{
  "title": "Security headers",
  "human_url": "https://happytails.ai/en/web-tools/security-headers/",
  "agent_url": "https://happytails.ai/agents/en/web-tools/security-headers/",
  "language": "en",
  "markdown_url": "https://happytails.ai/en/web-tools/security-headers.md",
  "content": "Security headers\nObserved response headers with scoped explanations.\nHow to use Security headers\nEnter a complete website URL in the input field.\nReview the settings, then choose Check URL.\nReview the result, then use Copy result or a download link when available.\nWorking with security headers\nWebsite checks examine different layers: the HTTP response, page source and rendered document may not be identical. Decide whether you need to inspect a URL, validate supplied markup or preview how a browser renders a page.\nCommon questions\nWhy can a browser page differ from its source?\nJavaScript can add or modify content after the initial HTML arrives. Server responses and client rendering should be examined separately when diagnosing missing content.\nDoes a passing checker guarantee search rankings?\nNo. A technical check answers a bounded question, such as whether a tag is present or a URL responds. It does not measure every aspect of usefulness, relevance or search quality.\nUseful next steps\nHTTP status checker\nRedirect chain, status, selected headers and fetch timestamp.\nRedirect checker\nFull chain including loops and relative locations.\nSSL checker\nHostname match, certificate chain and expiry.\nDNS lookup\nA AAAA MX TXT CNAME NS SOA records with resolver and time.",
  "content_format": "text/plain",
  "visibility": "public",
  "links": [
    {
      "name": "HTTP status checker Redirect chain, status, selected headers and fetch timestamp.",
      "url": "https://happytails.ai/en/web-tools/http-status-checker/"
    },
    {
      "name": "Redirect checker Full chain including loops and relative locations.",
      "url": "https://happytails.ai/en/web-tools/redirect-checker/"
    },
    {
      "name": "SSL checker Hostname match, certificate chain and expiry.",
      "url": "https://happytails.ai/en/web-tools/ssl-checker/"
    },
    {
      "name": "DNS lookup A AAAA MX TXT CNAME NS SOA records with resolver and time.",
      "url": "https://happytails.ai/en/network-tools/dns-lookup/"
    }
  ],
  "tool": {
    "id": "security-headers",
    "category": "web-tools",
    "built": true,
    "requirements": "Observed response headers with scoped explanations; no universal security score.",
    "implementation": {
      "fields": [],
      "processing": "Server required",
      "note": "Uses the local diagnostic server to contact the supplied public host or DNS/RDAP provider. Only public internet addresses are permitted; requests time out and redirects are bounded.",
      "experience": {
        "automatic": false,
        "single": true,
        "label": "Website URL",
        "placeholder": "https://happytails.ai",
        "help": "Enter one complete HTTP or HTTPS URL. Only public addresses and ports 80 or 443 are supported.",
        "action": "Check URL"
      },
      "mode": "explicit",
      "interactive": false
    },
    "execution": "POST /api/v1/tools/security-headers/run",
    "api": {
      "id": "security-headers",
      "name": "Security headers",
      "category": "web-tools",
      "description": "Observed response headers with scoped explanations.",
      "notes": "Uses the local diagnostic server to contact the supplied public host or DNS/RDAP provider. Only public internet addresses are permitted; requests time out and redirects are bounded.",
      "human_path": "/en/web-tools/security-headers/",
      "method": "POST",
      "endpoint": "/api/v1/tools/security-headers/run",
      "schema_url": "/api/v1/tools/security-headers",
      "input_schema": {
        "type": "object",
        "additionalProperties": false,
        "properties": {
          "input": {
            "type": "string",
            "maxLength": 1000000,
            "default": "",
            "description": "Plain text input. File tools use files instead unless otherwise documented."
