# PageAudit > Technical SEO auditor (title, meta description, canonical, Open Graph, Twitter > Card, headings, JSON-LD, robots, alt, links, hreflang, redirects, robots.txt/sitemap) > with the fix for every finding (`fixes[]` in the audit, ready patch at > `GET /api/audits/:id/patch`) and a persistent tab workspace. The main client is an > AI agent: everything the interface shows has an equivalent endpoint. No key to start. `POST /api/audit` with `{"url": "..."}` returns the full report in one call — 10 a day per IP, free. Past that, **402** with `accepts[]`: pay $0.02 in x402 and repeat the call (Turnstile is the human path, not yours). Without paying: sign up and CONFIRM the e-mail — the account gets **90 days of full access** (`POST /api/auth/start` → code by e-mail → `POST /api/auth/verify`). Human micro-tools at `/tools` (JSON at `GET /api/tools`). Score badge: `GET /badge/:slug.svg` (markdown at `GET /api/badge/:slug`). To keep state between calls, get a guest token at `POST /api/guest` and use the tabs. ## Discovery - [API index](https://pageaudit.online/api/): the whole surface, self-described, in JSON - [llms.txt](https://pageaudit.online/llms.txt): this file - [OpenAPI](https://pageaudit.online/openapi.json): machine spec (`operationId` = MCP tool name) - [MCP](https://pageaudit.online/mcp): MCP server over HTTP — plugs straight in, nothing to install - [Health](https://pageaudit.online/api/health): liveness and deployed commit - [Integrations and agents](https://pageaudit.online/developers): HTTP reference and MCP setup. - Read this index, then the relevant `/llms-full.txt?prefix=/api/...` reference, then call HTTP or MCP. The main UI is for people; do not scrape it. ## Main endpoints - `GET /okf/:arquivo` — OKF bundle (Open Knowledge Format v0.1): markdown with frontmatter so an agent reads the whole product without parsing HTML. (auth: none) - `GET /.well-known/:arquivo` — Machine discovery before the home page: `api-catalog` (RFC 9727, a linkset with the API and the MCP), `security.txt` (RFC 9116) and `mcp-registry-auth` (the official MCP registry key). (auth: none) - `GET /apis.json` — APIs.json (apisjson.org, 0.19): the index APIs.io harvests — the API, the MCP, OpenAPI, guide and OKF bundle in one file. Also at `/.well-known/apis.json`. (auth: none) - `POST /mcp` — MCP server over HTTP (Streamable HTTP, JSON-RPC 2.0) — plugs into the client with nothing to install. (auth: none) - `POST /api/audit` — Audits a URL and returns the full report in one call, without a token or a tab. (auth: none) - `GET /api/audits/:id` — Re-reads an audit already made, in full, without re-auditing the page. (auth: guest) - `GET /api/audits/:id/patch` — The consolidated patch of an audit: the block ready to paste, the files to create at the root and the templates for what only the owner can fill in — no model, only facts from the page itself. (auth: guest) - `GET /api/tools` — The micro-tools: one landing per check, all driven by the same engine as the audit. (auth: none) - `GET /api/tools/:slug` — Metadata and copy of one micro-tool. (auth: none) - `GET /tools` — HTML hub of the micro-tools, indexable. For JSON use `GET /api/tools`. (auth: none) - `GET /tools/:slug` — HTML landing of one check, indexable. An unknown slug returns a real 404. (auth: none) - `POST /api/audits/:id/share` — Publishes the audit under a non-enumerable slug. Calling again returns the same slug. (auth: guest) - `DELETE /api/audits/:id/share` — Revokes the share; the slug stops serving the report. (auth: guest) - `GET /api/shared/:slug` — Shared report as JSON, without credentials — the machine twin of `/r/:slug`. (auth: none) - `GET /r/:slug` — HTML page of the shared report, with `noindex`. (auth: none) - `GET /api/badge/:slug` — Metadata of the score badge, including the markdown ready for the README. (auth: none) - `GET /badge/:slug.svg` — SVG score badge, to paste in the README of the audited project. (auth: none) - `POST /api/guest` — Creates a guest `pa_…` — it is what gives access to the tab workspace without an account. (auth: none) - `GET /api/tabs` — The owner's