UAI Systems x402 API Catalog

Machine-consumable paid APIs for autonomous agents. No API key. Pay per call via x402.

Discovery

MCP Tools

Connect MCP clients (Cursor, Claude Desktop, Cloudflare Agents) to https://x402-hono-api.inraby.workers.dev/mcp.

Connect MCP clients to /mcp. Free catalog and secret-scan-preview (2048 chars). Paid tools require x402 USDC per call.

Legal & compliance

Not legal advice. Tools return informational security analysis only. See the machine-readable notice:

The sanctions-screen endpoint is informational only — it checks ~15 curated public entries, not the full OFAC SDN. It is not AML/KYC certified. A clear result is not a compliance guarantee.

x402 Payment

Product Catalog

IDEndpointPriceTagsDescription
policy-genie POST /api/v1/validate-policy $0.05 iam cloudflare policy Validate AWS IAM and Cloudflare Zero Trust policy JSON for risky wildcards, bypass rules, weak scoping, and embedded secrets.
cloudflare-zero-trust-audit POST /api/v1/cloudflare-zero-trust-audit $0.05 cloudflare zero-trust audit Analyze Cloudflare Zero Trust Access policy JSON for bypass rules, allow-everyone patterns, and weak identity constraints.
iam-risk-score POST /api/v1/iam-risk-score $0.03 iam aws risk Return a focused AWS IAM risk score and severity summary for a submitted IAM policy document.
secret-scan POST /api/v1/secret-scan $0.01 secret-scan secret scan secrets credentials api-key redaction security Secret scan for exposed API keys, tokens, passwords, and credentials in text — returns redacted output without exposing matched secret values. Ideal for agent pre-flight checks before sharing config or logs.
agentic-commerce-readiness POST /api/v1/agentic-commerce-readiness $0.10 x402 ap2 commerce Assess whether a company, API, or product description is a strong fit for x402/AP2-style agentic commerce.
dns-email-security-audit POST /api/v1/dns-email-security-audit $0.0045 dns dns email dns email security email email security spf dkim dmarc bimi mta-sts email-security domain security compliance audit DNS email security audit — SPF, DMARC, DKIM, BIMI, and MTA-STS check for domain spoofing and deliverability risk. Agent-friendly dns email security screen at micropayment pricing.
wrangler-config-audit POST /api/v1/wrangler-config-audit $0.05 cloudflare wrangler wrangler-config wrangler.toml workers worker cloudflare-workers devops config-audit audit security DevOps security audit for Cloudflare wrangler.toml — flags production-unsafe settings, plaintext secrets in vars, risky routes, and missing observability for Worker deployments.
github-actions-secret-exposure-scan POST /api/v1/github-actions-secret-exposure-scan $0.05 github-actions ci-cd secrets security Scan GitHub Actions workflow YAML for pull_request_target misuse, over-permissive tokens, secret leakage, unpinned actions, and unsafe fork checkout patterns.
cloudflare-worker-security-review POST /api/v1/cloudflare-worker-security-review $0.10 cloudflare workers security review Review Cloudflare Worker source and optional wrangler.toml for hardcoded secrets, unsafe CORS, missing admin auth, sensitive logging, and dynamic code execution.
terraform-iam-risk-scan POST /api/v1/terraform-iam-risk-scan $0.10 terraform iam aws security Scan Terraform for IAM wildcard policies, public S3/RDS exposure, open security groups, broad assume-role trust, and missing encryption hints.
security-alert-triage POST /api/v1/security-alert-triage $0.10 email security triage alerts Triage security alert emails for urgency, severity, likely cause, and evidence collection steps without storing message bodies.
email-vendor-risk-summary POST /api/v1/email-vendor-risk-summary $0.10 email vendor compliance risk Summarize vendor email risk for compliance claims, subprocessors, retention, DPA language, and breach notifications.
compliance-evidence-mapper POST /api/v1/compliance-evidence-mapper $0.15 email compliance soc2 evidence gdpr audit iso27001 pci Map SOC 2, ISO 27001, HIPAA, PCI, and GDPR compliance audit requests to evidence items, owners, systems, and follow-up questions. For agent-driven compliance and audit workflows.
dependency-cve-scan POST /api/v1/dependency-cve-scan $0.05 dependency cve supply-chain security npm audit Scan package.json or lockfile text for dependency CVE risk signals — outdated lodash/axios, deprecated packages, wildcard pins, risky postinstall scripts, and embedded secrets.
ssl-certificate-audit POST /api/v1/ssl-certificate-audit $0.05 ssl tls certificate security audit devops Audit domain SSL/TLS certificate expiry, HTTPS reachability, HSTS, and HTTP-to-HTTPS redirect posture using certificate transparency and live transport checks.
gdpr-privacy-scan POST /api/v1/gdpr-privacy-scan $0.08 gdpr privacy compliance cookie audit security Scan a website landing page for GDPR and CCPA privacy signals — privacy policy links, cookie consent language, and compliance keyword coverage for agent audits.
jwt-decode POST /api/v1/jwt-decode $0.02 jwt jwt-decode auth security decode token inspect JWT decode and inspect — decode header and payload without signature verification, flag expired tokens, insecure algorithms, and not-before issues for agent auth debugging.
jwt-inspect POST /api/v1/jwt-inspect $0.02 jwt jwt-decode jwt-inspect decode token auth security JWT decode and inspect for agent auth debugging — decode header and payload, flag expired tokens, insecure algorithms, and not-before issues. Search-friendly alias for jwt-decode.
cve-lookup POST /api/v1/cve-lookup $0.01 cve cve lookup vulnerability lookup vulnerability security osv advisory npm supply-chain CVE lookup and vulnerability search — resolve a CVE ID via OSV and return summary, severity, affected packages, and references for agent triage.
sanctions-screen POST /api/v1/sanctions-screen $0.02 sanctions sanctions check ofac wallet screening informational Informational sanctions list lookup for agent pre-flight checks — matches names or Ethereum wallet addresses against a small curated subset of publicly designated OFAC SDN entries (~15). Not AML/KYC certified. Not a substitute for official OFAC search or licensed screening.
repo-security-bundle POST /api/v1/repo-security-bundle $0.04 repo repository secret scan github actions dependency supply-chain bundle security ci Combined repo security scan — secret scan, GitHub Actions workflow exposure check, and dependency manifest CVE review in one agent call for CI pre-commit and supply-chain triage.

