Organizations
The team's customers, as requests name them.
GET/organizations
List organizationsPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
suspendedquery | boolean |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "organization",
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"plan": "pro",
"suspended": false,
"state": "active",
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/organizations
Create an organizationPermission: manage
Organizations are also created by the first request that names them. Creating one first sets its name and metadata before any traffic.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
OrganizationCreate
Responses
Example request body
{
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"}
}
Example response · 201
{
"object": "organization",
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"plan": "pro",
"suspended": false,
"state": "active",
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/organizations/{id}
Get an organizationPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | OrganizationId |
|---|
Responses
Example response · 200
{
"object": "organization",
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"plan": "pro",
"suspended": false,
"state": "active",
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/organizations/{id}
Update an organizationPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | OrganizationId |
|---|
Body
OrganizationUpdate
Responses
Example request body
{"name": "Acme", "metadata": {"tier": "enterprise"}}
Example response · 200
{
"object": "organization",
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"plan": "pro",
"suspended": false,
"state": "active",
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
DELETE/organizations/{id}
Delete an organizationPermission: manage
Destroys the organization's key at once, which makes its content, attachments and pseudonyms unreadable, then a job removes the rest. Its key leaves backups within 7 days. Records keep a keyed hash in place of its id.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | OrganizationId |
|---|
Responses
Example response · 202
{
"object": "organization",
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"plan": "pro",
"suspended": false,
"state": "active",
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/organizations/external_id/{external_id}
Get an organization by the team's identifierPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
external_idpath, required | ExternalId |
|---|
Responses
Example response · 200
{
"object": "organization",
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"plan": "pro",
"suspended": false,
"state": "active",
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
Users
The people or accounts in the team's product that requests are made for.
GET/users
List usersPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
organization_idquery | OrganizationId |
|---|
suspendedquery | boolean |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "user",
"id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"suspended": false,
"signals": [
{
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"score": 0.5
}
],
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/users
Create a userPermission: manage
Users are also created by the first request that names them.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
UserCreate
Responses
Example request body
{
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"}
}
Example response · 201
{
"object": "user",
"id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"suspended": false,
"signals": [
{
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"score": 0.5
}
],
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/users/{id}
Get a userPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | UserId |
|---|
Responses
Example response · 200
{
"object": "user",
"id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"suspended": false,
"signals": [
{
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"score": 0.5
}
],
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/users/{id}
Update a userPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | UserId |
|---|
Body
UserUpdate
Responses
Example request body
{"name": "Acme", "metadata": {"tier": "enterprise"}}
Example response · 200
{
"object": "user",
"id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"suspended": false,
"signals": [
{
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"score": 0.5
}
],
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/users/external_id/{external_id}
Get a user by the team's identifierPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
external_idpath, required | ExternalId |
|---|
Responses
Example response · 200
{
"object": "user",
"id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme",
"name": "Acme",
"metadata": {"tier": "enterprise"},
"suspended": false,
"signals": [
{
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"score": 0.5
}
],
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/related_users
Users who share prompt templates with a userPermission: read
Users whose requests share template fingerprints with this user's, most shared first.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
user_idquery, required | UserId |
|---|
limitquery | integer |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "related_user",
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"shared_fingerprints": 1
}
],
"list_metadata": {"before": null, "after": null}
}
GET/organization_memberships
List which users have made requests for which organizationsPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
organization_idquery | OrganizationId |
|---|
user_idquery | UserId |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "organization_membership",
"id": "om_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"first_seen_at": "2026-09-29T14:02:11.482Z",
"last_seen_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
Suspensions
Blocking a user's or an organization's requests.
GET/suspensions
List suspensionsPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
organization_idquery | OrganizationId |
|---|
user_idquery | UserId |
|---|
activequery | booleanOnly suspensions in force, or only lifted and expired ones.
|
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "suspension",
"id": "suspension_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"reason": "Set by our scripts.",
"note": "Set by our scripts.",
"created_by": {
"type": "member",
"id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"
},
"created_at": "2026-09-29T14:02:11.482Z",
"expires_at": null,
"lifted_at": null,
"lifted_by": null
}
],
"list_metadata": {"before": null, "after": null}
}
POST/suspensions
Suspend a user or an organizationPermission: manage
Every gateway task refuses the suspended party's next request, within 10 seconds.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
SuspensionCreate
Responses
Example request body
{
"user_id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"reason": "abuse",
"note": "Scraping answers at volume.",
"expires_at": "2026-10-09T00:00:00.000Z"
}
Example response · 201
{
"object": "suspension",
"id": "suspension_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"reason": "Set by our scripts.",
"note": "Set by our scripts.",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"expires_at": null,
"lifted_at": null,
"lifted_by": null
}
GET/suspensions/{id}
Get a suspensionPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | SuspensionId |
|---|
Responses
Example response · 200
{
"object": "suspension",
"id": "suspension_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"reason": "Set by our scripts.",
"note": "Set by our scripts.",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"expires_at": null,
"lifted_at": null,
"lifted_by": null
}
POST/suspensions/{id}/lift
Lift a suspensionPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
idpath, required | SuspensionId |
|---|
Responses
Example response · 200
{
"object": "suspension",
"id": "suspension_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"reason": "Set by our scripts.",
"note": "Set by our scripts.",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"expires_at": null,
"lifted_at": null,
"lifted_by": null
}
Policies
Matches and settings, and how they combine.
