# Delx Commerce — CSP Source Check

> Delx Commerce — CSP Source Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Checks whether a given source URL is permitted by a Content Security Policy (CSP) header for a specified directive

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/csp-source-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-csp-source-check-4ed8db1b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_vWT9w4zeH7d2ajZC3x6Ce

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-csp-source-check-4ed8db1b -d '<json body>'
```

Example prompt: Check whether 'https://api.example.com' is allowed under the connect-src directive of this CSP header: "default-src 'self'; connect-src 'self' https://api.example.com https://cdn.example.com"

## When to prefer this

Use this endpoint when you need a fast, cheap, privacy-preserving check of whether a specific URL is covered by a CSP directive — especially when no data retention is acceptable (evidenced by the retained:false field). Prefer this over manually parsing CSP headers when you need deterministic, auditable results with a cryptographic input hash for logging.

## Known failure modes

- Malformed CSP header may cause unexpected parse results
- Directive not found in header returns absent/false result
- Source URL exceeding 8192 characters will be rejected
- Invalid JSON input returns an error response
- Network timeout on the API call

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object indicating whether the specified source is present in the given CSP directive, the list of sources found in that directive, a pass/fail status, and evidence fields including a SHA-256 hash of the input and confirmation that no data was retained or external calls made.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "header": {
   "type": "string",
   "maxLength": 8192,
   "description": "Header supplied to CSP Source Check; used only for this bounded calculation and processed in memory without retention."
  },
  "source": {
   "type": "string",
   "maxLength": 8192,
   "description": "Source supplied to CSP Source Check; used only for this bounded calculation and processed in memory without retention."
  },
  "directive": {
   "type": "string",
   "maxLength": 8192,
   "description": "Directive supplied to CSP Source Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "source": "https://api.example.com",
   "present": true,
   "sources": [
    "'self'",
    "https://api.example.com"
   ],
   "directive": "connect-src"
  },
  "schema": "delx/util-csp-source-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "28ce2f05a29beab331ef11c94ccca09b3de52f20fc1aaf0a876da89ecbba12bd",
   "external_calls": 0
  },
  "operation": "web_reliability:csp_source_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-csp-source-check-4ed8db1b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
