# Delx Commerce — URL Redirect Target Check

> Delx Commerce — URL Redirect Target Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Validates whether a URL redirect target is allowed by checking its host, scheme, and resolved URL against a configurable allowlist

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/url-redirect-target-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-url-redirect-target-check-6cfc5b3f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_RflB2PVZ7D1S3YydZi05q

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-url-redirect-target-check-6cfc5b3f -d '<json body>'
```

Example prompt: Check whether the redirect target 'https://evil.com/steal' is allowed when the base URL is 'https://myapp.com' — only https scheme should be permitted and only example.com and myapp.com are allowed hosts.

## When to prefer this

Choose this endpoint when you need a lightweight, verifiable, pay-per-use URL redirect safety check with no retained data and cryptographic evidence of the inputs processed. Ideal for agents handling user-supplied redirect URLs, OAuth callbacks, or link shortener destinations where open redirect vulnerabilities are a concern and you need an auditable result without standing up your own validation infrastructure.

## Known failure modes

- Invalid or malformed target URL — validation fails with an error
- Base URL cannot be resolved or is malformed
- Allowed hosts list exceeds 256 entries — request rejected
- Target URL exceeds 8192 character limit
- Network-level issues reaching the Delx Commerce endpoint
- Payment not included or insufficient USDC — 402 response returned

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object indicating whether the redirect target is allowed, including the resolved URL, extracted host, scheme, and a pass/fail status. Also provides an evidence block with a SHA-256 hash of the input, confirmation that no data was retained, and a count of external calls made (zero for this in-memory check).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "target": {
   "type": "string",
   "maxLength": 8192,
   "description": "Target supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."
  },
  "base_url": {
   "type": "string",
   "maxLength": 8192,
   "description": "Base URL supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."
  },
  "allowed_hosts": {
   "type": "array",
   "items": {
    "type": "string",
    "maxLength": 8192
   },
   "maxItems": 256,
   "description": "Allowed Hosts supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."
  },
  "allowed_schemes": {
   "type": "array",
   "items": {
    "type": "string",
    "maxLength": 8192
   },
   "maxItems": 256,
   "description": "Allowed Schemes supplied to URL Redirect Target Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "host": "example.com",
   "scheme": "https",
   "allowed": true,
   "resolved_url": "https://example.com/account"
  },
  "schema": "delx/util-url-redirect-target-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "6a1d59c98f30fc06ce9df9cfcba2c305b66be8e5eb56388a33bf40e364792c0c",
   "external_calls": 0
  },
  "operation": "web_reliability:url_redirect_target_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-url-redirect-target-check-6cfc5b3f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
