Guardrails API
Endpoint for evaluating content against guardrail rules.
Hook plane (September 2026)
Guardrails now attach at six lifecycle hooks (prompt.pre, input.pre, output.pre, output.stream.delta, tool.pre, tool.post) across nine policy families, each with its own enforce/monitor mode. The /evaluate contract below is unchanged; see the Guardrails guide for the hook model and the full family list.
Evaluate
POST /api/client/v1/guardrails/evaluateRequest
json
{
"guardrail_key": "pii-checker",
"text": "My email is john@example.com and my phone is 555-0100"
}Parameters
| Field | Type | Required | Description |
|---|---|---|---|
guardrail_key | string | Yes | Key of the guardrail to evaluate |
text | string | Yes | Content to evaluate |
Response
json
{
"passed": false,
"guardrail_key": "pii-checker",
"guardrail_name": "PII Checker",
"action": "flag",
"findings": [
{ "category": "email", "message": "Email address detected", "block": false },
{ "category": "phone", "message": "Phone number detected", "block": false }
],
"message": null
}Response Fields
| Field | Description |
|---|---|
passed | true if no findings triggered, false otherwise |
guardrail_key | Key of the evaluated guardrail |
guardrail_name | Display name |
action | Configured action: block, flag, or redact |
findings | Array of detected issues |
message | Optional message for blocked content |
Policy Families
| Family | Evaluation Method |
|---|---|
| Personal data (PII) | Regex-based pattern matching (15 categories) |
| Credentials | Pattern + entropy matching |
| Word Filter | Deterministic list/regex matching |
| Moderation | LLM classifier |
| Prompt Shield | LLM classifier (prompt injection detection) |
| Tool Access | Deterministic tool allow/deny policy |
A guardrail's type (preset vs custom) is separate from its policy families — custom runs an LLM judged against your own rule text instead of the bundled families above.
Inference Integration
Guardrails can be attached to models and evaluated automatically during chat completions. When a guardrail blocks a request, the chat API returns:
json
{
"error": {
"type": "guardrail_block",
"guardrail_key": "pii-checker",
"action": "block",
"findings": [...]
}
}Errors
| Status | Description |
|---|---|
| 400 | Missing guardrail_key or text |
| 401 | Invalid API token |
| 404 | Guardrail not found |