          },
          "options": {
            "type": "object",
            "additionalProperties": false,
            "properties": {}
          }
        }
      },
      "output_schema": {
        "type": "object",
        "required": [
          "tool",
          "result"
        ],
        "properties": {
          "tool": {
            "type": "string"
          },
          "result": {
            "type": "object",
            "required": [
              "text",
              "files"
            ],
            "properties": {
              "text": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "data": {
                "description": "Parsed JSON when the textual result is JSON."
              },
              "name": {
                "type": "string"
              },
              "mime": {
                "type": "string"
              },
              "files": {
                "type": "array",
                "items": {
                  "type": "object",
                  "required": [
                    "name",
                    "mime",
                    "bytes",
                    "base64"
                  ],
                  "properties": {
                    "name": {
                      "type": "string"
                    },
                    "mime": {
                      "type": "string"
                    },
                    "bytes": {
                      "type": "integer"
                    },
                    "base64": {
                      "type": "string",
                      "contentEncoding": "base64"
                    }
                  }
                }
              }
            }
          }
        }
      },
      "processing": "Server; contacts public network services",
      "limits": {
        "request_bytes": 8388608,
        "input_characters": 1000000,
        "files_bytes": 5242880,
        "max_files": 0,
        "timeout_seconds": null
      }
    },
    "agent_processing": "Server; contacts public network services",
    "browser_agent": {
      "supported": true,
      "name": "run_current_tool",
      "discovery": "WebMCP on the human page in a supporting browser",
      "verification": "See audit/API-AUDIT.md; availability is not verification"
    }
  },
  "markdown": "# Security headers\n\n- Human page: https://happytails.ai/en/web-tools/security-headers/\n- Markdown: https://happytails.ai/en/web-tools/security-headers.md\n- Structured JSON: https://happytails.ai/agents/en/web-tools/security-headers/index.json\n- Visibility: public\n\n## Tool capabilities\n\n| Property | Value |\n| --- | --- |\n| Tool ID | `security-headers` |\n| Category | web-tools |\n| Implementation | Registered implementation. Registration alone is not a production-quality guarantee. |\n| Browser execution | Use the visible action or interactive controls. |\n| Browser processing | Server required |\n| HTTP API | /api/v1/tools/security-headers/run |\n| Browser-agent interface | run_current_tool |\n\n### Implementation notes\n\nUses the local diagnostic server to contact the supplied public host or DNS/RDAP provider. Only public internet addresses are permitted; requests time out and redirects are bounded.\n\n### Inputs and settings\n\nText input: Website URL.\n\nExample or placeholder shown in the interface (not a validated fixture):\n\n```text\nhttps://happytails.ai\n```\n\nEnter one complete HTTP or HTTPS URL. Only public addresses and ports 80 or 443 are supported.\n\nNo additional settings are declared for this tool.\n\n### HTTP contract\n\nAPI calls process supplied data on the server. The website origin is `https://happytails.ai`. Server API hosting is not connected on the public website yet. Use your local server origin to test these requests.\n\n```http\nPOST https://happytails.ai/api/v1/tools/security-headers/run\nContent-Type: application/json\n```\n\n[Detailed operation reference](https://happytails.ai/en/api/tools/security-headers.md) · [Shared API guide](https://happytails.ai/en/api.md)\n\n#### Limits\n\n| Limit | Value |\n| --- | --- |\n| request_bytes | 8388608 |\n| input_characters | 1000000 |\n| files_bytes | 5242880 |\n| max_files | 0 |\n| timeout_seconds | Operation-specific network bounds |\n\n#### Complete input schema\n\n```json\n{\n  \"type\": \"object\",\n  \"additionalProperties\": false,\n  \"properties\": {\n    \"input\": {\n      \"type\": \"string\",\n      \"maxLength\": 1000000,\n      \"default\": \"\",\n      \"description\": \"Plain text input. File tools use files instead unless otherwise documented.