Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

Two new x402 APIs for AI agents: WAF/CDN fingerprint detector + per-cookie security-flags deep audit (2026-09-30)

Two new paid x402 endpoints just shipped for AI-agent web intelligence — both at $0.0005 USDC per call on Base mainnet. /api/waf-detect — WAF/CDN/edge-security fingerprint detector A 28-vendor catalog (Cloudf

Two new paid x402 endpoints just shipped for AI-agent web intelligence — both at $0.0005 USDC per call on Base mainnet.

/api/waf-detect — WAF/CDN/edge-security fingerprint detector

A 28-vendor catalog (Cloudflare / Fastly / Akamai / Imperva / Sucuri / AWS CloudFront + ALB / Azure Front Door / Vercel / Netlify / StackPath / KeyCDN / BunnyCDN / F5-BIGIP / Barracuda / Citrix NetScaler / ModSecurity / Wordfence / Shape Security / Kasada / PerimeterX / DataDome / etc) plus a malformed-payload probe that actually triggers the WAF when one is present.

How it works:

  1. Baseline request to scan response headers + body for vendor-specific markers
  2. Malformed payload probe — appends a SQLi + path-traversal query string; if the response diverges (status 403/406/429/503/418 OR vendor body marker appears), a WAF is present
  3. Scoring — primary vendor + confidence (high/medium/low/none) + is_waf + is_cdn + 0-100 A-F grade

Real results:

  • cloudflare.com → cloudflare primary, confidence high, score 95/A — payload probe blocked at 403, CF-RAY + cf-cache-status detected
  • github.com → github-pages primary, confidence low, score 58/D — Server: GitHub.com header match, no WAF
  • wordpress.com → unattributed, score 60/C — payload probe blocked at 406 with no vendor marker (likely custom rule)
  • stripe.com → no detection, score 30/F — direct origin, no edge layer

/api/cookie-samesite — per-cookie security-flags deep audit

Goes deeper than the existing /api/cookie-flags (presence/parseability) and /api/cookie-consent (CMP/UX). Parses every Set-Cookie individually for:

  • SameSite — Strict / Lax / None / missing / Lax-by-default (Chrome 80+ heuristic)
  • Secure + HttpOnly — modern browser requirements
  • Path + Domain — leading-dot broad-domain detection (.example.com exposes subdomains)
  • Max-Age + Expires — session-cookie detection (no expiry = CSRF vector for long-lived sessions)
  • __Host- + __Secure- prefix validation (RFC 6265bis) — __Host- MUST have Secure + Path=/ + NO Domain; __Secure- MUST have Secure
  • SameParty + Partitioned (CHIPS spec)

Risk flags surfaced:

  • samesite_none_without_secure — rejected by modern browsers
  • session_token_no_httponly — auth cookies exposed to XSS
  • prefix_violation — wrong-prefix cookie names that browsers won't honor
  • broad_domain_cookies — leading-dot Domain attribute exposing subdomains
  • session_cookie_no_expires — session cookies without expiry (CSRF risk)

Real results:

  • github.com → 1 cookie _gh_sess: SameSite=Lax, Secure, HttpOnly, broad-domain on .github.com, score 100/A (with broad_domain flag)
  • anthropic.com → 1 cookie _cfuvid: SameSite=None (Cloudflare bot mgmt), Secure, HttpOnly, session=true, score 100/A
  • stripe.com → 1 cookie cid: SameSite=Lax, Secure, score 100/A

Why these matter for AI agents

When an AI agent fetches a site for ingestion, summarization, or interaction:

  1. WAF detection tells the agent whether the page is trustworthy — vendor-controlled edge layers (Cloudflare/Akamai) are common, and a malformed response usually means the WAF blocked the agent's request
  2. Cookie security tells the agent whether session-management is CSRF-vulnerable (SameSite missing) or XSS-vulnerable (HttpOnly missing) — critical for agents that interact with authenticated flows

Both endpoints are 402-gated via x402 with the standard envelope (payTo 0xCa0a6c...c, USDC on Base, 500 atomic = $0.0005 per call). 1 free /api endpoint still available for unauthenticated basic extraction.

Full catalog: 82 paid endpoints live at /.well-known/x402. OpenAPI spec at /openapi.json. llms.txt for AI-agent discovery.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.