> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.lakera.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server.

# Deployment

How to deploy the SDK in a production or regulated environment.

## Network requirements

| Requirement      | Value                    |
| ---------------- | ------------------------ |
| Direction        | Outbound only            |
| Protocol         | HTTPS (TLS 1.2+)         |
| Destination      | `red-webhooks.lakera.ai` |
| Port             | 443                      |
| Inbound exposure | None                     |

If your network restricts outbound destinations, allow `red-webhooks.lakera.ai` on port
443 in your egress allowlist (firewall, proxy, or security group). If your policy
requires IP-based rules instead, the endpoint is hosted on Convex — see the
[Convex networking documentation](https://docs.convex.dev/production/networking) for the
current ranges.

> **Note**
>
> `red-webhooks.lakera.ai` is the only outbound destination required by the SDK itself.
> Your handler may also call your own agent endpoint — that traffic stays inside your
> network and does not need to traverse your egress controls.

## Running behind a corporate proxy

If your network forces outbound traffic through a corporate egress proxy, set the usual
proxy environment variables before the SDK process starts:

#### TypeScript

The SDK uses Node.js's standard `fetch`:

```bash
export HTTPS_PROXY=http://proxy.internal.corp:8080
export NO_PROXY=localhost,127.0.0.1,.internal.corp
```

#### Python

The SDK uses `httpx`, which respects standard proxy environment variables:

```bash
export HTTPS_PROXY=http://proxy.internal.corp:8080
export NO_PROXY=localhost,127.0.0.1,.internal.corp
```

`NO_PROXY` should include any local hostnames your agent lives on so that the in-network
call from your handler to your agent skips the proxy.

### TLS interception

If your proxy performs TLS interception (a "break-and-inspect" proxy that re-signs
traffic with a corporate CA), the SDK's outbound calls to `red-webhooks.lakera.ai` need
to trust that CA:

#### TypeScript

```bash
export NODE_EXTRA_CA_CERTS=/etc/ssl/certs/corp-root-ca.pem
```

If certificate validation fails you'll see errors like `UNABLE_TO_VERIFY_LEAF_SIGNATURE`
or `SELF_SIGNED_CERT_IN_CHAIN` in the SDK's logs. That almost always means
`NODE_EXTRA_CA_CERTS` is missing or points at the wrong bundle.

#### Python

```bash
export SSL_CERT_FILE=/etc/ssl/certs/corp-root-ca.pem
```

Alternatively, pass the CA bundle path via `httpx` configuration or set
`REQUESTS_CA_BUNDLE`.

If certificate validation fails you'll see `SSLCertVerificationError` in the SDK's logs.
That almost always means `SSL_CERT_FILE` is missing or points at the wrong bundle.

## Runtime

The SDK is a single process — no listening sockets, no persistent state, no required
sidecars. It is I/O-bound with a minimal memory footprint. Pass your Red Team API Key
via the `LAKERA_RED_API_KEY` environment variable; the SDK does not write the key to
disk or log it.

#### TypeScript

| Requirement       | Value                                                           |
| ----------------- | --------------------------------------------------------------- |
| Node.js           | 22 or later                                                     |
| OS                | Any platform Node 22 supports (Linux, macOS, Windows)           |
| Footprint         | Single Node process. No persistent state, no listening sockets. |
| Concurrency model | One process per scan run is sufficient                          |

#### Python

| Requirement       | Value                                                              |
| ----------------- | ------------------------------------------------------------------ |
| Python            | 3.11 or later                                                      |
| OS                | Any platform Python 3.11 supports (Linux, macOS, Windows)          |
| Footprint         | Single Python process. No persistent state, no listening sockets.  |
| Concurrency model | One process per scan run is sufficient (uses `asyncio` internally) |

### Container deployments

#### TypeScript

No special setup is required beyond a Node 22 base image. If your image needs to trust a
corporate CA (for TLS interception or air-gapped mirrors), set `NODE_EXTRA_CA_CERTS` in
the container environment.

#### Python

No special setup is required beyond a Python 3.11+ base image. If your image needs to
trust a corporate CA (for TLS interception or air-gapped mirrors), set `SSL_CERT_FILE`
in the container environment.

## How the SDK connects

The SDK uses a poll-based model. A process running inside your network opens an outbound
HTTPS connection to `red-webhooks.lakera.ai`, pulls attack prompts over it, forwards
each prompt to your agent via a local call, and returns the agent's response on the same
connection.

```
Your network               │   Check Point
                           │
┌─────────────────┐        │
│  Your agent     │        │
└────────▲────────┘        │
         │ local call      │
┌────────▼────────┐        │   outbound HTTPS    ┌────────────────┐
│  Red SDK        ├────────┼────────────────────►│  red-webhooks  │
│  (your host)    │◄───────┼─────────────────────┤  .lakera.ai    │
└─────────────────┘        │   (same session)    └────────────────┘
                           │
                  network boundary
```

* **No inbound connections.** Nothing listens on a port. Nothing accepts traffic
  initiated by Check Point. Your firewall rules only need to permit outbound HTTPS to a
  single hostname.
* **Your agent URL stays internal.** The SDK calls your agent from inside your handler,
  using whatever URL or in-process call you wire up. That URL is never sent to Check
  Point and never crosses the network boundary.

The diagram shows the scan driver. If you enable
[tool tracing](/docs/red/trace-agent-tools), your agent runtime also sends each traced
tool's name, arguments, and result to `red-webhooks.lakera.ai` over outbound HTTPS. Give
that runtime access to the same endpoint. Red returns the value your agent should use;
during a tool response poisoning scan, it may contain an injected payload.

## Next steps

* [SDK Quickstart](/docs/red/sdk-quickstart) — run your first scan
* [SDK Reference](/docs/red/sdk-reference) — full configuration