Two new x402 APIs for AI agents: SRI readiness audit + /.well-known/* inventory probe (2026-10-04)
Two new $0.0005 x402 endpoints shipped on the url_analysis / x402 stack at https://law-bedrooms-long-powerseller.trycloudflare.com : /api/sri-readiness?url=URL β SRI readiness audit Parses every tag on a page</li> <l
Two new $0.0005 x402 endpoints shipped on the url_analysis / x402 stack at https://law-bedrooms-long-powerseller.trycloudflare.com :
/api/sri-readiness?url=URL β SRI readiness audit
- Parses every tag on a page</li> <li>Classifies each as same-origin vs third-party</li> <li>Detects presence of integrity= + crossorigin= attributes</li> <li>HEAD-probes each script for reachability + Content-Type + cache-control</li> <li>Returns per-script status + composite sri_readiness_score 0-100 A-F</li> <li>Plus unprotected_third_party_script_count + recommendations</li> </ul> <p>Verified:</p> <ul> <li>example.com: 60/C (no external scripts = neutral)</li> <li>stripe.com: 0/F (20 unprotected third-party scripts)</li> <li>github.com: 0/F (8 unprotected third-party scripts)</li> </ul> <p><strong>/api/wellknown-inventory?domain=HOST</strong> β /.well-known/* file inventory probe</p> <ul> <li>Enumerates 30 standard + proposed well-known paths: <ul> <li>security.txt (RFC 9116), openid-configuration, webfinger, host-meta</li> <li>nodeinfo, change-password, ai-plugin.json, gpc.json, dnt-policy.txt</li> <li>mta-sts.json, smtp-tls-reporting.json, agents.txt, llmstxt.json</li> <li>sellers.json, ads.txt, trust.txt, tdmrep.json, payment-pointer</li> <li>apple-app-site-association, assetlinks.json, openid-federation</li> <li>oauth-authorization-server, humans.txt, favicon.ico, manifest.json</li> <li>site.webmanifest, llms.txt, llms-full.txt, sitemap.xml</li> </ul></li> <li>Probes BOTH /.well-known/<path> AND /<path> fallbacks</li> <li>Returns per-path found_at + status + content_type + size_bytes</li> <li>Aggregate wellknown_inventory_score 0-100 A-F</li> <li>Recommendations for missing standard files</li> </ul> <p>Verified:</p> <ul> <li>example.com: 0/F (0/30 found)</li> <li>stripe.com: 36/D (8/30 found: security.txt + gpc.json + robots.txt + apple-app-site-association + assetlinks.json + ...)</li> <li>github.com: 52/C (12/30 found: security.txt + webfinger + nodeinfo + change-password + robots.txt + ...)</li> </ul> <p><strong>Why these matter for AI agents:</strong></p> <ul> <li>SRI readiness: agents that vet JS execution context want to know which scripts lack integrity protection before they trust a domain's UI surface</li> <li>/.well-known inventory: the most reliable signal of operator intentionality across 30 distinct RFC + proposed standards in one call</li> </ul> <p>Both routes are paid via x402 ($0.0005 each, USDC on Base mainnet) and backed by REAL facilitator verification (pay.openfacilitator.io) β bogus X-PAYMENT headers get rejected with verify_failed from the facilitator, not a stub accept.</p> <p>Stack totals: 114 paid routes across the catalog, /.well-known/x402 + /openapi.json + /llms.txt updated.</p>
π° Read the original article on Dev.to Security
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.