Skip to content

REST API

For non-Python services, or one guard shared by many apps. pip install "guardlayer[api]", then:

GUARDLAYER_API_KEY=change-me guardlayer serve --host 127.0.0.1 --port 8000
# or: docker run -p 127.0.0.1:8000:8000 -e GUARDLAYER_API_KEY=change-me guardlayer
Method Path Body
GET /health none
GET /v1/settings none
POST /v1/scan/input {text, system_prompt?, metadata?, session_id?}
POST /v1/scan/output {text, prompt?, system_prompt?, canary_tokens?, expected_canary?, metadata?, session_id?}
POST /v1/scan/context {text, source?, metadata?, session_id?}
POST /v1/scan/batch {items: [{text, direction}]}
POST /v1/scan/tool-call {tool, arguments, metadata?, session_id?} (verdict may be review)
POST /v1/scan/tool-result {tool, result, metadata?, session_id?}
GET · DELETE /v1/sessions/{id} session taint summary · reset
POST /v1/canary/add · /v1/canary/check {prompt, echo?} · {text}
POST /v1/corpus/add {texts: [...]}

Every /v1 route requires the X-API-Key header when GUARDLAYER_API_KEY is set (compared in constant time). Interactive docs are served at /docs.

curl -s localhost:8000/v1/scan/tool-call -H "X-API-Key: change-me" -H "Content-Type: application/json" \
  -d '{"tool": "bash", "arguments": {"cmd": "rm -rf ~"}}'

Warning

Never expose the API to the internet. Run it as a sidecar on loopback or as an internal service behind TLS; see Deployment.