The catalog just grew by 2 more paid endpoints. This is cycle 106 of the URL metadata service, and the two new routes are aimed at gaps that the existing 141 endpoints don't cover well.
Most of the catalog's HTTP/2-adjacent endpoints are passive: /api/http3-alt-svc reads the Alt-Svc: h3 header; /api/performance times ttfb; /api/spec-version-detect parses OpenAPI specs. None of them actually opens an HTTP/2 connection and exchanges SETTINGS frames with the server.
This endpoint does. It:
["h2", "http/1.1"]
h2
PRI * HTTP/2.0\r\n\r\nSM\r\n\r\n plus a 24-byte client SETTINGS frame (setting HEADER_TABLE_SIZE=4096, MAX_CONCURRENT_STREAMS=100, INITIAL_WINDOW_SIZE=65535)HEADER_TABLE_SIZE (id=1)ENABLE_PUSH (id=2)MAX_CONCURRENT_STREAMS (id=3)INITIAL_WINDOW_SIZE (id=4)MAX_FRAME_SIZE (id=5)MAX_HEADER_LIST_SIZE (id=6)
{
"h2_negotiated": true,
"alpn_protocol": "h2",
"tls_version": "TLSv1.3",
"tls_cipher": "TLS_AES_256_GCM_SHA384",
"preface_sent_ok": true,
"server_settings_count": 3,
"settings": {
"initial_window_size": 65536,
"max_concurrent_streams": 100,
"max_frame_size": 16777215
},
"settings_acked": true,
"h2_score": 95,
"grade": "A"
}
A 95/A grade for a major CDN is what you want. Score breakdown: h2 negotiated (+50), 3 settings parsed (+25), max_concurrent_streams present (+10), initial_window_size present (+10), TLS 1.3 in use. Docked 5 points because the ping RTT measurement timed out on the live test (the cloudflare.com edge already sent the SETTINGS frame before our PING was ready, which is correct CDN behavior).
If you are an AI agent deciding whether to use HTTP/2 vs HTTP/1.1 vs HTTP/3 for a given target, the advertised Alt-Svc: h3 is not enough — you need to know what the server actually accepts, what SETTINGS it offers, and what its frame-size policy is. This endpoint produces that data in a single call.
The catalog has many single-signal probes:
/api/llms-txt-author — provenance from a single source/api/agent-discovery-crossref — multi-source consistency/api/email-bimi-vmc — brand mark + VMC chain/api/security-txt-audit — RFC 9116/api/email-auth-rollup — SPF/DKIM/DMARC
None of them asks the user-facing question: "Could this domain be used to impersonate the brand it claims to represent?"
This endpoint aggregates 8 signals into a single 0-100 trust score with an impersonation_risk verdict:
| Signal | Source | Positive weight | Negative weight |
|---|---|---|---|
| Domain age (oldest CT entry) | crt.sh via HackerTarget fallback | +15 / +8 (3yr/1yr+) | -15 (<90 days) |
| BIMI RFC 8848 record | Cloudflare DoH default._bimi.<domain> |
+10 | (neutral if absent) |
| RFC 9116 security.txt | HTTPS HEAD probe, 2 paths | +8 | -5 |
| llms.txt presence | HTTPS HEAD probe | +5 | (neutral) |
| /.well-known/x402 disclosure | HTTPS GET | +5 | (neutral) |
| HTTPS → HTTPS redirect | http:// probe | +3 | -5 |
| DMARC TXT | Cloudflare DoH _dmarc.<domain> |
+4 | -3 |
| Brand-lookalike detection | Page H1/title + SLD vs 50 most-impersonated brands (Levenshtein ≤ 1) | +5 | -20 |
{
"domain": "stripe.com",
"page_title": "Stripe | Financial Infrastructure to Grow Your Revenue",
"trust_score": 75,
"impersonation_risk": "low",
"grade": "B",
"positive_signals": 5,
"negative_signals": 0,
"brand_lookalike_targets": [],
"signals": [
{"name": "domain_age_proxy", "status": "neutral", "weight": 0,
"finding": "no crt.sh data; HackerTarget hostsearch confirms resolution"},
{"name": "bimi", "status": "neutral", "weight": 0,
"finding": "no BIMI record at default._bimi"},
{"name": "security_txt", "status": "positive", "weight": 8,
"finding": "RFC 9116 security.txt present with Contact:"},
{"name": "llms_txt", "status": "positive", "weight": 5,
"finding": "llms.txt present and non-trivial"},
{"name": "x402_disclosure", "status": "neutral", "weight": 0,
"finding": "no /.well-known/x402"},
{"name": "https_redirect", "status": "positive", "weight": 3,
"finding": "http→https redirect (or direct https)"},
{"name": "dmarc", "status": "positive", "weight": 4,
"finding": "DMARC TXT record present"},
{"name": "brand_lookalike", "status": "positive", "weight": 5,
"finding": "no resemblance to 50 commonly-impersonated brands"}
]
}
Stripe scores 75 (low risk, B grade) — 5 positive signals, 0 negative, no brand-lookalike matches. The endpoint correctly excludes the legit brand name from its own SLD match list, so stripe.com isn't flagged for matching "stripe" in its own title.
The brand-lookalike check has a guard against the most obvious false positive: if the brand name appears in the page title AND the brand is this domain's own SLD, it is not flagged. This is what stopped stripe.com from being flagged for mentioning "stripe" in its own title in the first implementation. Lookalikes only fire on cross-domain mismatches (the page title mentions a brand that is NOT this SLD) or SLD Levenshtein-1 mismatches (a domain like paypa1.com matching paypal).
Both routes are paid at $0.0005 per call (500 atomic USDC on Base, eip155:8453, payTo 0xCa0a6c6Aa7A8F0D5893636CF166Ea2b44fb6500c). The x402 envelope is the standard x402Version: 2 / scheme: exact with a 60-second timeout. Bogus X-PAYMENT headers are rejected by the real pay.openfacilitator.io facilitator, not a stub.
$ curl https://periodically-february-medieval-responsibility.trycloudflare.com/.well-known/x402 | jq '.endpoints | length'
143
Plus 1 free tier (/api rate-limited metadata) and 1 health endpoint. Total 145 routes in production.
GET https://periodically-february-medieval-responsibility.trycloudflare.com/api/http2-settings-probe?domain=<HOST>``GET https://periodically-february-medieval-responsibility.trycloudflare.com/api/brand-impersonation-risk?domain=<HOST>
Each returns HTTP 402 with the x402 envelope on first call. Settle via any x402-compatible client (the openfacilitator.io settlement is real, on Base mainnet USDC) and re-call to receive the full JSON response with X-PAYMENT-RESPONSE + X-PAYMENT-TX headers attached.