GET/policies
List policiesPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "policy",
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
},
"version": 1,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/policies
Create a policyPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
PolicyCreate
Responses
Example request body
{
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
}
}
Example response · 201
{
"object": "policy",
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
},
"version": 1,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/policies/{id}
Get a policyPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | PolicyId |
|---|
Responses
Example response · 200
{
"object": "policy",
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
},
"version": 1,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/policies/{id}
Update a policyPermission: manage
Each change makes a new version. The body merges like every PATCH, settings included, except match: when given, it replaces the whole match, so send every field the policy should still match on. A merge would read a null in it as "clear this field" and widen the policy to requests it never matched.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | PolicyId |
|---|
Body
PolicyUpdate
Responses
Example request body
{
"settings": {
"limits": {
"spend": [{"per": "user", "period": "day", "amount": "1.00"}]
}
}
}
Example response · 200
{
"object": "policy",
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
},
"version": 1,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
DELETE/policies/{id}
Delete a policyPermission: manage
Its versions are kept, so requests that matched it still explain themselves.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | PolicyId |
|---|
Responses
Example response · 200
{
"object": "policy",
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
},
"version": 1,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/policies/{id}/versions
List a policy's versionsPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | PolicyId |
|---|
limitquery | integer |
|---|
orderquery | "asc" | "desc" |
|---|
beforequery | integer |
|---|
afterquery | integer |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "policy_version",
"policy_id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"version": 1,
"name": "Acme",
"match": {"organization": "globex"},
"settings": {
"routing": {
"connections": ["own", "environment"],
"regions": ["eu", "global"],
"models": ["claude-sonnet-5-5", "claude-haiku-4-5"],
"data_terms": {"retention": "zero", "training": "no"}
},
"retention": {"content": "none"},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 60}],
"spend": [
{"per": "user", "period": "day", "amount": "2.00"},
{
"per": "organization",
"period": "month",
"amount": "500.00"
}
]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {
"action": "pseudonymize",
"mode": "enforce",
"parts": ["user", "tool_result"],
"kinds": ["email", "phone"],
"exclusions": ["support@acme.example"]
},
"prompt_injection": {
"action": "cut",
"mode": "enforce",
"parts": ["tool_result"]
},
"illegal_content": {"action": "block", "mode": "monitor"}
},
"uninspected": "allow",
"abuse": {"suspend_at": 0.9}
},
"deleted": false,
"created_by": {
"type": "member",
"id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"
},
"created_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
GET/effective_policy
The effective policy for an identityPermission: read
Combines every policy that matches the identity, as the gateway would for a request carrying these values in its Alectura-* headers. An omitted parameter means the header is absent.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
organizationquery | ExternalId |
|---|
userquery | ExternalId |
|---|
planquery | ExternalId |
|---|
Responses
Example response · 200
{
"object": "effective_policy",
"identity": {"organization": "acme", "user": "user_42", "plan": "pro"},
"policies": [{"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T", "version": 1}],
"settings": {
"routing": {
"connections": ["own", "environment"],
"regions": ["eu", "global"],
"models": ["claude-sonnet-5-5", "claude-haiku-4-5"],
"data_terms": {"retention": "zero", "training": "no"}
},
"retention": {"content": "none"},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 60}],
"spend": [
{"per": "user", "period": "day", "amount": "2.00"},
{
"per": "organization",
"period": "month",
"amount": "500.00"
}
]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {
"action": "pseudonymize",
"mode": "enforce",
"parts": ["user", "tool_result"],
"kinds": ["email", "phone"],
"exclusions": ["support@acme.example"]
},
"prompt_injection": {
"action": "cut",
"mode": "enforce",
"parts": ["tool_result"]
},
"illegal_content": {"action": "block", "mode": "monitor"}
},
"uninspected": "allow",
"abuse": {"suspend_at": 0.9}
},
"sources": {"routing.regions": ["policy_01M3PQG7FEV8Q4X0M5R7T9W2YA"]}
}
Connections
Ways to reach a model provider.
GET/connections
List connectionsPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
organization_idquery | OrganizationIdOnly the connections this organization owns.
|
|---|
providerquery | Provider |
|---|
statequery | ConnectionState |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "connection",
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "OpenAI EU",
"provider": "openai",
"owner": {"type": "environment"},
"base_url": "https://eu.api.openai.com/v1",
"aws_region": null,
"inference_profile": null,
"region": "eu",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "hint": "Qk3x"},
"aws_external_id": null,
"state": "draft",
"cooling_down_until": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/connections
Create a connectionPermission: manage
A new connection is a draft, and routes nothing until it is activated.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
ConnectionCreate
Responses
Example request body
{
"name": "OpenAI EU",
"provider": "openai",
"base_url": "https://eu.api.openai.com/v1",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "api_key": "sk-proj-…"}
}
Example response · 201
{
"object": "connection",
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "OpenAI EU",
"provider": "openai",
"owner": {"type": "environment"},
"base_url": "https://eu.api.openai.com/v1",
"aws_region": null,
"inference_profile": null,
"region": "eu",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "hint": "Qk3x"},
"aws_external_id": null,
"state": "draft",
"cooling_down_until": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/connections/{id}
Get a connectionPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ConnectionId |
|---|
Responses
Example response · 200
{
"object": "connection",
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "OpenAI EU",
"provider": "openai",
"owner": {"type": "environment"},
"base_url": "https://eu.api.openai.com/v1",
"aws_region": null,
"inference_profile": null,
"region": "eu",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "hint": "Qk3x"},
"aws_external_id": null,
"state": "draft",
"cooling_down_until": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/connections/{id}
Update, activate or disable a connectionPermission: manage
Setting state to active runs the connection's test first, and fails with 422 connection_test_failed, listing the failed checks, unless every check passes. Replacing the credential of an active connection tests the new one the same way before it is used.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ConnectionId |
|---|
Body
ConnectionUpdate
Responses
Example request body
{
"name": "Acme",
"models": ["models"],
"data_terms": {"retention": "undeclared", "training": "undeclared"},
"credential": {"type": "api_key", "api_key": "sk-proj-…"},
"state": "draft"
}
Example response · 200
{
"object": "connection",
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "OpenAI EU",
"provider": "openai",
"owner": {"type": "environment"},
"base_url": "https://eu.api.openai.com/v1",
"aws_region": null,
"inference_profile": null,
"region": "eu",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "hint": "Qk3x"},
"aws_external_id": null,
"state": "draft",
"cooling_down_until": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
DELETE/connections/{id}
Delete a connectionPermission: manage
Its credential is destroyed. Requests that used it keep its id.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ConnectionId |
|---|
Responses
Example response · 200
{
"object": "connection",
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "OpenAI EU",
"provider": "openai",
"owner": {"type": "environment"},
"base_url": "https://eu.api.openai.com/v1",
"aws_region": null,
"inference_profile": null,
"region": "eu",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "hint": "Qk3x"},
"aws_external_id": null,
"state": "draft",
"cooling_down_until": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
POST/connections/{id}/test
Test a connectionPermission: manage
Sends a small request for each of the connection's models and checks the answers, without changing the connection's state.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ConnectionId |
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Responses
Example response · 200
{
"object": "connection_test",
"connection_id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"passed": false,
"checks": [
{
"name": "Acme",
"passed": false,
"reason": "Set by our scripts.",
"message": "The provider answered 401.",
"upstream_status": 1
}
],
"created_at": "2026-09-29T14:02:11.482Z"
}
Content store
Where content kept under team retention goes, in the team's own AWS account.
