| fetchx402 Resolve public DNS records (A, AAAA, MX, TXT, CNAME, NS, SOA) for a domain. Use when you need live DNS data and must not guess from memory or training data. | - | $0.005 | - | listed | call recipe → |
| fetchx402 Read allowlisted HTTPS response headers for a hostname (HSTS, CSP, server, CORS). Use when you need live origin headers and must not guess. HEAD of https://{domain}/ on :443; GET if HEAD is 405/501. Redirects are not followed. | - | $0.005 | - | listed | call recipe → |
| fetchx402 Trace HTTPS redirects for a hostname. Use when you need live hop facts and must not guess. HEAD of https://{domain}/ on :443 (GET if 405/501); follow Location up to 5 hops. HTTPS :443 only after ConnectGuard. Bodies are omitted. | - | $0.005 | - | listed | call recipe → |
| fetchx402 Inspect the leaf TLS certificate for a public hostname (validity, issuer, SANs, fingerprint, expiry). Use when you need live cert facts and must not guess. Expired or hostname-mismatched certs still return JSON flags. | - | $0.005 | - | listed | call recipe → |
| fetchx402 Look up domain registration facts via RDAP (registrar, status, dates, nameservers, DNSSEC). Use when you need live registry data and must not guess. Unregistered names return not_found. | - | $0.005 | - | listed | call recipe → |
| fetchx402 DNS, leaf TLS, and RDAP/WHOIS for one hostname in a single settle. Use when you need live host facts together and must not guess. Child errors stay in-field; we do not invent data. | - | $0.015 | - | listed | call recipe → |
| fetchx402 One-shot reachability: DNS, leaf TLS, and origin headers for one hostname in a single settle. Use when you need live up/degraded/down and must not guess. Child errors stay in-field; we do not invent data. | - | $0.015 | - | listed | call recipe → |