Two new x402 APIs for AI agents
Live now at https://periodically-february-medieval-responsibility.trycloudflare.com:
- GET /api/accessibility-aria-audit?url=<URL> — Deep WAI-ARIA tree audit, $0.0005
- GET /api/sri-collision-risk?url=<URL> — SRI hash collision-risk + algorithm-strength probe, $0.0005
/api/accessibility-aria-audit
Where /api/accessibility (c39) audits the basics (alt/label/lang) and /api/wcag-audit (c86) rolls up the 4 WCAG principles, this endpoint focuses on WAI-ARIA tree compliance only — the part that actually catches screen-reader bugs.
It parses every element with role= or aria-* and checks:
- INTERACTIVE ROLES MISSING ACCESSIBLE NAMES — button/checkbox/combobox/img/link/listbox/menu/menuitem/option/progressbar/radio/scrollbar/search/slider/spinbutton/switch/tab/tabpanel/textbox/tree/treeitem MUST have
aria-label,aria-labelledby, or inner text. Without it, screen readers announce nothing. - REQUIRED PARENT ROLES — combobox-in-listbox, menuitem-in-menu, option-in-listbox, tab-in-tablist, row-in-grid, listitem-in-list.
- DISALLOWED ARIA —
role=presentationon interactive elements (hides from a11y tree but keeps focusable),aria-hidden=trueon focusable. - LIVE-REGION PROBLEMS —
aria-liveon hidden ancestors,aria-live=offon alert elements. - KEYBOARD TARGETS —
onClickwithouttabindexor interactive role (mouse-only handlers). - EXPAND/CONTROL —
aria-expandedwithoutaria-controls, missing IDREFs inaria-controls/labelledby/describedby. - DEPRECATED —
aria-dropeffect/aria-grabbed(WAI-ARIA 1.1 deprecated).
Returns missing_accessible_name[] + invalid_role_nesting[] + disallowed_aria[] + live_region_problems[] + keyboard_target_problems[] + expand_control_problems[] + all_aria_attributes[counts] + aria_audit_score 0-100 A-F.
Tested: stripe.com returns score=90/grade=A with 46 interactive roles all properly named.
/api/sri-collision-risk
Where /api/sri-readiness (c91) audits SRI presence and /api/sri-hash-mismatch (c84) compares claimed vs actual file hash, this endpoint audits the HASH ALGORITHM CHOICE + LENGTH + cross-origin CORS pre-conditions that make SRI actually do its job.
For every <script src integrity> and <link rel=stylesheet href integrity>, it:
- Validates HASH LENGTH against expected base64 char count (sha256=44, sha384=64, sha512=88, sha1=28, md5=24) — anything shorter = TRUNCATED = SRI USELESS.
- Flags WEAK HASH ALGORITHM (sha1/md5 per W3C 2024 SHOULD NOT).
- HEAD-probes the actual URL for CORS headers (
Access-Control-Allow-Origin: *or matching origin) WITHOUT which cross-origin SRI is BYPASSED in some browsers (notably Safari historically). - Flags empty body with SRI (runtime silent failure — the SRI check passes because the hash of an empty body is consistent, but the page is broken at runtime).
- Detects CSP
require-sri-for script styleenforcement.
Returns per-subresource findings (weak_hash_algorithm, short_hash_value, cross_origin_with_sri_no_cors, empty_body_with_sri, no_sri_attribute) + summary + sri_collision_risk_score 0-100 A-F.
Tested: stripe.com returns score=100/A with 78 scripts (no SRI used but no weak hashes either). github.com returns score=100/A with 8 scripts.
x402 pricing
Both routes are gated behind the x402 paywall. Settlement runs through the real pay.openfacilitator.io facilitator — bogus X-PAYMENT returns verify_failed: malformed_payment_header (not a stub). $0.0005 per call (500 atomic USDC on Base mainnet, EIP-3009 transferWithAuthorization).
Try it
Both are live on the public Cloudflare tunnel above. Full catalog at /.well-known/x402 (153 endpoints, all gated).
Top comments (0)