SVG Sanitizer

Removes scripts, event handlers, external references, foreignObject and unsafe data URLs from SVG, listing every element and attribute removed.

POST /v1/svg/sanitize $0.01 per call

Specification

Endpoint
POST /v1/svg/sanitize
Price
$0.01 per call · tier standard_data
Payment
x402 on X Layer (chain 196) · settled in USDG or USDT0 · scheme exact
Data source
Local sandboxed processing of the uploaded image
Timeout
60 seconds
Max request
20 MB
Version
1.0.0

Calling it

The first call returns a 402 with the payment challenge. Retry with a signed authorisation in the X-PAYMENT header — see the payment guide for the exact shape.

curl -i -X POST "https://api.dana-edu.pp.ua/v1/svg/sanitize" \
  -H "content-type: application/json" \
  -d '{ ... }'

Response

Real output, captured by running this endpoint at build time — not written by hand. Volatile fields such as timestamps are elided. Captured 2026-07-30.

{
  "original_size_bytes": 396,
  "sanitised_size_bytes": 255,
  "was_modified": true,
  "removals": [
    {
      "type": "element",
      "name": "script"
    },
    {
      "type": "attribute",
      "name": "href",
      "reason": "external reference"
    },
    {
      "type": "attribute",
      "name": "href",
      "reason": "script URL"
    },
    {
      "type": "attribute",
      "name": "style",
      "reason": "script or external URL in CSS"
    },
    {
      "type": "attribute",
      "name": "onload",
      "reason": "event handler"
    }
  ],
  "removal_count": 5,
  "removals_by_reason": {
    "element": 1,
    "external reference": 1,
    "script URL": 1,
    "script or external URL in CSS": 1,
    "event handler": 1
  },
  "output_base64": "<base64 payload elided from the published example>",
  "output_utf8": "<base64 payload elided from the published example>",
  "policy": {
    "elements_removed": [
      "animate",
      "animatemotion",
      "animatetransform",
      "audio",
      "embed",
      "foreignobject",
      "handler",
      "iframe",
      "object",
      "script",
      "set",
      "video"
    ],
    "attributes_removed": [
      "any on* event handler",
      "href/src pointing at javascript:, external URLs, or non-image data URLs",
      "style containing script, expression() or an external url()"
    ],
  … truncated for display

Trimmed for display. The full body is returned by the endpoint and described by its schema.

Every response is wrapped in the same envelope: data plus warnings, sources, confidence, informational_only and a measured processing_ms. See the envelope reference.

Related endpoints