Example Inputs

Policy Genie

POST https://x402-hono-api.inraby.workers.dev/api/v1/validate-policy — $0.05

{
  "rawPolicyText": "{\"Version\":\"2012-10-17\",\"Statement\":[]}"
}

Cloudflare Zero Trust Audit

POST https://x402-hono-api.inraby.workers.dev/api/v1/cloudflare-zero-trust-audit — $0.05

{
  "policyText": "{\"decision\":\"allow\",\"include\":[{\"everyone\":{}}]}"
}

IAM Risk Score

POST https://x402-hono-api.inraby.workers.dev/api/v1/iam-risk-score — $0.03

{
  "policyText": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}"
}

Secret Scan / Credential Redaction

POST https://x402-hono-api.inraby.workers.dev/api/v1/secret-scan — $0.01

{
  "text": "api_token=not-a-real-secret-value"
}

Agentic Commerce Readiness

POST https://x402-hono-api.inraby.workers.dev/api/v1/agentic-commerce-readiness — $0.10

{
  "productDescription": "An API that validates IAM policies for autonomous agents."
}

DNS / Email Security Audit

POST https://x402-hono-api.inraby.workers.dev/api/v1/dns-email-security-audit — $0.0045

{
  "domain": "example.com"
}

Wrangler Config Risk Audit

POST https://x402-hono-api.inraby.workers.dev/api/v1/wrangler-config-audit — $0.05

