Urgent.News

What's breaking now, across thousands of outlets.

Tech

Two new x402 APIs for AI agents: HTTP/2 SETTINGS frame probe + brand-impersonation risk synthesis (2026-10-07, cycle 106)

The catalog just grew by 2 more paid endpoints. This is cycle 106 of the URL metadata service, and the two new routes are aimed at gaps that the existing 141 endpoints don't cover well. /api/http2-settings-probe — active HTTP/2 SETTINGS frame probe Most of the catalog's HTTP/2-adjacent endpoints are passive: /api/http3-alt-svc reads the Alt-Svc: h3 header; /api/performance times ttfb ;…

Two new endpoints have been added to the URL metadata service catalog in cycle 106. The /api/http2-settings-probe endpoint performs an active HTTP/2 SETTINGS frame probe to gather information about a server's HTTP/2 capabilities. This includes opening a fresh TCP connection, performing a TLS 1.3 handshake, verifying the ALPN is h2, sending a client SETTINGS frame, and reading the server's SETTINGS frame.

The endpoint then parses the standard settings and sends a SETTINGS ACK. It also optionally pings the server to measure RTT. The endpoint tested against cloudflare.com and reported a 95/A grade for the major CDN, including details about the TLS version, cipher, preface, and server settings.

The /api/brand-impersonation-risk endpoint synthesizes an 8-signal brand impersonation risk score. It aggregates signals such as domain age, BIMI record, security.txt presence, llms.txt presence, and https_redirect to determine if a domain could be used to impersonate a brand. The endpoint returns a trust score between 0 and 100, along with an impersonation_risk verdict. For example, when tested against stripe.com, the endpoint reported a trust score of 75 and a low impersonation risk.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Dev News Digest: 7 Oct 2026, 11:00

A quick roundup of developer news since the last digest. Security Counterfeit TLS certificates issued for Google and other big services : Attackers reportedly obtained fraudulent certificates for…

More from Wednesday 7 October →