openapi: 3.2.0 info: title: MERCURY x402 storefront Cited Headers API version: '1' x-spec: mercury-storefront/1 description: Agent-payable resources over HTTP 402 (x402). LIVE — Base mainnet, real USDC, no token. Only currently-deliverable routes are listed (web-fetch is the live paid SKU; mints are gated off). Free discovery at /.well-known/x402, /x402/discovery, /catalog, and /manifest. servers: - url: https://network.mercury-hq.com tags: - name: cited-headers paths: /buy/headers: get: summary: MERCURY Cited Security-Headers Audit description: URL → a deterministic HTTP security-headers audit (HSTS, CSP, X-Frame, X-Content-Type, Referrer-Policy, Permissions-Policy + more) with a letter grade and concrete findings, wrapped in a signed, offline-verifiable provenance receipt. Keyless, no LLM, no signup. operationId: buy_cited_headers tags: - cited-headers responses: '200': description: Delivered after the x402 payment settles on Base mainnet. content: application/json: schema: type: object properties: ok: type: boolean description: true on success; false on an honest failure (never charged for a stub) url: type: string description: final URL after redirects status: type: integer description: upstream HTTP status of the audited response text: type: string description: canonical sorted-key JSON of `data` — the exact string the receipt signs over fetchedAt: type: string description: ISO-8601 fetch time (provenance metadata) data: type: object description: the deterministic security-headers verdict properties: grade: type: string enum: - A - B - C - D - E - F score: type: integer maxScore: type: integer percentage: type: integer passed: type: integer failed: type: integer checks: type: array items: type: object properties: header: type: string label: type: string present: type: boolean pass: type: boolean weight: type: integer value: type: - string - 'null' note: type: string findings: type: array items: type: object properties: header: type: string severity: type: string enum: - high - medium - low remediate: type: string serverBanner: type: - string - 'null' rubric: type: string error: type: string description: present only when ok:false required: - ok - url additionalProperties: true '402': description: Payment Required — retry with an x402-signed payment (e.g. x402-fetch). Terms are in the challenge body (x402 v1). parameters: - name: url in: query required: true schema: type: string maxLength: 2048 description: the page/endpoint to audit (http/https) description: the page/endpoint to audit (http/https) x-payment-info: protocols: - x402 scheme: exact price: $0.005 currency: USDC network: base networkCaip2: eip155:8453 testnet: false asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' payTo: '0xe10B9d44e72A29B9c19da02981FFCd875308e3C1' facilitator: https://api.cdp.coinbase.com/platform/v2/x402 x402Version: 1 x-x402: scheme: exact price: $0.005 currency: USDC network: base networkCaip2: eip155:8453 asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' payTo: '0xe10B9d44e72A29B9c19da02981FFCd875308e3C1' facilitator: https://api.cdp.coinbase.com/platform/v2/x402 testnet: false maxTimeoutSeconds: 60 x-payment-info: protocols: - x402 network: base currency: USDC payTo: '0xe10B9d44e72A29B9c19da02981FFCd875308e3C1' facilitator: https://api.cdp.coinbase.com/platform/v2/x402 testnet: false spec: mercury-storefront/1