# Delx Commerce CORS Preflight Check

> Delx Commerce CORS Preflight Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-02).

Validates whether a CORS preflight request is allowed given a method, allowed headers, allowed methods, and request headers, returning a pass/fail result with detailed missing-header diagnostics.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/cors-preflight-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-cors-preflight-check-d8c0af8f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_cN_-L1Gflf81vt5Jwoosj

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-cors-preflight-check-d8c0af8f -d '<json body>'
```

Example prompt: Can you check whether a CORS preflight for a POST request with headers Content-Type and Authorization would be allowed, given allowed methods GET and POST and allowed headers Content-Type and Authorization?

## When to prefer this

Choose this endpoint when you need a lightweight, pay-per-call, cryptographically verifiable CORS preflight validation without any signup or session management. It is ideal for agents, CI pipelines, or automated tools that need to audit CORS policies programmatically and want tamper-evident evidence (input hash) that the check was performed without data retention. Prefer it over building custom CORS logic when you need a neutral third-party validation with an auditable result.

## Known failure modes

- Invalid or missing method field may cause unexpected validation results
- Malformed header names in arrays may result in false negatives for missing_headers
- Exceeding 256 items in allowed_headers, allowed_methods, or request_headers arrays will be rejected
- Payment failure (402) if USDC payment via x402 is not properly attached
- Network timeout if the Base or Solana payment settlement is delayed

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object indicating whether the preflight is allowed overall (allowed: bool), whether the specific HTTP method is permitted (method_allowed: bool), and a list of any missing headers (missing_headers: array). Also includes operation metadata: schema version, status (pass/fail), an SHA-256 hash of the input for verifiability, a flag confirming no data was retained, and external call count (0).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "method": {
   "type": "string",
   "maxLength": 8192,
   "description": "Method supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."
  },
  "allowed_headers": {
   "type": "array",
   "items": {
    "type": "string",
    "maxLength": 8192
   },
   "maxItems": 256,
   "description": "Allowed Headers supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."
  },
  "allowed_methods": {
   "type": "array",
   "items": {
    "type": "string",
    "maxLength": 8192
   },
   "maxItems": 256,
   "description": "Allowed Methods supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."
  },
  "request_headers": {
   "type": "array",
   "items": {
    "type": "string",
    "maxLength": 8192
   },
   "maxItems": 256,
   "description": "Request Headers supplied to CORS Preflight Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "allowed": true,
   "method_allowed": true,
   "missing_headers": []
  },
  "schema": "delx/util-cors-preflight-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "571002a70ff839ab886cb4c05bd47a50845ad003d3ec5eba7e599a0b18fee704",
   "external_calls": 0
  },
  "operation": "web_reliability:cors_preflight_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-cors-preflight-check-d8c0af8f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
