UAI Systems x402 API Catalog
Machine-consumable paid APIs for autonomous agents. No API key. Pay per call via x402.
Discovery
- Catalog: https://x402-hono-api.inraby.workers.dev/api/v1/catalog
- Well-known: https://x402-hono-api.inraby.workers.dev/.well-known/x402-catalog
- Health: https://x402-hono-api.inraby.workers.dev/health
- MCP (streamable HTTP): https://x402-hono-api.inraby.workers.dev/mcp
- MCP setup: https://x402-hono-api.inraby.workers.dev/docs/mcp-setup
- Agentic Market: https://agentic.market/services/x402-hono-api-inraby-workers-dev
- CDP Bazaar merchant: https://api.cdp.coinbase.com/platform/v2/x402/discovery/merchant?payTo=0xe2433f056f953b7d4c946cffb1201d2e9601eabf
MCP Tools
Connect MCP clients (Cursor, Claude Desktop, Cloudflare Agents) to https://x402-hono-api.inraby.workers.dev/mcp.
- Transport:
streamable-http - Free tools:
catalog, secret-scan-preview - Paid tools:
21x402-paid security tools (same prices as REST)
Connect MCP clients to /mcp. Free catalog and secret-scan-preview (2048 chars). Paid tools require x402 USDC per call.
Legal & compliance
Not legal advice. Tools return informational security analysis only. See the machine-readable notice:
The sanctions-screen endpoint is informational only — it checks ~15 curated public entries, not the full OFAC SDN. It is not AML/KYC certified. A clear result is not a compliance guarantee.
x402 Payment
- Network:
eip155:8453 - Facilitator:
https://api.cdp.coinbase.com/platform/v2/x402 - Testnet:
false - Payment header:
X-PAYMENT - Expected unpaid behavior:
402 Payment Requiredwithpayment-requiredmetadata
Product Catalog
| ID | Endpoint | Price | Tags | Description |
|---|---|---|---|---|
policy-genie |
POST /api/v1/validate-policy |
$0.05 | iam cloudflare policy |
Validate AWS IAM and Cloudflare Zero Trust policy JSON for risky wildcards, bypass rules, weak scoping, and embedded secrets. |
cloudflare-zero-trust-audit |
POST /api/v1/cloudflare-zero-trust-audit |
$0.05 | cloudflare zero-trust audit |
Analyze Cloudflare Zero Trust Access policy JSON for bypass rules, allow-everyone patterns, and weak identity constraints. |
iam-risk-score |
POST /api/v1/iam-risk-score |
$0.03 | iam aws risk |
Return a focused AWS IAM risk score and severity summary for a submitted IAM policy document. |
secret-scan |
POST /api/v1/secret-scan |
$0.01 | secret-scan secret scan secrets credentials api-key redaction security |
Secret scan for exposed API keys, tokens, passwords, and credentials in text — returns redacted output without exposing matched secret values. Ideal for agent pre-flight checks before sharing config or logs. |
agentic-commerce-readiness |
POST /api/v1/agentic-commerce-readiness |
$0.10 | x402 ap2 commerce |
Assess whether a company, API, or product description is a strong fit for x402/AP2-style agentic commerce. |
dns-email-security-audit |
POST /api/v1/dns-email-security-audit |
$0.0045 | dns dns email dns email security email email security spf dkim dmarc bimi mta-sts email-security domain security compliance audit |
DNS email security audit — SPF, DMARC, DKIM, BIMI, and MTA-STS check for domain spoofing and deliverability risk. Agent-friendly dns email security screen at micropayment pricing. |
wrangler-config-audit |
POST /api/v1/wrangler-config-audit |
$0.05 | cloudflare wrangler wrangler-config wrangler.toml workers worker cloudflare-workers devops config-audit audit security |
DevOps security audit for Cloudflare wrangler.toml — flags production-unsafe settings, plaintext secrets in vars, risky routes, and missing observability for Worker deployments. |
github-actions-secret-exposure-scan |
POST /api/v1/github-actions-secret-exposure-scan |
$0.05 | github-actions ci-cd secrets security |
Scan GitHub Actions workflow YAML for pull_request_target misuse, over-permissive tokens, secret leakage, unpinned actions, and unsafe fork checkout patterns. |
cloudflare-worker-security-review |
POST /api/v1/cloudflare-worker-security-review |
$0.10 | cloudflare workers security review |
Review Cloudflare Worker source and optional wrangler.toml for hardcoded secrets, unsafe CORS, missing admin auth, sensitive logging, and dynamic code execution. |
terraform-iam-risk-scan |
POST /api/v1/terraform-iam-risk-scan |
