{"uid":"cap_Yyo1ZZLgS6rqVRFYq1sh_","slug":"delx-cors-policy-audit-9f0b4187","name":"Delx CORS Policy Audit","description":"Audit CORS response headers for wildcard, credential, and cache-variance risks. Use it before an autonomous workflow acts on untrusted input, changes an API, retries a request, or evaluates production reliability. Returns bounded machine-readable JSON for $0.002 USDC via x402 on Base. Execution is deterministic, first-party, local-only, stateless, and does not call an upstream provider; structured validation failures are not billed.","url":"https://api.delx.ai/api/v1/x402/cors-policy-audit","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"headers":{"type":"object","additionalProperties":{"type":"string"}}}},"responseSchema":{"type":"json","example":{"risk":"low","schema":"delx/cors-policy-audit/v1","findings":[],"credentials":false,"allow_origin":"*"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_d9xW9aJ3FMg-3mRJvsHzX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits CORS response headers for wildcard origins, credential exposure, and cache-variance risks, returning machine-readable JSON findings.","exampleAgentPrompt":"Can you audit these CORS headers for wildcard origin, credential exposure, and cache-variance risks: {'Access-Control-Allow-Origin': '*', 'Access-Control-Allow-Credentials': 'true', 'Vary': 'Origin'}?","exampleUseCases":[{"title":"Pre-deploy API security check","prompt":"Before I push this API change live, audit these CORS response headers for any wildcard or credential risks: {'Access-Control-Allow-Origin': '*', 'Access-Control-Allow-Credentials': 'true', 'Vary': 'Accept-Encoding'}."},{"title":"Agentic workflow preflight gate","prompt":"My agent is about to act on a response from an untrusted API endpoint — can you check these CORS headers first and tell me if there are any credential or cache-variance issues: {'Access-Control-Allow-Origin': 'https://example.com', 'Access-Control-Allow-Credentials': 'true'}?"},{"title":"Production reliability CORS review","prompt":"We're evaluating whether our production API is reliably configured — please audit these CORS headers for wildcard, credential, and Vary cache risks: {'Access-Control-Allow-Origin': '*', 'Vary': 'Origin', 'Access-Control-Expose-Headers': 'Authorization'}."}],"resultDescription":"Returns a bounded machine-readable JSON object describing identified CORS risks, including findings for wildcard origin exposure, credential leakage (Access-Control-Allow-Credentials with broad origins), and cache-variance misconfigurations (Vary header issues). Structured validation failures are returned without charge.","failureModes":["Missing or empty headers object returns a structured validation failure (not billed)","Malformed header values may produce partial findings with flagged parse errors","Non-CORS headers passed in may be ignored or noted as irrelevant","Network or payment authorization failures prevent execution"],"whenToPreferThis":"Use this endpoint when an autonomous agent or CI pipeline needs a cheap, deterministic, stateless CORS security check before acting on an API, deploying a change, or approving a request for production. Prefer it over manual review when you need machine-readable JSON output at scale with no upstream dependencies. At $0.002 USDC it is cost-effective as a preflight gate in agentic workflows.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T19:02:19.523Z","isFirstParty":false}