# Delx Commerce — CSP Directive Parse

> Delx Commerce — CSP Directive Parse is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Parses a Content-Security-Policy header string and returns a structured breakdown of all directives and their values

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/csp-directive-parse?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-csp-directive-parse-f0e09835
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_JzTFrNVKiO4SON6ULr0Oo

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-csp-directive-parse-f0e09835 -d '<json body>'
```

Example prompt: Parse this Content-Security-Policy header for me and tell me what directives it contains: "default-src 'self'; img-src 'self' https:; object-src 'none'"

## When to prefer this

Use this endpoint when you need a deterministic, privacy-preserving parse of a raw Content-Security-Policy header string into structured directives with no data retention. It is ideal for automated security audits, agent pipelines that inspect HTTP headers at scale, or any workflow where verifiable, pay-per-call pricing and in-memory-only processing are important. Prefer this over rolling your own CSP parser when auditability (input hash evidence) and guaranteed no-retention processing matter.

## Known failure modes

- Malformed or empty header string may result in zero directives parsed
- Header string exceeding 8192 characters will be rejected
- Invalid JSON request body returns an error
- Network or service unavailability returns a non-200 response
- Payment failure via x402 protocol prevents the call from completing

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with the total count of parsed directives, a map of each directive name to its list of allowed source values, the operation status ('pass'), and evidence metadata including whether input was retained (always false), the SHA-256 hash of the input, and the number of external calls made (always 0).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "header": {
   "type": "string",
   "maxLength": 8192,
   "description": "Header supplied to CSP Directive Parse; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "count": 3,
   "directives": {
    "img-src": [
     "'self'",
     "https:"
    ],
    "object-src": [
     "'none'"
    ],
    "default-src": [
     "'self'"
    ]
   }
  },
  "schema": "delx/util-csp-directive-parse/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "16664d9b05dde627e8d811fbffe5a404de8cef67d018c7c5f1017d3fed519e30",
   "external_calls": 0
  },
  "operation": "web_reliability:csp_directive_parse"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-csp-directive-parse-f0e09835/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
