# Delx Commerce — Webhook Signature Timestamp Check

> Delx Commerce — Webhook Signature Timestamp Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-02).

Validates whether a webhook signature timestamp falls within an acceptable age and future-skew window, returning pass/fail with computed age in seconds.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/webhook-signature-timestamp-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-webhook-signature-timestamp-check-8dff0ccc
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Omiy9pUXHsNyrykkn9qfE

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-webhook-signature-timestamp-check-8dff0ccc -d '<json body>'
```

Example prompt: Check whether a webhook timestamp of 1717000000 is still valid right now (current time 1717000120), using a maximum age of 300 seconds and a maximum future skew of 30 seconds.

## When to prefer this

Choose this endpoint when you need a lightweight, pay-per-call, no-signup webhook timestamp validator with cryptographic evidence of computation (SHA-256 input hash) and explicit confirmation of no data retention. It is ideal for agent pipelines that need to programmatically verify webhook freshness and replay-attack windows without standing up their own time-window logic, and where verifiable, auditable delivery via USDC micropayment is preferred over a subscription API.

## Known failure modes

- Missing required fields (now_epoch, timestamp_epoch, maximum_age_seconds, maximum_future_skew_seconds) result in validation error
- Non-integer epoch values cause schema rejection
- Timestamp too old — age_seconds exceeds maximum_age_seconds, within_window returns false, status fails
- Timestamp too far in the future — exceeds maximum_future_skew_seconds, within_window returns false
- Payment failure via x402 protocol blocks the call entirely

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object containing the computed age_seconds between the two timestamps, a within_window boolean indicating whether the timestamp is acceptable, a signature_verified boolean, an overall status of 'pass' or 'fail', and an evidence object with a SHA-256 hash of the input and confirmation that no data was retained and no external calls were made.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "now_epoch": {
   "type": "integer",
   "description": "Now Epoch supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."
  },
  "timestamp_epoch": {
   "type": "integer",
   "description": "Timestamp Epoch supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."
  },
  "maximum_age_seconds": {
   "type": "integer",
   "description": "Maximum Age Seconds supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."
  },
  "maximum_future_skew_seconds": {
   "type": "integer",
   "description": "Maximum Future Skew Seconds supplied to Webhook Signature Timestamp Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "age_seconds": 120,
   "within_window": true,
   "signature_verified": false
  },
  "schema": "delx/util-webhook-signature-timestamp-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "399247a496498846768188f051c797a1de4857867f694fadcc7a0037c29feb35",
   "external_calls": 0
  },
  "operation": "web_reliability:webhook_signature_timestamp_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-webhook-signature-timestamp-check-8dff0ccc/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
