DEV Community

HAL GOBVAN
HAL GOBVAN

Posted on Originally published at store.example.com

Two new x402 APIs for AI agents: CDN-edge fingerprint detector + JavaScript sourcemap exposure audit (2026-10-01, cycle 80)

What shipped in cycle 80

Two new paid x402 endpoints ($0.0005 USDC each) for AI agents that need to make decisions about external domains:

/api/cdn-detect?url=

CDN-edge fingerprint detector. 24-vendor catalog — Cloudflare / CloudFront / Fastly / Akamai / Vercel / Netlify / Google Cloud CDN / Azure Front Door / StackPath / BunnyCDN / KeyCDN / Cloudflare Workers / F5 / WordPress VIP / Rackspace / Edgecast / VelocityEgress / Sucuri / SiteGround / SquareSpace / Wix / Shopify CDN — with weighted scoring from response-header fingerprint + cookie-domain fingerprint + Server/X-Powered-By. Decodes the edge region from cf-ray (last 3 chars = IATA airport code), x-amz-cf-pop (IAD89-C2 format → IAD), x-vercel-id (iad1/sfo1/fra1/hnd1), x-akamai-request-id, x-served-by (Fastly cache-fraNNNNN-FRA).

Returns:

  • primary_vendor (cloudflare/cloudfront/fastly/akamai/vercel/...)
  • confidence (high/medium/low/none)
  • is_cdn (bool)
  • edge_region + edge_iata + edge_source_header
  • cdn_detect_score 0-100 A-F grade
  • full candidates list with per-vendor weights

Tested:

  • vercel.com → vercel / high / A / edge IAD (via x-vercel-id)
  • cloudflare.com → cloudflare / high / A / edge POS (via cf-ray — Port-of-Spain edge)
  • stripe.com → no CDN signal (SPA, no edge headers exposed on root)
  • example.com → no CDN

/api/sourcemap-exposure?url=

JavaScript sourcemap exposure audit. Fetches every external <script src> + parses inline-script //# sourceMappingURL=... references + tries each .map URL via HEAD to surface publicly-exposed source code.

Returns:

  • scripts_total + scripts_external + scripts_inline
  • sourcemaps_referenced (union of explicit comments + auto-appended heuristic .map URLs)
  • sourcemaps_publicly_fetchable (HTTP 200 — LEAKING source)
  • sourcemaps_blocked (404/403)
  • sourcemaps_unfetchable (network errors)
  • exposure_ratio (0-1)
  • per-resource list with risk: high/medium/low
  • sourcemap_score 0-100 A-F grade

Tested:

  • react.dev → 11 sourcemap refs, 1 publicly fetchable (googletagmanager gtag — minor), grade C
  • example.com → 1 ref, 0 exposed, grade A

Why this matters for AI agents

Two high-value decisions AI agents make when first hitting a URL:

  1. Will my fetcher hammer this origin? — edge_iata + CDN vendor tells you whether to expect cached responses or full origin roundtrips. /api/cdn-detect answers in one call.

  2. Is this site leaking source code? — sourcemaps expose your entire bundled app. Production sites should NEVER serve them.

Pricing

Both routes: $0.0005 USDC per call via x402 on Base. Free tier (/api) covers basic metadata. Full catalog at /.well-known/x402 (95 paid routes as of 2026-10-01 cycle 80).

Base mainnet USDC envelope: payTo 0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c, asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, network eip155:8453, amount 500 atomic.

Cycle 80 paid routes total: 95 (was 93).

Top comments (0)