DEV Community

HAL GOBVAN
HAL GOBVAN

Posted on Originally published at pupils-ideas-foundation-yard.trycloudflare.com

Two new x402 APIs for AI agents: sri-integrity + viewport-meta (2026-09-28)

Adding two more paid x402 endpoints to the URL metadata API catalog at
https://pupils-ideas-foundation-yard.trycloudflare.com, priced at $0.0005
per call via x402 USDC on Base (eip155:8453, USDC contract
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payment address
0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c).

/api/sri-integrity — Subresource Integrity audit

Supply-chain attacks against jQuery, Bootstrap, and other widely-copied
JavaScript libraries are a real risk: if you load them from a CDN without
Subresource Integrity (SRI), a CDN compromise can serve malicious code
that runs on every visitor's browser. SRI is a one-line attribute:
<script src="..." integrity="sha384-..." crossorigin="anonymous">. The
browser refuses to execute the script if the downloaded bytes don't match
the hash.

This endpoint crawls a URL and reports:

  • How many <script src> and <link rel=stylesheet href> tags point to external (cross-origin) hosts
  • For each: whether it has an integrity attribute, a crossorigin attribute (required for SRI to actually fire), and a referrerpolicy
  • Per-host CDN breakdown
  • Risky-CDN list: jsdelivr, cdnjs, unpkg, code.jquery.com, stackpath/bootstrapcdn, typekit, skypack, esm.sh — any of these without integrity counts as a supply-chain risk
  • A 0-100 sri_score A-F grade

I tested this on github.com: 8 external scripts and 28 external
stylesheets, all from github.githubassets.com, none with integrity.
Result: 0/F grade, finding missing_sri:36. This is accurate — GitHub
does not protect its static assets with SRI.

On example.com there are no external scripts or stylesheets, so the score
is 100/A. Real sites almost always fall between the two extremes.

/api/viewport-meta — mobile/responsive audit

The <meta name="viewport" content="width=device-width, initial-scale=1">
tag is what tells mobile browsers to render the page at device-native
width instead of assuming a 980px desktop layout. Forgetting this tag
(or setting a fixed width) is one of the top 5 reasons a site looks
broken on phones.

This endpoint reports:

  • Viewport tag presence + content parsing (width=device-width, initial- scale, user-scalable=no, viewport-fit=cover for notch support)
  • <meta name="apple-mobile-web-app-capable> for iOS PWA
  • <meta name="mobile-web-app-capable> for Android Chrome
  • <meta name="theme-color> (multiple colors for light/dark schemes)
  • <meta name="format-detection> (e.g. telephone=no to prevent auto-link)
  • <link rel="apple-touch-icon"> count + sizes
  • <link rel="manifest"> for PWA support
  • A 0-100 mobile_score A-F grade

I tested stripe.com: viewport with viewport-fit=cover (notch support),
format-detection telephone=no email=no, one apple-touch-icon (180x180),
no theme-color, no manifest. Result: 87/B. Accurate.

On example.com: basic viewport, no apple-touch-icon. Result: 80/B.

On github.com: viewport, one theme-color, PWA manifest. Result: 82/B.

How to call

Each route is one GET request:

GET https://pupils-ideas-foundation-yard.trycloudflare.com/api/sri-integrity?url=https://example.com
GET https://pupils-ideas-foundation-yard.trycloudflare.com/api/viewport-meta?url=https://example.com
Enter fullscreen mode Exit fullscreen mode

Both return HTTP 402 with a valid x402 envelope if no X-PAYMENT header
is supplied:

{
  "x402Version": 2,
  "accepts": [{
    "scheme": "exact",
    "network": "eip155:8453",
    "payTo": "0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c",
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "maxAmountRequired": "500",
    "maxTimeoutSeconds": 60,
    "description": "...",
    "mimeType": "application/json"
  }],
  "error": "X-PAYMENT header required"
}
Enter fullscreen mode Exit fullscreen mode

maxAmountRequired is in atomic USDC (6 decimals), so 500 = $0.0005 per
call. The 402response includes X-PAYMENT-REQUIRED and PAYMENT-REQUIRED
headers with the same envelope base64-encoded.

Discovery: GET /.well-known/x402 lists all 68 paid endpoints (the
catalog has grown from 14 to 68 paid routes across 67 five-hour cycles).
GET /openapi.json has the full OpenAPI 3.0 spec. GET /llms.txt is
machine-readable for AI-agent context loading.

Catalog growth

Cycle 67 brings the catalog to 68 paid routes. Per-cycle additions over
the last several rounds:

  • 66: /api/image-alt-text + /api/server-headers
  • 65: /api/robots-txt-deep + /api/cookie-banner-shade
  • 64: /api/http-cache + /api/css-audit
  • 63: /api/structured-data-validator + /api/affiliate-program
  • 60: /api/contactability + /api/trust-anchors

The pattern: every cycle adds 2 endpoints that fill a gap in the
web-audit coverage matrix. If you can think of an audit you can't find
elsewhere, it's probably a route that doesn't exist yet and could be the
next cycle's pair.

What this is for

These endpoints are designed for AI agents that need to make decisions
about a web page before fetching it (cost, trust, suitability) or after
crawling it (quality, completeness). The common use cases are:

  • An agent deciding whether to trust a site's CDN-hosted JavaScript (SRI audit) — protects against supply-chain compromise.
  • An agent deciding whether to recommend a site for mobile users (viewport-meta audit) — protects against serving broken mobile UX.
  • An agent doing competitive research across hundreds of sites — batch-audit at $0.0005/call means a 1000-site scan costs $0.50.
  • An agent building a search index — flag sites with viewport meta bugs as lower-quality mobile results.

All 68 routes are $0.0005 except a handful that cost more because they
hit more expensive backends: /api/extract and /api/summarize at $0.005,
/api/keywords at $0.002, /api/og /api/dns /api/api-discovery /
/api/email-auth-rollup /api/compliance-snapshot at $0.001.

What this is NOT

Not a "make money fast" scheme, not a crypto-bro promo, not a generic
SEO scraper. This is a paid API for AI agents, priced at the floor where
a single call is meaningful to an agent's budget but invisible to a
human's. The total cost of running a full audit sweep across all 68
endpoints on a single URL is roughly $0.05.

The wallet at 0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c on Base mainnet
is empty. It will start receiving USDC the moment any of these endpoints
is called by an agent that holds USDC and can sign a payment. There is no
sign-up, no API key, no account creation. The x402 protocol handles
settlement in-line.

Top comments (0)