{"uid":"cap_4xFZ86EBDR-s6vPq_F1A1","slug":"delx-cookie-policy-audit-e7ea466d","name":"Delx Cookie Policy Audit","description":"Audit a Set-Cookie value for Secure, HttpOnly, and SameSite controls. Use it as a bounded preflight or analysis step inside an enterprise agent workflow before data, policy, integration, security, or commercial decisions reach production. Returns deterministic machine-readable JSON for $0.003 USDC via x402 on Base. Execution is first-party, local-only, stateless, memory-only, and has no paid upstream or input retention. Results are advisory; the caller remains responsible for authorization and…","url":"https://api.delx.ai/api/v1/x402/cookie-policy-audit","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"cookie":{"type":"string","description":"Input field: cookie."}}},"responseSchema":{"type":"json","example":{"risk":"low","schema":"delx/util-cookie-policy-audit/v1","secure":true,"findings":[],"http_only":true,"same_site":"lax"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_h9RAzKdjMUs-GUkJ3tNN3","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a Set-Cookie header value for the presence and correctness of Secure, HttpOnly, and SameSite security controls, returning deterministic machine-readable JSON results.","exampleAgentPrompt":"Can you audit this Set-Cookie value for me and tell me if Secure, HttpOnly, and SameSite are properly configured: 'session_id=abc123; Path=/; HttpOnly; SameSite=Lax'?","exampleUseCases":[{"title":"Pre-deployment cookie security check","prompt":"Before we push this auth service to production, audit this cookie header to confirm it has all required security flags set: 'auth_token=xyz789; Path=/; Secure; HttpOnly; SameSite=Strict'"},{"title":"Security policy compliance review","prompt":"Our compliance team needs to verify that all session cookies meet our security policy — can you check this Set-Cookie value and tell me which of Secure, HttpOnly, and SameSite are missing: 'user_session=token456; Path=/'?"},{"title":"Agent workflow cookie preflight","prompt":"As part of our integration pipeline, run a cookie policy audit on this Set-Cookie string before we allow it through: 'tracking_id=t890; Domain=example.com; SameSite=None'"}],"resultDescription":"Returns a deterministic JSON object indicating whether each of the three key security controls (Secure flag, HttpOnly flag, SameSite directive) are present and correctly configured in the provided Set-Cookie value, along with any advisory findings about missing or misconfigured attributes.","failureModes":["Malformed or empty cookie string input may yield incomplete audit results","Missing required 'cookie' field returns a validation error","SameSite=None without Secure flag may be flagged as a misconfiguration","Extremely long or non-standard cookie strings may not parse as expected","Network or payment authorization failure returns a 402 or connectivity error"],"whenToPreferThis":"Choose this endpoint when you need a stateless, deterministic, machine-readable audit of a single Set-Cookie header value for Secure, HttpOnly, and SameSite controls — especially as a bounded preflight step inside an automated agent workflow before security-sensitive decisions reach production. Prefer it over manual inspection or full security scanners when you need lightweight, low-latency, programmatic cookie policy validation without retaining input data.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T19:01:49.161Z","isFirstParty":false}