# Delx Commerce — OAuth Scope Auditor

> Delx Commerce — OAuth Scope Auditor is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-02).

Audits a set of OAuth scopes, identifying missing required scopes, excess scopes, and whether the set satisfies least-privilege principles

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/oauth-scope-audit?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-oauth-scope-auditor-3f5bb096
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_VJVk-t-_FaaeZytPLLUr_

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-oauth-scope-auditor-3f5bb096 -d '<json body>'
```

Example prompt: Can you check whether the OAuth scopes my app is requesting — read, write, admin — actually cover the minimum required scopes of read and profile, and flag anything excessive or missing?

## When to prefer this

Use this endpoint when you need a quick, structured, pay-per-call audit of OAuth scope sets without setting up a full IAM system. Ideal for agents that dynamically request tokens and need to verify permission correctness before making downstream API calls, or for security pipelines checking least-privilege compliance on a per-request basis.

## Known failure modes

- Missing or malformed 'required' or 'requested' arrays may return a validation error
- Empty arrays may return trivially sufficient/least-privilege results with no useful insight
- Payment failure via x402 will block the request before processing
- Scope strings must match expected format; non-standard scope names may produce misleading results

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with: 'sufficient' (boolean — whether requested scopes cover all required ones), 'least_privilege' (boolean — whether no excess scopes are present), 'missing' (array of scopes that are required but not present in the requested set), 'excess' (array of scopes that are requested but not required), and a 'schema' identifier string.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "required": {
   "type": "array",
   "description": "Input field: required."
  },
  "requested": {
   "type": "array",
   "description": "Input field: requested."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "excess": [
   "write"
  ],
  "schema": "delx/util-oauth-scope-audit/v1",
  "missing": [],
  "sufficient": true,
  "least_privilege": false
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-oauth-scope-auditor-3f5bb096/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
