{"uid":"cap_JzTFrNVKiO4SON6ULr0Oo","slug":"delx-commerce-csp-directive-parse-f0e09835","name":"Delx Commerce — CSP Directive Parse","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/csp-directive-parse?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"header":{"type":"string","maxLength":8192,"description":"Header supplied to CSP Directive Parse; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"count":3,"directives":{"img-src":["'self'","https:"],"object-src":["'none'"],"default-src":["'self'"]}},"schema":"delx/util-csp-directive-parse/v1","status":"pass","evidence":{"retained":false,"input_sha256":"16664d9b05dde627e8d811fbffe5a404de8cef67d018c7c5f1017d3fed519e30","external_calls":0},"operation":"web_reliability:csp_directive_parse"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_vb5IKC-iZ_jTdZIRyBgxU","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Parses a Content-Security-Policy header string and returns a structured breakdown of all directives and their values","exampleAgentPrompt":"Parse this Content-Security-Policy header for me and tell me what directives it contains: \"default-src 'self'; img-src 'self' https:; object-src 'none'\"","exampleUseCases":[{"title":"Audit a site's CSP directives","prompt":"I just fetched the CSP header from example.com — it's \"default-src 'self'; script-src 'self' https://cdn.example.com; object-src 'none'\". Can you parse it and show me every directive and what sources it allows?"},{"title":"Check if object-src is locked down","prompt":"I need to verify that this CSP header has object-src set to 'none'. Here's the header value: \"default-src 'self'; img-src https:; object-src 'none'\". Can you break it down and confirm?"},{"title":"Structured CSP extraction for security report","prompt":"We're building a security audit report and I need a structured breakdown of this CSP header: \"script-src 'self' 'unsafe-inline'; style-src 'self'; img-src *; default-src 'none'\". Parse it into individual directives so I can list them in the report."}],"resultDescription":"Returns a JSON object with the total count of parsed directives, a map of each directive name to its list of allowed source values, the operation status ('pass'), and evidence metadata including whether input was retained (always false), the SHA-256 hash of the input, and the number of external calls made (always 0).","failureModes":["Malformed or empty header string may result in zero directives parsed","Header string exceeding 8192 characters will be rejected","Invalid JSON request body returns an error","Network or service unavailability returns a non-200 response","Payment failure via x402 protocol prevents the call from completing"],"whenToPreferThis":"Use this endpoint when you need a deterministic, privacy-preserving parse of a raw Content-Security-Policy header string into structured directives with no data retention. It is ideal for automated security audits, agent pipelines that inspect HTTP headers at scale, or any workflow where verifiable, pay-per-call pricing and in-memory-only processing are important. Prefer this over rolling your own CSP parser when auditability (input hash evidence) and guaranteed no-retention processing matter.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:53:49.059Z","isFirstParty":false,"canonicalSlug":"delx-commerce-csp-directive-parse-f0e09835"}