# Delx Commerce — Permissions Policy Parse

> Delx Commerce — Permissions Policy Parse is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Parses an HTTP Permissions-Policy header string and returns a structured breakdown of all directives and their allowed origins.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/permissions-policy-parse?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-permissions-policy-parse-606aae0f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_FilhNbST1t6Ircz8dw1O1

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-permissions-policy-parse-606aae0f -d '<json body>'
```

Example prompt: Can you parse this Permissions-Policy header for me and show me all the directives and which origins are allowed for each: 'camera=(), geolocation=(self "https://maps.example")'?

## When to prefer this

Choose this endpoint when you need a fast, cheap, privacy-safe parse of a Permissions-Policy header string with verifiable no-retention guarantees and a structured JSON breakdown. Ideal for agents auditing web security posture, CI pipelines validating header configs, or any workflow that needs deterministic, pay-per-call parsing without API key setup.

## Known failure modes

- Malformed or non-standard Permissions-Policy header syntax may produce incomplete directive extraction
- Input exceeding 8192 characters will be rejected
- Empty or null header string returns no directives
- Headers using older Feature-Policy syntax may not parse correctly

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with the total count of directives found, a map of each directive name to its list of allowed origins (empty array means blocked for all), plus evidence metadata including whether input was retained (always false), the SHA-256 hash of the input, and the number of external calls made (always 0).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "header": {
   "type": "string",
   "maxLength": 8192,
   "description": "Header supplied to Permissions Policy Parse; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "count": 2,
   "directives": {
    "camera": [],
    "geolocation": [
     "self",
     "https://maps.example"
    ]
   }
  },
  "schema": "delx/util-permissions-policy-parse/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "a1872fcef7cbb2aabc0236a508d2693762a12cc6b5fbda254856f878202d8afc",
   "external_calls": 0
  },
  "operation": "web_reliability:permissions_policy_parse"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-permissions-policy-parse-606aae0f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
