curl --request POST \
--url https://api.promptguard.co/api/v1/guard \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"messages": [
{
"role": "<string>",
"content": ""
}
],
"direction": "input",
"model": "<string>",
"context": {
"framework": "<string>",
"chain_name": "<string>",
"agent_id": "<string>",
"session_id": "<string>",
"tool_calls": [
{}
],
"metadata": {}
},
"retrieved_context": [
{
"content": "<string>",
"source": "<string>",
"metadata": {}
}
],
"media": [
{
"type": "<string>",
"mime_type": "<string>",
"url": "<string>",
"base64": "<string>",
"metadata": {}
}
]
}
'import requests
url = "https://api.promptguard.co/api/v1/guard"
payload = {
"messages": [
{
"role": "<string>",
"content": ""
}
],
"direction": "input",
"model": "<string>",
"context": {
"framework": "<string>",
"chain_name": "<string>",
"agent_id": "<string>",
"session_id": "<string>",
"tool_calls": [{}],
"metadata": {}
},
"retrieved_context": [
{
"content": "<string>",
"source": "<string>",
"metadata": {}
}
],
"media": [
{
"type": "<string>",
"mime_type": "<string>",
"url": "<string>",
"base64": "<string>",
"metadata": {}
}
]
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
messages: [{role: '<string>', content: ''}],
direction: 'input',
model: '<string>',
context: {
framework: '<string>',
chain_name: '<string>',
agent_id: '<string>',
session_id: '<string>',
tool_calls: [{}],
metadata: {}
},
retrieved_context: [{content: '<string>', source: '<string>', metadata: {}}],
media: [
{
type: '<string>',
mime_type: '<string>',
url: '<string>',
base64: '<string>',
metadata: {}
}
]
})
};
fetch('https://api.promptguard.co/api/v1/guard', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.promptguard.co/api/v1/guard",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'messages' => [
[
'role' => '<string>',
'content' => ''
]
],
'direction' => 'input',
'model' => '<string>',
'context' => [
'framework' => '<string>',
'chain_name' => '<string>',
'agent_id' => '<string>',
'session_id' => '<string>',
'tool_calls' => [
[
]
],
'metadata' => [
]
],
'retrieved_context' => [
[
'content' => '<string>',
'source' => '<string>',
'metadata' => [
]
]
],
'media' => [
[
'type' => '<string>',
'mime_type' => '<string>',
'url' => '<string>',
'base64' => '<string>',
'metadata' => [
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.promptguard.co/api/v1/guard"
payload := strings.NewReader("{\n \"messages\": [\n {\n \"role\": \"<string>\",\n \"content\": \"\"\n }\n ],\n \"direction\": \"input\",\n \"model\": \"<string>\",\n \"context\": {\n \"framework\": \"<string>\",\n \"chain_name\": \"<string>\",\n \"agent_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"tool_calls\": [\n {}\n ],\n \"metadata\": {}\n },\n \"retrieved_context\": [\n {\n \"content\": \"<string>\",\n \"source\": \"<string>\",\n \"metadata\": {}\n }\n ],\n \"media\": [\n {\n \"type\": \"<string>\",\n \"mime_type\": \"<string>\",\n \"url\": \"<string>\",\n \"base64\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.promptguard.co/api/v1/guard")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"messages\": [\n {\n \"role\": \"<string>\",\n \"content\": \"\"\n }\n ],\n \"direction\": \"input\",\n \"model\": \"<string>\",\n \"context\": {\n \"framework\": \"<string>\",\n \"chain_name\": \"<string>\",\n \"agent_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"tool_calls\": [\n {}\n ],\n \"metadata\": {}\n },\n \"retrieved_context\": [\n {\n \"content\": \"<string>\",\n \"source\": \"<string>\",\n \"metadata\": {}\n }\n ],\n \"media\": [\n {\n \"type\": \"<string>\",\n \"mime_type\": \"<string>\",\n \"url\": \"<string>\",\n \"base64\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.promptguard.co/api/v1/guard")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"messages\": [\n {\n \"role\": \"<string>\",\n \"content\": \"\"\n }\n ],\n \"direction\": \"input\",\n \"model\": \"<string>\",\n \"context\": {\n \"framework\": \"<string>\",\n \"chain_name\": \"<string>\",\n \"agent_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"tool_calls\": [\n {}\n ],\n \"metadata\": {}\n },\n \"retrieved_context\": [\n {\n \"content\": \"<string>\",\n \"source\": \"<string>\",\n \"metadata\": {}\n }\n ],\n \"media\": [\n {\n \"type\": \"<string>\",\n \"mime_type\": \"<string>\",\n \"url\": \"<string>\",\n \"base64\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"decision": "<string>",
