Pangea AI Guard API

Detect and redact malicious content in LLM inputs and outputs.

Documentation

Specifications

Other Resources

OpenAPI Specification

pangea-ai-guard-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Pangea Security Services AI Guard API
  description: Specification of representative Pangea security service APIs. Pangea exposes each security capability as its own REST service reachable at https://{service}.{csp}.{geo}.pangea.cloud (for example https://redact.aws.us.pangea.cloud). All requests are POST with a JSON body and are authenticated with a Bearer service token (or OAuth 2 access token) in the Authorization header. This document models several representative services - AuthN, Secure Audit Log, Redact, Vault, File Scan, IP Intel, Domain Intel, and AI Guard - and is not exhaustive of every endpoint or field.
  termsOfService: https://pangea.cloud/legal/terms-of-service/
  contact:
    name: Pangea Support
    url: https://pangea.cloud/contact/
  version: '1.0'
servers:
- url: https://{service}.{csp}.{geo}.pangea.cloud
  description: Per-service Pangea host. Each service is reached at its own subdomain.
  variables:
    service:
      default: redact
      description: Service name (authn, audit, redact, vault, file-scan, ip-intel, domain-intel, ai-guard).
    csp:
      default: aws
      description: Cloud service provider hosting the service.
    geo:
      default: us
      description: Geographic region (us, eu).
security:
- bearerAuth: []
tags:
- name: AI Guard
  description: Detect and redact malicious content in LLM inputs and outputs.
paths:
  /v1/text/guard:
    servers:
    - url: https://ai-guard.{csp}.{geo}.pangea.cloud
      variables:
        csp:
          default: aws
        geo:
          default: us
    post:
      operationId: aiGuardText
      tags:
      - AI Guard
      summary: Guard LLM text.
      description: Detect, remove, or block malicious content and intent in LLM inputs and outputs to prevent model manipulation and data leakage.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AiGuardRequest'
      responses:
        '200':
          description: Guard result.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AiGuardResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    PangeaResponse:
      type: object
      description: Standard Pangea response envelope wrapping every service result.
      properties:
        request_id:
          type: string
        request_time:
          type: string
          format: date-time
        response_time:
          type: string
          format: date-time
        status:
          type: string
          example: Success
        summary:
          type: string
        result:
          type: object
    AiGuardResponse:
      allOf:
      - $ref: '#/components/schemas/PangeaResponse'
      - type: object
        properties:
          result:
            type: object
            properties:
              blocked:
                type: boolean
              transformed:
                type: boolean
              recipe:
                type: string
              detectors:
                type: object
                description: Per-detector analysis (prompt_injection, pii, secrets, malicious_entity).
              prompt_text:
                type: string
    AiGuardRequest:
      type: object
      properties:
        text:
          type: string
          description: Plain text input (up to 20 KiB).
        messages:
          type: array
          items:
            type: object
            properties:
              role:
                type: string
              content:
                type: string
        recipe:
          type: string
          default: pangea_prompt_guard
        debug:
          type: boolean
          default: false
  responses:
    Unauthorized:
      description: Missing or invalid authentication token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PangeaResponse'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Pangea service token or OAuth 2 access token passed as a Bearer token.