\"\n    },\n    \"options\": {\n      \"type\": \"object\",\n      \"additionalProperties\": false,\n      \"properties\": {}\n    }\n  }\n}\n```\n\n#### Complete output schema\n\n```json\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"tool\",\n    \"result\"\n  ],\n  \"properties\": {\n    \"tool\": {\n      \"type\": \"string\"\n    },\n    \"result\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"text\",\n        \"files\"\n      ],\n      \"properties\": {\n        \"text\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"data\": {\n          \"description\": \"Parsed JSON when the textual result is JSON.\"\n        },\n        \"name\": {\n          \"type\": \"string\"\n        },\n        \"mime\": {\n          \"type\": \"string\"\n        },\n        \"files\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"name\",\n              \"mime\",\n              \"bytes\",\n              \"base64\"\n            ],\n            \"properties\": {\n              \"name\": {\n                \"type\": \"string\"\n              },\n              \"mime\": {\n                \"type\": \"string\"\n              },\n              \"bytes\": {\n                \"type\": \"integer\"\n              },\n              \"base64\": {\n                \"type\": \"string\",\n                \"contentEncoding\": \"base64\"\n              }\n            }\n          }\n        }\n      }\n    }\n  }\n}\n```\n\n#### Error and retry handling\n\nFailures return a non-200 status and `error.code` plus `error.message`. Correct invalid input before retrying; retry server-busy responses with bounded backoff. Returned files contain Base64 data, not persistent download URLs. Decode and inspect the output before treating conversion as successful. See the shared API guide for the complete status and timeout rules.\n\n### Browser-agent workflow\n\n1. Open the human page in a browser that supports WebMCP.\n2. Discover the interface exposed by that page; use its actual schema.\n3. Select files on the page first when the tool requires files.\n4. Call `run_current_tool` with valid input and settings.\n5. Inspect the returned result or error and the displayed output. Retrieve files from the displayed download links.\n\nCalls do not automatically copy or download results. Browser permissions still apply. Interface availability alone is not proof of successful execution.\n\n### Planning specification\n\nObserved response headers with scoped explanations; no universal security score.\n\nThis describes intended requirements. Use the implementation notes, interface schema and observed output to determine current support.\n\n### Complete machine-readable capability record\n\n```json\n{\n  \"id\": \"security-headers\",\n  \"category\": \"web-tools\",\n  \"built\": true,\n  \"requirements\": \"Observed response headers with scoped explanations; no universal security score.\",\n  \"implementation\": {\n    \"fields\": [],\n    \"processing\": \"Server required\",\n    \"note\": \"Uses the local diagnostic server to contact the supplied public host or DNS/RDAP provider. Only public internet addresses are permitted; requests time out and redirects are bounded.\",\n    \"experience\": {\n      \"automatic\": false,\n      \"single\": true,\n      \"label\": \"Website URL\",\n      \"placeholder\": \"https://happytails.ai\",\n      \"help\": \"Enter one complete HTTP or HTTPS URL. Only public addresses and ports 80 or 443 are supported.\",\n      \"action\": \"Check URL\"\n    },\n    \"mode\": \"explicit\",\n    \"interactive\": false\n  },\n  \"execution\": \"POST /api/v1/tools/security-headers/run\",\n  \"api\": {\n    \"id\": \"security-headers\",\n    \"name\": \"Security headers\",\n    \"category\": \"web-tools\",\n    \"description\": \"Observed response headers with scoped explanations.\",\n    \"notes\": \"Uses the local diagnostic server to contact the supplied public host or DNS/RDAP provider. Only public internet addresses are permitted; requests time out and redirects are bounded.\",\n    \"human_path\": \"/en/web-tools/security-headers/\",\n    \"method\": \"POST\",\n    \"endpoint\": \"/api/v1/tools/security-headers/run\",\n    \"schema_url\": \"/api/v1/tools/security-headers\",\n    \"input_schema\": {\n      \"type\": \"object\",\n      \"additionalProperties\": false,\n      \"properties\": {\n        \"input\": {\n          \"type\": \"string\",\n          \"maxLength\": 1000000,\n          \"default\": \"\",\n          \"description\": \"Plain text input. File tools use files instead unless otherwise documented.