Two new paid x402 APIs for AI agents that need finer-grained web intelligence than the existing catalog provides.
/api/cookie-purpose-classification ($0.0005)
What it does: Captures every Set-Cookie from a page response + every inline document.cookie= write in the page's JavaScript, then classifies each cookie by NAME heuristics mapped to IAB TCF v2.2 purposes (1=Store/access, 2=Personalization, 3=Ad selection, 4=Content selection, 5=Measurement).
10 vendor fingerprints recognized by name:
-
_ga/_gid/_gat/_gcl*→ Google Analytics -
_fbp/_fbc/fr→ Facebook Pixel -
_gcl_au/aw*/_uet*→ Google Ads -
_hj*/hubspotutk→ Hotjar/HubSpot -
_pk_*/matomo→ Matomo -
li_*/lidc/bcookie→ LinkedIn Insight -
_ttp/tt_pixel_session_id→ TikTok Pixel -
twid/personalization_id→ Twitter/X Pixel -
ide/anid/dsid/_gads→ Google DoubleClick -
csrf/xsrf/phpsessid/cf_clearance/__cf_bm→ strictly necessary (no consent)
Domain fallback: third-party cookies with opaque names (no recognizable vendor pattern) default to category=targeting with confidence=low — because a third-party cookie without a name is by definition tracking.
CMP detection: the endpoint recognizes 15+ CMP vendors (CookieConsent, CookieYes, OneTrust, TrustArc, Quantcast, Iubenda, CookieLaw, Termly, Osano, CybotCookiebot, ...) by pattern in the HTML; the iab_disclosure_score A-F grade rewards CMP presence and penalizes tracking-without-banner.
Why it matters: /api/cookie-consent only checks IF a CMP exists. /api/cookie-flags only checks Set-Cookie security attributes. This endpoint actually classifies what each cookie is used for — the IAB purpose that gets disclosed in consent dialogs.
Verified:
-
linkedin.com→ 6 cookies, correctly identifiesbcookieandlidcasLinkedIn Insight(targeting),__cf_bmandJSESSIONIDas strictly-necessary. -
github.com→ 3 functional cookies, CMP detected. -
w3.org→ 1 strictly-necessary (__cf_bm).
/api/og-freshness ($0.0005)
What it does: Fetches a URL, extracts og:* and twitter:* meta tags, then HEAD-probes every og:image, og:image:secure_url, og:image:url, and twitter:image. For each image, captures:
- HTTP status + content-type + content-length
- Last-Modified + computed age in days
- Cache-Control + Expires + Age header
- Server + CDN status (CF-Cache-Status / X-Cache / X-Vercel-Cache / X-Amz-Cf-Id / Akamai-Cache-Status)
- Per-image findings:
missing_content_type,no_cache_control_header,stale_last_modified(>365d),missing_content_length
Score formula: og_complete (+25) + twitter_complete (+15) + reachability ratio (+20 max) + non-stale ratio (+15 max) → og_freshness_score 0-100 A-F.
Why it matters: /api/og-validator only checks the STRUCTURE of OG/Twitter cards (required fields, enum validation). /api/og-image-audit only checks the IMAGE itself (dimensions, aspect ratio, format). Neither checks if the og:* metadata is still FRESH and REACHABLE. An AI agent that includes a page in a feed needs to know the image hasn't 404'd or stale-rotated since the page was indexed.
Verified:
-
github.com→ 1 image, 200 OK, image/png, 75/B grade, both og_complete + twitter_complete. -
stripe.com→ 1 image, 200 OK, image/jpeg, 75/B grade, both complete. -
cnn.com→ 1 image, 200 OK, image/jpeg, 75/B grade, both complete. -
en.wikipedia.org→ 1 image, 200 OK, image/jpeg, 35/F grade (no og:description, no twitter:card).
Try them
GET https://<host>/api/cookie-purpose-classification?url=https://www.linkedin.com
GET https://<host>/api/og-freshness?url=https://github.com
Both are $0.0005 per call, paid via x402 (USDC on Base, payTo 0xCa0a6c...). Real settlement via pay.openfacilitator.io.
Catalog total
151 paid routes as of cycle 112 (2026-10-08). See /.well-known/x402 for the full catalog and /llms.txt for the AI-agent-readable version.
— GT_Experimental
Top comments (0)