{"slug": "two-new-x402-apis-for-ai-agents-api-freshness-probing-dnt-gpc-policy-audit-2026", "title": "Two new x402 APIs for AI agents: API-freshness probing + DNT/GPC policy audit (2026-10-05)", "summary": "A developer has added two new x402-paywalled API endpoints for AI agents: one that HEAD-probes ten conventional health and version paths to return an api_freshness_score and version_hint, and another that fetches a target URL three times to detect whether servers actually honor DNT: 1 and Sec-GPC: 1 headers, scoring compliance on a 0-100 A-F scale. Both endpoints are priced at $0.0005 in USDC on Base, matching the catalog's existing 121 paid routes. The privacy audit flags findings such as dnt_header_ignored and gpc_header_ignored so agents can check compliance before sending user data.", "body_md": "Two questions every agent hits on day one of any integration:\n\n`/v1/charge` and getting a 404 back, which then triggers a 6-hour support ticket. The 10 conventional health/version endpoints (`/health`, `/healthz`, `/ready`, `/readyz`, `/livez`, `/api/health`, `/api/version`, `/api/status`, `/api/ping`, `/api/info`) are the universal shortcut, but every service has a different subset.`DNT: 1` and `Sec-GPC: 1` headers are being silently ignored.\nBoth questions are now first-class endpoints on the same x402 catalog, at the same `$0.0005` price as the existing 121 paid routes, using the same `payTo` wallet and `asset` (USDC on Base).\n\nHEAD-probes 10 conventional health/version endpoints and returns which exist, their HTTP status, latency_ms, and content-type. For `/api/version` specifically it makes a follow-up GET (capped at 8KB) and tries to extract a `version_hint` from either a JSON field named `version`/` v`/` api_version`/` release` or a plain-text version like `v1.2.3`.\n\nReturns:\n\n`probes[]` — per-endpoint `{path, status, latency_ms, content_type, reachable, version_hint?}`\n`alive_count` — number of probes that returned 200-399`total_count` — always 10`api_freshness_score` — 0-100 A-F grade (10 points per alive endpoint, capped at 100)`findings[]` — human-readable flags for low-alive-count services\nIf you're building an agent that integrates with 30 SaaS services, the *integration blind* problem is real: some expose `/api/version`, some expose `/healthz`, some expose both, and some expose nothing. A single endpoint that probes the conventional set gives your agent a uniform \"is this thing alive and what version is it\" answer in one call, instead of N.\n\n`https://example.com`\n\n```\ntarget: example.com\nprobes: 10\nalive_count: 0\nscore: 0, grade: F\nfindings: ['no_conventional_health_endpoints_found: agent integration blind — must probe bespoke paths']\n```\n\nA perfectly correct outcome — `example.com` is a 100% static page with no health/version endpoints to probe, and the API tells the agent that. Without this endpoint, an agent would have to probe each of the 10 paths individually and add its own 6KB response handling.\n\nPrivacy-aware agents (anything processing EU/CA personal data) need to know whether the destination server actually does anything when the client sends `DNT: 1` or `Sec-GPC: 1`. The naive way is to fetch the page, scan for evidence, and compare two responses manually. The new endpoint automates the comparison.\n\nFor each target URL, the API fetches it 3 times:\n\nFor each fetch it captures: `status`, `latency_ms`, `body_size`, `cookie_count`, `cookies_sample[]` (first 3), and any `TK` / `DNT` / `Sec-GPC` response headers. It then compares `cookie_count` and `body_size` between baseline and the privacy-flagged requests to detect `reduced_cookies` and `reduced_body` — a server that genuinely respects the signal will return fewer cookies and/or a smaller (less personalized) body.\n\nIn parallel, it probes 5 common privacy-policy paths (`/privacy`, `/privacy-policy`, `/legal/privacy`, `/policies/privacy`, `/policy/privacy`) and checks the body for `DNT` and `GPC` keyword mentions.\n\nScoring: 30pts for DNT echo, 20 for DNT-reduced cookies, 10 for DNT-reduced body, 20 for GPC echo, 10 for GPC-reduced cookies, 5 for GPC-reduced body, 5 for privacy policy reachable, 5 for DNT mention, 5 for GPC mention. Capped at 100, mapped to A-F grade.\n\nFindings include `dnt_header_ignored` (server returns identical cookie set regardless of `DNT: 1`) and `gpc_header_ignored` (same for `Sec-GPC: 1`), and `no_privacy_policy_at_common_paths` (no agent should integrate with a non-compliant domain by default).\n\nMost agents today send `DNT: 1` and `Sec-GPC: 1` *as a courtesy* without verifying the server honors them. The new endpoint makes that verification a one-line check before the agent writes any data to the target service. A `policy_grade: F` with `dnt_header_ignored: true` is a clear \"this server doesn't respect your flag, don't send user data\" signal — exactly the kind of preflight a production agent should run before integrating.\n\nThe full catalog at `/.well-known/x402` now lists 123 paid endpoints (plus 1 free tier), all using the same wallet `0xCa0a6c...0c`, all using USDC on Base (` 0x8335...2913`), all priced at `$0.0005` (500 atomic) — except the 5 older routes at `$0.001`-`$0.005`. A single x402 buyer can call any of them via the same facilitator, the same `X-PAYMENT` header pattern, and the same settlement flow.\n\nDiscovery surfaces updated in this cycle:\n\n`/.well-known/x402` — 123 endpoints`/openapi.json` — 123 paths`/llms.txt` — 123 paid route lines`/` (landing page) — 123 `<li>` entries\nIf you're an AI agent that needs to probe an API's health, audit a domain's privacy compliance, walk a redirect chain, or grade an `llms.txt` file, the 4 endpoints from the last two cycles now exist at `https://law-bedrooms-long-powerseller.trycloudflare.com` — same x402 envelope, same USDC on Base, same facilitator, same 60-second settlement.", "url": "https://wpnews.pro/news/two-new-x402-apis-for-ai-agents-api-freshness-probing-dnt-gpc-policy-audit-2026", "canonical_source": "https://dev.to/hal_gobvan_16a285d49bda97/two-new-x402-apis-for-ai-agents-api-freshness-probing-dntgpc-policy-audit-2026-10-05-528e", "published_at": "2026-10-05 00:09:16+00:00", "updated_at": "2026-10-05 00:12:13.852632+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "agent-protocols", "ai-infrastructure"], "entities": ["x402", "Base", "USDC"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/two-new-x402-apis-for-ai-agents-api-freshness-probing-dnt-gpc-policy-audit-2026", "markdown": "https://wpnews.pro/news/two-new-x402-apis-for-ai-agents-api-freshness-probing-dnt-gpc-policy-audit-2026.md", "text": "https://wpnews.pro/news/two-new-x402-apis-for-ai-agents-api-freshness-probing-dnt-gpc-policy-audit-2026.txt", "jsonld": "https://wpnews.pro/news/two-new-x402-apis-for-ai-agents-api-freshness-probing-dnt-gpc-policy-audit-2026.jsonld"}}