{"slug":"api-zfinia-com-x402-v1-csp-structural-audit-8d4e7e","title":"Parse one Content-Security-Policy and report its structure, with the fallback ru","host":"api.zfinia.com","method":"POST","resource":"https://api.zfinia.com/x402/v1/csp-structural-audit","category":"code","description":"Parse one Content-Security-Policy and report its structure, with the fallback rules applied. A fetch directive absent while default-src is present is reported as covered; base-uri and frame-ancestors do not fall back, so absence there is a finding. unsafe-inline alongside a nonce is reported differe","price_listed":0.16,"price_asked":0.16,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":4868,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"policy":"default-src 'self'; script-src 'self' 'unsafe-inline' data:; style-src 'self'; connect-src *; style-src 'unsafe-inline'; frame-ancestors 'none' https://partner.test; report-uri /csp","report_only":false},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"additionalProperties":false,"properties":{"policy":{"maxLength":16384,"type":"string"},"report_only":{"type":"boolean"},"require_directives":{"items":{"maxLength":64,"type":"string"},"maxItems":40,"minItems":1,"type":"array"}},"required":["policy"],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-10-04","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.16,"price_match":true,"latency_ms":4868,"error":null}],"description_full":"Parse one Content-Security-Policy and report its structure, with the fallback rules applied. A fetch directive absent while default-src is present is reported as covered; base-uri and frame-ancestors do not fall back, so absence there is a finding. unsafe-inline alongside a nonce is reported differently from unsafe-inline alone, since supporting browsers ignore it. A repeated directive is reported because only the first takes effect. Structure only, not an assessment of adequacy.","last_updated":"2026-10-04T08:13:35.249Z","schemes":["exact"]}