generated: '2026-09-07' method: searched source: https://pageaudit.online/api/ note: >- Captured from the self-describing API index (GET /api/), llms.txt and the OpenAPI, all fetched 2026-09-07. PageAudit is deliberately agent-first: every UI screen has an equivalent endpoint, every resource carries its own API URL, and the MCP server is a thin pass-through over the same REST surface. authentication: style: bearer token (guest pa_… / session sess_… / prepaid credit cred_…), plus anonymous public endpoints reference: authentication/pageaudit-authentication.yml error_envelope: shape: '{ error, detail? } with the HTTP status code' format: custom JSON (not RFC 9457 problem+json) reference: errors/pageaudit-problem-types.yml cors: policy: 'Access-Control-Allow-Origin: * on every /api/* response — callable straight from the browser' exposed_headers: [X-PAYMENT-RESPONSE, PAYMENT-RESPONSE, X-PAYMENT-REQUIRED, PAYMENT-REQUIRED] hypermedia: style: >- A resource returns `api` (or `_links`) with absolute URLs of related resources, so a client navigates without building paths by hand. versioning: scheme: continuous deployment; the OpenAPI info.version and GET /api/health expose the deployed build hash current: f5ac3ca0 (observed 2026-09-07) pagination: style: none documented — collections (tabs, audits, credit statement) return bounded windows (e.g. last 50 audits) request_tracing: style: none documented — no request-id header in the spec or docs rate_limit_signaling: style: >- No X-RateLimit-* headers. The runtime signal is GET /api/gate (free_remaining for the caller's IP) and an HTTP 402 with `accepts[]` when the allowance is exhausted; HTTP 429 past the hourly ceiling. See rate-limits/pageaudit-rate-limits.yml. payment_signaling: style: >- x402 — HTTP 402 with `accepts[]` (USDC on Base); repeat the same call with `X-PAYMENT`. Machine-readable parameters at GET /api/billing. idempotency: coverage: partial scope: - post_api_audits_by_id_share - create_tab mechanism: >- No Idempotency-Key header. Two mutating operations are documented as replay-safe by design: POST /api/audits/{id}/share ("Calling again returns the same slug") and POST /api/tabs ("Opens a tab for the URL, or focuses the one that already exists for it"). Other writes (POST /api/audit, POST /api/tabs/{id}/run, POST /api/credito) create a new audit/charge on each call and have no documented replay protection. reversibility: status: documented operations: - action: share an audit report (post_api_audits_by_id_share) reversal: delete_api_audits_by_id_share window: >- not stated — DELETE /api/audits/{id}/share revokes the share and "the slug stops serving the report" docs: https://pageaudit.online/llms.txt - action: open a workspace tab (create_tab) reversal: delete_api_tabs_by_id window: 'not stated — closing a tab keeps its audit history ("Its audit history keeps existing")' docs: https://pageaudit.online/llms.txt note: >- Audits themselves are immutable records (re-read via GET /api/audits/{id}); paid x402 calls have no documented refund path. Reversal windows are not stated anywhere, so this grades documented, not verified.