{"uid":"cap_17xa1SBedemnoNQ7fxzhx","slug":"delx-commerce-open-redirect-audit-22c27bc7","name":"Delx Commerce — Open Redirect Audit","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/open-redirect-audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"target":{"type":"string","description":"Input field: target."},"allowed_hosts":{"type":"array","description":"Input field: allowed_hosts."}}},"responseSchema":{"type":"json","example":{"schema":"delx/util-open-redirect-audit/v1","allowed":false,"finding":"external_host_not_allowlisted","target_host":"evil.example","recommendation":"resolve relative paths and enforce exact host allowlist"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NrCzZC_Rsp-ClG-JjoNiP","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a URL target for open redirect vulnerabilities by checking whether its host is in an allowed hosts list","exampleAgentPrompt":"Can you audit the URL 'https://evil.example/callback?next=http://attacker.com' for open redirect risks, with allowed hosts set to ['myapp.com', 'api.myapp.com']?","exampleUseCases":[{"title":"Pre-redirect safety check in web app","prompt":"Before my app redirects the user to 'https://partner.example.com/landing', check if that's safe given my allowed hosts are 'myapp.com' and 'partner.example.com' — flag it if it looks like an open redirect."},{"title":"CI pipeline security gate for redirect URLs","prompt":"In my deployment pipeline, audit this redirect target 'https://evil.net/phish' against my allowlist ['mycompany.com', 'auth.mycompany.com'] and tell me whether it's safe to proceed."},{"title":"Agent-generated link validation before sending","prompt":"My agent is about to send a redirect URL 'https://accounts.google.com.phish.io/auth' to a user — check it against my approved hosts list ['accounts.google.com', 'mysite.com'] and tell me if it's flagged as an open redirect."}],"resultDescription":"Returns a JSON object with: 'allowed' (boolean indicating if the redirect is safe), 'finding' (a string code describing the security finding, e.g. 'external_host_not_allowlisted'), 'target_host' (the extracted hostname from the target URL), and 'recommendation' (a plain-English remediation suggestion).","failureModes":["Invalid or malformed target URL may return an error or unexpected finding","Empty allowed_hosts array may cause all redirects to be flagged as not allowed","Missing required 'target' field will likely return a validation error","Non-HTTP URLs (e.g. javascript:) may produce unexpected findings or errors","Payment failure (insufficient USDC balance) will block the request entirely"],"whenToPreferThis":"Use this endpoint when you need a lightweight, pay-per-call open redirect security check without standing up your own URL validation infrastructure. Ideal for AI agents that dynamically generate or handle redirect URLs and need a verifiable, auditable security gate before following or serving those redirects. Prefer this over manual host-matching logic when you want a standardized finding schema and recommendation, or when auditability of the security check is important.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:54:04.440Z","isFirstParty":false,"canonicalSlug":"delx-commerce-open-redirect-audit-22c27bc7"}