Two new x402 APIs for AI agents: API-freshness probing + DNT/GPC policy audit (2026-10-05) A developer has added two new x402-paywalled API endpoints for AI agents: one that HEAD-probes ten conventional health and version paths to return an api_freshness_score and version_hint, and another that fetches a target URL three times to detect whether servers actually honor DNT: 1 and Sec-GPC: 1 headers, scoring compliance on a 0-100 A-F scale. Both endpoints are priced at $0.0005 in USDC on Base, matching the catalog's existing 121 paid routes. The privacy audit flags findings such as dnt_header_ignored and gpc_header_ignored so agents can check compliance before sending user data. Two questions every agent hits on day one of any integration: /v1/charge and getting a 404 back, which then triggers a 6-hour support ticket. The 10 conventional health/version endpoints /health , /healthz , /ready , /readyz , /livez , /api/health , /api/version , /api/status , /api/ping , /api/info are the universal shortcut, but every service has a different subset. DNT: 1 and Sec-GPC: 1 headers are being silently ignored. Both questions are now first-class endpoints on the same x402 catalog, at the same $0.0005 price as the existing 121 paid routes, using the same payTo wallet and asset USDC on Base . HEAD-probes 10 conventional health/version endpoints and returns which exist, their HTTP status, latency ms, and content-type. For /api/version specifically it makes a follow-up GET capped at 8KB and tries to extract a version hint from either a JSON field named version / v / api version / release or a plain-text version like v1.2.3 . Returns: probes — per-endpoint {path, status, latency ms, content type, reachable, version hint?} alive count — number of probes that returned 200-399 total count — always 10 api freshness score — 0-100 A-F grade 10 points per alive endpoint, capped at 100 findings — human-readable flags for low-alive-count services If you're building an agent that integrates with 30 SaaS services, the integration blind problem is real: some expose /api/version , some expose /healthz , some expose both, and some expose nothing. A single endpoint that probes the conventional set gives your agent a uniform "is this thing alive and what version is it" answer in one call, instead of N. https://example.com target: example.com probes: 10 alive count: 0 score: 0, grade: F findings: 'no conventional health endpoints found: agent integration blind — must probe bespoke paths' A perfectly correct outcome — example.com is a 100% static page with no health/version endpoints to probe, and the API tells the agent that. Without this endpoint, an agent would have to probe each of the 10 paths individually and add its own 6KB response handling. Privacy-aware agents anything processing EU/CA personal data need to know whether the destination server actually does anything when the client sends DNT: 1 or Sec-GPC: 1 . The naive way is to fetch the page, scan for evidence, and compare two responses manually. The new endpoint automates the comparison. For each target URL, the API fetches it 3 times: For each fetch it captures: status , latency ms , body size , cookie count , cookies sample first 3 , and any TK / DNT / Sec-GPC response headers. It then compares cookie count and body size between baseline and the privacy-flagged requests to detect reduced cookies and reduced body — a server that genuinely respects the signal will return fewer cookies and/or a smaller less personalized body. In parallel, it probes 5 common privacy-policy paths /privacy , /privacy-policy , /legal/privacy , /policies/privacy , /policy/privacy and checks the body for DNT and GPC keyword mentions. Scoring: 30pts for DNT echo, 20 for DNT-reduced cookies, 10 for DNT-reduced body, 20 for GPC echo, 10 for GPC-reduced cookies, 5 for GPC-reduced body, 5 for privacy policy reachable, 5 for DNT mention, 5 for GPC mention. Capped at 100, mapped to A-F grade. Findings include dnt header ignored server returns identical cookie set regardless of DNT: 1 and gpc header ignored same for Sec-GPC: 1 , and no privacy policy at common paths no agent should integrate with a non-compliant domain by default . Most agents today send DNT: 1 and Sec-GPC: 1 as a courtesy without verifying the server honors them. The new endpoint makes that verification a one-line check before the agent writes any data to the target service. A policy grade: F with dnt header ignored: true is a clear "this server doesn't respect your flag, don't send user data" signal — exactly the kind of preflight a production agent should run before integrating. The full catalog at /.well-known/x402 now lists 123 paid endpoints plus 1 free tier , all using the same wallet 0xCa0a6c...0c , all using USDC on Base 0x8335...2913 , all priced at $0.0005 500 atomic — except the 5 older routes at $0.001 - $0.005 . A single x402 buyer can call any of them via the same facilitator, the same X-PAYMENT header pattern, and the same settlement flow. Discovery surfaces updated in this cycle: /.well-known/x402 — 123 endpoints /openapi.json — 123 paths /llms.txt — 123 paid route lines / landing page — 123