HeaderGuard

Scan a website's HTTP security headers (HSTS, CSP, framing, COOP/CORP, cookies). Score + fixes.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
80%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~857Tokens (tool definitions)
~7.6 KBTypical response size
Moderate attention impact (0.67% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "headerguard": {
      "url": "https://headerguard.mike-tusa.workers.dev/mcp"
    }
  }
}

Remote endpoints

https://headerguard.mike-tusa.workers.dev/mcpstreamable-http

What it can do

Tool inventory

Tools (1)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢scan_headers(url, include_raw)

Scan the HTTP security headers of a public website. Returns a 0–100 score and A+–F grade (HTTPS 10, HSTS 15, CSP 25, framing 10, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 5, COOP 5, CORP 5, cookies 5, minus up to 5 for version-leak headers; without HTTPS the score is capped at 39), each header's status and notes, recommended fix headers, and a link to the full report with copy-paste snippets for nginx, Apache, Cloudflare, Netlify, Vercel and Express. Read-only: it sends ordinary GET requests to the site (following up to 10 redirects, each safety-checked) and never reads page bodies. Same engine and scoring as the HeaderGuard JSON API (GET /api/scan).

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "minLength": 1,
      "maxLength": 2048,
      "description": "URL or bare domain to scan, e.g. example.com or https://example.com/login. A bare domain is scanned as https://<domain>/ (plain HTTP if HTTPS does not answer)."
    },
    "include_raw": {
      "type": "boolean",
      "default": false,
      "description": "Also return the full /api/scan JSON (redirect chain, all response headers with cookie values redacted, per-platform fix snippets) in structuredContent.raw. Larger output."
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Normalized URL that was scanned"
    },
    "finalUrl": {
      "type": "string"
    },
    "finalStatus": {
      "type": "number"
    },
    "redirectCount": {
      "type": "number"
    },
    "score": {
      "type": "number",
      "description": "Omitted when the grade is withheld"
    },
    "grade": {
      "type": "string",
      "enum": [
        "A+",
        "A",
        "B",
        "C",
        "D",
        "F"
      ],
      "description": "Omitted when the grade is withheld"
    },
    "gradeWithheld": {
      "type": "boolean",
      "description": "true when the site blocked, rate-limited or challenged the scanner"
    },
    "gradeWithheldReason": {
      "type": "string"
    },
    "reliability": {
      "type": "string",
      "enum": [
        "ok",
        "blocked_or_challenged"
      ]
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "description": "https, hsts, csp, framing, xcto, referrer, permissions, coop, corp, cookies, coep, xxss or leaks"
          },
          "name": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "enum": [
              "pass",
              "warn",
              "fail",
              "info"
            ]
          },
          "points": {
            "type": "number"
          },
          "max": {
            "type": "number"
          },
          "summary": {
            "type": "string"
          },
          "notes": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "level": {
                  "type": "string",
                  "enum": [
                    "pass",
                    "info",
                    "warn",
                    "fail"
                  ]
                },
                "text": {
                  "type": "string"
                }
              },
              "required": [
                "level",
                "text"
              ]
            }
          }
        },
        "required": [
          "id",
          "name",
          "status",
          "points",
          "max",
          "notes"
        ]
      }
    },
    "fixes": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "title": {
            "type": "string"
          },
          "header": {
            "type": "string",
            "description": "Header to send (omitted for non-header fixes such as the HTTPS redirect)"
          },
          "value": {
            "type": "string",
            "description": "Recommended value (a fixed, conservative constant)"
          },
          "note": {
            "type": "string"
          }
        },
        "required": [
          "id",
          "title"
        ]
      }
    },
    "notes": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "scannedAt": {
      "type": "string"
    },
    "cached": {
      "type": "boolean"
    },
    "plan": {
      "type": "string",
      "enum": [
        "free",
        "pro"
      ]
    },
    "reportUrl": {
      "type": "string"
    },
    "apiUrl": {
      "type": "string"
    },
    "version": {
      "type": "string"
    },
    "raw": {
      "type": "object",
      "description": "Full /api/scan response (only when include_raw is true)"
    }
  },
  "required": [
    "url",
    "finalUrl",
    "gradeWithheld",
    "reliability",
    "findings",
    "fixes",
    "plan",
    "reportUrl"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded1 tools