (a bare domain like github.com is normalized to
https://github.com). One dataset row is returned per item; rows with "found": false
are never charged. maxConcurrency (default 5) caps parallel requests — this target has no
browser fallback, so a conservative concurrency avoids getting blocked. proxyConfiguration
lets you route through Apify Proxy; residential proxies are recommended for anti-bot-sensitive
targets.
Output
{"query": "github.com","found": true,"data": {"url": "https://github.com/","statusCode": 200,"headers": {"hsts": "max-age=31536000; includeSubdomains","contentSecurityPolicy": null,"xFrameOptions": "deny","xContentTypeOptions": "nosniff","referrerPolicy": "origin-when-cross-origin","permissionsPolicy": null,"crossOriginOpenerPolicy": "same-origin","crossOriginResourcePolicy": "same-origin"},"score": 5,"maxScore": 8,"grade": "C","cookiesSetSecure": true,"cookiesSetHttpOnly": true},"scrapedAt": "2026-08-20T14:03:11.000Z"}
A row is only marked found: true — and only then billed — once the URL returns an
actual HTTP response the actor can read headers from. A header that isn't set comes back
as null rather than being omitted, so you can tell "checked, absent" apart from "not
checked." A missing header only lowers the grade — it never causes a found: false row;
that only happens when the request itself fails (DNS error, timeout, connection refused).
Use cases
- Audit your own production sites for missing security headers before a compliance review.
- Screen a list of vendor or partner domains for baseline header hygiene during due diligence.
- Track header grade over time across a fleet of sites after infrastructure or CDN changes.
- Feed a security dashboard or ticketing pipeline that flags any domain scoring below a given grade.
- Spot-check whether a WAF, CDN, or reverse proxy is stripping expected security headers.
Pricing
$5 per 1,000 results, plus a $0.005 start fee. Misses (found:false) are never charged.
Use it from Clay, n8n, Make, or an AI agent
This actor runs synchronously over plain HTTP — call it directly from a script, a workflow tool, or an AI agent, no Apify Console needed once you have an API token.
curl "https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>" \-X POST \-H "Content-Type: application/json" \-d '{"items":["github.com"]}'
n8n. Add an HTTP Request node: Method POST, URL https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>, Body Content Type JSON, JSON Body {"items":["github.com"]} (swap in an expression from an earlier node for a real value).
Clay. Add an "HTTP API" column: Method POST, URL https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>, Body {"items":["{{value}}"]}, mapping the row's value into the items array.
MCP. In Claude, Cursor, or any MCP client with the Apify MCP server, ask for "Security Headers Lookup | Apify" — the agent will find and run this actor.
FAQ
What counts as "found" vs "not found"? Any URL that returns an HTTP response (even a
4xx or 5xx status) counts as found, because the headers are still readable and gradable.
Only requests that fail entirely — DNS resolution errors, timeouts, connection refused —
come back as found: false.
Does a missing header fail the whole lookup? No. Each of the 8 headers is checked
independently; missing ones just lower the score and grade. A site with zero security
headers still returns found: true with grade: "F".
Is CSP or Permissions-Policy content validated? No — presence is scored, not policy
quality. A Content-Security-Policy header with a weak or misconfigured value still counts
as present. Parsing policy correctness is out of scope for a single-fetch actor.
Does it follow redirects? Yes, and data.url reflects the final URL after any
redirects, which may differ from the input if the target redirects (e.g. HTTP → HTTPS or
apex → www).
Can I check localhost or internal domains? No — this actor runs on Apify's infrastructure and can only reach publicly routable URLs.
Does it use a browser? No, this is a plain HTTP request via Cheerio's crawler, not a headless browser — headers set by client-side JavaScript after page load won't appear, only headers present on the initial server response.