Skip to content
GET /api/v1/inspect-headers

Security Headers Checker

Paste a URL to analyze its HTTP security headers. The tool checks for Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, and other headers that protect against common web attacks. You'll get a grade and a list of missing protections.

url required
X-Sandbox-Remaining: - get an api key

returns

data.grade
Letter grade based on how many security headers are missing.
data.missing
Recommended security headers the site doesn't send.
data.headers
Every response header, keyed by lowercase name.
data.status_code
HTTP status the URL answered with.
data.url
The URL that was scanned.
response awaiting request sending
Fill in the fields and send a request. The response lands here.

Run it from your code

A temporary key takes one request and lasts seven days at 20 calls a day. Register and it becomes 75 a day, still free.

$ curl -s "https://apixies.io/api/v1/inspect-headers?url=https://github.com" \
    -H "X-API-Key: $APIXIES_KEY" | jq '.data.grade'

"B"

questions

What security headers should every website have?

At minimum: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy. These protect against XSS, clickjacking, MIME sniffing, and information leakage.

What does the security grade mean?

The grade reflects how many recommended security headers are present and correctly configured. An A means all critical headers are set. Lower grades indicate missing protections.

cookies

We use analytics cookies to see how the site gets used. Nothing loads until you accept. Privacy policy