\"\n        },\n        \"options\": {\n          \"type\": \"object\",\n          \"additionalProperties\": false,\n          \"properties\": {}\n        }\n      }\n    },\n    \"output_schema\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"tool\",\n        \"result\"\n      ],\n      \"properties\": {\n        \"tool\": {\n          \"type\": \"string\"\n        },\n        \"result\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"text\",\n            \"files\"\n          ],\n          \"properties\": {\n            \"text\": {\n              \"type\": [\n                \"string\",\n                \"null\"\n              ]\n            },\n            \"data\": {\n              \"description\": \"Parsed JSON when the textual result is JSON.\"\n            },\n            \"name\": {\n              \"type\": \"string\"\n            },\n            \"mime\": {\n              \"type\": \"string\"\n            },\n            \"files\": {\n              \"type\": \"array\",\n              \"items\": {\n                \"type\": \"object\",\n                \"required\": [\n                  \"name\",\n                  \"mime\",\n                  \"bytes\",\n                  \"base64\"\n                ],\n                \"properties\": {\n                  \"name\": {\n                    \"type\": \"string\"\n                  },\n                  \"mime\": {\n                    \"type\": \"string\"\n                  },\n                  \"bytes\": {\n                    \"type\": \"integer\"\n                  },\n                  \"base64\": {\n                    \"type\": \"string\",\n                    \"contentEncoding\": \"base64\"\n                  }\n                }\n              }\n            }\n          }\n        }\n      }\n    },\n    \"processing\": \"Server; contacts public network services\",\n    \"limits\": {\n      \"request_bytes\": 8388608,\n      \"input_characters\": 1000000,\n      \"files_bytes\": 5242880,\n      \"max_files\": 0,\n      \"timeout_seconds\": null\n    }\n  },\n  \"agent_processing\": \"Server; contacts public network services\",\n  \"browser_agent\": {\n    \"supported\": true,\n    \"name\": \"run_current_tool\",\n    \"discovery\": \"WebMCP on the human page in a supporting browser\",\n    \"verification\": \"See audit/API-AUDIT.md; availability is not verification\"\n  }\n}\n```\n\n## Page guide\n\nObserved response headers with scoped explanations.\n\n## How to use Security headers\n\n1. Enter a complete website URL in the input field.\n2. Review the settings, then choose Check URL.\n3. Review the result, then use Copy result or a download link when available.\n\n## Working with security headers\n\nWebsite checks examine different layers: the HTTP response, page source and rendered document may not be identical. Decide whether you need to inspect a URL, validate supplied markup or preview how a browser renders a page.\n\n## Common questions\n\n### Why can a browser page differ from its source?\n\nJavaScript can add or modify content after the initial HTML arrives. Server responses and client rendering should be examined separately when diagnosing missing content.\n\n### Does a passing checker guarantee search rankings?\n\nNo. A technical check answers a bounded question, such as whether a tag is present or a URL responds. It does not measure every aspect of usefulness, relevance or search quality.\n\n## Useful next steps\n\n- [HTTP status checker](https://happytails.ai/en/web-tools/http-status-checker/): Redirect chain, status, selected headers and fetch timestamp. ([Markdown](https://happytails.ai/en/web-tools/http-status-checker.md))\n\n- [Redirect checker](https://happytails.ai/en/web-tools/redirect-checker/): Full chain including loops and relative locations. ([Markdown](https://happytails.ai/en/web-tools/redirect-checker.md))\n\n- [SSL checker](https://happytails.ai/en/web-tools/ssl-checker/): Hostname match, certificate chain and expiry. ([Markdown](https://happytails.ai/en/web-tools/ssl-checker.md))\n\n- [DNS lookup](https://happytails.ai/en/network-tools/dns-lookup/): A AAAA MX TXT CNAME NS SOA records with resolver and time. ([Markdown](https://happytails.ai/en/network-tools/dns-lookup.md))\n"
}