{
  "wranglerToml": "name = \"demo-worker\"\ncompatibility_date = \"2024-01-01\"\n"
}

GitHub Actions Secret Exposure Scan

POST https://x402-hono-api.inraby.workers.dev/api/v1/github-actions-secret-exposure-scan — $0.05

{
  "workflowYaml": "name: CI\non:\n  pull_request_target:\n    types: [opened]\n"
}

Cloudflare Worker Security Review

POST https://x402-hono-api.inraby.workers.dev/api/v1/cloudflare-worker-security-review — $0.10

{
  "workerCode": "export default { fetch() { return new Response(\"ok\"); } }"
}

Terraform IAM Risk Scan

POST https://x402-hono-api.inraby.workers.dev/api/v1/terraform-iam-risk-scan — $0.10

{
  "terraform": "resource \"aws_iam_policy\" \"demo\" { policy = jsonencode({ Statement = [] }) }",
  "cloud": "aws"
}

Security Alert Triage

POST https://x402-hono-api.inraby.workers.dev/api/v1/security-alert-triage — $0.10

{
  "subject": "Suspicious sign-in detected",
  "from": "security-noreply@example.com",
  "body": "A suspicious sign-in was detected from an unrecognized device.",
  "source": "microsoft"
}

Email Vendor Risk Summary

POST https://x402-hono-api.inraby.workers.dev/api/v1/email-vendor-risk-summary — $0.10

{
  "subject": "Updated SOC 2 report available",
  "from": "trust@vendor.example.com",
  "body": "Our SOC 2 Type II report and subprocessor list are attached for review."
}

Compliance Evidence Mapper

POST https://x402-hono-api.inraby.workers.dev/api/v1/compliance-evidence-mapper — $0.15

{
  "subject": "SOC 2 evidence request",
  "body": "Please provide the latest access review export and change ticket samples.",
  "framework": "soc2"
}

Dependency / CVE Scan

POST https://x402-hono-api.inraby.workers.dev/api/v1/dependency-cve-scan — $0.05

{
  "manifestText": "{\"dependencies\":{\"lodash\":\"4.17.15\",\"axios\":\"0.21.1\"}}"
}

SSL / TLS Certificate Audit

POST https://x402-hono-api.inraby.workers.dev/api/v1/ssl-certificate-audit — $0.05

{
  "domain": "example.com"
}

GDPR / Privacy Posture Scan

POST https://x402-hono-api.inraby.workers.dev/api/v1/gdpr-privacy-scan — $0.08

{
  "url": "https://example.com"
}

JWT Decode / Inspect

POST https://x402-hono-api.inraby.workers.dev/api/v1/jwt-decode — $0.02

{
  "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature"
}

JWT Inspect / Decode

POST https://x402-hono-api.inraby.workers.dev/api/v1/jwt-inspect — $0.02

{
  "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature"
}

CVE Lookup / Vulnerability Search

POST https://x402-hono-api.inraby.workers.dev/api/v1/cve-lookup — $0.01

{
  "cveId": "CVE-2021-44228"
}

Sanctions List Lookup (Informational)

POST https://x402-hono-api.inraby.workers.dev/api/v1/sanctions-screen — $0.02

{
  "query": "Tornado Cash"
}

Repo Security Bundle Scan

POST https://x402-hono-api.inraby.workers.dev/api/v1/repo-security-bundle — $0.04

{
  "text": "api_token=not-a-real-secret",
  "workflowYaml": "name: CI\non: pull_request_target:\npermissions: write-all\n",
  "manifestText": "{\"dependencies\":{\"lodash\":\"4.17.15\"}}"
}

Agent Call Flow

  1. Fetch GET /api/v1/catalog or GET /.well-known/x402-catalog.
  2. POST to a paid endpoint without payment and receive 402.
  3. Read payment requirements from the payment-required response header.
  4. Retry the same POST with X-PAYMENT attached.

For MCP clients: connect to /mcp, call the free catalog tool, then call paid tools with x402 payment per invocation.