# Delx Commerce — HTTP Headers Inspector

> Delx Commerce — HTTP Headers Inspector is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-01).

Fetches and analyzes HTTP response headers for a given URL, identifying present and missing security headers

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/http-headers-inspect?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-http-headers-inspector-4c15a011
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Zz_In7ux6it2SaxHoRNiY

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-http-headers-inspector-4c15a011 -d '<json body>'
```

Example prompt: Can you inspect the HTTP response headers for https://example.com with a 10-second timeout and tell me which security headers are present and which ones are missing?

## When to prefer this

Use this endpoint when you need a quick, cheap ($0.01 USDC) programmatic inspection of HTTP headers for any URL, especially for security audits that check for missing or misconfigured headers. Prefer this over manual browser devtools or curl when running automated agent workflows that need structured, machine-readable header data including a clear breakdown of security header presence and absence.

## Known failure modes

- URL is unreachable or DNS fails — returns an error with no headers
- Timeout exceeded (max 15 seconds) — request is aborted and returns timeout error
- Invalid URL format — request rejected with validation error
- Target server returns non-200 status — still returns headers and status code but may indicate an error state

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object containing the HTTP status code, all response headers as key-value pairs, the final URL after following any redirects, a list of security headers that are present, and a list of security headers that are missing (e.g. content-security-policy, referrer-policy, strict-transport-security, x-content-type-options).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string"
  },
  "timeout": {
   "type": "integer",
   "maximum": 15,
   "minimum": 1,
   "description": "Per-network-phase cap; the whole tool shares a 10-second active budget including resolution and fallbacks. Not an end-to-end latency SLA."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "status": 200,
   "headers": {
    "server": "cloudflare",
    "cache-control": "max-age=0"
   },
   "final_url": "https://example.com",
   "missing_security_headers": [
    "content-security-policy",
    "referrer-policy"
   ],
   "security_headers_present": [
    "strict-transport-security",
    "x-content-type-options"
   ]
  },
  "tool_name": "util_http_headers_inspect"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-http-headers-inspector-4c15a011/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
