Security Headers Lookup — HSTS, CSP & Header Grade API avatar

Security Headers Lookup — HSTS, CSP & Header Grade API

Pricing

from $3.00 / 1,000 successful lookups

Go to Apify Store
Security Headers Lookup — HSTS, CSP & Header Grade API

Security Headers Lookup — HSTS, CSP & Header Grade API

Check any website's security-relevant HTTP response headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and more) and get an A-F letter grade in one request. No key, no browser, just the live headers a browser would see.

Pricing

from $3.00 / 1,000 successful lookups

Rating

0.0

(0)

Developer

Adrian Voss

Adrian Voss

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

4 days ago

Last modified

Share

Security Headers Lookup

Check any website's security-relevant HTTP response headers — HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the two Cross-Origin isolation headers — and get back a letter grade (A–F), the same manual check tools like securityheaders.com run one URL at a time. No API key, no browser rendering — this reads the raw response headers from a single HTTP request.

Features

  • Full header sweep. Checks all 8 major security headers in one request: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
  • Letter grade. score / maxScore out of 8, converted to an A–F grade based on the percentage of headers present.
  • Cookie flags. Reports whether Set-Cookie uses the Secure and HttpOnly flags.
  • Raw values included. Every present header's actual value is returned, not just a pass/fail flag — useful for spotting a misconfigured-but-present CSP.
  • Pay only for resolved checks. URLs that don't respond cost nothing — see Pricing.

How to use Security Headers Lookup — HSTS, CSP & Header Grade API

  1. In the Apify Console. Open the actor page and click Start — the items field is already pre-filled with a working example. Results land in the run's dataset as soon as each item is found.
  2. Via the API. Call it directly with a POST request — no Console needed once you have an API token:
    curl "https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>" \
    -X POST \
    -H "Content-Type: application/json" \
    -d '{"items":["github.com"]}'
  3. On a schedule. Save this actor as an Apify Task with the input you want, then add a Schedule (hourly, daily, weekly) so it runs on its own — no server of your own required.

Input

{
"items": ["github.com", "cloudflare.com"],
"maxConcurrency": 5,
"proxyConfiguration": { "useApifyProxy": true }
}

items is a list of domains or full URLs (a bare domain like github.com is normalized to https://github.com). One dataset row is returned per item; rows with "found": false are never charged. maxConcurrency (default 5) caps parallel requests — this target has no browser fallback, so a conservative concurrency avoids getting blocked. proxyConfiguration lets you route through Apify Proxy; residential proxies are recommended for anti-bot-sensitive targets.

Output

{
"query": "github.com",
"found": true,
"data": {
"url": "https://github.com/",
"statusCode": 200,
"headers": {
"hsts": "max-age=31536000; includeSubdomains",
"contentSecurityPolicy": null,
"xFrameOptions": "deny",
"xContentTypeOptions": "nosniff",
"referrerPolicy": "origin-when-cross-origin",
"permissionsPolicy": null,
"crossOriginOpenerPolicy": "same-origin",
"crossOriginResourcePolicy": "same-origin"
},
"score": 5,
"maxScore": 8,
"grade": "C",
"cookiesSetSecure": true,
"cookiesSetHttpOnly": true
},
"scrapedAt": "2026-08-20T14:03:11.000Z"
}

A row is only marked found: true — and only then billed — once the URL returns an actual HTTP response the actor can read headers from. A header that isn't set comes back as null rather than being omitted, so you can tell "checked, absent" apart from "not checked." A missing header only lowers the grade — it never causes a found: false row; that only happens when the request itself fails (DNS error, timeout, connection refused).

Use cases

  • Audit your own production sites for missing security headers before a compliance review.
  • Screen a list of vendor or partner domains for baseline header hygiene during due diligence.
  • Track header grade over time across a fleet of sites after infrastructure or CDN changes.
  • Feed a security dashboard or ticketing pipeline that flags any domain scoring below a given grade.
  • Spot-check whether a WAF, CDN, or reverse proxy is stripping expected security headers.

Pricing

$5 per 1,000 results, plus a $0.005 start fee. Misses (found:false) are never charged.

Use it from Clay, n8n, Make, or an AI agent

This actor runs synchronously over plain HTTP — call it directly from a script, a workflow tool, or an AI agent, no Apify Console needed once you have an API token.

curl "https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>" \
-X POST \
-H "Content-Type: application/json" \
-d '{"items":["github.com"]}'

n8n. Add an HTTP Request node: Method POST, URL https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>, Body Content Type JSON, JSON Body {"items":["github.com"]} (swap in an expression from an earlier node for a real value).

Clay. Add an "HTTP API" column: Method POST, URL https://api.apify.com/v2/acts/accountable_eel~security-headers-lookup/run-sync-get-dataset-items?token=<YOUR_TOKEN>, Body {"items":["{{value}}"]}, mapping the row's value into the items array.

MCP. In Claude, Cursor, or any MCP client with the Apify MCP server, ask for "Security Headers Lookup | Apify" — the agent will find and run this actor.

FAQ

What counts as "found" vs "not found"? Any URL that returns an HTTP response (even a 4xx or 5xx status) counts as found, because the headers are still readable and gradable. Only requests that fail entirely — DNS resolution errors, timeouts, connection refused — come back as found: false.

Does a missing header fail the whole lookup? No. Each of the 8 headers is checked independently; missing ones just lower the score and grade. A site with zero security headers still returns found: true with grade: "F".

Is CSP or Permissions-Policy content validated? No — presence is scored, not policy quality. A Content-Security-Policy header with a weak or misconfigured value still counts as present. Parsing policy correctness is out of scope for a single-fetch actor.

Does it follow redirects? Yes, and data.url reflects the final URL after any redirects, which may differ from the input if the target redirects (e.g. HTTP → HTTPS or apex → www).

Can I check localhost or internal domains? No — this actor runs on Apify's infrastructure and can only reach publicly routable URLs.

Does it use a browser? No, this is a plain HTTP request via Cheerio's crawler, not a headless browser — headers set by client-side JavaScript after page load won't appear, only headers present on the initial server response.