# Delx Commerce — Secret Exposure Scan

> Delx Commerce — Secret Exposure Scan is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-03).

Scans arbitrary text for exposed secrets (API keys, tokens, credentials) and returns a risk rating, finding count, and finding types.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/secret-exposure-scan?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-03
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-secret-exposure-scan-3c0177ad
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_EPEWu5NSPhdE7jiBboJZ6

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-secret-exposure-scan-3c0177ad -d '<json body>'
```

Example prompt: Scan this code snippet for any exposed secrets or leaked credentials and tell me the risk level and what types were found: `AWS_SECRET_KEY=abc123...`

## When to prefer this

Choose this endpoint when you need a fast, pay-per-result secrets scan with no signup or account management, especially in agent pipelines that require verifiable delivery (SHA-256 hash) and deterministic pricing ($0.002 USDC). Ideal for pre-publish, pre-commit, or pre-share checks on arbitrary text blobs, config files, logs, or source code. Prefer over free heuristic tools when auditability and micropayment-based automation are required.

## Known failure modes

- Text exceeds 500,000 character limit — request rejected
- Payment not provided or insufficient — 402 Payment Required
- Malformed JSON body — 400 Bad Request
- Service temporarily unavailable — 503 error
- Empty text field — may return zero findings without error

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

A JSON object containing: a 'risk' field ('low', 'medium', 'high'), a schema identifier ('delx/secret-exposure-scan/v1'), a SHA-256 hash of the input text for verifiable delivery, a 'finding_count' integer, a 'finding_types' object mapping detected secret categories to counts, and a 'values_returned' boolean indicating whether actual secret values are included in the response.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "text": {
   "type": "string",
   "maxLength": 500000
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "risk": "low",
  "schema": "delx/secret-exposure-scan/v1",
  "text_sha256": "2fb2835f6697091bb0ecb740d8691cd3d31407453033b2aafb19d203f0150ab0",
  "finding_count": 0,
  "finding_types": {},
  "values_returned": false
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-secret-exposure-scan-3c0177ad/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
