openapi: 3.2.0 info: title: AppOmni AI Agent Guard API description: 'Marlin AI autonomous analysis plans and the AgentGuard prompt classification endpoint. Derived faithfully from the AppOmni public Postman collection published by AppOmni at https://api.appomni.com/ — every path, method, parameter, request body and example response below is taken verbatim from that collection. No operation was invented.' version: 1.0.0 contact: name: AppOmni url: https://appomni.com/support/ license: name: Proprietary url: https://appomni.com/terms-of-service/ x-generated-from: AppOmni public Postman collection (publishedId 2sBXc7Mjib) + AppOmni's published @appomni/n8n-nodes-agentguard source x-generated-source: https://api.appomni.com/api/collections/45135595/2sBXc7Mjib?segregateAuth=true&versionTag=latest x-generated-method: derived x-generated-date: '2026-09-04' servers: - url: https://{instance}.appomni.com description: AppOmni tenant. Replace {instance} with your AppOmni subdomain — e.g. `acme` if you log in at acme.appomni.com. variables: instance: default: example description: Your AppOmni tenant subdomain security: - bearerAuth: [] tags: - name: AgentGuard description: AppOmni AgentGuard runtime prompt security — DLP and prompt-firewall classification for AI agent traffic. paths: /api/v1/ai/prompts/agents/classify: post: operationId: classifyAgentPrompt summary: Classify an agent prompt (AgentGuard) tags: - AgentGuard description: 'Send a prompt to AppOmni AgentGuard for DLP and/or prompt-firewall analysis. Returns an allow/block verdict with per-classifier scores and block reasons. Authenticated with an AppOmni-issued ingest token in the `X-AppOmni-Ingest-Token` header (not the platform bearer token). Schema derived verbatim from AppOmni''s own published n8n community node source (github.com/appomni/n8n-nodes-agentguard, credentials/AgentGuardApi.credentials.ts and nodes/AgentGuard/Agentguard.node.ts).' security: - ingestToken: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AgentGuardClassifyRequest' example: messages: - role: user content: AppOmni AgentGuard credential test content_type: text/plain include_details: false responses: '200': description: Classification verdict content: application/json: schema: $ref: '#/components/schemas/AgentGuardClassifyResponse' '401': description: Unauthorized — missing or invalid ingest token content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: Error: type: object title: Error description: Standard Django REST Framework error envelope returned by the AppOmni API. properties: detail: type: string description: Human readable error message AgentGuardPrompt: type: object title: AgentGuardPrompt required: - role - content - content_type properties: role: type: string description: Message role, e.g. `user` or `system` content: type: string description: The prompt text to classify content_type: type: string description: Media type of `content` example: text/plain AgentGuardClassifyResponse: type: object title: AgentGuardClassifyResponse required: - response_action - response_message - scores - block_reasons - classifiers - effective_threshold properties: response_action: type: string enum: - allow - block description: Verdict — `block` means the prompt must not be forwarded to the model response_message: type: string scores: type: object properties: benign: type: number malicious: type: number block_reasons: type: array items: type: string classifiers: type: array items: $ref: '#/components/schemas/AgentGuardClassifierResult' effective_threshold: type: number event_id: type: string AgentGuardClassifyRequest: type: object title: AgentGuardClassifyRequest required: - messages properties: messages: type: array items: $ref: '#/components/schemas/AgentGuardPrompt' include_details: type: boolean description: Return per-classifier detail in the response metadata: type: object title: AgentGuardClassifyMetadata description: Optional caller context used for attribution and user quarantine properties: user: type: object properties: id: type: string username: type: string email: type: string principal_type: type: string session: type: object properties: id: type: string agent: type: object properties: id: type: string name: type: string request: type: object properties: src_app: type: string interface: type: string user_agent: type: string src_ip: type: string AgentGuardClassifierResult: type: object title: AgentGuardClassifierResult properties: name: type: string type: type: string status: type: string enum: - success - timeout - error - skipped duration_ms: type: integer applied_threshold: type: number scores: type: object properties: benign: type: number malicious: type: number block_reasons: type: array items: type: string details: type: object additionalProperties: true error: type: string skip_reason: type: string securitySchemes: bearerAuth: type: http scheme: bearer description: 'AppOmni API access token, created and managed in the AppOmni platform under Settings > API Settings. Sent as `Authorization: Bearer `.' ingestToken: type: apiKey in: header name: X-AppOmni-Ingest-Token description: AppOmni-issued ingest token used by AgentGuard and the AODP ingest endpoint. Sent as the `X-AppOmni-Ingest-Token` request header.