GET/content_store
Get the content storePermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Responses
Example response · 200
{
"object": "content_store",
"bucket": "acme-alectura-content",
"region": "eu-west-1",
"prefix": "alectura/",
"role_arn": "arn:aws:iam::123456789012:role/alectura-content",
"external_id": "acme",
"state": "draft",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
POST/content_store
Set the content storePermission: manage
Sets where the environment's team-held content goes, replacing the store it had. A new store, or one whose bucket, region, prefix or role changed, is a draft, and takes no content until its test passes. The environment's external id stays the same across changes. The bucket's region must be in the environment's own region (R20), such as eu-central-1 for an eu environment; any other is refused with 422 validation_failed, code outside_region.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
ContentStoreSet
Responses
Example request body
{
"bucket": "acme-alectura-content",
"region": "eu-west-1",
"prefix": "alectura/",
"role_arn": "arn:aws:iam::123456789012:role/alectura-content"
}
Example response · 200
{
"object": "content_store",
"bucket": "acme-alectura-content",
"region": "eu-west-1",
"prefix": "alectura/",
"role_arn": "arn:aws:iam::123456789012:role/alectura-content",
"external_id": "acme",
"state": "draft",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
DELETE/content_store
Remove the content storePermission: manage
From now on, content kept under team retention is kept nowhere. What the store holds stays there, the team's to keep or delete; Alectura reads none of it any more.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Responses
Example response · 200
{
"object": "content_store",
"bucket": "acme-alectura-content",
"region": "eu-west-1",
"prefix": "alectura/",
"role_arn": "arn:aws:iam::123456789012:role/alectura-content",
"external_id": "acme",
"state": "draft",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
POST/content_store/test
Test the content storePermission: manage
Assumes the store's role with the environment's external id, then writes, reads and deletes {prefix}{environment}/alectura-test in its bucket. When that works, the store becomes active.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Responses
Example response · 200
{
"object": "content_store_test",
"passed": false,
"message": "The provider answered 401.",
"content_store": {
"object": "content_store",
"bucket": "acme-alectura-content",
"region": "eu-west-1",
"prefix": "alectura/",
"role_arn": "arn:aws:iam::123456789012:role/alectura-content",
"external_id": "acme",
"state": "draft",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
}
API keys
Sending keys for the gateway, and management keys for this API.
GET/api_keys
List API keysPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
typequery | ApiKeyType |
|---|
statequery | ApiKeyState |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "api_key",
"id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"type": "sending",
"permissions": ["send"],
"label": "sk-alectura-eu-live-…2Yl4IC",
"state": "active",
"expires_at": null,
"previous_secret_expires_at": "2026-09-29T14:02:11.482Z",
"created_by": {
"type": "member",
"id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"
},
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/api_keys
Create an API keyPermission: manage
The response is the only time the secret is shown. A retry with the same Idempotency-Key returns the key without its secret; rotate it to get a new one.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
ApiKeyCreate
Responses
Example request body
{
"name": "Acme",
"type": "sending",
"permissions": ["read"],
"expires_at": "2026-09-29T14:02:11.482Z"
}
Example response · 201
{
"object": "api_key",
"id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"type": "sending",
"permissions": ["send"],
"label": "sk-alectura-eu-live-…2Yl4IC",
"state": "active",
"expires_at": null,
"previous_secret_expires_at": "2026-09-29T14:02:11.482Z",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z",
"secret": "sk-alectura-eu-live-0123456789abcdefghijABCDEFGHIJ01234567892Yl4IC"
}
GET/api_keys/{id}
Get an API keyPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ApiKeyId |
|---|
Responses
Example response · 200
{
"object": "api_key",
"id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"type": "sending",
"permissions": ["send"],
"label": "sk-alectura-eu-live-…2Yl4IC",
"state": "active",
"expires_at": null,
"previous_secret_expires_at": "2026-09-29T14:02:11.482Z",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/api_keys/{id}
Rename, disable, enable or set the expiry of an API keyPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ApiKeyId |
|---|
Body
ApiKeyUpdate
Responses
Example request body
{"name": "Acme", "state": "active", "expires_at": null}
Example response · 200
{
"object": "api_key",
"id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"type": "sending",
"permissions": ["send"],
"label": "sk-alectura-eu-live-…2Yl4IC",
"state": "active",
"expires_at": null,
"previous_secret_expires_at": "2026-09-29T14:02:11.482Z",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
DELETE/api_keys/{id}
Revoke an API keyPermission: manage
Every gateway task refuses the key within 10 seconds. A revoked key can't be restored.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ApiKeyId |
|---|
Responses
Example response · 200
{
"object": "api_key",
"id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"type": "sending",
"permissions": ["send"],
"label": "sk-alectura-eu-live-…2Yl4IC",
"state": "active",
"expires_at": null,
"previous_secret_expires_at": "2026-09-29T14:02:11.482Z",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
POST/api_keys/{id}/rotate
Rotate an API key's secretPermission: manage
Gives the key a new secret. The old secret keeps working for the grace period, so servers can move over without downtime.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
idpath, required | ApiKeyId |
|---|
Body
grace_period_seconds | integer |
|---|
Responses
Example request body
{"grace_period_seconds": 86400}
Example response · 200
{
"object": "api_key",
"id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"type": "sending",
"permissions": ["send"],
"label": "sk-alectura-eu-live-…2Yl4IC",
"state": "active",
"expires_at": null,
"previous_secret_expires_at": "2026-09-29T14:02:11.482Z",
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z",
"secret": "sk-alectura-eu-live-0123456789abcdefghijABCDEFGHIJ01234567892Yl4IC"
}
Requests
What each request did, and its content.