"event_id": "<string>",
"confidence": 123,
"latency_ms": 123,
"threat_type": "<string>",
"redacted_messages": [
{
"role": "<string>",
"content": ""
}
],
"threats": [
{
"type": "<string>",
"confidence": 123,
"details": "<string>"
}
]
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>"
}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"input": "<unknown>",
"ctx": {}
}
]
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"current_plan": "<string>",
"requests_used": 123,
"requests_limit": 123,
"upgrade_url": "<string>",
"retry_after": 123
}
}Guard Content
Scan messages for security threats without proxying to an LLM.
This is the primary endpoint for auto-instrumentation and framework callback integrations. It runs the same policy engine, ML ensemble, preset configuration, custom rules, and entitlements checks as the proxy pipeline.
Use direction="input" before sending messages to the LLM and
direction="output" after receiving a response.
Returns a decision of allow, block, or redact along with
detailed threat information and optional redacted messages.
curl --request POST \
--url https://api.promptguard.co/api/v1/guard \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"messages": [
{
"role": "<string>",
"content": ""
}
],
"direction": "input",
"model": "<string>",
"context": {
"framework": "<string>",
"chain_name": "<string>",
"agent_id": "<string>",
"session_id": "<string>",
"tool_calls": [
{}
],
"metadata": {}
},
"retrieved_context": [
{
"content": "<string>",
"source": "<string>",
"metadata": {}
}
],
"media": [
{
"type": "<string>",
"mime_type": "<string>",
"url": "<string>",
"base64": "<string>",
"metadata": {}
}
]
}
'import requests
url = "https://api.promptguard.co/api/v1/guard"
payload = {
"messages": [
{
"role": "<string>",
"content": ""
}
],
"direction": "input",
"model": "<string>",
"context": {
"framework": "<string>",
"chain_name": "<string>",
"agent_id": "<string>",
"session_id": "<string>",
"tool_calls": [{}],
"metadata": {}
},
"retrieved_context": [
{
"content": "<string>",
"source": "<string>",
"metadata": {}
}
],
"media": [
{
"type": "<string>",
"mime_type": "<string>",
"url": "<string>",
"base64": "<string>",
"metadata": {}
}
]
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
messages: [{role: '<string>', content: ''}],
direction: 'input',
model: '<string>',
context: {
framework: '<string>',
chain_name: '<string>',
agent_id: '<string>',
session_id: '<string>',
tool_calls: [{}],
metadata: {}
},
retrieved_context: [{content: '<string>', source: '<string>', metadata: {}}],
media: [
{
type: '<string>',
mime_type: '<string>',
url: '<string>',
base64: '<string>',
metadata: {}
}
]
})
};
fetch('https://api.promptguard.co/api/v1/guard', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.promptguard.co/api/v1/guard",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'messages' => [
[
'role' => '<string>',
'content' => ''
]
],
'direction' => 'input',
'model' => '<string>',
'context' => [
'framework' => '<string>',
'chain_name' => '<string>',
'agent_id' => '<string>',
'session_id' => '<string>',
'tool_calls' => [
[
]
],
'metadata' => [
]
],
'retrieved_context' => [
[
'content' => '<string>',
'source' => '<string>',
'metadata' => [
]
]
],
'media' => [
[
'type' => '<string>',
'mime_type' => '<string>',
'url' => '<string>',
'base64' => '<string>',
'metadata' => [
