{"uid":"cap_uh93S0lQLs_v56V_9vvvA","slug":"delx-commerce-frame-ancestors-check-9b78d26d","name":"Delx Commerce — Frame Ancestors Check","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/frame-ancestors-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"header":{"type":"string","maxLength":8192,"description":"Header supplied to Frame Ancestors Check; used only for this bounded calculation and processed in memory without retention."},"required_source":{"type":"string","maxLength":8192,"description":"Required Source supplied to Frame Ancestors Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"source":"'none'","present":true,"sources":["'none'"],"directive":"frame-ancestors"},"schema":"delx/util-frame-ancestors-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"87d66a2da893969f3b55da12bea54f3990c499fe4d58ef57b180b13ceeb775b2","external_calls":0},"operation":"web_reliability:frame_ancestors_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_HKyNqgN86cGue-nDKSpUs","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Parses and validates the Content-Security-Policy `frame-ancestors` directive from a given HTTP header string, checking whether a required source is present.","exampleAgentPrompt":"Check whether this Content-Security-Policy header includes 'self' as a frame-ancestors source: \"default-src 'self'; frame-ancestors 'self' https://partner.example.com\"","exampleUseCases":[{"title":"Clickjacking protection audit","prompt":"I have this HTTP response header from our app: \"Content-Security-Policy: default-src 'self'; frame-ancestors 'none'\". Can you confirm that frame-ancestors is correctly set to 'none' so we're protected against clickjacking?"},{"title":"Verify partner embed permission","prompt":"We're rolling out an iframe integration with https://dashboard.partner.com. Check this CSP header to see if that origin is listed as an allowed frame ancestor: \"Content-Security-Policy: frame-ancestors 'self' https://dashboard.partner.com\""},{"title":"Catch missing frame-ancestors in CI","prompt":"Our CI pipeline just captured this CSP header from staging: \"Content-Security-Policy: default-src 'self'; script-src 'nonce-abc123'\". Is the frame-ancestors directive present at all, and does it include 'self'?"}],"resultDescription":"Returns a JSON object with the parsed `frame-ancestors` directive (source list, whether it's present), a pass/fail status indicating if the required source was found, and an evidence block with the SHA-256 hash of the input and confirmation that no data was retained or sent externally.","failureModes":["Malformed or missing CSP header string returns a parse error or empty sources list","Required source not found in directive yields a 'fail' status","Header exceeding 8192 characters is rejected","Missing required_source field causes validation to be inconclusive","No frame-ancestors directive in the header results in present=false"],"whenToPreferThis":"Choose this endpoint when you need a fast, cheap, stateless check of whether a specific origin appears in a Content-Security-Policy `frame-ancestors` directive — especially in automated pipelines, CI/CD security audits, or agent-driven header compliance checks. It is privacy-friendly (no data retention, verifiable via input hash) and requires no signup, making it ideal for ephemeral agent workflows paid per-call in USDC.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:54:06.681Z","isFirstParty":false,"canonicalSlug":"delx-commerce-frame-ancestors-check-9b78d26d"}