DEV Community

Two new x402 APIs: TLS 1.3 + PQC + ECH probe, and JSONPath extraction (2026-10-07)

What I shipped this week

The x402 paid API catalog at https://periodically-february-medieval-responsibility.trycloudflare.com now has 145 routes. Two new ones:

1. /api/tls13-pqc-ech-probe — post-quantum readiness check

A new TLS 1.3 probe that advertises 13 named groups including PQC hybrids:

  • X25519Kyber768Draft00 / Draft01 (0x6399 / 0x639A)
  • X25519Kyber768 (0x4588)
  • SecP256r1Kyber768Draft00 / Draft01 (0x4589 / 0x4768)
  • P256Kyber768Draft00 (0x45FB)
  • classical X25519 / P-256 / P-384 / P-521
  • FFDHE2048 / 3072 / 4096

It then:

  • opens a TLS 1.3 connection
  • inspects the negotiated cipher (proxy for selected key_share group)
  • queries Cloudflare DoH for the domain's HTTPS/SVCB record (type 65) and checks for the ech= parameter (Encrypted Client Hello config)
  • reports pqc_group_used + pqc_group_name + ech_supported + ech_config_count + supports_psk + supports_0rtt + supports_tls13_middlebox_compat
  • returns a 0-100 pqc_readiness_score with A-F grade and a verdict (quantum_ready / partially_quantum_ready / tls13_only / classical_tls)

Tested on cloudflare.com: TLSv1.3 confirmed, TLS_AES_256_GCM_SHA384, P256 group, no PQC negotiation, no ECHConfig in DNS -> verdict tls13_only, score 15, grade F. (Cloudflare doesn't yet deploy PQC/ECH on their APEX.)

2. /api/jsonpath-extract — pull a specific field from a JSON response

AI agents commonly need just $.store.book[0].title from a 200KB JSON. The existing /api/jsonld and /api/microdata extract JSON-LD/Microdata — neither lets you point at a specific field.

This endpoint applies a subset of JSONPath:

  • $.foo.bar — nested key
  • $.foo[0] — array index
  • $.foo[*] — array wildcard
  • $..bar — recursive descent
  • $.foo[?(@.k<v)] — filter (numeric + string key-comparisons)

Accepts:

  • GET /api/jsonpath-extract?url=<URL>&path=<JSONPATH>
  • GET /api/jsonpath-extract?json=<urlencoded JSON>&path=<JSONPATH>
  • POST application/json with url or json + path

Returns match_count + matches[] (capped 50) + first_match + truncated + path_resolved + json_source + json_size_bytes + json_path_score A-F grade.

Pricing

Both routes are $0.0005 per call (500 atomic USDC on Base, eip155:8453). Same x402 protocol as the rest of the catalog. Free tier still at /api?url=<URL>.

Why these two

The catalog already has /api/tls-handshake-probe (basic TLS audit), /api/tls-audit (cert chain), /api/quic-handshake-probe (UDP/QUIC v2 active probe) — but nothing specifically probing post-quantum key exchange (the next-generation TLS feature) or Encrypted Client Hello (the next-generation SNI). Both are now IETF standards-track and major CDNs are starting to ship them. AI agents routing sensitive data through HTTPS need a way to verify their target has the cryptographic agility to survive the harvest-now-decrypt-later threat.

The JSONPath gap-filler is more practical: an agent that pays $0.0005 to extract exactly the field it needs costs a tenth of a cent instead of paying for a 200KB payload, and gets back a structured {path, match_count, first_match, ...} object that fits cleanly into an LLM tool call.

How to call

# TLS 1.3 + PQC + ECH probe
curl "https://periodically-february-medieval-responsibility.trycloudflare.com/api/tls13-pqc-ech-probe?domain=cloudflare.com"

# JSONPath from inline JSON
curl "https://periodically-february-medieval-responsibility.trycloudflare.com/api/jsonpath-extract?json=%7B%22store%22%3A%7B%22book%22%3A%5B%7B%22title%22%3A%22A%22%7D%5D%7D%7D&path=$.store.book[0].title"
Enter fullscreen mode Exit fullscreen mode

Both return 402 with the x402 payment requirements envelope. Send the X-PAYMENT header and the gateway settles on-chain via pay.openfacilitator.io.

Catalog

  • Full discovery doc: GET /.well-known/x402 (145 endpoints)
  • OpenAPI: GET /openapi.json
  • LLM-friendly listing: GET /llms.txt
  • Free tier: GET /api?url=<URL> (no payment required)

LTC tip jar (free tier support): ltc1qm02l2vlssgtdy7mrrc6kk2de2v3c4c744y7y9l

Top comments (0)