{"uid":"cap_FilhNbST1t6Ircz8dw1O1","slug":"delx-commerce-permissions-policy-parse-606aae0f","name":"Delx Commerce — Permissions Policy Parse","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/permissions-policy-parse?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"header":{"type":"string","maxLength":8192,"description":"Header supplied to Permissions Policy Parse; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"count":2,"directives":{"camera":[],"geolocation":["self","https://maps.example"]}},"schema":"delx/util-permissions-policy-parse/v1","status":"pass","evidence":{"retained":false,"input_sha256":"a1872fcef7cbb2aabc0236a508d2693762a12cc6b5fbda254856f878202d8afc","external_calls":0},"operation":"web_reliability:permissions_policy_parse"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_HDYgoxpjJuiq_pGMW_FdF","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Parses an HTTP Permissions-Policy header string and returns a structured breakdown of all directives and their allowed origins.","exampleAgentPrompt":"Can you parse this Permissions-Policy header for me and show me all the directives and which origins are allowed for each: 'camera=(), geolocation=(self \"https://maps.example\")'?","exampleUseCases":[{"title":"Audit site browser feature permissions","prompt":"I just scraped the Permissions-Policy header from our production site — can you parse it and tell me every directive and which origins it grants access to? Header is: 'camera=(), microphone=(), geolocation=(self \"https://maps.example\")'"},{"title":"Validate CSP header during CI pipeline","prompt":"Our CI pipeline grabbed this Permissions-Policy header from a staging response and I need to confirm it has exactly the directives we configured — can you parse 'camera=(self), payment=(), usb=()' and list out all the directives?"},{"title":"Debug unexpected browser permission behavior","prompt":"Users are reporting the camera feature isn't working on our site. Can you parse this Permissions-Policy header and tell me what the camera directive is set to: 'camera=(), geolocation=(self \"https://maps.example\"), microphone=(self)'?"}],"resultDescription":"Returns a JSON object with the total count of directives found, a map of each directive name to its list of allowed origins (empty array means blocked for all), plus evidence metadata including whether input was retained (always false), the SHA-256 hash of the input, and the number of external calls made (always 0).","failureModes":["Malformed or non-standard Permissions-Policy header syntax may produce incomplete directive extraction","Input exceeding 8192 characters will be rejected","Empty or null header string returns no directives","Headers using older Feature-Policy syntax may not parse correctly"],"whenToPreferThis":"Choose this endpoint when you need a fast, cheap, privacy-safe parse of a Permissions-Policy header string with verifiable no-retention guarantees and a structured JSON breakdown. Ideal for agents auditing web security posture, CI pipelines validating header configs, or any workflow that needs deterministic, pay-per-call parsing without API key setup.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:54:03.471Z","isFirstParty":false,"canonicalSlug":"delx-commerce-permissions-policy-parse-606aae0f"}