← Redaxa

Scan API

For scripts, CI pipelines, and anything else that should check a prompt before it reaches an AI model.

The same endpoint every Redaxa surface uses is available to your own code. One call in, one decision out: the findings, a redacted version of the text, and the policy decision with its reason. The prompt is scanned and discarded — it is never stored, logged, or used for anything else.

Authentication

Create a dedicated API key from the dashboard: Preferences → API keys → Create API key. The key (psk_live_…) is shown exactly once — only a hash of it is stored, so it cannot be recovered, only revoked and replaced. Send it as a Bearer header. An active trial or subscription on the owning account is required to scan.

Up to 10 active keys per account; revoke any key from the same panel, effective immediately.

Scan a prompt

curl -s https://promptshield-beta.vercel.app/api/scan \
  -H "Authorization: Bearer psk_live_..." \
  -H "Content-Type: application/json" \
  -d '{
    "text": "Contact m.rossi@acme.com, api key sk_live_...",
    "application": "api"
  }'

Response (shape abbreviated):

{
  "findings": [
    { "kind": "email", "category": "personal", "severity": "medium",
      "label": "Email address", "value": "m.rossi@acme.com",
      "replacement": "[EMAIL]" },
    { "kind": "secret", "category": "credentials", "severity": "critical", ... }
  ],
  "redactedText": "Contact [EMAIL], api key [SECRET]",
  "decision": {
    "action": "redact",
    "decidedBy": {
      "ruleId": "default-credentials",
      "ruleName": "Protect credentials",
      "reason": "Passwords, API keys and private keys should never reach an AI model.",
      "findingIndexes": [1]
    },
    "matched": [ ... ]
  }
}

Read your activity

curl -s https://promptshield-beta.vercel.app/api/scan \
  -H "Authorization: Bearer psk_live_..."

Returns your last 50 scan events — metadata only (surface, detection kinds, decision). Organization owners and admins can add ?scope=org for the whole team's events. There is no endpoint that returns prompt content, because none is ever stored.

Honesty note

Before automating a check, read the practical guide to reducing and reviewing prompt content. A clean scan does not establish that material is safe or authorized to share.