# Delx Commerce — CORS Origin Check

> Delx Commerce — CORS Origin Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-02).

Validates whether a given origin is allowed by a CORS policy, checking against a list of permitted origins and credential requirements.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/cors-origin-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-cors-origin-check-5906e3f5
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_jE3cfXWIGDwj_70vVh7p9

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-cors-origin-check-5906e3f5 -d '<json body>'
```

Example prompt: Check if the origin https://app.example.com is allowed by my CORS policy, given the allowed origins list ['https://app.example.com', 'https://admin.example.com'], with credentials enabled.

## When to prefer this

Use this endpoint when you need a trustless, pay-per-use, verifiable CORS origin validation with no signup or persistent data storage. Ideal for AI agents or automated pipelines that need on-demand CORS checks with cryptographic evidence of computation, especially when you want to avoid standing up your own CORS logic or need auditability via input hash. Prefer over self-hosted solutions when you need verifiable, stateless, zero-retention computation with micro-payment billing.

## Known failure modes

- Invalid or malformed origin URL may produce unexpected results
- Allowed list exceeding 256 items will be rejected
- Payment failure via x402 protocol will block the request
- Origin string exceeding 8192 characters will be rejected
- Missing required fields may result in validation errors

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with the normalized origin, a boolean indicating whether it is allowed, and whether credentials are permitted. Also includes a schema identifier, a pass/fail status, and an evidence block containing a SHA-256 hash of the input, a flag confirming no data is retained, and a count of external calls made (always 0, meaning fully in-memory computation).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "origin": {
   "type": "string",
   "maxLength": 8192,
   "description": "Origin supplied to CORS Origin Check; used only for this bounded calculation and processed in memory without retention."
  },
  "allowed": {
   "type": "array",
   "items": {
    "type": "string",
    "maxLength": 8192
   },
   "maxItems": 256,
   "description": "Allowed supplied to CORS Origin Check; used only for this bounded calculation and processed in memory without retention."
  },
  "credentials": {
   "type": "boolean",
   "description": "Credentials supplied to CORS Origin Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "origin": "https://app.example.com/",
   "allowed": true,
   "credentials": true
  },
  "schema": "delx/util-cors-origin-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "502a62c83d87812324c4b1fe1a2a0df77db850e0a6e49fef68313499e8d02d82",
   "external_calls": 0
  },
  "operation": "web_reliability:cors_origin_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-cors-origin-check-5906e3f5/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
