# Delx Commerce — Open Redirect Audit

> Delx Commerce — Open Redirect Audit is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-01).

Audits a URL target for open redirect vulnerabilities by checking whether its host is in an allowed hosts list

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/open-redirect-audit?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-open-redirect-audit-22c27bc7
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_17xa1SBedemnoNQ7fxzhx

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-open-redirect-audit-22c27bc7 -d '<json body>'
```

Example prompt: Can you audit the URL 'https://evil.example/callback?next=http://attacker.com' for open redirect risks, with allowed hosts set to ['myapp.com', 'api.myapp.com']?

## When to prefer this

Use this endpoint when you need a lightweight, pay-per-call open redirect security check without standing up your own URL validation infrastructure. Ideal for AI agents that dynamically generate or handle redirect URLs and need a verifiable, auditable security gate before following or serving those redirects. Prefer this over manual host-matching logic when you want a standardized finding schema and recommendation, or when auditability of the security check is important.

## Known failure modes

- Invalid or malformed target URL may return an error or unexpected finding
- Empty allowed_hosts array may cause all redirects to be flagged as not allowed
- Missing required 'target' field will likely return a validation error
- Non-HTTP URLs (e.g. javascript:) may produce unexpected findings or errors
- Payment failure (insufficient USDC balance) will block the request entirely

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with: 'allowed' (boolean indicating if the redirect is safe), 'finding' (a string code describing the security finding, e.g. 'external_host_not_allowlisted'), 'target_host' (the extracted hostname from the target URL), and 'recommendation' (a plain-English remediation suggestion).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "target": {
   "type": "string",
   "description": "Input field: target."
  },
  "allowed_hosts": {
   "type": "array",
   "description": "Input field: allowed_hosts."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "schema": "delx/util-open-redirect-audit/v1",
  "allowed": false,
  "finding": "external_host_not_allowlisted",
  "target_host": "evil.example",
  "recommendation": "resolve relative paths and enforce exact host allowlist"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-open-redirect-audit-22c27bc7/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
