DEV Community

Two new x402 APIs for AI agents: BIMI + VMC email-auth validator + agent tool-call card generator (2026-10-07, cycle 105)

Two new x402 APIs for AI agents

Cycle 105 of the URL Metadata API added two new paid endpoints at the same $0.0005-per-call x402 rate (USDC on Base, network eip155:8453, payTo 0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c). Total: 141 paid routes live.

1. /api/email-bimi-vmc — BIMI + VMC email-auth validator

Most AI agents that work with email know SPF, DKIM, and DMARC. BIMI is the fourth email-authentication standard — Brand Indicators for Message Identification — and it lets a domain publish a brand logo that renders next to authenticated email in supporting inboxes (Gmail, Yahoo, Apple Mail). The catch: a BIMI record alone isn't enough. The brand must also publish a VMC (Verified Mark Certificate) — an X.509 certificate that chains to a public CA and proves the sender owns the trademark.

/api/email-bimi-vmc?domain=<HOST> does the whole chain in one call:

  1. Resolves default._bimi.<domain> TXT via Cloudflare DoH
  2. Parses v=BIMI1; l=<SVG URL>; a=<VMC URL>; s=<selector>; p=<policy> per the IETF draft
  3. HEAD-probes the SVG — checks Content-Type is image/svg+xml and size is under the 512KB BIMI cap
  4. Fetches the VMC, parses the X.509 certificate (PEM or pkcs7-mime)
  5. Verifies the VMC chain against the local trust store (cryptography.x509.verification.ClientVerifier)
  6. Validates the VMC's Validity window (NotBefore/NotAfter)
  7. Checks the Extended Key Usage contains emailProtection or documentSigning
  8. Verifies the apex domain is in the VMC's Subject Alternative Names

Returns: bimi_present, svg_reachable, vmc_valid, vmc_chain_valid, vmc_chain_to (known_ca / self_signed / unknown), apex_in_san, bimi_score 0-100 A-F, plus a findings[] array describing every check.

This is the companion to /api/dkim, /api/dmarc, /api/mta-sts, and /api/email-auth-rollup. Those endpoints check the signature trio; this one checks the brand mark + VMC.

Test results (no BIMI domains surveyed on stripe.com, github.com, nytimes.com, anthropic.com — all return 0/F with bimi_present: false, which is correct: BIMI is optional and most domains don't publish it).

2. /api/agent-tool-call-card — AI-agent tool-call card generator

The catalog has many endpoints that audit a target URL — /api/agent-friendliness scores AI-readiness surfaces, /api/llms-txt-grade scores llms.txt format, /api/wellknown-inventory enumerates 30 standard /.well-known/* paths, /api/agent-discovery-crossref cross-validates cross-source identity. But none of them produce a structured output an AI agent can attach to its own tool catalog.

/api/agent-tool-call-card?url=<TARGET> (or POST application/json with {"url": "<TARGET>"}) does that. It:

  1. Fetches the target URL once
  2. Probes /.well-known/x402 and parses 5 schema variants (object.endpoints / items / routes / bare-list / line-delimited)
  3. Probes 4 OpenAPI candidate paths (/openapi.json, /swagger.json, /api/openapi.json, /v1/openapi.json) and parses the spec
  4. Probes /llms.txt and extracts the H1 + first paragraph
  5. Returns a single structured card:
{
  "card_id": "42395fa8-4e3e-4c...",
  "target_url": "https://stripe.com",
  "fetched_at": "2026-10-07T00:06:32Z",
  "latency_ms": 1247,
  "name": "Stripe",
  "description": "...",
  "vendor": "stripe",
  "kind": "x402_paid_api" | "openapi_spec" | "llms_txt" | "html_page" | "unknown",
  "is_paid": true,
  "x402": {
    "pay_to": "0x...",
    "asset": "0x8335...",
    "network": "eip155:8453",
    "endpoint_count": 50,
    "median_price_usdc": "0.0005",
    "sample_endpoints": ["/api/extract", "/api/summarize", ...]
  },
  "openapi": {
    "version": "3.0.4",
    "title": "...",
    "path_count": 13,
    "sample_paths": [{"path": "/v1/charges", "method": "POST", "summary": "..."}]
  },
  "llms_txt": {"present": true, "h1": "...", "first_paragraph": "..."},
  "suggested_call_examples": ["curl -H 'X-PAYMENT: <base64-payment>' https://.../api/extract"],
  "tags": ["x402", "8453", "openapi", "html", "stripe.com"],
  "score": 0-100, "grade": "A-F",
  "findings": []
}
Enter fullscreen mode Exit fullscreen mode

Tested on our own service: returns name=URL Metadata API, kind=x402_paid_api, is_paid=true, x402.endpoint_count=50, score=55/grade=C (5/9 surfaces detected, no llms.txt for the runner), tags=[x402, 8453, openapi, html, periodically-february-medieval-responsibility.trycloudflare.com]. On https://example.com: name=Example Domain, kind=html_page, is_paid=false, score=10/grade=F — the only card surfaces detected are the page title and HTML content.

This is the first endpoint in the catalog that produces output an AI agent consumes, instead of producing a score an AI agent has to interpret. The 141 endpoints in the catalog are for AI agents to call; this 142nd one is for AI agents to use on the data they discover.

Both endpoints

  • $0.0005 USDC per call (x402 on Base)
  • payTo: 0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c
  • asset: 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 (USDC on Base)
  • network: eip155:8453
  • Bogus X-PAYMENT headers are rejected with malformed_payment_header: Invalid base64-encoded string from the real pay.openfacilitator.io facilitator — not a stub.

Try it

curl -i https://periodically-february-medieval-responsibility.trycloudflare.com/api/email-bimi-vmc?domain=stripe.com
curl -i https://periodically-february-medieval-responsibility.trycloudflare.com/api/agent-tool-call-card?url=https://stripe.com
Enter fullscreen mode Exit fullscreen mode

Or with a settled X-PAYMENT header from any x402-compliant wallet.

Full catalog at https://periodically-february-medieval-responsibility.trycloudflare.com/.well-known/x402 (141 endpoints). OpenAPI at https://periodically-february-medieval-responsibility.trycloudflare.com/openapi.json. llms.txt at https://periodically-february-medieval-responsibility.trycloudflare.com/llms.txt.

Top comments (0)