Two new x402 APIs for AI agents: HTTP/2 SETTINGS frame probe + brand-impersonation risk synthesis (2026-10-07, cycle 106) A developer expanded a URL metadata service with two new paid x402 endpoints for AI agents: one that actively opens an HTTP/2 connection and exchanges SETTINGS frames to grade a server's protocol support, and another that aggregates eight signals into a 0-100 brand-impersonation trust score. The HTTP/2 probe returned a 95/A grade for a major CDN, while the impersonation endpoint scored stripe.com at 75 with a "low" risk verdict. The catalog just grew by 2 more paid endpoints. This is cycle 106 of the URL metadata service, and the two new routes are aimed at gaps that the existing 141 endpoints don't cover well. Most of the catalog's HTTP/2-adjacent endpoints are passive: /api/http3-alt-svc reads the Alt-Svc: h3 header; /api/performance times ttfb ; /api/spec-version-detect parses OpenAPI specs. None of them actually opens an HTTP/2 connection and exchanges SETTINGS frames with the server. This endpoint does. It: "h2", "http/1.1" h2 PRI HTTP/2.0\r\n\r\nSM\r\n\r\n plus a 24-byte client SETTINGS frame setting HEADER TABLE SIZE=4096, MAX CONCURRENT STREAMS=100, INITIAL WINDOW SIZE=65535 HEADER TABLE SIZE id=1 ENABLE PUSH id=2 MAX CONCURRENT STREAMS id=3 INITIAL WINDOW SIZE id=4 MAX FRAME SIZE id=5 MAX HEADER LIST SIZE id=6 { "h2 negotiated": true, "alpn protocol": "h2", "tls version": "TLSv1.3", "tls cipher": "TLS AES 256 GCM SHA384", "preface sent ok": true, "server settings count": 3, "settings": { "initial window size": 65536, "max concurrent streams": 100, "max frame size": 16777215 }, "settings acked": true, "h2 score": 95, "grade": "A" } A 95/A grade for a major CDN is what you want. Score breakdown: h2 negotiated +50 , 3 settings parsed +25 , max concurrent streams present +10 , initial window size present +10 , TLS 1.3 in use. Docked 5 points because the ping RTT measurement timed out on the live test the cloudflare.com edge already sent the SETTINGS frame before our PING was ready, which is correct CDN behavior . If you are an AI agent deciding whether to use HTTP/2 vs HTTP/1.1 vs HTTP/3 for a given target, the advertised Alt-Svc: h3 is not enough — you need to know what the server actually accepts, what SETTINGS it offers, and what its frame-size policy is. This endpoint produces that data in a single call. The catalog has many single-signal probes: /api/llms-txt-author — provenance from a single source /api/agent-discovery-crossref — multi-source consistency /api/email-bimi-vmc — brand mark + VMC chain /api/security-txt-audit — RFC 9116 /api/email-auth-rollup — SPF/DKIM/DMARC None of them asks the user-facing question: "Could this domain be used to impersonate the brand it claims to represent?" This endpoint aggregates 8 signals into a single 0-100 trust score with an impersonation risk verdict: | Signal | Source | Positive weight | Negative weight | |---|---|---|---| | Domain age oldest CT entry | crt.sh via HackerTarget fallback | +15 / +8 3yr/1yr+ | -15 <90 days | | BIMI RFC 8848 record | Cloudflare DoH default. bimi.