# Delx Commerce SSRF URL Audit

> Delx Commerce SSRF URL Audit is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-01).

Audits a URL for SSRF (Server-Side Request Forgery) risk by checking if its hostname resolves to private, internal, or cloud metadata IP ranges

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/ssrf-url-audit?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-ssrf-url-audit-85b1f790
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_oTB6iPCOmncbhpuaU2lZt

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-ssrf-url-audit-85b1f790 -d '<json body>'
```

Example prompt: Before we fetch this webhook URL from our backend, can you run an SSRF safety check on https://webhook.example.com/callback to see if it resolves to any private, internal, or cloud metadata host?

## When to prefer this

Use this endpoint when your agent or backend needs to validate user-supplied or third-party URLs before making server-side HTTP requests, particularly when SSRF attacks are a concern. It is purpose-built for SSRF detection — not generic URL reachability or link preview — and returns structured risk verdicts suitable for automated decision-making. Prefer it over manual IP-range checks or regex heuristics, especially when redirect chains or DNS rebinding could obscure a malicious destination.

## Known failure modes

- Invalid or malformed URL input returns an error
- Unresolvable hostnames may yield inconclusive results
- Dynamic DNS or redirect-based obfuscation may require re-auditing at execution time (as noted in the advisory)
- Payment failure or insufficient USDC balance blocks the request

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with a `risk` field (e.g. 'high'), a `schema` identifier, a human-readable `advisory` message, a list of `findings` (e.g. ['private_or_metadata_host']), and the resolved `hostname`. The agent can use the risk level and findings to decide whether to proceed with a server-side fetch.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string",
   "description": "Input field: url."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "risk": "high",
  "schema": "delx/util-ssrf-url-audit/v1",
  "advisory": "Resolve DNS and re-check every redirect at execution time.",
  "findings": [
   "private_or_metadata_host"
  ],
  "hostname": "169.254.169.254"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-ssrf-url-audit-85b1f790/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
