{"uid":"cap_-sqALRf4p5t-Bud6lueEh","slug":"dns-tlsa-record-shape-check-ecb5f20b","name":"DNS TLSA Record Shape Check","description":"DNS TLSA Record Shape Check: DNS TLSA Record Shape Check checks TLSA usage, selector, matching type, and certificate data shape from bounded caller-supplied values without an external provider. Call DNS TLSA Record Shape Check before accepting, caching, redirecting, or retrying a caller-supplied web response. Returns normalized web evidence, the computed finding, and an explicit pass or advisory status for DNS TLSA Record Shape Check as versioned deterministic JSON. Price: $0.001 USDC via x402…","url":"https://api.delx.ai/api/v1/x402/dns-tlsa-record-shape-check","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"record":{"type":"string","maxLength":8192,"description":"Record supplied to DNS TLSA Record Shape Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"fields":["3","1","1","AABBCCDDEEFF00112233445566778899"],"shape_valid":true},"schema":"delx/util-dns-tlsa-record-shape-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"196aa204b00dfac705caab97f837b021d005fd5bf93f628bbea265486ff16a9c","external_calls":0},"operation":"web_reliability:dns_tlsa_record_shape_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_tROfnXRUWVFHZ7iIFnfxX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates the structural shape of a DNS TLSA record by checking usage, selector, matching type, and certificate data fields, returning a deterministic pass/advisory result.","exampleAgentPrompt":"Can you check whether this TLSA record has a valid shape — usage, selector, matching type, and certificate data all look right? Here's the record: '3 1 1 abc123def456...'","exampleUseCases":[{"title":"Preflight TLSA before caching","prompt":"Before I cache this TLSA record from the response, can you validate its shape — usage, selector, matching type, and cert data — to make sure it's well-formed? The record is '2 0 1 aabbccdd1122...'"},{"title":"DANE implementation sanity check","prompt":"I'm building a DANE validator and want to confirm this TLSA record passes a shape check: '3 1 2 deadbeef9900aa...' — can you tell me if the usage, selector, and matching type fields are structurally valid?"},{"title":"Redirect safety check on web response","prompt":"I just got a web response I need to redirect through, and it includes a TLSA record '1 1 1 f00ba4cafe...' — can you run a shape check on it before I proceed, so I know the structure is correct?"}],"resultDescription":"Returns a versioned deterministic JSON object containing normalized web evidence derived from the input, a computed finding describing what was evaluated, and an explicit pass or advisory status indicating whether the TLSA record's structure (usage, selector, matching type, and certificate data) is valid.","failureModes":["Record string exceeds 8192 character limit — rejected with validation error","Malformed or unparseable record input — returns advisory status with finding detail","Missing required fields in TLSA record — advisory status returned","Empty record string — likely returns error or advisory with missing-data finding","Payment not completed via x402 — request not processed"],"whenToPreferThis":"Choose this endpoint when you need a fast, deterministic, no-external-dependency structural check on a TLSA record before accepting, caching, redirecting, or retrying a caller-supplied web response. It does not perform live DNS lookups or cryptographic verification — it validates the shape and field values only, making it ideal as a lightweight preflight step in DANE-aware agents or security pipelines.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T19:02:56.118Z","isFirstParty":false}