HTTP headers
LiveHSTS, CSP, cookies flags — what the server actually sends.
Fetches a public URL with the Site Audit SSRF guard and lists the headers that matter for security and caching.
Server URL
https://toolcargo.com/mcp/http-headersClaude Code
claude mcp add --transport http --scope user toolcargo-http-headers https://toolcargo.com/mcp/http-headers \
--header "Authorization: Bearer YOUR_API_KEY"Create a key in your dashboard. Other clients: setup guides.
What it helps you do
- Presence of HSTS/CSP/framing headers
- Cookie HttpOnly/Secure/SameSite without values
Built for: Developers and SEOs hardening a launch.
Example requests
Launch hygiene
“Inspect headers for https://client.com with ToolCargo.”
A list of present/absent headers and cookie flags.
Step-by-step workflows: pre-launch check · fixing link previews
Tools
| Tool | What it does | Access |
|---|---|---|
inspect_headersInspect HTTP headers | Fetch a public URL (SSRF-guarded) and report HSTS, CSP, framing, cookies flags and a few other headers. | Read-only |
Requirements
- • A ToolCargo account with Site Audit activated (free).
- • A public https URL.
Limitations
- • Does not grade TLS ciphers. Cookie values are not returned.
Supported clients
“Tested” means we connected that client to this endpoint and ran a tool call ourselves. “Documented” means the client supports this setup per its own docs, but we have not tested it yet.
| Claude Code | API key header | Tested | Remote HTTP server with an Authorization header. Tested 2026-09-11 (v2.1.268). |
| Claude (claude.ai) | OAuth sign-in | Tested | Custom connector with OAuth sign-in; tested on claude.ai web 2026-09-11. Desktop and mobile use the same account connectors but were not tested separately. |
| Cursor | API key header | Documented, not yet tested | mcp.json with url and headers. |
| VS Code (Copilot agent mode) | API key header | Documented, not yet tested | .vscode/mcp.json with type http and headers. |
| ChatGPT (developer mode) | OAuth sign-in | Documented, not yet tested | Requires OAuth; API keys cannot be entered. |
| MCP Inspector | API key header | Tested | CLI mode, tested 2026-09-11. Useful for calling tools directly. |
More in SEO
Pricing
Free
$0For trying the connector on your own sites.
50 calls/month · 25 links per check
Pro
$12/moFor freelancers and agencies auditing client sites every week.
2,000 calls/month · 100 links per check
Proposed test price. See the pricing page for checkout status.