{"service":"uai-x402-api-catalog","displayName":"UAI Systems Security API Catalog","description":"x402-paid security and DevOps APIs for AI agents: secret scan, CVE lookup, IAM/Terraform/GitHub Actions audits, Cloudflare Worker and Wrangler config review, DNS/SPF/DMARC email security, SSL/TLS and GDPR privacy scans, compliance mapping, and agentic commerce readiness.","network":"eip155:8453","pay_to":"0xe2433f056f953b7d4c946cffb1201d2e9601eabf","networks":[{"network":"eip155:8453","pay_to":"0xe2433f056f953b7d4c946cffb1201d2e9601eabf"}],"mode":"cdp","catalog":"/api/v1/catalog","wellKnownCatalog":"https://x402-hono-api.inraby.workers.dev/.well-known/x402-catalog","docs":"/docs","health":"/health","mcp":"/mcp","agent402Register":"https://agent402.tools/api/index/register","endpoints":{"POST /api/v1/validate-policy":{"price":"$0.05","method":"POST","description":"Policy Genie — Validate AWS IAM and Cloudflare Zero Trust policy JSON for risky wildcards, bypass rules, weak scoping, and embedded secrets.","tags":["iam","cloudflare","policy"],"body":{"rawPolicyText":"IAM or Cloudflare Access policy JSON"}},"POST /api/v1/cloudflare-zero-trust-audit":{"price":"$0.05","method":"POST","description":"Cloudflare Zero Trust Audit — Analyze Cloudflare Zero Trust Access policy JSON for bypass rules, allow-everyone patterns, and weak identity constraints.","tags":["cloudflare","zero-trust","audit"],"body":{"policyText":"Cloudflare Zero Trust Access policy JSON"}},"POST /api/v1/iam-risk-score":{"price":"$0.03","method":"POST","description":"IAM Risk Score — Return a focused AWS IAM risk score and severity summary for a submitted IAM policy document.","tags":["iam","aws","risk"],"body":{"policyText":"AWS IAM policy JSON"}},"POST /api/v1/secret-scan":{"price":"$0.01","method":"POST","description":"Secret Scan / Credential Redaction — Secret scan for exposed API keys, tokens, passwords, and credentials in text — returns redacted output without exposing matched secret values. Ideal for agent pre-flight checks before sharing config or logs.","tags":["secret-scan","secret scan","secrets","credentials","api-key","redaction","security"],"body":{"text":"Text to scan for exposed secrets and credentials"}},"POST /api/v1/agentic-commerce-readiness":{"price":"$0.10","method":"POST","description":"Agentic Commerce Readiness — Assess whether a company, API, or product description is a strong fit for x402/AP2-style agentic commerce.","tags":["x402","ap2","commerce"],"body":{"companyUrl":"string","productDescription":"string","targetBuyer":"string","suggestedPrice":"string"}},"POST /api/v1/dns-email-security-audit":{"price":"$0.0045","method":"POST","description":"DNS / Email Security Audit — DNS email security audit — SPF, DMARC, DKIM, BIMI, and MTA-STS check for domain spoofing and deliverability risk. Agent-friendly dns email security screen at micropayment pricing.","tags":["dns","dns email","dns email security","email","email security","spf","dkim","dmarc","bimi","mta-sts","email-security","domain","security","compliance","audit"],"body":{"domain":"Domain to audit (example.com)"}},"POST /api/v1/wrangler-config-audit":{"price":"$0.05","method":"POST","description":"Wrangler Config Risk Audit — DevOps security audit for Cloudflare wrangler.toml — flags production-unsafe settings, plaintext secrets in vars, risky routes, and missing observability for Worker deployments.","tags":["cloudflare","wrangler","wrangler-config","wrangler.toml","workers","worker","cloudflare-workers","devops","config-audit","audit","security"],"body":{"wranglerToml":"Full wrangler.toml contents"}},"POST /api/v1/github-actions-secret-exposure-scan":{"price":"$0.05","method":"POST","description":"GitHub Actions Secret Exposure Scan — Scan GitHub Actions workflow YAML for pull_request_target misuse, over-permissive tokens, secret leakage, unpinned actions, and unsafe fork checkout patterns.","tags":["github-actions","ci-cd","secrets","security"],"body":{"workflowYaml":"GitHub Actions workflow YAML contents"}},"POST /api/v1/cloudflare-worker-security-review":{"price":"$0.10","method":"POST","description":"Cloudflare Worker Security Review — Review Cloudflare Worker source and optional wrangler.toml for hardcoded secrets, unsafe CORS, missing admin auth, sensitive logging, and dynamic code execution.","tags":["cloudflare","workers","security","review"],"body":{"workerCode":"Worker JavaScript/TypeScript source","wranglerToml":"Optional wrangler.toml contents"}},"POST /api/v1/terraform-iam-risk-scan":{"price":"$0.10","method":"POST","description":"Terraform IAM Risk Scan — Scan Terraform for IAM wildcard policies, public S3/RDS exposure, open security groups, broad assume-role trust, and missing encryption hints.","tags":["terraform","iam","aws","security"],"body":{"terraform":"Terraform HCL contents","cloud":"Cloud provider hint (aws recommended)"}},"POST /api/v1/security-alert-triage":{"price":"$0.10","method":"POST","description":"Security Alert Triage — Triage security alert emails for urgency, severity, likely cause, and evidence collection steps without storing message bodies.","tags":["email","security","triage","alerts"],"body":{"subject":"Email subject line","from":"Sender address or display name","body":"Email body text (not stored server-side)","source":"string"}},"POST /api/v1/email-vendor-risk-summary":{"price":"$0.10","method":"POST","description":"Email Vendor Risk Summary — Summarize vendor email risk for compliance claims, subprocessors, retention, DPA language, and breach notifications.","tags":["email","vendor","compliance","risk"],"body":{"subject":"string","from":"string","body":"string","vendorName":"Optional vendor display name"}},"POST /api/v1/compliance-evidence-mapper":{"price":"$0.15","method":"POST","description":"Compliance Evidence Mapper — Map SOC 2, ISO 27001, HIPAA, PCI, and GDPR compliance audit requests to evidence items, owners, systems, and follow-up questions. For agent-driven compliance and audit workflows.","tags":["email","compliance","soc2","evidence","gdpr","audit","iso27001","pci"],"body":{"subject":"string","body":"string","framework":"string"}},"POST /api/v1/dependency-cve-scan":{"price":"$0.05","method":"POST","description":"Dependency / CVE Scan — Scan package.json or lockfile text for dependency CVE risk signals — outdated lodash/axios, deprecated packages, wildcard pins, risky postinstall scripts, and embedded secrets.","tags":["dependency","cve","supply-chain","security","npm","audit"],"body":{"manifestText":"package.json, package-lock.json, or yarn.lock contents"}},"POST /api/v1/ssl-certificate-audit":{"price":"$0.05","method":"POST","description":"SSL / TLS Certificate Audit — Audit domain SSL/TLS certificate expiry, HTTPS reachability, HSTS, and HTTP-to-HTTPS redirect posture using certificate transparency and live transport checks.","tags":["ssl","tls","certificate","security","audit","devops"],"body":{"domain":"Domain to audit (example.com)"}},"POST /api/v1/gdpr-privacy-scan":{"price":"$0.08","method":"POST","description":"GDPR / Privacy Posture Scan — Scan a website landing page for GDPR and CCPA privacy signals — privacy policy links, cookie consent language, and compliance keyword coverage for agent audits.","tags":["gdpr","privacy","compliance","cookie","audit","security"],"body":{"url":"Website URL or domain to scan"}},"POST /api/v1/jwt-decode":{"price":"$0.02","method":"POST","description":"JWT Decode / Inspect — JWT decode and inspect — decode header and payload without signature verification, flag expired tokens, insecure algorithms, and not-before issues for agent auth debugging.","tags":["jwt","jwt-decode","auth","security","decode","token","inspect"],"body":{"jwt":"JWT string (header.payload.signature)"}},"POST /api/v1/jwt-inspect":{"price":"$0.02","method":"POST","description":"JWT Inspect / Decode — JWT decode and inspect for agent auth debugging — decode header and payload, flag expired tokens, insecure algorithms, and not-before issues. Search-friendly alias for jwt-decode.","tags":["jwt","jwt-decode","jwt-inspect","decode","token","auth","security"],"body":{"jwt":"JWT string (header.payload.signature)"}},"POST /api/v1/cve-lookup":{"price":"$0.01","method":"POST","description":"CVE Lookup / Vulnerability Search — CVE lookup and vulnerability search — resolve a CVE ID via OSV and return summary, severity, affected packages, and references for agent triage.","tags":["cve","cve lookup","vulnerability lookup","vulnerability","security","osv","advisory","npm","supply-chain"],"body":{"cveId":"CVE identifier (CVE-2021-44228)"}},"POST /api/v1/sanctions-screen":{"price":"$0.02","method":"POST","description":"Sanctions List Lookup (Informational) — Informational sanctions list lookup for agent pre-flight checks — matches names or Ethereum wallet addresses against a small curated subset of publicly designated OFAC SDN entries (~15). Not AML/KYC certified. Not a substitute for official OFAC search or licensed screening.","tags":["sanctions","sanctions check","ofac","wallet","screening","informational"],"body":{"query":"Person name, entity name, or Ethereum wallet address (0x...)"}},"POST /api/v1/repo-security-bundle":{"price":"$0.04","method":"POST","description":"Repo Security Bundle Scan — Combined repo security scan — secret scan, GitHub Actions workflow exposure check, and dependency manifest CVE review in one agent call for CI pre-commit and supply-chain triage.","tags":["repo","repository","secret scan","github actions","dependency","supply-chain","bundle","security","ci"],"body":{"text":"Optional text/config to scan for secrets","workflowYaml":"Optional GitHub Actions workflow YAML","manifestText":"Optional package.json, lockfile, or yarn.lock contents"}}},"status":"operational"}