HeaderGuard
Scan a website's HTTP security headers (HSTS, CSP, framing, COOP/CORP, cookies). Score + fixes.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"headerguard": {
"url": "https://headerguard.mike-tusa.workers.dev/mcp"
}
}
}Remote endpoints
https://headerguard.mike-tusa.workers.dev/mcpstreamable-httpWhat it can do
Tool inventory
Tools (1)
🟢scan_headers(url, include_raw)
Scan the HTTP security headers of a public website. Returns a 0–100 score and A+–F grade (HTTPS 10, HSTS 15, CSP 25, framing 10, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 5, COOP 5, CORP 5, cookies 5, minus up to 5 for version-leak headers; without HTTPS the score is capped at 39), each header's status and notes, recommended fix headers, and a link to the full report with copy-paste snippets for nginx, Apache, Cloudflare, Netlify, Vercel and Express. Read-only: it sends ordinary GET requests to the site (following up to 10 redirects, each safety-checked) and never reads page bodies. Same engine and scoring as the HeaderGuard JSON API (GET /api/scan).
Input Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"minLength": 1,
"maxLength": 2048,
"description": "URL or bare domain to scan, e.g. example.com or https://example.com/login. A bare domain is scanned as https://<domain>/ (plain HTTP if HTTPS does not answer)."
},
"include_raw": {
"type": "boolean",
"default": false,
"description": "Also return the full /api/scan JSON (redirect chain, all response headers with cookie values redacted, per-platform fix snippets) in structuredContent.raw. Larger output."
}
},
"required": [
"url"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "Normalized URL that was scanned"
},
"finalUrl": {
"type": "string"
},
"finalStatus": {
"type": "number"
},
"redirectCount": {
"type": "number"
},
"score": {
"type": "number",
"description": "Omitted when the grade is withheld"
},
"grade": {
"type": "string",
"enum": [
"A+",
"A",
"B",
"C",
"D",
"F"
],
"description": "Omitted when the grade is withheld"
},
"gradeWithheld": {
"type": "boolean",
"description": "true when the site blocked, rate-limited or challenged the scanner"
},
"gradeWithheldReason": {
"type": "string"
},
"reliability": {
"type": "string",
"enum": [
"ok",
"blocked_or_challenged"
]
},
"findings": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "https, hsts, csp, framing, xcto, referrer, permissions, coop, corp, cookies, coep, xxss or leaks"
},
"name": {
"type": "string"
},
"status": {
"type": "string",
"enum": [
"pass",
"warn",
"fail",
"info"
]
},
"points": {
"type": "number"
},
"max": {
"type": "number"
},
"summary": {
"type": "string"
},
"notes": {
"type": "array",
"items": {
"type": "object",
"properties": {
"level": {
"type": "string",
"enum": [
"pass",
"info",
"warn",
"fail"
]
},
"text": {
"type": "string"
}
},
"required": [
"level",
"text"
]
}
}
},
"required": [
"id",
"name",
"status",
"points",
"max",
"notes"
]
}
},
"fixes": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"title": {
"type": "string"
},
"header": {
"type": "string",
"description": "Header to send (omitted for non-header fixes such as the HTTPS redirect)"
},
"value": {
"type": "string",
"description": "Recommended value (a fixed, conservative constant)"
},
"note": {
"type": "string"
}
},
"required": [
"id",
"title"
]
}
},
"notes": {
"type": "array",
"items": {
"type": "string"
}
},
"scannedAt": {
"type": "string"
},
"cached": {
"type": "boolean"
},
"plan": {
"type": "string",
"enum": [
"free",
"pro"
]
},
"reportUrl": {
"type": "string"
},
"apiUrl": {
"type": "string"
},
"version": {
"type": "string"
},
"raw": {
"type": "object",
"description": "Full /api/scan response (only when include_raw is true)"
}
},
"required": [
"url",
"finalUrl",
"gradeWithheld",
"reliability",
"findings",
"fixes",
"plan",
"reportUrl"
]
}Community
Evidence