openapi: 3.0.1 info: title: LLM Guard Output API description: Self-hostable REST API for LLM Guard, Protect AI's open-source (Apache 2.0) security toolkit for LLM interactions. The llm-guard-api service wraps the llm-guard Python library in a FastAPI application and exposes scanners that detect, redact, and sanitize prompts and outputs for prompt injection, PII, toxicity, secrets, banned topics, and more. Scanners are configured per deployment via scanners.yml. This specification documents the real self-hosted API surface; Protect AI's commercial products (Guardian, Recon, Layer) do not publish a public REST API and are not modeled here. termsOfService: https://protectai.com/terms contact: name: Protect AI / LLM Guard url: https://llm-guard.com/ license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 version: '1.0' servers: - url: http://localhost:8000 description: Default local llm-guard-api deployment (FastAPI/Uvicorn). security: - bearerAuth: [] - {} tags: - name: Output paths: /analyze/output: post: operationId: analyzeOutput tags: - Output summary: Analyze and sanitize an output. description: Runs the configured output scanners over the LLM response (with the originating prompt for context) and returns the sanitized output, an overall validity flag, and per-scanner risk scores. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AnalyzeOutputRequest' responses: '200': description: Output analyzed. content: application/json: schema: $ref: '#/components/schemas/AnalyzeOutputResponse' '400': description: Invalid request. '403': description: Authentication failed. /scan/output: post: operationId: scanOutput tags: - Output summary: Scan an output. description: Runs the configured output scanners over the LLM response (with the originating prompt for context) and returns the validity flag and per-scanner risk scores without returning a modified output. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ScanOutputRequest' responses: '200': description: Output scanned. content: application/json: schema: $ref: '#/components/schemas/ScanOutputResponse' '400': description: Invalid request. '403': description: Authentication failed. components: schemas: ScanOutputResponse: type: object properties: is_valid: type: boolean scanners: type: object additionalProperties: type: number format: float AnalyzeOutputResponse: type: object properties: sanitized_output: type: string is_valid: type: boolean scanners: type: object additionalProperties: type: number format: float ScanOutputRequest: type: object required: - prompt - output properties: prompt: type: string output: type: string scanners_suppress: type: array items: type: string AnalyzeOutputRequest: type: object required: - prompt - output properties: prompt: type: string description: The originating prompt, used by output scanners for context. output: type: string description: The LLM response to analyze and sanitize. scanners_suppress: type: array items: type: string securitySchemes: bearerAuth: type: http scheme: bearer description: Optional bearer token authentication, enabled per deployment via the llm-guard-api configuration. Deployments may also run without auth.