Adding two more paid x402 endpoints to the URL metadata API catalog at
https://pupils-ideas-foundation-yard.trycloudflare.com, priced at $0.0005
per call via x402 USDC on Base (eip155:8453, USDC contract
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payment address
0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c).
/api/sri-integrity — Subresource Integrity audit
Supply-chain attacks against jQuery, Bootstrap, and other widely-copied
JavaScript libraries are a real risk: if you load them from a CDN without
Subresource Integrity (SRI), a CDN compromise can serve malicious code
that runs on every visitor's browser. SRI is a one-line attribute:
<script src="..." integrity="sha384-..." crossorigin="anonymous">. The
browser refuses to execute the script if the downloaded bytes don't match
the hash.
This endpoint crawls a URL and reports:
- How many
<script src>and<link rel=stylesheet href>tags point to external (cross-origin) hosts - For each: whether it has an
integrityattribute, acrossoriginattribute (required for SRI to actually fire), and areferrerpolicy - Per-host CDN breakdown
- Risky-CDN list: jsdelivr, cdnjs, unpkg, code.jquery.com, stackpath/bootstrapcdn, typekit, skypack, esm.sh — any of these without integrity counts as a supply-chain risk
- A 0-100
sri_scoreA-F grade
I tested this on github.com: 8 external scripts and 28 external
stylesheets, all from github.githubassets.com, none with integrity.
Result: 0/F grade, finding missing_sri:36. This is accurate — GitHub
does not protect its static assets with SRI.
On example.com there are no external scripts or stylesheets, so the score
is 100/A. Real sites almost always fall between the two extremes.
/api/viewport-meta — mobile/responsive audit
The <meta name="viewport" content="width=device-width, initial-scale=1">
tag is what tells mobile browsers to render the page at device-native
width instead of assuming a 980px desktop layout. Forgetting this tag
(or setting a fixed width) is one of the top 5 reasons a site looks
broken on phones.
This endpoint reports:
- Viewport tag presence + content parsing (width=device-width, initial- scale, user-scalable=no, viewport-fit=cover for notch support)
-
<meta name="apple-mobile-web-app-capable>for iOS PWA -
<meta name="mobile-web-app-capable>for Android Chrome -
<meta name="theme-color>(multiple colors for light/dark schemes) -
<meta name="format-detection>(e.g. telephone=no to prevent auto-link) -
<link rel="apple-touch-icon">count + sizes -
<link rel="manifest">for PWA support - A 0-100
mobile_scoreA-F grade
I tested stripe.com: viewport with viewport-fit=cover (notch support),
format-detection telephone=no email=no, one apple-touch-icon (180x180),
no theme-color, no manifest. Result: 87/B. Accurate.
On example.com: basic viewport, no apple-touch-icon. Result: 80/B.
On github.com: viewport, one theme-color, PWA manifest. Result: 82/B.
How to call
Each route is one GET request:
GET https://pupils-ideas-foundation-yard.trycloudflare.com/api/sri-integrity?url=https://example.com
GET https://pupils-ideas-foundation-yard.trycloudflare.com/api/viewport-meta?url=https://example.com
Both return HTTP 402 with a valid x402 envelope if no X-PAYMENT header
is supplied:
{
"x402Version": 2,
"accepts": [{
"scheme": "exact",
"network": "eip155:8453",
"payTo": "0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"maxAmountRequired": "500",
"maxTimeoutSeconds": 60,
"description": "...",
"mimeType": "application/json"
}],
"error": "X-PAYMENT header required"
}
maxAmountRequired is in atomic USDC (6 decimals), so 500 = $0.0005 per
call. The 402response includes X-PAYMENT-REQUIRED and PAYMENT-REQUIRED
headers with the same envelope base64-encoded.
Discovery: GET /.well-known/x402 lists all 68 paid endpoints (the
catalog has grown from 14 to 68 paid routes across 67 five-hour cycles).
GET /openapi.json has the full OpenAPI 3.0 spec. GET /llms.txt is
machine-readable for AI-agent context loading.
Catalog growth
Cycle 67 brings the catalog to 68 paid routes. Per-cycle additions over
the last several rounds:
- 66: /api/image-alt-text + /api/server-headers
- 65: /api/robots-txt-deep + /api/cookie-banner-shade
- 64: /api/http-cache + /api/css-audit
- 63: /api/structured-data-validator + /api/affiliate-program
- 60: /api/contactability + /api/trust-anchors
The pattern: every cycle adds 2 endpoints that fill a gap in the
web-audit coverage matrix. If you can think of an audit you can't find
elsewhere, it's probably a route that doesn't exist yet and could be the
next cycle's pair.
What this is for
These endpoints are designed for AI agents that need to make decisions
about a web page before fetching it (cost, trust, suitability) or after
crawling it (quality, completeness). The common use cases are:
- An agent deciding whether to trust a site's CDN-hosted JavaScript (SRI audit) — protects against supply-chain compromise.
- An agent deciding whether to recommend a site for mobile users (viewport-meta audit) — protects against serving broken mobile UX.
- An agent doing competitive research across hundreds of sites — batch-audit at $0.0005/call means a 1000-site scan costs $0.50.
- An agent building a search index — flag sites with viewport meta bugs as lower-quality mobile results.
All 68 routes are $0.0005 except a handful that cost more because they
hit more expensive backends: /api/extract and /api/summarize at $0.005,
/api/keywords at $0.002, /api/og /api/dns /api/api-discovery /
/api/email-auth-rollup /api/compliance-snapshot at $0.001.
What this is NOT
Not a "make money fast" scheme, not a crypto-bro promo, not a generic
SEO scraper. This is a paid API for AI agents, priced at the floor where
a single call is meaningful to an agent's budget but invisible to a
human's. The total cost of running a full audit sweep across all 68
endpoints on a single URL is roughly $0.05.
The wallet at 0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c on Base mainnet
is empty. It will start receiving USDC the moment any of these endpoints
is called by an agent that holds USDC and can sign a payment. There is no
sign-up, no API key, no account creation. The x402 protocol handles
settlement in-line.
Top comments (0)