# Delx Commerce — X-Content-Type-Options Header Validator

> Delx Commerce — X-Content-Type-Options Header Validator is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Validates whether a given X-Content-Type-Options HTTP header value is correct and accepted (e.g. 'nosniff'), returning a pass/fail result with verifiable evidence.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/x-content-type-options-check?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-x-content-type-options-header-validator-f777bc1d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_EM2jK9mzDmk1paEghAoF3

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-x-content-type-options-header-validator-f777bc1d -d '<json body>'
```

Example prompt: Can you check if 'nosniff' is a valid and accepted value for the X-Content-Type-Options HTTP security header?

## When to prefer this

Choose this endpoint when you need a lightweight, verifiable, pay-per-call check of an X-Content-Type-Options header value without setting up an account or long-term subscription. It is ideal for automated agents, CI pipelines, or security audits that require cryptographic evidence of the result (input SHA-256) and guaranteed no data retention — distinguishing it from general-purpose HTTP header scanners or full website security scanners.

## Known failure modes

- Invalid or malformed input string may return a fail status with accepted=false
- Value exceeding 8192 character maxLength will be rejected
- Missing or empty 'value' field may cause a validation error
- Network or payment processing failure may result in no response

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with the validated result value, a boolean 'accepted' flag, a 'pass' or 'fail' status, the operation name, and an evidence block containing the SHA-256 hash of the input, a flag confirming no data was retained, and the count of external calls made (zero, indicating pure in-memory processing).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "value": {
   "type": "string",
   "maxLength": 8192,
   "description": "Value supplied to X Content Type Options Check; used only for this bounded calculation and processed in memory without retention."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "value": "nosniff",
   "accepted": true
  },
  "schema": "delx/util-x-content-type-options-check/v1",
  "status": "pass",
  "evidence": {
   "retained": false,
   "input_sha256": "bea2556c6cc6e1b92f986ac1504063041a0fbd184228061905e268ef7eeebd31",
   "external_calls": 0
  },
  "operation": "web_reliability:x_content_type_options_check"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-x-content-type-options-header-validator-f777bc1d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
