{"uid":"cap_O8yrglrpWanjk6LM_Vzsq","slug":"redirect-callback-validator-4b7ed8a5","name":"Redirect Callback Validator","description":"Validate HTTPS callback and redirect destinations against an explicit host allowlist","url":"https://phion.systems/v1/paid/trust/redirect-callback-validator","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema"},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_dFy2_oyPTibmwAHgirxRw","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates HTTPS callback and redirect destination URLs against an explicit host allowlist to prevent open redirect and SSRF attacks","exampleAgentPrompt":"Before following this redirect to https://payments.example.com/callback, check it against my approved host allowlist — [payments.example.com, api.myapp.io] — and confirm it's safe to proceed.","exampleUseCases":[{"title":"OAuth callback safety check","prompt":"I'm about to receive an OAuth callback to https://auth.myservice.com/oauth/callback — can you verify that host is on my allowlist [auth.myservice.com, login.myservice.com] before I process the token?"},{"title":"Agent webhook destination guard","prompt":"My agent is about to send results to a webhook at https://hooks.partner.io/receive — validate that against my permitted hosts [hooks.partner.io, api.partner.io] so I know it's not being redirected somewhere unauthorized."},{"title":"Payment redirect validation","prompt":"Before redirecting the user after checkout to https://shop.acme.com/thankyou, check that destination against my approved redirect hosts [shop.acme.com, www.acme.com] and tell me if it's safe."}],"resultDescription":"A validation decision indicating whether the callback or redirect destination URL matches an entry on the provided host allowlist, including which host was checked, whether it was approved or rejected, and any policy violations detected.","failureModes":["URL not on allowlist — returns rejection with the offending host","Malformed or non-HTTPS URL — returns validation error","Empty or missing allowlist — returns policy configuration error","Subdomain mismatch when exact-host matching is enforced — returns rejection","Network timeout or service unavailability — returns 5xx error"],"whenToPreferThis":"Use this endpoint when an agent or automated workflow must follow a redirect or invoke a callback URL and needs a signed, auditable decision that the destination is authorized — especially in OAuth flows, payment callbacks, webhook dispatching, or any scenario where an attacker could manipulate the redirect target to cause open redirect or SSRF attacks. Prefer this over ad-hoc string matching when you need an explicit allowlist enforcement record.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:36:25.148Z","isFirstParty":false}