Scan API
For scripts, CI pipelines, and anything else that should check a prompt before it reaches an AI model.
The same endpoint every Redaxa surface uses is available to your own code. One call in, one decision out: the findings, a redacted version of the text, and the policy decision with its reason. The prompt is scanned and discarded — it is never stored, logged, or used for anything else.
Authentication
Create a dedicated API key from the dashboard: Preferences → API keys → Create API key. The key (psk_live_…) is shown exactly once — only a hash of it is stored, so it cannot be recovered, only revoked and replaced. Send it as a Bearer header. An active trial or subscription on the owning account is required to scan.
Up to 10 active keys per account; revoke any key from the same panel, effective immediately.
Scan a prompt
curl -s https://promptshield-beta.vercel.app/api/scan \
-H "Authorization: Bearer psk_live_..." \
-H "Content-Type: application/json" \
-d '{
"text": "Contact m.rossi@acme.com, api key sk_live_...",
"application": "api"
}'
Response (shape abbreviated):
{
"findings": [
{ "kind": "email", "category": "personal", "severity": "medium",
"label": "Email address", "value": "m.rossi@acme.com",
"replacement": "[EMAIL]" },
{ "kind": "secret", "category": "credentials", "severity": "critical", ... }
],
"redactedText": "Contact [EMAIL], api key [SECRET]",
"decision": {
"action": "redact",
"decidedBy": {
"ruleId": "default-credentials",
"ruleName": "Protect credentials",
"reason": "Passwords, API keys and private keys should never reach an AI model.",
"findingIndexes": [1]
},
"matched": [ ... ]
}
}
decision.actionis one ofallow,warn,redact,block— your organization's policies apply if you belong to one, the default policy otherwise. Serialized decisions reference findings by index only; they can never carry a sensitive value.application: "api"tags the audit event so your dashboard activity distinguishes pipeline checks from interactive ones. It grants nothing.- Optional
options:{"includePersonalData": true, "includeCredentials": true, "includeFinancialData": true, "customTerms": ["Project Falcon"]}. Organization protected terms are always applied on top. - Limits: prompts up to 20,000 characters; 120 checks per minute per account. Exceeding them returns
400/429with a plain-Englisherror.
Read your activity
curl -s https://promptshield-beta.vercel.app/api/scan \
-H "Authorization: Bearer psk_live_..."
Returns your last 50 scan events — metadata only (surface, detection kinds, decision). Organization owners and admins can add ?scope=org for the whole team's events. There is no endpoint that returns prompt content, because none is ever stored.
Honesty note
Before automating a check, read the practical guide to reducing and reviewing prompt content. A clean scan does not establish that material is safe or authorized to share.