# Delx Commerce — Frame Ancestors Check

> Delx Commerce — Frame Ancestors Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Parses and validates the Content-Security-Policy `frame-ancestors` directive from a given HTTP header string, checking whether a required source is present.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/frame-ancestors-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-frame-ancestors-check-9b78d26d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_uh93S0lQLs_v56V_9vvvA

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-frame-ancestors-check-9b78d26d -d '<json body>'
```

Example prompt: Check whether this Content-Security-Policy header includes 'self' as a frame-ancestors source: "default-src 'self'; frame-ancestors 'self' https://partner.example.com"

## When to prefer this

Choose this endpoint when you need a fast, cheap, stateless check of whether a specific origin appears in a Content-Security-Policy `frame-ancestors` directive — especially in automated pipelines, CI/CD security audits, or agent-driven header compliance checks. It is privacy-friendly (no data retention, verifiable via input hash) and requires no signup, making it ideal for ephemeral agent workflows paid per-call in USDC.

## Known failure modes

- Malformed or missing CSP header string returns a parse error or empty sources list
- Required source not found in directive yields a 'fail' status
- Header exceeding 8192 characters is rejected
- Missing required_source field causes validation to be inconclusive
- No frame-ancestors directive in the header results in present=false

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with the parsed `frame-ancestors` directive (source list, whether it's present), a pass/fail status indicating if the required source was found, and an evidence block with the SHA-256 hash of the input and confirmation that no data was retained or sent externally.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "header": {
   "type": "string",
   "maxLength": 8192,
   "description": "Header supplied to Frame Ancestors Check; used only for this bounded calculation and processed in memory without retention."
  },
  "required_source": {
   "type": "string",
   "maxLength": 8192,
   "description": "Required Source supplied to Frame Ancestors Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "source": "'none'",
   "present": true,
   "sources": [
    "'none'"
   ],
   "directive": "frame-ancestors"
  },
  "schema": "delx/util-frame-ancestors-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "87d66a2da893969f3b55da12bea54f3990c499fe4d58ef57b180b13ceeb775b2",
   "external_calls": 0
  },
  "operation": "web_reliability:frame_ancestors_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-frame-ancestors-check-9b78d26d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