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.promptguard.co/api/v1/guard"
payload := strings.NewReader("{\n \"messages\": [\n {\n \"role\": \"<string>\",\n \"content\": \"\"\n }\n ],\n \"direction\": \"input\",\n \"model\": \"<string>\",\n \"context\": {\n \"framework\": \"<string>\",\n \"chain_name\": \"<string>\",\n \"agent_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"tool_calls\": [\n {}\n ],\n \"metadata\": {}\n },\n \"retrieved_context\": [\n {\n \"content\": \"<string>\",\n \"source\": \"<string>\",\n \"metadata\": {}\n }\n ],\n \"media\": [\n {\n \"type\": \"<string>\",\n \"mime_type\": \"<string>\",\n \"url\": \"<string>\",\n \"base64\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.promptguard.co/api/v1/guard")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"messages\": [\n {\n \"role\": \"<string>\",\n \"content\": \"\"\n }\n ],\n \"direction\": \"input\",\n \"model\": \"<string>\",\n \"context\": {\n \"framework\": \"<string>\",\n \"chain_name\": \"<string>\",\n \"agent_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"tool_calls\": [\n {}\n ],\n \"metadata\": {}\n },\n \"retrieved_context\": [\n {\n \"content\": \"<string>\",\n \"source\": \"<string>\",\n \"metadata\": {}\n }\n ],\n \"media\": [\n {\n \"type\": \"<string>\",\n \"mime_type\": \"<string>\",\n \"url\": \"<string>\",\n \"base64\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.promptguard.co/api/v1/guard")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"messages\": [\n {\n \"role\": \"<string>\",\n \"content\": \"\"\n }\n ],\n \"direction\": \"input\",\n \"model\": \"<string>\",\n \"context\": {\n \"framework\": \"<string>\",\n \"chain_name\": \"<string>\",\n \"agent_id\": \"<string>\",\n \"session_id\": \"<string>\",\n \"tool_calls\": [\n {}\n ],\n \"metadata\": {}\n },\n \"retrieved_context\": [\n {\n \"content\": \"<string>\",\n \"source\": \"<string>\",\n \"metadata\": {}\n }\n ],\n \"media\": [\n {\n \"type\": \"<string>\",\n \"mime_type\": \"<string>\",\n \"url\": \"<string>\",\n \"base64\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"decision": "<string>",
"event_id": "<string>",
"confidence": 123,
"latency_ms": 123,
"threat_type": "<string>",
"redacted_messages": [
{
"role": "<string>",
"content": ""
}
],
"threats": [
{
"type": "<string>",
"confidence": 123,
"details": "<string>"
}
]
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>"
}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>",
"input": "<unknown>",
"ctx": {}
}
]
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"current_plan": "<string>",
"requests_used": 123,
"requests_limit": 123,
"upgrade_url": "<string>",
"retry_after": 123
}
}Authorizations
PromptGuard API key for developer endpoints. Keys start with pg_live_ and are created in the dashboard.
Headers
Body
Request body for the guard endpoint.
Messages to scan (OpenAI-style message array)
1Show child attributes
Show child attributes
Scan direction: 'input' (pre-LLM) or 'output' (post-LLM)
^(input|output)$Model being used (for logging)
Optional framework context
Show child attributes
Show child attributes
RAG-retrieved documents to scan for knowledge poisoning. Each document is individually scanned before being merged into the LLM prompt. Optional; backwards-compatible.
Show child attributes
Show child attributes
Media attachments to scan for steganographic payloads, adversarial patches, and font injection. Optional.
Show child attributes
Show child attributes
Response
Successful Response
Response from the guard endpoint.
Policy decision: 'allow', 'block', or 'redact'
Unique event identifier for tracking
Confidence score of the decision
Processing time in milliseconds
Primary threat type detected
Redacted messages (only present when decision='redact')
Show child attributes
Show child attributes
Detailed threat breakdown
Show child attributes
Show child attributes