GET/requests
List requestsPermission: read
About 2 seconds behind the gateway. Poll with after and order=asc for a live tail.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
organization_idquery | OrganizationId |
|---|
user_idquery | UserId |
|---|
conversation_idquery | ConversationId |
|---|
verdictquery | Verdict |
|---|
modelquery | string |
|---|
connection_idquery | ConnectionId |
|---|
policy_idquery | PolicyId |
|---|
guardrailquery | GuardrailOnly requests with a finding from this guardrail.
|
|---|
created_afterquery | string (date-time) |
|---|
created_beforequery | string (date-time) |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "request",
"id": "req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"state": "pending",
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null,
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"plan": "pro",
"conversation_id": "conv_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"api_key_id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"endpoint": "openai.chat_completions",
"model": "claude-sonnet-5-5",
"stream": false,
"status": 1,
"verdict": "passed",
"refusal": {"code": "user_suspended"},
"connection": {
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"provider": "openai",
"region": "us"
},
"attempts": [
{
"connection": {
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"provider": "openai",
"region": "us"
},
"started_at": "2026-09-29T14:02:11.482Z",
"status": 1,
"error": null,
"duration_ms": 0.5
}
],
"policies": [
{
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"version": 1
}
],
"findings": [
{
"object": "finding",
"id": "finding_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"guardrail": "secrets",
"kind": "injection_attempts",
"action": "record",
"mode": "monitor",
"applied": false,
"block": 1,
"part": "system"
}
],
"coverage": [
{
"block": 1,
"part": "system",
"modality": "text",
"inspected_by": ["secrets"],
"reason": "images_uninspected"
}
],
"usage": {
"input_tokens": 1,
"output_tokens": 1,
"cache_read_input_tokens": 1,
"cache_creation_input_tokens": 1,
"reasoning_tokens": 1,
"estimated": false,
"raw": {}
},
"cost": {"amount": "2.00", "currency": "USD", "estimated": false},
"timings": {
"overhead_ms": 0.5,
"first_byte_ms": 0.5,
"duration_ms": 0.5
},
"content": {
"retained": false,
"retention": "none",
"expires_at": null,
"reason": "Set by our scripts."
}
}
],
"list_metadata": {"before": null, "after": null}
}
GET/requests/{id}
Get a requestPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | RequestId |
|---|
Responses
Example response · 200
{
"object": "request",
"id": "req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"state": "pending",
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null,
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"plan": "pro",
"conversation_id": "conv_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"api_key_id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"endpoint": "openai.chat_completions",
"model": "claude-sonnet-5-5",
"stream": false,
"status": 1,
"verdict": "passed",
"refusal": {"code": "user_suspended"},
"connection": {
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"provider": "openai",
"region": "us"
},
"attempts": [
{
"connection": {
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"provider": "openai",
"region": "us"
},
"started_at": "2026-09-29T14:02:11.482Z",
"status": 1,
"error": null,
"duration_ms": 0.5
}
],
"policies": [{"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T", "version": 1}],
"findings": [
{
"object": "finding",
"id": "finding_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"guardrail": "secrets",
"kind": "injection_attempts",
"action": "record",
"mode": "monitor",
"applied": false,
"block": 1,
"part": "system"
}
],
"coverage": [
{
"block": 1,
"part": "system",
"modality": "text",
"inspected_by": ["secrets"],
"reason": "images_uninspected"
}
],
"usage": {
"input_tokens": 1,
"output_tokens": 1,
"cache_read_input_tokens": 1,
"cache_creation_input_tokens": 1,
"reasoning_tokens": 1,
"estimated": false,
"raw": {}
},
"cost": {"amount": "2.00", "currency": "USD", "estimated": false},
"timings": {"overhead_ms": 0.5, "first_byte_ms": 0.5, "duration_ms": 0.5},
"content": {
"retained": false,
"retention": "none",
"expires_at": null,
"reason": "Set by our scripts."
}
}
GET/requests/{id}/content
Get one version of a request's contentPermission: read_content
Rebuilds the version byte for byte, except that each detected secret is replaced by its keyed hash. An attachment is referenced by its hash, and fetched with the attachments endpoint. Every read is recorded as a request.content_read event.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | RequestId |
|---|
versionquery, required | ContentVersion |
|---|
viewquery | "raw" | "events" | "assembled"For a streamed response: raw is the stream as it arrived; events is newline-delimited JSON, one event per line with the milliseconds since the request began; assembled is the response as one JSON object, as if it hadn't been streamed.
|
|---|
Responses
GET/requests/{id}/attachments/{hash}
Get an attachmentPermission: read_content
Recorded as a request.content_read event.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | RequestId |
|---|
hashpath, required | string |
|---|
Responses
GET/requests/{id}/conversation
The requests in this request's conversationPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | RequestId |
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "request",
"id": "req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"state": "pending",
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null,
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"plan": "pro",
"conversation_id": "conv_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"api_key_id": "key_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"endpoint": "openai.chat_completions",
"model": "claude-sonnet-5-5",
"stream": false,
"status": 1,
"verdict": "passed",
"refusal": {"code": "user_suspended"},
"connection": {
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"provider": "openai",
"region": "us"
},
"attempts": [
{
"connection": {
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"provider": "openai",
"region": "us"
},
"started_at": "2026-09-29T14:02:11.482Z",
"status": 1,
"error": null,
"duration_ms": 0.5
}
],
"policies": [
{
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"version": 1
}
],
"findings": [
{
"object": "finding",
"id": "finding_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"guardrail": "secrets",
"kind": "injection_attempts",
"action": "record",
"mode": "monitor",
"applied": false,
"block": 1,
"part": "system"
}
],
"coverage": [
{
"block": 1,
"part": "system",
"modality": "text",
"inspected_by": ["secrets"],
"reason": "images_uninspected"
}
],
"usage": {
"input_tokens": 1,
"output_tokens": 1,
"cache_read_input_tokens": 1,
"cache_creation_input_tokens": 1,
"reasoning_tokens": 1,
"estimated": false,
"raw": {}
},
"cost": {"amount": "2.00", "currency": "USD", "estimated": false},
"timings": {
"overhead_ms": 0.5,
"first_byte_ms": 0.5,
"duration_ms": 0.5
},
"content": {
"retained": false,
"retention": "none",
"expires_at": null,
"reason": "Set by our scripts."
