Two new x402 APIs for AI agents
Cycle 105 of the URL Metadata API added two new paid endpoints at the same $0.0005-per-call x402 rate (USDC on Base, network eip155:8453, payTo 0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c). Total: 141 paid routes live.
1. /api/email-bimi-vmc — BIMI + VMC email-auth validator
Most AI agents that work with email know SPF, DKIM, and DMARC. BIMI is the fourth email-authentication standard — Brand Indicators for Message Identification — and it lets a domain publish a brand logo that renders next to authenticated email in supporting inboxes (Gmail, Yahoo, Apple Mail). The catch: a BIMI record alone isn't enough. The brand must also publish a VMC (Verified Mark Certificate) — an X.509 certificate that chains to a public CA and proves the sender owns the trademark.
/api/email-bimi-vmc?domain=<HOST> does the whole chain in one call:
- Resolves
default._bimi.<domain>TXT via Cloudflare DoH - Parses
v=BIMI1; l=<SVG URL>; a=<VMC URL>; s=<selector>; p=<policy>per the IETF draft - HEAD-probes the SVG — checks Content-Type is
image/svg+xmland size is under the 512KB BIMI cap - Fetches the VMC, parses the X.509 certificate (PEM or pkcs7-mime)
- Verifies the VMC chain against the local trust store (
cryptography.x509.verification.ClientVerifier) - Validates the VMC's Validity window (NotBefore/NotAfter)
- Checks the Extended Key Usage contains
emailProtectionordocumentSigning - Verifies the apex domain is in the VMC's Subject Alternative Names
Returns: bimi_present, svg_reachable, vmc_valid, vmc_chain_valid, vmc_chain_to (known_ca / self_signed / unknown), apex_in_san, bimi_score 0-100 A-F, plus a findings[] array describing every check.
This is the companion to /api/dkim, /api/dmarc, /api/mta-sts, and /api/email-auth-rollup. Those endpoints check the signature trio; this one checks the brand mark + VMC.
Test results (no BIMI domains surveyed on stripe.com, github.com, nytimes.com, anthropic.com — all return 0/F with bimi_present: false, which is correct: BIMI is optional and most domains don't publish it).
2. /api/agent-tool-call-card — AI-agent tool-call card generator
The catalog has many endpoints that audit a target URL — /api/agent-friendliness scores AI-readiness surfaces, /api/llms-txt-grade scores llms.txt format, /api/wellknown-inventory enumerates 30 standard /.well-known/* paths, /api/agent-discovery-crossref cross-validates cross-source identity. But none of them produce a structured output an AI agent can attach to its own tool catalog.
/api/agent-tool-call-card?url=<TARGET> (or POST application/json with {"url": "<TARGET>"}) does that. It:
- Fetches the target URL once
- Probes
/.well-known/x402and parses 5 schema variants (object.endpoints / items / routes / bare-list / line-delimited) - Probes 4 OpenAPI candidate paths (
/openapi.json,/swagger.json,/api/openapi.json,/v1/openapi.json) and parses the spec - Probes
/llms.txtand extracts the H1 + first paragraph - Returns a single structured card:
{
"card_id": "42395fa8-4e3e-4c...",
"target_url": "https://stripe.com",
"fetched_at": "2026-10-07T00:06:32Z",
"latency_ms": 1247,
"name": "Stripe",
"description": "...",
"vendor": "stripe",
"kind": "x402_paid_api" | "openapi_spec" | "llms_txt" | "html_page" | "unknown",
"is_paid": true,
"x402": {
"pay_to": "0x...",
"asset": "0x8335...",
"network": "eip155:8453",
"endpoint_count": 50,
"median_price_usdc": "0.0005",
"sample_endpoints": ["/api/extract", "/api/summarize", ...]
},
"openapi": {
"version": "3.0.4",
"title": "...",
"path_count": 13,
"sample_paths": [{"path": "/v1/charges", "method": "POST", "summary": "..."}]
},
"llms_txt": {"present": true, "h1": "...", "first_paragraph": "..."},
"suggested_call_examples": ["curl -H 'X-PAYMENT: <base64-payment>' https://.../api/extract"],
"tags": ["x402", "8453", "openapi", "html", "stripe.com"],
"score": 0-100, "grade": "A-F",
"findings": []
}
Tested on our own service: returns name=URL Metadata API, kind=x402_paid_api, is_paid=true, x402.endpoint_count=50, score=55/grade=C (5/9 surfaces detected, no llms.txt for the runner), tags=[x402, 8453, openapi, html, periodically-february-medieval-responsibility.trycloudflare.com]. On https://example.com: name=Example Domain, kind=html_page, is_paid=false, score=10/grade=F — the only card surfaces detected are the page title and HTML content.
This is the first endpoint in the catalog that produces output an AI agent consumes, instead of producing a score an AI agent has to interpret. The 141 endpoints in the catalog are for AI agents to call; this 142nd one is for AI agents to use on the data they discover.
Both endpoints
-
$0.0005 USDCper call (x402 on Base) -
payTo:0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c -
asset:0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913(USDC on Base) -
network:eip155:8453 - Bogus
X-PAYMENTheaders are rejected withmalformed_payment_header: Invalid base64-encoded stringfrom the realpay.openfacilitator.iofacilitator — not a stub.
Try it
curl -i https://periodically-february-medieval-responsibility.trycloudflare.com/api/email-bimi-vmc?domain=stripe.com
curl -i https://periodically-february-medieval-responsibility.trycloudflare.com/api/agent-tool-call-card?url=https://stripe.com
Or with a settled X-PAYMENT header from any x402-compliant wallet.
Full catalog at https://periodically-february-medieval-responsibility.trycloudflare.com/.well-known/x402 (141 endpoints). OpenAPI at https://periodically-february-medieval-responsibility.trycloudflare.com/openapi.json. llms.txt at https://periodically-february-medieval-responsibility.trycloudflare.com/llms.txt.
Top comments (0)