$0.10 | terraform iam aws security |
Scan Terraform for IAM wildcard policies, public S3/RDS exposure, open security groups, broad assume-role trust, and missing encryption hints. |
security-alert-triage |
POST /api/v1/security-alert-triage |
$0.10 | email security triage alerts |
Triage security alert emails for urgency, severity, likely cause, and evidence collection steps without storing message bodies. |
email-vendor-risk-summary |
POST /api/v1/email-vendor-risk-summary |
$0.10 | email vendor compliance risk |
Summarize vendor email risk for compliance claims, subprocessors, retention, DPA language, and breach notifications. |
compliance-evidence-mapper |
POST /api/v1/compliance-evidence-mapper |
$0.15 | email compliance soc2 evidence gdpr audit iso27001 pci |
Map SOC 2, ISO 27001, HIPAA, PCI, and GDPR compliance audit requests to evidence items, owners, systems, and follow-up questions. For agent-driven compliance and audit workflows. |
dependency-cve-scan |
POST /api/v1/dependency-cve-scan |
$0.05 | dependency cve supply-chain security npm audit |
Scan package.json or lockfile text for dependency CVE risk signals — outdated lodash/axios, deprecated packages, wildcard pins, risky postinstall scripts, and embedded secrets. |
ssl-certificate-audit |
POST /api/v1/ssl-certificate-audit |
$0.05 | ssl tls certificate security audit devops |
Audit domain SSL/TLS certificate expiry, HTTPS reachability, HSTS, and HTTP-to-HTTPS redirect posture using certificate transparency and live transport checks. |
gdpr-privacy-scan |
POST /api/v1/gdpr-privacy-scan |
$0.08 | gdpr privacy compliance cookie audit security |
Scan a website landing page for GDPR and CCPA privacy signals — privacy policy links, cookie consent language, and compliance keyword coverage for agent audits. |
jwt-decode |
POST /api/v1/jwt-decode |
$0.02 | jwt jwt-decode auth security decode token inspect |
JWT decode and inspect — decode header and payload without signature verification, flag expired tokens, insecure algorithms, and not-before issues for agent auth debugging. |
jwt-inspect |
POST /api/v1/jwt-inspect |
$0.02 | jwt jwt-decode jwt-inspect decode token auth security |
JWT decode and inspect for agent auth debugging — decode header and payload, flag expired tokens, insecure algorithms, and not-before issues. Search-friendly alias for jwt-decode. |
cve-lookup |
POST /api/v1/cve-lookup |
$0.01 | cve cve lookup vulnerability lookup vulnerability security osv advisory npm supply-chain |
CVE lookup and vulnerability search — resolve a CVE ID via OSV and return summary, severity, affected packages, and references for agent triage. |
sanctions-screen |
POST /api/v1/sanctions-screen |
$0.02 | sanctions sanctions check ofac wallet screening informational |
Informational sanctions list lookup for agent pre-flight checks — matches names or Ethereum wallet addresses against a small curated subset of publicly designated OFAC SDN entries (~15). Not AML/KYC certified. Not a substitute for official OFAC search or licensed screening. |
repo-security-bundle |
POST /api/v1/repo-security-bundle |
$0.04 | repo repository secret scan github actions dependency supply-chain bundle security ci |
Combined repo security scan — secret scan, GitHub Actions workflow exposure check, and dependency manifest CVE review in one agent call for CI pre-commit and supply-chain triage. |
Example Inputs
Policy Genie
POST https://x402-hono-api.inraby.workers.dev/api/v1/validate-policy — $0.05
{
"rawPolicyText": "{\"Version\":\"2012-10-17\",\"Statement\":[]}"
}
Cloudflare Zero Trust Audit
POST https://x402-hono-api.inraby.workers.dev/api/v1/cloudflare-zero-trust-audit — $0.05
{
"policyText": "{\"decision\":\"allow\",\"include\":[{\"everyone\":{}}]}"
}
IAM Risk Score
POST https://x402-hono-api.inraby.workers.dev/api/v1/iam-risk-score — $0.03
{
"policyText": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}"
}
Secret Scan / Credential Redaction
POST https://x402-hono-api.inraby.workers.dev/api/v1/secret-scan — $0.01
{
"text": "api_token=not-a-real-secret-value"
}
Agentic Commerce Readiness
POST https://x402-hono-api.inraby.workers.dev/api/v1/agentic-commerce-readiness — $0.10
{
"productDescription": "An API that validates IAM policies for autonomous agents."
