{"uid":"cap_pKrbeEaIzZt3tlO7VFb-x","slug":"delx-commerce-cors-policy-audit-6d0bd4e4","name":"Delx Commerce CORS Policy Audit","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/cors-policy-audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"headers":{"type":"object","additionalProperties":{"type":"string"}}}},"responseSchema":{"type":"json","example":{"risk":"low","schema":"delx/cors-policy-audit/v1","findings":[],"credentials":false,"allow_origin":"*"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_kY54N-EzcERTvdvt0jvq0","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits HTTP response headers for CORS policy risks, reporting findings like wildcard origins, credential exposure, and misconfiguration risk level","exampleAgentPrompt":"Can you audit these HTTP response headers for CORS security issues and tell me the risk level: Access-Control-Allow-Origin: *, Access-Control-Allow-Credentials: true?","exampleUseCases":[{"title":"API security pre-deployment check","prompt":"Before I deploy my new API, can you check these response headers for CORS misconfigurations and tell me if there are any security risks I should fix: Access-Control-Allow-Origin: https://myapp.com, Access-Control-Allow-Credentials: true?"},{"title":"Wildcard origin risk detection","prompt":"My backend is returning 'Access-Control-Allow-Origin: *' — can you audit that header configuration and tell me whether it's a low, medium, or high security risk?"},{"title":"Third-party API header review","prompt":"I'm integrating a third-party API and got these headers back — can you run a CORS policy audit on them and tell me if there are any credential exposure issues: Access-Control-Allow-Origin: *, Access-Control-Allow-Methods: GET, POST?"}],"resultDescription":"Returns a JSON object with a risk level (e.g. 'low', 'medium', 'high'), a schema identifier ('delx/cors-policy-audit/v1'), an array of findings describing specific CORS issues detected, a boolean indicating whether credentials are exposed, and the parsed allow_origin value from the submitted headers.","failureModes":["Empty or missing headers object returns no meaningful findings","Malformed header values may result in parse errors or incomplete analysis","Non-CORS headers submitted yield empty findings with low risk by default","Payment failure via x402 protocol blocks request processing"],"whenToPreferThis":"Choose this endpoint when you need a fast, pay-per-call, no-signup CORS security audit with structured, machine-readable output including risk classification and credential exposure flags. Prefer it over manual header inspection or generic security scanners when building automated CI/CD pipelines, agent-driven security workflows, or when you need verifiable, priced-per-result delivery via USDC on Base or Solana.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:34:58.906Z","isFirstParty":false,"canonicalSlug":"delx-commerce-cors-policy-audit-6d0bd4e4"}