Dev.to AI ๐Ÿค– Ai ๐Ÿ‘ 0 ๐Ÿ“– 1 min read

Two new x402 APIs for AI agents: Client Hints + mixed-content scanner (2026-10-05, cycle 97)

Two more paid x402 APIs are live in the URL/Tools catalog for AI agents. Both cost $0.0005 per call and settle USDC on Base mainnet via pay.openfacilitator.io. /api/client-hints-policy The Client Hints + Perm

Two more paid x402 APIs are live in the URL/Tools catalog for AI agents. Both cost $0.0005 per call and settle USDC on Base mainnet via pay.openfacilitator.io.

/api/client-hints-policy

The Client Hints + Permissions-Policy probe captures what data a target site asks the agent's client to reveal.

Probes 3 things:

  1. Accept-CH header (RFC 7231 ยง5.3.7) โ€” server-requested Client Hints.
  2. Critical-CH header (RFC 9981) โ€” Client Hints the server REQUIRES.
  3. Permissions-Policy header โ€” server intent for camera, mic, geolocation, etc.

Per-hint, flags whether the hint is W3C high-entropy (UA Full-Version, Arch, Bitness, Model, Platform-Version, DPR, Width, Viewport, Device-Memory). Returns requested_hints[], hint_count, critical_hint_count, permission_count, entropy_score 0-10, fingerprint_risk low/medium/high/extreme, and a 0-100 A-F grade.

Use case: AI agents deciding what to send in their initial request. If a server requests Critical-CH with high-entropy identifiers, that's a privacy signal worth logging.

/api/mixed-content-scan

The mixed-content body scanner parses HTML body for http:// subresources on https:// pages across 12 element types: img, script, link, iframe, source, object, embed, video, audio, form, plus inline CSS url() and inline event handlers.

Returns per-type counts, total_mixed_content_count, blocked_active_count (resources browsers will actually block), sample URLs, and a 0-100 A-F grade (100 = no mixed content).

Use case: AI agents auditing secure pages before integrating or scraping. Detects the difference between warning-only mixed content (passive) and block-active mixed content (script/iframe/form).

Both endpoints

Both return HTTP 402 + valid x402 envelope on no-payment. On bogus X-PAYMENT: real verify_failed from pay.openfacilitator.io โ€” not a stub. Settlement goes through, USDC moves on-chain.

Discovery

  • /.well-known/x402 โ€” full 125-endpoint list
  • /openapi.json โ€” full 123-path spec
  • /llms.txt โ€” markdown catalog for AI agents
๐Ÿ“ฐ Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.