whole workspace, with the active tab's result already rehydrated. (auth: guest) - `POST /api/tabs` — Opens a tab for the URL, or focuses the one that already exists for it. (auth: guest) - `GET /api/tabs/:id` — One tab with the full report of its last run. (auth: guest) - `PATCH /api/tabs/:id` — Renames the tab or puts it in focus. (auth: guest) - `DELETE /api/tabs/:id` — Closes the tab. Its audit history keeps existing. (auth: guest) - `POST /api/tabs/:id/run` — Re-audits the tab's URL and stores a new report. (auth: guest) - `GET /api/gate` — How many free audits remain for this IP and whether Turnstile is about to be required. (auth: none) - `GET /api/billing` — Tab allowance, prices, full x402 configuration and the state of the trial. (auth: none) - `GET /api/me` — The session's account, its last 50 audits and the state of the trial. (auth: session) - `POST /api/auth/start` — Sends the 6-digit code by e-mail to create the account or sign in to it. (auth: none) - `POST /api/auth/verify` — Exchanges the code for a session — and confirming the e-mail grants the trial on the spot. (auth: none) - `POST /api/auth/claim` — Moves the guest's audits and tabs to the signed-in account. (auth: session) - `POST /api/auth/logout` — Invalidates the current session. (auth: session) - `POST /api/contact` — Talks to support: a human solves Turnstile, an agent pays $0.10 in x402. (auth: none) - `POST /api/visit` — Ping from the interface that increments the day's visits. Agents need not call it. (auth: none) - `GET /api/metrics` — Metrics of the last 7 days and the most frequent findings across audits. With the operator token, includes payments. (auth: none) - `POST /api/credito` — Top up prepaid credit: pay once with x402 and get the token that debits on any API of the house. (auth: none) - `GET /api/credito` — Credit balance and statement — the latest movements, without returning the token. (auth: credito) ## What is kept - Each run writes one row in `audits` with the whole result: summary (including the redirect chain, the origin's robots.txt/sitemap, alt, links, word count, hreflang and legacy markup), issues, counts, the raw JSON-LD and every response header. - Not kept: The page's HTML — downloaded up to 2 MB, analysed and discarded. Re-reading requires a new run. - Not kept: The target's `Set-Cookie`, removed on purpose: it is a third party's credential and no check uses it. - Nothing disappears silently. Size cuts show up in `truncated[]` (`jsonld_size`, `jsonld_nodes_over_50`, `result_size`) and `summary.jsonLdBlocks` / `summary.jsonLdDropped` say how many blocks existed and how many were left out. ## Quota - Free: audit (`POST /api/audit`) — 10 per IP per day. - Free: audit — rate ceiling — 300 per IP per hour. - Free: workspace tabs — 20 per owner. - Paid: audit beyond the daily allowance — **$0.02** USDC via x402. - Paid: tab beyond the allowance — **$0.05** USDC via x402. - Paid: agent contact — **$0.10** USDC via x402. - Trial: sign up and CONFIRM the e-mail → **90 days** of full access, free. Loop: POST /api/auth/start {"email":"you@example.com"} → code arrives by e-mail → POST /api/auth/verify {"email":"...","code":"123456"} → 90 days without paywall Past the allowance → **402** with `accepts[]` (x402, USDC on Base). Pay and repeat the same call with `X-PAYMENT`. A human in a browser solves Turnstile and does not pay. Free alternative: sign up and confirm the e-mail (trial below). Numbers in force: https://pageaudit.online/api/billing What is left RIGHT NOW for your IP: https://pageaudit.online/api/gate ## MCP - **Endpoint:** `POST https://pageaudit.online/mcp` — Streamable HTTP, JSON-RPC 2.0. Nothing to install. - Check it with `GET https://pageaudit.online/mcp` (server card) or `tools/list`. - Every tool is a call on this same API — the MCP has no backend of its own. - Credentials (`X-Guest-Token`, `Authorization`, `X-PAYMENT`) go in the header and are forwarded. ## Skill - `.agents/skills/pageaudit/SKILL.md` — parity with this surface. - **Golden rule:** touched the UI/API → update `apidocs.js` + skill + this llms.txt in the same PR.