}
}
],
"list_metadata": {"before": null, "after": null}
}
Summaries
Totals from rollups, minutes behind.
GET/summary
Totals for the environment, for one organization, or for one userPermission: read
A user's totals are kept by the day, so user_id takes interval=day only, and can't be given with organization_id.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
fromquery, required | string (date-time) |
|---|
toquery, required | string (date-time) |
|---|
intervalquery | "hour" | "day"The width of each point in the series.
|
|---|
organization_idquery | OrganizationId |
|---|
user_idquery | UserId |
|---|
Responses
Example response · 200
{
"object": "summary",
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z",
"interval": "hour",
"organization_id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"user_id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"totals": {
"requests": 1,
"verdicts": {"passed": 1, "modified": 1, "blocked": 1, "cut": 1},
"errors": 1,
"input_tokens": 1,
"output_tokens": 1,
"cost": {"amount": "2.00", "currency": "USD", "estimated": false},
"findings": {
"secrets": 1,
"personal_data": 1,
"prompt_injection": 1,
"illegal_content": 1
},
"organizations": 1,
"users": 1,
"models": {"key": 1},
"providers": {"key": 1}
},
"series": [
{
"start": "2026-09-29T14:02:11.482Z",
"totals": {
"requests": 1,
"verdicts": {"passed": 1, "modified": 1, "blocked": 1, "cut": 1},
"errors": 1,
"input_tokens": 1,
"output_tokens": 1,
"cost": {
"amount": "2.00",
"currency": "USD",
"estimated": false
},
"findings": {
"secrets": 1,
"personal_data": 1,
"prompt_injection": 1,
"illegal_content": 1
},
"organizations": 1,
"users": 1,
"models": {"key": 1},
"providers": {"key": 1}
}
}
]
}
GET/summary/users
Totals for several users at oncePermission: read
Each user's summary by the day, as getSummary gives it for user_id, in the order of user_ids: a page of users' weeks in one call.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
fromquery, required | string (date-time) |
|---|
toquery, required | string (date-time) |
|---|
user_idsquery, required | UserId[] |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "summary",
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z",
"interval": "hour",
"organization_id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"user_id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"totals": {
"requests": 1,
"verdicts": {"passed": 1, "modified": 1, "blocked": 1, "cut": 1},
"errors": 1,
"input_tokens": 1,
"output_tokens": 1,
"cost": {
"amount": "2.00",
"currency": "USD",
"estimated": false
},
"findings": {
"secrets": 1,
"personal_data": 1,
"prompt_injection": 1,
"illegal_content": 1
},
"organizations": 1,
"users": 1,
"models": {"key": 1},
"providers": {"key": 1}
},
"series": [
{
"start": "2026-09-29T14:02:11.482Z",
"totals": {
"requests": 1,
"verdicts": {"passed": 1, "modified": 1, "blocked": 1, "cut": 1},
"errors": 1,
"input_tokens": 1,
"output_tokens": 1,
"cost": {
"amount": "2.00",
"currency": "USD",
"estimated": false
},
"findings": {
"secrets": 1,
"personal_data": 1,
"prompt_injection": 1,
"illegal_content": 1
},
"organizations": 1,
"users": 1,
"models": {"key": 1},
"providers": {"key": 1}
}
}
]
}
],
"list_metadata": {"before": null, "after": null}
}
Signals
Observations about users and organizations drawn from many requests.
GET/signals
List signalsPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
organization_idquery | OrganizationId |
|---|
user_idquery | UserId |
|---|
statequery | SignalState |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "signal",
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"score": 0.5,
"window": {
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z"
},
"evidence": {
"requests": ["req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"],
"features": {"key": 0.5}
},
"state": "open",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
GET/signals/{id}
Get a signalPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | SignalId |
|---|
Responses
Example response · 200
{
"object": "signal",
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"score": 0.5,
"window": {
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z"
},
"evidence": {
"requests": ["req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"],
"features": {"key": 0.5}
},
"state": "open",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
POST/signals/{id}/dismiss
Dismiss a signalPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
idpath, required | SignalId |
|---|
Responses
Example response · 200
{
"object": "signal",
"id": "signal_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"kind": "injection_attempts",
"organization": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"user": {
"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"external_id": "acme"
},
"score": 0.5,
"window": {
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z"
},
"evidence": {
"requests": ["req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"],
"features": {"key": 0.5}
},
"state": "open",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
Webhooks
Endpoints that receive events, and their deliveries.
