Web security audit
Scan a public website for TLS and browser security header weaknesses and return a security score with fixes.
Endpoint
https://apiacre.com/v1/web/security-auditSend the JSON body below. An unpaid request returns HTTP 402 with a PAYMENT-REQUIRED header; an x402-compatible buyer signs the requirement and retries with PAYMENT-SIGNATURE.
Pay $0.05 USDC and run in your browserOfficial Coinbase agent path
Coinbase Agentic Wallet can satisfy this x402 request in one command. Running it may pay automatically, so --max-amount is fixed to $0.05 USDC in atomic units. Copying the command does not install, authenticate, sign, or pay; review the request and use a separate low-value wallet before running it.
npx --yes awal@latest x402 pay https://apiacre.com/v1/web/security-audit \
-X POST \
-d '{"url":"https://example.com"}' \
--max-amount 50000 \
--jsonCoinbase pay-for-service documentation · Buyer setup and wallet safety
Alternative third-party AgentCash commands
Run check first without payment. Its fetch command may automatically pay up to the exact listed price.
npx --yes agentcash@latest check https://apiacre.com/v1/web/security-audit
npx --yes agentcash@latest fetch https://apiacre.com/v1/web/security-audit \
--method POST \
--header 'content-type: application/json' \
--body '{"url":"https://example.com"}' \
--payment-protocol x402 \
--payment-network base \
--max-amount 0.050Input example
{
"url": "https://example.com"
}Response shape
{
"request_id": "018f1f54-7f38-7ba2-8dc3-5f90272d9f1a",
"service": "web.security-audit",
"version": "1",
"data": {
"url": "https://example.com/",
"score": 0,
"present": {},
"missing": [
{
"header": "strict-transport-security",
"purpose": "HSTS"
},
{
"header": "content-security-policy",
"purpose": "CSP"
},
{
"header": "x-content-type-options",
"purpose": "MIME sniffing protection"
},
{
"header": "referrer-policy",
"purpose": "Referrer policy"
},
{
"header": "permissions-policy",
"purpose": "Permissions policy"
},
{
"header": "cross-origin-opener-policy",
"purpose": "Cross-origin isolation"
}
],
"cookieFlags": {
"secure": false,
"httpOnly": false,
"sameSite": false
}
},
"meta": {
"duration_ms": 42,
"cached": false,
"sources": [],
"warnings": [],
"next_actions": []
}
}Try the payment challenge
curl -i -X POST 'https://apiacre.com/v1/web/security-audit' \
-H 'content-type: application/json' \
--data '{"url":"https://example.com"}'