}
DNS / Email Security Audit
POST https://x402-hono-api.inraby.workers.dev/api/v1/dns-email-security-audit — $0.0045
{
"domain": "example.com"
}
Wrangler Config Risk Audit
POST https://x402-hono-api.inraby.workers.dev/api/v1/wrangler-config-audit — $0.05
{
"wranglerToml": "name = \"demo-worker\"\ncompatibility_date = \"2024-01-01\"\n"
}
GitHub Actions Secret Exposure Scan
POST https://x402-hono-api.inraby.workers.dev/api/v1/github-actions-secret-exposure-scan — $0.05
{
"workflowYaml": "name: CI\non:\n pull_request_target:\n types: [opened]\n"
}
Cloudflare Worker Security Review
POST https://x402-hono-api.inraby.workers.dev/api/v1/cloudflare-worker-security-review — $0.10
{
"workerCode": "export default { fetch() { return new Response(\"ok\"); } }"
}
Terraform IAM Risk Scan
POST https://x402-hono-api.inraby.workers.dev/api/v1/terraform-iam-risk-scan — $0.10
{
"terraform": "resource \"aws_iam_policy\" \"demo\" { policy = jsonencode({ Statement = [] }) }",
"cloud": "aws"
}
Security Alert Triage
POST https://x402-hono-api.inraby.workers.dev/api/v1/security-alert-triage — $0.10
{
"subject": "Suspicious sign-in detected",
"from": "security-noreply@example.com",
"body": "A suspicious sign-in was detected from an unrecognized device.",
"source": "microsoft"
}
Email Vendor Risk Summary
POST https://x402-hono-api.inraby.workers.dev/api/v1/email-vendor-risk-summary — $0.10
{
"subject": "Updated SOC 2 report available",
"from": "trust@vendor.example.com",
"body": "Our SOC 2 Type II report and subprocessor list are attached for review."
}
Compliance Evidence Mapper
POST https://x402-hono-api.inraby.workers.dev/api/v1/compliance-evidence-mapper — $0.15
{
"subject": "SOC 2 evidence request",
"body": "Please provide the latest access review export and change ticket samples.",
"framework": "soc2"
}
Dependency / CVE Scan
POST https://x402-hono-api.inraby.workers.dev/api/v1/dependency-cve-scan — $0.05
{
"manifestText": "{\"dependencies\":{\"lodash\":\"4.17.15\",\"axios\":\"0.21.1\"}}"
}
SSL / TLS Certificate Audit
POST https://x402-hono-api.inraby.workers.dev/api/v1/ssl-certificate-audit — $0.05
{
"domain": "example.com"
}
GDPR / Privacy Posture Scan
POST https://x402-hono-api.inraby.workers.dev/api/v1/gdpr-privacy-scan — $0.08
{
"url": "https://example.com"
}
JWT Decode / Inspect
POST https://x402-hono-api.inraby.workers.dev/api/v1/jwt-decode — $0.02
{
"jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature"
}
JWT Inspect / Decode
POST https://x402-hono-api.inraby.workers.dev/api/v1/jwt-inspect — $0.02
{
"jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature"
}
CVE Lookup / Vulnerability Search
POST https://x402-hono-api.inraby.workers.dev/api/v1/cve-lookup — $0.01
{
"cveId": "CVE-2021-44228"
}
Sanctions List Lookup (Informational)
POST https://x402-hono-api.inraby.workers.dev/api/v1/sanctions-screen — $0.02
{
"query": "Tornado Cash"
}
Repo Security Bundle Scan
POST https://x402-hono-api.inraby.workers.dev/api/v1/repo-security-bundle — $0.04
{
"text": "api_token=not-a-real-secret",
"workflowYaml": "name: CI\non: pull_request_target:\npermissions: write-all\n",
"manifestText": "{\"dependencies\":{\"lodash\":\"4.17.15\"}}"
}
Agent Call Flow
- Fetch
GET /api/v1/catalogorGET /.well-known/x402-catalog. - POST to a paid endpoint without payment and receive
402. - Read payment requirements from the
payment-requiredresponse header. - Retry the same POST with
X-PAYMENTattached.
For MCP clients: connect to /mcp, call the free catalog tool, then call paid tools with x402 payment per invocation.