{"uid":"cap_cN_-L1Gflf81vt5Jwoosj","slug":"delx-commerce-cors-preflight-check-d8c0af8f","name":"Delx Commerce CORS Preflight Check","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/cors-preflight-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"method":{"type":"string","maxLength":8192,"description":"Method supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."},"allowed_headers":{"type":"array","items":{"type":"string","maxLength":8192},"maxItems":256,"description":"Allowed Headers supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."},"allowed_methods":{"type":"array","items":{"type":"string","maxLength":8192},"maxItems":256,"description":"Allowed Methods supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."},"request_headers":{"type":"array","items":{"type":"string","maxLength":8192},"maxItems":256,"description":"Request Headers supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"allowed":true,"method_allowed":true,"missing_headers":[]},"schema":"delx/util-cors-preflight-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"571002a70ff839ab886cb4c05bd47a50845ad003d3ec5eba7e599a0b18fee704","external_calls":0},"operation":"web_reliability:cors_preflight_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_mojHEZt3j00zplyZ3UvQf","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates whether a CORS preflight request is allowed given a method, allowed headers, allowed methods, and request headers, returning a pass/fail result with detailed missing-header diagnostics.","exampleAgentPrompt":"Can you check whether a CORS preflight for a POST request with headers Content-Type and Authorization would be allowed, given allowed methods GET and POST and allowed headers Content-Type and Authorization?","exampleUseCases":[{"title":"Debugging a blocked cross-origin API call","prompt":"My browser is getting CORS errors when calling an API with a PUT request and the X-Custom-Header header. The server allows GET and POST methods and only Content-Type as an allowed header. Can you run a CORS preflight check and tell me exactly which headers or methods are missing?"},{"title":"Pre-flight validation before deploying a web app","prompt":"Before I launch my app, can you verify that a CORS preflight for a DELETE request with headers Accept and Content-Type will pass, given that the server's allowed methods are GET, POST, DELETE and allowed headers are Content-Type and Accept?"},{"title":"Automated CORS policy audit in CI pipeline","prompt":"As part of our CI checks, validate that a CORS preflight request using the PATCH method with headers Authorization, Content-Type, and X-Request-ID is allowed, where allowed methods are GET, POST, PATCH and allowed headers are Authorization and Content-Type — and list any missing headers."}],"resultDescription":"Returns a JSON object indicating whether the preflight is allowed overall (allowed: bool), whether the specific HTTP method is permitted (method_allowed: bool), and a list of any missing headers (missing_headers: array). Also includes operation metadata: schema version, status (pass/fail), an SHA-256 hash of the input for verifiability, a flag confirming no data was retained, and external call count (0).","failureModes":["Invalid or missing method field may cause unexpected validation results","Malformed header names in arrays may result in false negatives for missing_headers","Exceeding 256 items in allowed_headers, allowed_methods, or request_headers arrays will be rejected","Payment failure (402) if USDC payment via x402 is not properly attached","Network timeout if the Base or Solana payment settlement is delayed"],"whenToPreferThis":"Choose this endpoint when you need a lightweight, pay-per-call, cryptographically verifiable CORS preflight validation without any signup or session management. It is ideal for agents, CI pipelines, or automated tools that need to audit CORS policies programmatically and want tamper-evident evidence (input hash) that the check was performed without data retention. Prefer it over building custom CORS logic when you need a neutral third-party validation with an auditable result.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:36:13.898Z","isFirstParty":false,"canonicalSlug":"delx-commerce-cors-preflight-check-d8c0af8f"}