{"uid":"cap_vWT9w4zeH7d2ajZC3x6Ce","slug":"delx-commerce-csp-source-check-4ed8db1b","name":"Delx Commerce — CSP Source Check","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/csp-source-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"header":{"type":"string","maxLength":8192,"description":"Header supplied to CSP Source Check; used only for this bounded calculation and processed in memory without retention."},"source":{"type":"string","maxLength":8192,"description":"Source supplied to CSP Source Check; used only for this bounded calculation and processed in memory without retention."},"directive":{"type":"string","maxLength":8192,"description":"Directive supplied to CSP Source Check; used only for this bounded calculation and processed in memory without retention."}}},"responseSchema":{"type":"json","example":{"result":{"source":"https://api.example.com","present":true,"sources":["'self'","https://api.example.com"],"directive":"connect-src"},"schema":"delx/util-csp-source-check/v1","status":"pass","evidence":{"retained":false,"input_sha256":"28ce2f05a29beab331ef11c94ccca09b3de52f20fc1aaf0a876da89ecbba12bd","external_calls":0},"operation":"web_reliability:csp_source_check"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ozCatGyZZVBFa_wT6z1Vf","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether a given source URL is permitted by a Content Security Policy (CSP) header for a specified directive","exampleAgentPrompt":"Check whether 'https://api.example.com' is allowed under the connect-src directive of this CSP header: \"default-src 'self'; connect-src 'self' https://api.example.com https://cdn.example.com\"","exampleUseCases":[{"title":"Debug a CSP violation in production","prompt":"I'm getting a CSP violation for 'https://analytics.mysite.com' under script-src. Can you check if it's actually covered by this header: \"default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.mysite.com\"?"},{"title":"Verify third-party API is whitelisted","prompt":"Before I deploy, check whether 'https://api.stripe.com' is permitted under the connect-src directive of my CSP: \"default-src 'self'; connect-src 'self' https://api.stripe.com https://checkout.stripe.com\""},{"title":"Audit new CDN domain against existing policy","prompt":"We just switched CDN providers to 'https://cdn.fastly.net'. Can you check if that source is listed under img-src in our current CSP header: \"default-src 'self'; img-src 'self' https://cdn.cloudfront.net data:\"?"}],"resultDescription":"Returns a JSON object indicating whether the specified source is present in the given CSP directive, the list of sources found in that directive, a pass/fail status, and evidence fields including a SHA-256 hash of the input and confirmation that no data was retained or external calls made.","failureModes":["Malformed CSP header may cause unexpected parse results","Directive not found in header returns absent/false result","Source URL exceeding 8192 characters will be rejected","Invalid JSON input returns an error response","Network timeout on the API call"],"whenToPreferThis":"Use this endpoint when you need a fast, cheap, privacy-preserving check of whether a specific URL is covered by a CSP directive — especially when no data retention is acceptable (evidenced by the retained:false field). Prefer this over manually parsing CSP headers when you need deterministic, auditable results with a cryptographic input hash for logging.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:53:59.934Z","isFirstParty":false,"canonicalSlug":"delx-commerce-csp-source-check-4ed8db1b"}