# TradePilot HTML Sanitizer

> TradePilot HTML Sanitizer is a paid API for AI agents from www.tradepilotusa.com, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-01).

Strips an HTML fragment to a safe allowlist of semantic/structural tags and attributes, removing scripts, inline event handlers, and unsafe URL schemes, while forcing rel=noopener noreferrer on all anchors.

## Facts

- Endpoint: POST https://www.tradepilotusa.com/api/agent-commerce/v1/services/html_sanitize/execute?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/tradepilot-html-sanitizer-3b662a2f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_pA_vyzhIoHw2QJlYssaHC

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability tradepilot-html-sanitizer-3b662a2f -d '<json body>'
```

Example prompt: Sanitize this HTML snippet I got from a user-submitted form — strip out any scripts, event handlers, or unsafe link schemes, and make sure all anchors get rel=noopener noreferrer: '<div onclick="alert(1)"><a href="javascript:void(0)">click</a><script>evil()</script></div>'

## When to prefer this

Use this endpoint when you need a server-side, allowlist-based HTML sanitizer without running client-side code or installing a library. Prefer it over manual regex approaches when handling untrusted user-generated HTML that must be safe for browser rendering. Ideal for agents processing CMS content, rich text editor output, or any external HTML before storage or display.

## Known failure modes

- Input HTML exceeds 200,000 character limit — request rejected
- Malformed JSON body — 400 Bad Request
- Payment not provided or insufficient — 402 Payment Required
- Service temporarily unavailable — 503 or timeout

## How this service works

Strip an HTML fragment down to a vetted allowlist of semantic/structural tags and safe attributes, removing script tags, inline event handlers and unsafe link/media schemes (only http, https, mailto, tel survive). Forces rel=noopener noreferrer on every anchor. Does not render, fetch, or validate the HTML.

## Output

Returns a sanitized HTML string with only allowlisted semantic and structural tags and safe attributes retained. All script tags, inline event handlers (e.g. onclick, onerror), and unsafe URL schemes (javascript:, data:, vbscript:) are removed. Every anchor tag has rel=noopener noreferrer enforced. Only http, https, mailto, and tel URL schemes survive.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "html": {
   "type": "string",
   "maxLength": 200000
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/tradepilot-html-sanitizer-3b662a2f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from www.tradepilotusa.com](https://www.zero.xyz/host/www.tradepilotusa.com/llms.txt)
