ToolAssay

Parse one Content-Security-Policy and report its structure, with the fallback ru

Parse one Content-Security-Policy and report its structure, with the fallback rules applied. A fetch directive absent while default-src is present is reported as covered; base-uri and frame-ancestors do not fall back, so absence there is a finding. unsafe-inline alongside a nonce is reported differently from unsafe-inline alone, since supporting browsers ignore it. A repeated directive is reported because only the first takes effect. Structure only, not an assessment of adequacy.

Answeringour last check, 2026-10-04
1 of 1checks answered this week
4868 msmedian answer time
$0.16listed price per call
$0.16price it asked us

Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.

Endpoint

POST https://api.zfinia.com/x402/v1/csp-structural-audit

CategoryCode and developer
Provider hostapi.zfinia.com
Networkseip155:8453
Payment schemesexact
Self-reported calls, 30 days1 from 1 payers (the provider's figure, not ours)

Our checks, last 30 days

DayResultHTTPAskedTime
2026-10-04 valid payment request 402$0.16 4868 ms

Example input (from the provider)

{
  "body": {
    "policy": "default-src 'self'; script-src 'self' 'unsafe-inline' data:; style-src 'self'; connect-src *; style-src 'unsafe-inline'; frame-ancestors 'none' https://partner.test; report-uri /csp",
    "report_only": false
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
}

Promised output schema (from the provider)

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "input": {
      "additionalProperties": false,
      "properties": {
        "body": {
          "additionalProperties": false,
          "properties": {
            "policy": {
              "maxLength": 16384,
              "type": "string"
            },
            "report_only": {
              "type": "boolean"
            },
            "require_directives": {
              "items": {
                "maxLength": 64,
                "type": "string"
              },
              "maxItems": 40,
              "minItems": 1,
              "type": "array"
            }
          },
          "required": [
            "policy"
          ],
          "type": "object"
        },
        "bodyType": {
          "enum": [
            "json",
            "form-data",
            "text"
          ],
          "type": "string"
        },
        "method": {
          "enum": [
            "POST"
          ],
          "type": "string"
        },
        "type": {
          "const": "http",
          "type": "string"
        }
      },
      "required": [
        "type",
        "method",
        "bodyType",
        "body"
      ],
      "type": "object"
    },
    "output": {
      "properties": {
        "example": {
          "type": "object"
        },
        "type": {
          "type": "string"
        }
      },
      "required": [
        "type"
      ],
      "type": "object"
    }
  },
  "required": [
    "input"
  ],
  "type": "object"
}

This page as JSON