{"uid":"cap_R_inzk5vRWjltWeomlKkD","slug":"permissions-policy-parse-a8ca11d6","name":"Permissions Policy Parse","description":"Permissions Policy Parse: Permissions Policy Parse parses Permissions-Policy feature allowlists into normalized entries from bounded caller-supplied values without an external provider. Call Permissions Policy Parse before accepting, caching, redirecting, or retrying a caller-supplied web response. Returns normalized web evidence, the computed finding, and an explicit pass or advisory status for Permissions Policy Parse as versioned deterministic JSON. Price: $0.001 USDC via x402 on Base. First…","url":"https://api.delx.ai/api/v1/x402/permissions-policy-parse","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"header":{"type":"string","maxLength":8192,"description":"Header supplied to Permissions Policy Parse; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"count":2,"directives":{"camera":[],"geolocation":["self","https://maps.example"]}},"schema":"delx/util-permissions-policy-parse/v1","status":"pass","evidence":{"retained":false,"input_sha256":"a1872fcef7cbb2aabc0236a508d2693762a12cc6b5fbda254856f878202d8afc","external_calls":0},"operation":"web_reliability:permissions_policy_parse"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_8sJd8e2BscpplVCT_9ocG","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Parses a Permissions-Policy HTTP header value into normalized feature allowlist entries and returns a structured pass/advisory finding","exampleAgentPrompt":"Can you parse this Permissions-Policy header value and tell me if it's well-formed, what features are allowed, and whether it passes or has any advisories: 'camera=(), microphone=(self), geolocation=(self \"https://example.com\")'?","exampleUseCases":[{"title":"Pre-cache web response header audit","prompt":"Before I cache this web response, parse and normalize its Permissions-Policy header — 'camera=(), fullscreen=(self), payment=(\"https://pay.example.com\")' — and tell me if it passes or has any issues."},{"title":"Security scan of third-party API response","prompt":"I just got a response from a third-party API and want to check the Permissions-Policy header before I redirect users to it. Can you parse 'geolocation=(), usb=(self), microphone=()' and give me the normalized entries and a pass or advisory verdict?"},{"title":"Pre-acceptance check on incoming web header","prompt":"Before my agent accepts this caller-supplied web response, analyze the Permissions-Policy header value 'accelerometer=(), gyroscope=(self), camera=(self \"https://trusted.com\")' and return the normalized allowlists and finding."}],"resultDescription":"Returns versioned deterministic JSON containing: the normalized Permissions-Policy feature allowlist entries parsed from the input, the computed finding describing any structural issues or policy observations, and an explicit pass or advisory status verdict.","failureModes":["Header string exceeds 8192 character limit — request rejected","Malformed header value that cannot be parsed — advisory or error finding returned","Empty or missing header field — may return advisory status","Invalid feature directive syntax — flagged in finding output"],"whenToPreferThis":"Choose this endpoint when you need deterministic, bounded, in-memory parsing of a Permissions-Policy HTTP header value before accepting, caching, redirecting, or retrying a caller-supplied web response. It requires no external provider, retains no data, and returns versioned JSON suitable for audit logging or automated policy enforcement pipelines.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T07:14:59.168Z","isFirstParty":false}