{
  "name": "http-headers",
  "summary": "Returns the response headers, final status, redirect chain and a security-header grade for a URL, without downloading the body.",
  "rationale": "It needs a hardened HTTP client -- an agent that fetches the URL itself can walk a redirect into a private address -- and the security grade is a deterministic, documented rubric it would otherwise have to build and maintain.",
  "family": "fetch",
  "price_usd": "0.002",
  "free": false,
  "timeout_ms": 8000,
  "max_timeout_seconds": 29,
  "input_schema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "url": {
        "type": "string",
        "maxLength": 2048,
        "format": "uri",
        "description": "Absolute http(s) URL to request, up to 2048 characters; up to five redirects are followed and every hop goes through the SSRF guard."
      },
      "method": {
        "default": "HEAD",
        "description": "HTTP method for the request, HEAD by default; GET is for servers that mishandle HEAD, and its body is still never read.",
        "type": "string",
        "enum": [
          "HEAD",
          "GET"
        ]
      }
    },
    "required": [
      "url"
    ],
    "additionalProperties": false
  },
  "input_example": {
    "url": "https://example.com/",
    "method": "HEAD"
  },
  "output_example": {
    "url": "https://example.com/",
    "source_url": "https://example.com/",
    "final_url": "https://example.com/",
    "redirect_count": 0,
    "http_status": 200,
    "headers": {
      "content-security-policy": "default-src 'self'",
      "content-type": "text/html; charset=utf-8",
      "cross-origin-opener-policy": "same-origin",
      "cross-origin-resource-policy": "same-origin",
      "permissions-policy": "geolocation=()",
      "referrer-policy": "strict-origin-when-cross-origin",
      "strict-transport-security": "max-age=63072000; includeSubDomains; preload",
      "x-content-type-options": "nosniff",
      "x-frame-options": "DENY"
    },
    "security": {
      "hsts": {
        "present": true,
        "max_age": 63072000,
        "include_subdomains": true,
        "preload": true
      },
      "csp_present": true,
      "x_content_type_options": "nosniff",
      "x_frame_options": "DENY",
      "referrer_policy": "strict-origin-when-cross-origin",
      "permissions_policy": "geolocation=()",
      "cross_origin_opener_policy": "same-origin",
      "cross_origin_resource_policy": "same-origin"
    },
    "security_grade": "A",
    "missing_security_headers": [],
    "fetched_at": "2026-08-26T18:00:00.000Z"
  },
  "errors": [
    "invalid_input",
    "blocked_target",
    "unreachable_target",
    "upstream_timeout",
    "internal"
  ]
}