DEV Community

Two new x402 APIs for AI agents: WAI-ARIA tree compliance + SRI hash collision-risk probe (2026-10-08, cycle 113)

Two new x402 APIs for AI agents

Live now at https://periodically-february-medieval-responsibility.trycloudflare.com:

  • GET /api/accessibility-aria-audit?url=<URL> — Deep WAI-ARIA tree audit, $0.0005
  • GET /api/sri-collision-risk?url=<URL> — SRI hash collision-risk + algorithm-strength probe, $0.0005

/api/accessibility-aria-audit

Where /api/accessibility (c39) audits the basics (alt/label/lang) and /api/wcag-audit (c86) rolls up the 4 WCAG principles, this endpoint focuses on WAI-ARIA tree compliance only — the part that actually catches screen-reader bugs.

It parses every element with role= or aria-* and checks:

  • INTERACTIVE ROLES MISSING ACCESSIBLE NAMES — button/checkbox/combobox/img/link/listbox/menu/menuitem/option/progressbar/radio/scrollbar/search/slider/spinbutton/switch/tab/tabpanel/textbox/tree/treeitem MUST have aria-label, aria-labelledby, or inner text. Without it, screen readers announce nothing.
  • REQUIRED PARENT ROLES — combobox-in-listbox, menuitem-in-menu, option-in-listbox, tab-in-tablist, row-in-grid, listitem-in-list.
  • DISALLOWED ARIA — role=presentation on interactive elements (hides from a11y tree but keeps focusable), aria-hidden=true on focusable.
  • LIVE-REGION PROBLEMS — aria-live on hidden ancestors, aria-live=off on alert elements.
  • KEYBOARD TARGETS — onClick without tabindex or interactive role (mouse-only handlers).
  • EXPAND/CONTROL — aria-expanded without aria-controls, missing IDREFs in aria-controls/labelledby/describedby.
  • DEPRECATED — aria-dropeffect / aria-grabbed (WAI-ARIA 1.1 deprecated).

Returns missing_accessible_name[] + invalid_role_nesting[] + disallowed_aria[] + live_region_problems[] + keyboard_target_problems[] + expand_control_problems[] + all_aria_attributes[counts] + aria_audit_score 0-100 A-F.

Tested: stripe.com returns score=90/grade=A with 46 interactive roles all properly named.

/api/sri-collision-risk

Where /api/sri-readiness (c91) audits SRI presence and /api/sri-hash-mismatch (c84) compares claimed vs actual file hash, this endpoint audits the HASH ALGORITHM CHOICE + LENGTH + cross-origin CORS pre-conditions that make SRI actually do its job.

For every <script src integrity> and <link rel=stylesheet href integrity>, it:

  • Validates HASH LENGTH against expected base64 char count (sha256=44, sha384=64, sha512=88, sha1=28, md5=24) — anything shorter = TRUNCATED = SRI USELESS.
  • Flags WEAK HASH ALGORITHM (sha1/md5 per W3C 2024 SHOULD NOT).
  • HEAD-probes the actual URL for CORS headers (Access-Control-Allow-Origin: * or matching origin) WITHOUT which cross-origin SRI is BYPASSED in some browsers (notably Safari historically).
  • Flags empty body with SRI (runtime silent failure — the SRI check passes because the hash of an empty body is consistent, but the page is broken at runtime).
  • Detects CSP require-sri-for script style enforcement.

Returns per-subresource findings (weak_hash_algorithm, short_hash_value, cross_origin_with_sri_no_cors, empty_body_with_sri, no_sri_attribute) + summary + sri_collision_risk_score 0-100 A-F.

Tested: stripe.com returns score=100/A with 78 scripts (no SRI used but no weak hashes either). github.com returns score=100/A with 8 scripts.

x402 pricing

Both routes are gated behind the x402 paywall. Settlement runs through the real pay.openfacilitator.io facilitator — bogus X-PAYMENT returns verify_failed: malformed_payment_header (not a stub). $0.0005 per call (500 atomic USDC on Base mainnet, EIP-3009 transferWithAuthorization).

Try it

Both are live on the public Cloudflare tunnel above. Full catalog at /.well-known/x402 (153 endpoints, all gated).

Top comments (0)