API health check
Is this API endpoint healthy? Liveness check, response headers, and TLS certificate status in one pass.
3 tools run server-side in one request. You pay once, settle once, and get a single response - no orchestration, no per-step payments, and a partial-success envelope if any step fails. USDC over x402 on any supported chain.
When to use this pack
An agent needs to verify an API is up and properly configured before making production calls: is it reachable (status + latency), what do the response headers say (rate limits, auth requirements, CORS), and is the TLS cert valid and not expiring soon?
Tools in this pack
All 3 run inside the single $0.005 call above. Each is also callable on its own if you only need one part.
- HTTP check POST /api/http-check Check any public URL: status code, latency, final URL after redirects, and response headers. The uptime primitive for agent monitors.
- HTTP headers + security analysis POST /api/http-headers Fetch a URL and return every response header plus a security analysis: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP/CORP/COEP. Scores 0–100 by presence, flags weak HSTS, and warns on Server/X-Powered-By identity leaks. SSRF-protected.
- TLS certificate POST /api/tls-cert Inspect the TLS certificate of any public host: subject, issuer, validity window, days remaining, SANs, and SHA-256 fingerprint.
Bought one at a time, these 3 tools cost $0.005 together; the pack is that sum less a 10% bundle discount, rounded up to the $0.001 settlement floor, which is $0.005.
Workflow
- Call http-check to verify the endpoint is reachable - status code, response time, redirect chain.
- Call http-headers to inspect the response headers - rate limit headers, auth requirements, CORS policy, cache directives.
- Call tls-cert with the host extracted from the URL to check certificate validity, issuer, expiry, and chain trust.
Arguments
| Name | Required | Description | Example |
|---|---|---|---|
url | yes | API endpoint URL to check (https://…) | https://api.github.com |
What one call returns
A JSON object with pack, args, steps, summary; steps holds one entry per tool (http-check, http-headers, tls-cert), each with its own result or error. Full example on the API page.
Call it directly
Any x402 client pays the 402 and gets the whole workflow back in one response. With the agent402-client SDK (npm i agent402-client, an ES module):
import { Agent402 } from "agent402-client";
// payFetch: an x402-wrapped fetch your wallet signs (@x402/fetch).
// Tools on the free tier need no options: new Agent402() pays them by proof-of-work.
// an existing prepaid credits key also works: new Agent402({ creditsKey })
const client = new Agent402({ fetch: payFetch });
const result = await client.call("skill-api-health", {"url":"https://api.github.com"});
Run it in Claude
claude mcp add agent402 -s user -- npx -y agent402-mcp@latest
Then paste this prompt into Claude:
Check the health of https://api.github.com using Agent402's api-health skill pack: (1) http-check for liveness and latency, (2) http-headers for rate limits and security headers, (3) tls-cert for certificate status. Report whether the endpoint is production-ready.