# Delx Commerce — Security.txt Inspector

> Delx Commerce — Security.txt Inspector is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-01).

Fetches and parses the security.txt file for a given URL, returning contact info, expiry, and policy links

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/security-txt-inspect?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-security-txt-inspector-021e60e7
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Mxsk2A9_qwmsD7KJqzadt

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-security-txt-inspector-021e60e7 -d '<json body>'
```

Example prompt: Check if stripe.com has a security.txt file and pull out the security contact email and any disclosure policy links — use a 10-second timeout.

## When to prefer this

Use this endpoint when you need to programmatically discover security contact information or responsible disclosure policies for a specific domain, especially when building vendor security audits, bug bounty workflows, or automated security contact databases. It saves the manual step of navigating to /.well-known/security.txt and parsing the file format.

## Known failure modes

- URL unreachable or times out — result will indicate not found
- No security.txt present at /.well-known/security.txt or /security.txt — found: false
- Malformed security.txt that cannot be parsed
- Timeout exceeded (max 15 seconds) — request aborted
- Invalid URL format provided as input

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with a boolean indicating whether security.txt was found, the parsed contact addresses (e.g. mailto: links), expiry date, policy URLs, and the resolved URL of the security.txt file itself.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string"
  },
  "timeout": {
   "type": "integer",
   "maximum": 15,
   "minimum": 1
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "found": true,
   "expires": "2030-01-01T00:00:00Z",
   "contacts": [
    "mailto:security@example.com"
   ],
   "policies": [
    "https://example.com/security-policy"
   ],
   "security_txt_url": "https://example.com/.well-known/security.txt"
  },
  "tool_name": "util_security_txt_inspect"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-security-txt-inspector-021e60e7/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