GET/webhook_endpoints
List webhook endpointsPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "webhook_endpoint",
"id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"url": "https://example.com/alectura/webhooks",
"events": ["organization.created"],
"state": "enabled",
"disabled_reason": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/webhook_endpoints
Create a webhook endpointPermission: manage
The response is the only time the signing secret is shown.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
WebhookEndpointCreate
Responses
Example request body
{
"url": "https://example.com/alectura/webhooks",
"events": ["user.suspended", "signal.detected"]
}
Example response · 201
{
"object": "webhook_endpoint",
"id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"url": "https://example.com/alectura/webhooks",
"events": ["organization.created"],
"state": "enabled",
"disabled_reason": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z",
"secret": "whsec_mJ3q8vXbT2kP9wR4sL7nY1cF6hD0gZ5aE8uB3oI2tK4"
}
GET/webhook_endpoints/{id}
Get a webhook endpointPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | WebhookEndpointId |
|---|
Responses
Example response · 200
{
"object": "webhook_endpoint",
"id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"url": "https://example.com/alectura/webhooks",
"events": ["organization.created"],
"state": "enabled",
"disabled_reason": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/webhook_endpoints/{id}
Update, enable or disable a webhook endpointPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | WebhookEndpointId |
|---|
Body
WebhookEndpointUpdate
Responses
Example request body
{
"url": "https://example.com/alectura/webhooks",
"events": ["organization.created"],
"state": "enabled"
}
Example response · 200
{
"object": "webhook_endpoint",
"id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"url": "https://example.com/alectura/webhooks",
"events": ["organization.created"],
"state": "enabled",
"disabled_reason": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
DELETE/webhook_endpoints/{id}
Delete a webhook endpointPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | WebhookEndpointId |
|---|
Responses
Example response · 200
{
"object": "webhook_endpoint",
"id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"url": "https://example.com/alectura/webhooks",
"events": ["organization.created"],
"state": "enabled",
"disabled_reason": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
POST/webhook_endpoints/{id}/rotate_secret
Rotate an endpoint's signing secretPermission: manage
For 24 hours, deliveries carry a v1 signature for each of the old and new secrets.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
idpath, required | WebhookEndpointId |
|---|
Responses
Example response · 200
{
"object": "webhook_endpoint",
"id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"url": "https://example.com/alectura/webhooks",
"events": ["organization.created"],
"state": "enabled",
"disabled_reason": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z",
"secret": "whsec_mJ3q8vXbT2kP9wR4sL7nY1cF6hD0gZ5aE8uB3oI2tK4"
}
POST/webhook_endpoints/{id}/test
Send a test deliveryPermission: manage
Delivers a webhook_endpoint.test event once, without retries, and returns the attempt.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | WebhookEndpointId |
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Responses
Example response · 200
{
"object": "delivery",
"id": "delivery_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"webhook_endpoint_id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"event_id": "event_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"event": "organization.created",
"state": "pending",
"attempts": [
{
"at": "2026-09-29T14:02:11.482Z",
"status": 1,
"duration_ms": 0.5,
"error": null
}
],
"next_attempt_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z"
}
GET/webhook_endpoints/{id}/deliveries
List an endpoint's deliveriesPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | WebhookEndpointId |
|---|
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
statequery | DeliveryState |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "delivery",
"id": "delivery_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"webhook_endpoint_id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"event_id": "event_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"event": "organization.created",
"state": "pending",
"attempts": [
{
"at": "2026-09-29T14:02:11.482Z",
"status": 1,
"duration_ms": 0.5,
"error": null
}
],
"next_attempt_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/deliveries/{id}/retry
Retry a failed deliveryPermission: manage
Tries once more now, with the same delivery id.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
idpath, required | DeliveryId |
|---|
Responses
Example response · 200
{
"object": "delivery",
"id": "delivery_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"webhook_endpoint_id": "webhook_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"event_id": "event_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"event": "organization.created",
"state": "pending",
"attempts": [
{
"at": "2026-09-29T14:02:11.482Z",
"status": 1,
"duration_ms": 0.5,
"error": null
}
],
"next_attempt_at": "2026-09-29T14:02:11.482Z",
"created_at": "2026-09-29T14:02:11.482Z"
}
Jobs
Replays, evidence packs and assessments, which run in the background.
POST/replays
Replay a draft policy against past requestsPermission: manage
Evaluates the draft against stored requests in the window and reports what would have changed. Requests without retained content replay their routing settings only.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
ReplayCreate
Responses
Example request body
{
"policy_id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"match": {"organization": "globex"},
"settings": {
"routing": {
"connections": ["own", "environment"],
"regions": ["eu", "global"],
"models": ["claude-sonnet-5-5", "claude-haiku-4-5"],
"data_terms": {"retention": "zero", "training": "no"}
},
"retention": {"content": "none"},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 60}],
"spend": [
{"per": "user", "period": "day", "amount": "2.00"},
{
"per": "organization",
"period": "month",
"amount": "500.00"
}
]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {
"action": "pseudonymize",
"mode": "enforce",
"parts": ["user", "tool_result"],
"kinds": ["email", "phone"],
"exclusions": ["support@acme.example"]
},
"prompt_injection": {
"action": "cut",
"mode": "enforce",
"parts": ["tool_result"]
},
"illegal_content": {"action": "block", "mode": "monitor"}
},
"uninspected": "allow",
"abuse": {"suspend_at": 0.9}
},
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z"
}
Example response · 202
{
"object": "replay",
"id": "replay_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"state": "queued",
"policy": {
"policy_id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"match": {"organization": "globex"},
"settings": {
"routing": {
"connections": ["own", "environment"],
"regions": ["eu", "global"],
"models": ["claude-sonnet-5-5", "claude-haiku-4-5"],
"data_terms": {"retention": "zero", "training": "no"}
},
"retention": {"content": "none"},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 60}],
"spend": [
{"per": "user", "period": "day", "amount": "2.00"},
{
"per": "organization",
"period": "month",
"amount": "500.00"
}
]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {
"action": "pseudonymize",
"mode": "enforce",
"parts": ["user", "tool_result"],
"kinds": ["email", "phone"],
"exclusions": ["support@acme.example"]
},
"prompt_injection": {
"action": "cut",
"mode": "enforce",
"parts": ["tool_result"]
},
"illegal_content": {"action": "block", "mode": "monitor"}
},
"uninspected": "allow",
"abuse": {"suspend_at": 0.9}
}
},
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z",
"progress": 0.5,
"result": {
"requests": 1,
"with_content": 1,
"verdicts_changed": {"key": 1},
"routing_changed": 1,
"findings_removed": 1,
"samples": ["req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"]
},
"error": null,
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null
}
GET/replays/{id}
Get a replayPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | ReplayId |
|---|
Responses
Example response · 200
{
"object": "replay",
"id": "replay_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"state": "queued",
"policy": {
"policy_id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"match": {"organization": "globex"},
"settings": {
"routing": {
"connections": ["own", "environment"],
"regions": ["eu", "global"],
"models": ["claude-sonnet-5-5", "claude-haiku-4-5"],
"data_terms": {"retention": "zero", "training": "no"}
},
"retention": {"content": "none"},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 60}],
"spend": [
{"per": "user", "period": "day", "amount": "2.00"},
{
"per": "organization",
"period": "month",
"amount": "500.00"
}
]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {
"action": "pseudonymize",
"mode": "enforce",
"parts": ["user", "tool_result"],
"kinds": ["email", "phone"],
"exclusions": ["support@acme.example"]
},
"prompt_injection": {
"action": "cut",
"mode": "enforce",
"parts": ["tool_result"]
},
"illegal_content": {"action": "block", "mode": "monitor"}
},
"uninspected": "allow",
"abuse": {"suspend_at": 0.9}
}
},
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z",
"progress": 0.5,
"result": {
"requests": 1,
"with_content": 1,
"verdicts_changed": {"key": 1},
"routing_changed": 1,
"findings_removed": 1,
"samples": ["req_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"]
},
"error": null,
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null
}
POST/evidence_packs
Build an organization's evidence packPermission: manage
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
EvidencePackCreate
Responses
Example request body
{
"organization_id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z"
}
Example response · 202
{
"object": "evidence_pack",
"id": "evidence_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"state": "queued",
"organization_id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z",
"error": null,
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null,
"expires_at": null
}
GET/evidence_packs/{id}
Get an evidence packPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | EvidencePackId |
|---|
Responses
Example response · 200
{
"object": "evidence_pack",
"id": "evidence_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"state": "queued",
"organization_id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z",
"error": null,
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null,
"expires_at": null
}
GET/evidence_packs/{id}/download
Download a completed evidence packPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | EvidencePackId |
|---|
formatquery | "pdf" | "json" |
|---|
Responses
POST/assessments
Start an assessmentPermission: manage
Returns an upload URL. Uploading the logs to it starts the assessment, which runs apart from live traffic and never touches its data.
