{"uid":"cap_RflB2PVZ7D1S3YydZi05q","slug":"delx-commerce-url-redirect-target-check-6cfc5b3f","name":"Delx Commerce — URL Redirect Target Check","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/url-redirect-target-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"target":{"type":"string","maxLength":8192,"description":"Target supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."},"base_url":{"type":"string","maxLength":8192,"description":"Base URL supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."},"allowed_hosts":{"type":"array","items":{"type":"string","maxLength":8192},"maxItems":256,"description":"Allowed Hosts supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."},"allowed_schemes":{"type":"array","items":{"type":"string","maxLength":8192},"maxItems":256,"description":"Allowed Schemes supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"host":"example.com","scheme":"https","allowed":true,"resolved_url":"https://example.com/account"},"schema":"delx/util-url-redirect-target-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"6a1d59c98f30fc06ce9df9cfcba2c305b66be8e5eb56388a33bf40e364792c0c","external_calls":0},"operation":"web_reliability:url_redirect_target_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_LRSBL1_ULvIki6SucaboA","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates whether a URL redirect target is allowed by checking its host, scheme, and resolved URL against a configurable allowlist","exampleAgentPrompt":"Check whether the redirect target 'https://evil.com/steal' is allowed when the base URL is 'https://myapp.com' — only https scheme should be permitted and only example.com and myapp.com are allowed hosts.","exampleUseCases":[{"title":"Open redirect vulnerability protection","prompt":"Before processing this user-supplied redirect URL 'https://phishing.io/login', verify it's safe — only allow hosts under myapp.com and partner.com, and only https scheme is acceptable."},{"title":"OAuth callback URL validation","prompt":"I need to verify that the redirect_uri 'http://callback.example.com/auth' coming from an OAuth request is pointing to an allowed host — my allowed hosts are example.com and auth.example.com, allowed schemes are https only."},{"title":"Link shortener destination check","prompt":"After resolving a short link, the target is 'ftp://files.unknown.org/download' — check if that destination is permitted, since I only allow https and http schemes and the hosts docs.mysite.com and assets.mysite.com."}],"resultDescription":"Returns a JSON object indicating whether the redirect target is allowed, including the resolved URL, extracted host, scheme, and a pass/fail status. Also provides an evidence block with a SHA-256 hash of the input, confirmation that no data was retained, and a count of external calls made (zero for this in-memory check).","failureModes":["Invalid or malformed target URL — validation fails with an error","Base URL cannot be resolved or is malformed","Allowed hosts list exceeds 256 entries — request rejected","Target URL exceeds 8192 character limit","Network-level issues reaching the Delx Commerce endpoint","Payment not included or insufficient USDC — 402 response returned"],"whenToPreferThis":"Choose this endpoint when you need a lightweight, verifiable, pay-per-use URL redirect safety check with no retained data and cryptographic evidence of the inputs processed. Ideal for agents handling user-supplied redirect URLs, OAuth callbacks, or link shortener destinations where open redirect vulnerabilities are a concern and you need an auditable result without standing up your own validation infrastructure.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:53:40.821Z","isFirstParty":false,"canonicalSlug":"delx-commerce-url-redirect-target-check-6cfc5b3f"}