> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.lakera.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server.

# API Overview

You can interact with the Guard API through HTTP requests to the available endpoints in any programming language. It is versioned via a URL path parameter, and the current version is `v2`.

```bash
https://api.lakera.ai/v2
```

## Available Endpoints

Working with the Guard API is as simple as making an HTTP request to any of the endpoints below:

* [`/guard`](/api-reference/lakera-api/guard/screen-content) - Request screening for text contents and receive a flagged response if any threats are detected
* [`/guard/results`](/api-reference/lakera-api/guard-results/get-results) - Request detailed results of detectors in order to understand Check Point AI Guardrails decisions and analyze policy suitability

> **Note**
>
> The `guard` endpoint screens agent interactions as well as user and LLM messages. Prompt attacks arriving through tool responses and tool descriptions, data leakage in tool calls, dangerous actions outside the agent's trusted mandate, and calls to denied tools are all screened according to your policy. See [Agent and Tool Integration](/docs/api/guard#agent-and-tool-integration) and [Agent Behavior Defense](/docs/agent-behavior-defense).

Additionally Enterprise SaaS customers can use the following Platform API endpoints to manage their security configuration:

* [`/policies`](/api-reference/platform-api/policies) - Create and manage AI Guardrails [policies](/docs/policies) via API
* [`/projects`](/api-reference/platform-api/projects) - Create and manage AI Guardrails [projects](/docs/projects) via API

Additionally self-hosting customers can use the following endpoints to check their AI Guardrails container deployment:

* [`/policies/health`](/api-reference/lakera-api/policies-health/check-policy-health) - Check the validity of the policy for a project
* [`/policies/lint`](/api-reference/lakera-api/policies-linter/lint-policy) - Check a policy file is valid
* [`/startupz`](/docs/api/k8s-probes#startup) - Implement a [startup probe](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes) for your K8s deployment
* [`/readyz`](/docs/api/k8s-probes#readiness) - Implement a [readiness probe](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes) for your K8s deployment
* [`/livez`](/docs/api/k8s-probes#liveness) - Implement a [liveness probe](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-a-liveness-http-request) for your K8s deployment

More details about each endpoint and any additional request or response parameters are available in the documentation for each endpoint linked above.

## Authentication

Self-hosted deployments of the Guard API do not use authorization so do not need API keys.

The public Guard SaaS API uses API keys to authenticate requests. You can view and manage your API keys in the [API access](https://platform.lakera.ai/account/api-keys) section of the AI Guardrails Dashboard.

Every API request must include your API key in the `Authorization` HTTP header:

```bash
Authorization: Bearer $LAKERA_GUARD_API_KEY
```

> **Warning**
>
> API keys are considered [secrets](https://www.cloudflare.com/learning/security/glossary/secrets-management/). Do not share them with other users or expose them in client-side code.

## Making Requests

You can make requests to the Guard API using any HTTP client.

#### Python

```python
import os
# requests library must be available in current Python environment
import requests

prompt = "Hello, world!"
session = requests.Session()  # Allows persistent connection

response = session.post(
    "https://api.lakera.ai/v2/guard",
    json={"messages": [{"role": "user", "content": prompt}]},
    headers={"Authorization": f'Bearer {os.getenv("LAKERA_GUARD_API_KEY")}'},
)

response_json = response.json()
print(response_json)
```

#### JavaScript

```javascript
const content = "Hello, world!";

fetch("https://api.lakera.ai/v2/guard", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "Authorization": `Bearer ${process.env.LAKERA_GUARD_API_KEY}`
  },
  body: JSON.stringify({
    messages: [
      { role: "user", content: content }
    ]
  })
})
  .then(response => response.json())
  .then(data => {
    console.log(data);
  })
  .catch(error => {
    console.error(error);
  });
```

#### cURL

```bash
curl https://api.lakera.ai/v2/guard \
  -X POST \
  -H "Authorization: Bearer $LAKERA_GUARD_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"messages": [{"role": "user", "content": "Hello, world!"}]}'
```

#### HTTPie

```bash
https POST api.lakera.ai/v2/guard \
  "Authorization:Bearer ${LAKERA_GUARD_API_KEY}" \
  messages:='[{"role": "user", "content": "Hello, world!"}]'
```

#### Other

```yaml
# For other languages, make an HTTP request with the following configuration:

Method: POST
URL: https://api.lakera.ai/v2/guard
Headers:
  - Authorization: Bearer $LAKERA_GUARD_API_KEY
  - Content-Type: application/json
Body:
  messages: [{"role": "user", "content": "Hello, world!"}]
```

## SaaS API Regions

The Guard SaaS API is available in multiple regions around the world. By default, requests to `https://api.lakera.ai` are sent to the region closest to you.

To pin processing to one place, use a regional endpoint:

* `https://eu.api.lakera.ai` (EU)
* `https://us.api.lakera.ai` (USA)
* `https://ap-southeast-1.api.lakera.ai` (Singapore, Asia)

You can also configure where your logs are stored and restrict which regions are allowed to process requests. See [Data Regions](/docs/data-regions) for details.

> **Warning**
>
> Changing the region will affect the latency of your requests. If you're unsure which region to choose, we recommend using `https://api.lakera.ai`.

## API Responses

The API response will be a JSON object. See the individual endpoint documentation for details.

### Developer Info

For relevant endpoints, you can request developer info to use in debugging by adding `"dev_info": true` to the request. The response will then include a JSON object with information about the build of AI Guardrails that generated the response containing the following properties:

* `git_revision`: First 8 characters of the [commit hash](https://docs.github.com/en/pull-requests/committing-changes-to-your-project/creating-and-editing-commits/about-commits#about-commits) of the build of AI Guardrails that sent the response
* `git_timestamp`: Timestamp of the commit in the [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format
* `model_version`: The model identifier string of the model type used for analysis. It is currently always `lakera-guard-1`, but new types of models may be introduced in the future
* `version`: The semantic version of AI Guardrails used. This tracks both code and detector model training updates