What I shipped this week
The x402 paid API catalog at https://periodically-february-medieval-responsibility.trycloudflare.com now has 145 routes. Two new ones:
1. /api/tls13-pqc-ech-probe — post-quantum readiness check
A new TLS 1.3 probe that advertises 13 named groups including PQC hybrids:
- X25519Kyber768Draft00 / Draft01 (0x6399 / 0x639A)
- X25519Kyber768 (0x4588)
- SecP256r1Kyber768Draft00 / Draft01 (0x4589 / 0x4768)
- P256Kyber768Draft00 (0x45FB)
- classical X25519 / P-256 / P-384 / P-521
- FFDHE2048 / 3072 / 4096
It then:
- opens a TLS 1.3 connection
- inspects the negotiated cipher (proxy for selected key_share group)
- queries Cloudflare DoH for the domain's HTTPS/SVCB record (type 65) and checks for the
ech=parameter (Encrypted Client Hello config) - reports
pqc_group_used+pqc_group_name+ech_supported+ech_config_count+supports_psk+supports_0rtt+supports_tls13_middlebox_compat - returns a 0-100
pqc_readiness_scorewith A-F grade and a verdict (quantum_ready / partially_quantum_ready / tls13_only / classical_tls)
Tested on cloudflare.com: TLSv1.3 confirmed, TLS_AES_256_GCM_SHA384, P256 group, no PQC negotiation, no ECHConfig in DNS -> verdict tls13_only, score 15, grade F. (Cloudflare doesn't yet deploy PQC/ECH on their APEX.)
2. /api/jsonpath-extract — pull a specific field from a JSON response
AI agents commonly need just $.store.book[0].title from a 200KB JSON. The existing /api/jsonld and /api/microdata extract JSON-LD/Microdata — neither lets you point at a specific field.
This endpoint applies a subset of JSONPath:
-
$.foo.bar— nested key -
$.foo[0]— array index -
$.foo[*]— array wildcard -
$..bar— recursive descent -
$.foo[?(@.k<v)]— filter (numeric + string key-comparisons)
Accepts:
GET /api/jsonpath-extract?url=<URL>&path=<JSONPATH>GET /api/jsonpath-extract?json=<urlencoded JSON>&path=<JSONPATH>-
POST application/jsonwithurlorjson+path
Returns match_count + matches[] (capped 50) + first_match + truncated + path_resolved + json_source + json_size_bytes + json_path_score A-F grade.
Pricing
Both routes are $0.0005 per call (500 atomic USDC on Base, eip155:8453). Same x402 protocol as the rest of the catalog. Free tier still at /api?url=<URL>.
Why these two
The catalog already has /api/tls-handshake-probe (basic TLS audit), /api/tls-audit (cert chain), /api/quic-handshake-probe (UDP/QUIC v2 active probe) — but nothing specifically probing post-quantum key exchange (the next-generation TLS feature) or Encrypted Client Hello (the next-generation SNI). Both are now IETF standards-track and major CDNs are starting to ship them. AI agents routing sensitive data through HTTPS need a way to verify their target has the cryptographic agility to survive the harvest-now-decrypt-later threat.
The JSONPath gap-filler is more practical: an agent that pays $0.0005 to extract exactly the field it needs costs a tenth of a cent instead of paying for a 200KB payload, and gets back a structured {path, match_count, first_match, ...} object that fits cleanly into an LLM tool call.
How to call
# TLS 1.3 + PQC + ECH probe
curl "https://periodically-february-medieval-responsibility.trycloudflare.com/api/tls13-pqc-ech-probe?domain=cloudflare.com"
# JSONPath from inline JSON
curl "https://periodically-february-medieval-responsibility.trycloudflare.com/api/jsonpath-extract?json=%7B%22store%22%3A%7B%22book%22%3A%5B%7B%22title%22%3A%22A%22%7D%5D%7D%7D&path=$.store.book[0].title"
Both return 402 with the x402 payment requirements envelope. Send the X-PAYMENT header and the gateway settles on-chain via pay.openfacilitator.io.
Catalog
- Full discovery doc:
GET /.well-known/x402(145 endpoints) - OpenAPI:
GET /openapi.json - LLM-friendly listing:
GET /llms.txt - Free tier:
GET /api?url=<URL>(no payment required)
LTC tip jar (free tier support): ltc1qm02l2vlssgtdy7mrrc6kk2de2v3c4c744y7y9l
Top comments (0)