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
AssessmentCreate
Responses
Example request body
{"name": "Acme", "format": "openai_chat_jsonl"}
Example response · 201
{
"object": "assessment",
"id": "assessment_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"state": "awaiting_upload",
"format": "openai_chat_jsonl",
"upload": {
"url": "https://example.com/alectura/webhooks",
"method": "PUT",
"max_bytes": 1,
"expires_at": "2026-09-29T14:02:11.482Z"
},
"progress": {
"step": "reading",
"bytes_read": 1,
"bytes_total": 1,
"rows_read": 1,
"accepted": 1,
"rejected": {"key": 1},
"users_seen": 1
},
"error": null,
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null
}
GET/assessments/{id}
Get an assessmentPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | AssessmentId |
|---|
Responses
Example response · 200
{
"object": "assessment",
"id": "assessment_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"state": "awaiting_upload",
"format": "openai_chat_jsonl",
"upload": {
"url": "https://example.com/alectura/webhooks",
"method": "PUT",
"max_bytes": 1,
"expires_at": "2026-09-29T14:02:11.482Z"
},
"progress": {
"step": "reading",
"bytes_read": 1,
"bytes_total": 1,
"rows_read": 1,
"accepted": 1,
"rejected": {"key": 1},
"users_seen": 1
},
"error": null,
"created_by": {"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"},
"created_at": "2026-09-29T14:02:11.482Z",
"completed_at": null
}
GET/assessments/{id}/report
Download a completed assessment's reportPermission: read
Parameters
Alectura-Environmentheader | EnvironmentIdThe environment a session acts on. Required with a session; with a management key, it may be sent only if it names the key's own environment.
|
|---|
idpath, required | AssessmentId |
|---|
formatquery | "pdf" | "json" |
|---|
Responses
Example response · 200
{
"object": "assessment_report",
"assessment_id": "assessment_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"format": "openai_chat_jsonl",
"from": "2026-09-29T14:02:11.482Z",
"to": "2026-09-29T14:02:11.482Z",
"generated_at": "2026-09-29T14:02:11.482Z",
"rows": {"read": 1, "accepted": 1, "rejected": {"key": 1}},
"users_analyzed": 1,
"suspicious_users": 1,
"tokens": {"total": 1, "suspicious": 1},
"suspicious_token_share": 0.5,
"estimated_cost": {"total": "2.00", "suspicious": "2.00"},
"users": [
{
"user": "user_42",
"organization": "acme",
"plan": "pro",
"score": 0.5,
"requests": 1,
"tokens": 1,
"estimated_cost": "2.00",
"signals": [
{
"kind": "injection_attempts",
"score": 0.5,
"lines": [1]
}
]
}
],
"unavailable_signals": ["unavailable_signals"]
}
Team
The team, its members, projects and environments, on us.api only. Sessions only.
GET/team
Get the signed-in member's team
Responses
Example response · 200
{
"object": "team",
"id": "team_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/team
Rename the team
Body
TeamUpdate
Responses
Example request body
{"name": "Acme"}
Example response · 200
{
"object": "team",
"id": "team_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/team/members
List team members
Parameters
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "member",
"id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"email": "ada@example.com",
"name": "Acme",
"role": "admin",
"state": "invited",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
PATCH/team/members/{id}
Change a member's role
Parameters
Body
MemberUpdate
Responses
Example request body
{"role": "admin"}
Example response · 200
{
"object": "member",
"id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"email": "ada@example.com",
"name": "Acme",
"role": "admin",
"state": "invited",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
DELETE/team/members/{id}
Remove a member
Locks the member out of every region within seconds, whatever their session says.
Parameters
Responses
Example response · 200
{
"object": "member",
"id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"email": "ada@example.com",
"name": "Acme",
"role": "admin",
"state": "invited",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
POST/team/invitations
Invite someone to the team
Stytch emails a sign-in link. The invited member holds the role once they sign in.
