MERCURY Cited Headers API

The cited-headers API from MERCURY — 1 operation(s) for cited-headers.

Operations 1

GET /buy/headers MERCURY Cited Security-Headers Audit #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/mercury-hq-com-cited-headers-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

mercury-hq-com-cited-headers-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: MERCURY x402 storefront Cited Headers API
  version: '1'
  x-spec: mercury-storefront/1
  description: Agent-payable resources over HTTP 402 (x402). LIVE — Base mainnet, real USDC, no token. Only currently-deliverable routes are listed (web-fetch is the live paid SKU; mints are gated off). Free discovery at /.well-known/x402, /x402/discovery, /catalog, and /manifest.
servers:
- url: https://network.mercury-hq.com
tags:
- name: cited-headers
paths:
  /buy/headers:
    get:
      summary: MERCURY Cited Security-Headers Audit
      description: URL → a deterministic HTTP security-headers audit (HSTS, CSP, X-Frame, X-Content-Type, Referrer-Policy, Permissions-Policy + more) with a letter grade and concrete findings, wrapped in a signed, offline-verifiable provenance receipt. Keyless, no LLM, no signup.
      operationId: buy_cited_headers
      tags:
      - cited-headers
      responses:
        '200':
          description: Delivered after the x402 payment settles on Base mainnet.
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                    description: true on success; false on an honest failure (never charged for a stub)
                  url:
                    type: string
                    description: final URL after redirects
                  status:
                    type: integer
                    description: upstream HTTP status of the audited response
                  text:
                    type: string
                    description: canonical sorted-key JSON of `data` — the exact string the receipt signs over
                  fetchedAt:
                    type: string
                    description: ISO-8601 fetch time (provenance metadata)
                  data:
                    type: object
                    description: the deterministic security-headers verdict
                    properties:
                      grade:
                        type: string
                        enum:
                        - A
                        - B
                        - C
                        - D
                        - E
                        - F
                      score:
                        type: integer
                      maxScore:
                        type: integer
                      percentage:
                        type: integer
                      passed:
                        type: integer
                      failed:
                        type: integer
                      checks:
                        type: array
                        items:
                          type: object
                          properties:
                            header:
                              type: string
                            label:
                              type: string
                            present:
                              type: boolean
                            pass:
                              type: boolean
                            weight:
                              type: integer
                            value:
                              type:
                              - string
                              - 'null'
                            note:
                              type: string
                      findings:
                        type: array
                        items:
                          type: object
                          properties:
                            header:
                              type: string
                            severity:
                              type: string
                              enum:
                              - high
                              - medium
                              - low
                            remediate:
                              type: string
                      serverBanner:
                        type:
                        - string
                        - 'null'
                      rubric:
                        type: string
                  error:
                    type: string
                    description: present only when ok:false
                required:
                - ok
                - url
                additionalProperties: true
        '402':
          description: Payment Required — retry with an x402-signed payment (e.g. x402-fetch). Terms are in the challenge body (x402 v1).
      parameters:
      - name: url
        in: query
        required: true
        schema:
          type: string
          maxLength: 2048
          description: the page/endpoint to audit (http/https)
        description: the page/endpoint to audit (http/https)
      x-payment-info:
        protocols:
        - x402
        scheme: exact
        price: $0.005
        currency: USDC
        network: base
        networkCaip2: eip155:8453
        testnet: false
        asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
        payTo: '0xe10B9d44e72A29B9c19da02981FFCd875308e3C1'
        facilitator: https://api.cdp.coinbase.com/platform/v2/x402
        x402Version: 1
      x-x402:
        scheme: exact
        price: $0.005
        currency: USDC
        network: base
        networkCaip2: eip155:8453
        asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
        payTo: '0xe10B9d44e72A29B9c19da02981FFCd875308e3C1'
        facilitator: https://api.cdp.coinbase.com/platform/v2/x402
        testnet: false
        maxTimeoutSeconds: 60
x-payment-info:
  protocols:
  - x402
  network: base
  currency: USDC
  payTo: '0xe10B9d44e72A29B9c19da02981FFCd875308e3C1'
  facilitator: https://api.cdp.coinbase.com/platform/v2/x402
  testnet: false
  spec: mercury-storefront/1