Parameters
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
InvitationCreate
Responses
Example request body
{"email": "ada@example.com", "role": "admin"}
Example response · 201
{
"object": "member",
"id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"email": "ada@example.com",
"name": "Acme",
"role": "admin",
"state": "invited",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/projects
List projects
Parameters
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "project",
"id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/projects
Create a project
Parameters
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
ProjectCreate
Responses
Example request body
{"name": "Acme"}
Example response · 201
{
"object": "project",
"id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/projects/{id}
Get a project
Parameters
Responses
Example response · 200
{
"object": "project",
"id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/projects/{id}
Rename a project
Parameters
Body
ProjectUpdate
Responses
Example request body
{"name": "Acme"}
Example response · 200
{
"object": "project",
"id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/environments
List the team's environments, in every region
Parameters
limitquery | integer |
|---|
beforequery | stringAn object id. Returns the page before it.
|
|---|
afterquery | stringAn object id. Returns the page after it.
|
|---|
orderquery | "asc" | "desc" |
|---|
project_idquery | ProjectId |
|---|
Responses
Example response · 200
{
"object": "list",
"data": [
{
"object": "environment",
"id": "env_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"project_id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"region": "us",
"production": false,
"api_base_url": "https://eu.api.alecturalabs.com/v1",
"gateway_base_url": "https://eu.gateway.alecturalabs.com",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
],
"list_metadata": {"before": null, "after": null}
}
POST/environments
Create an environment in a region
The environment lives in its region for good. Its region's host serves its config and traffic, and sets up its state there on first use, starting with a baseline policy that matches every request and allows only its own region.
Parameters
Idempotency-Keyheader | stringMakes a retry return the first result for 24 hours. The same key with a different body is refused with 422 idempotency_key_reused.
|
|---|
Body
EnvironmentCreate
Responses
Example request body
{
"project_id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"region": "us",
"production": false
}
Example response · 201
{
"object": "environment",
"id": "env_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"project_id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"region": "us",
"production": false,
"api_base_url": "https://eu.api.alecturalabs.com/v1",
"gateway_base_url": "https://eu.gateway.alecturalabs.com",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
GET/environments/{id}
Get an environment
Parameters
Responses
Example response · 200
{
"object": "environment",
"id": "env_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"project_id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"region": "us",
"production": false,
"api_base_url": "https://eu.api.alecturalabs.com/v1",
"gateway_base_url": "https://eu.gateway.alecturalabs.com",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PATCH/environments/{id}
Rename an environment
Parameters
Body
EnvironmentUpdate
Responses
Example request body
{"name": "Acme"}
Example response · 200
{
"object": "environment",
"id": "env_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"project_id": "project_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Acme",
"region": "us",
"production": false,
"api_base_url": "https://eu.api.alecturalabs.com/v1",
"gateway_base_url": "https://eu.gateway.alecturalabs.com",
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
Schemas
Error
coderequired | string |
|---|
messagerequired | string |
|---|
errors | object[]Each item fieldrequired | stringA dotted path into the body, such as settings.routing.regions.
|
|---|
coderequired | string |
|---|
message | string |
|---|
|
|---|
request_idrequired | RequestId |
|---|
ListMetadata
beforerequired | string | null |
|---|
afterrequired | string | null |
|---|
Timestamp
string (date-time)
Money
amountrequired | Decimal |
|---|
currencyrequired | "USD" |
|---|
estimatedrequired | booleanTrue for list prices from the pinned price map, rather than a provider's bill.
|
|---|
Decimal
string
ExternalId
The team's own identifier, as the Alectura-* headers carry it.
string
Metadata
map<string, string>
Actor
typerequired | "api_key" | "member" | "policy" | "system" |
|---|
idrequired | string | nullThe key's, member's or policy's id; null for the system.
|
|---|
Example
{"type": "member", "id": "member_01J9ZQ6V8D3K4M5N6P7Q8R9S0T"}
Region
A region Alectura runs in.
"us" | "eu" | "au"
ProviderRegion
Where a provider processes a request. global is for endpoints that promise no region, such as Bedrock's global. inference profiles.
"us" | "eu" | "au" | "apac" | "global"
OrganizationId
string
UserId
string
OrganizationMembershipId
string
SuspensionId
string
SystemPromptId
string
PolicyId
string
ConnectionId
string
ApiKeyId
string
RequestId
string
ConversationId
string
FindingId
string
DispositionId
string
SignalId
string
EventId
string
WebhookEndpointId
string
DeliveryId
string
ReplayId
string
EvidencePackId
string
AssessmentId
string
TeamId
string
MemberId
string
ProjectId
string
EnvironmentId
string
Ref
A reference to an organization or user, with the team's identifier.
Example
{"id": "org_01J9ZQ6V8D3K4M5N6P7Q8R9S0T", "external_id": "acme"}
Organization
objectrequired | "organization" |
|---|
idrequired | OrganizationId |
|---|
external_idrequired | ExternalId |
|---|
namerequired | string | null |
|---|
metadatarequired | Metadata |
|---|
planrequired | string | nullThe plan named by its latest request that sent Alectura-Plan; null until one does.
|
|---|
suspendedrequired | boolean |
|---|
staterequired | "active" | "deleting" |
|---|
first_seen_atrequired | string (date-time) | null |
|---|
last_seen_atrequired | string (date-time) | null |
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
OrganizationCreate
OrganizationUpdate
OrganizationList
User
objectrequired | "user" |
|---|
idrequired | UserId |
|---|
external_idrequired | ExternalId |
|---|
namerequired | string | null |
|---|
metadatarequired | Metadata |
|---|
suspendedrequired | boolean |
|---|
signals | UserSignal[]The user's open signals, strongest first: those neither dismissed nor acted on. The management API's users carry them; a user in an event's data doesn't.
|
|---|
first_seen_atrequired | string (date-time) | null |
|---|
last_seen_atrequired | string (date-time) | null |
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
UserSignal
An open signal on a user, as the users list shows it. getSignal has the rest.
idrequired | SignalId |
|---|
kindrequired | stringWhat was observed, as the signal's kind.
|
|---|
scorerequired | number |
|---|
UserCreate
UserUpdate
UserList
RelatedUserList
objectrequired | "list" |
|---|
datarequired | object[]Each item objectrequired | "related_user" |
|---|
userrequired | Ref |
|---|
shared_fingerprintsrequired | integerHow many prompt templates both users' requests share.
|
|---|
|
|---|
list_metadatarequired | ListMetadata |
|---|
OrganizationMembership
OrganizationMembershipList
Suspension
objectrequired | "suspension" |
|---|
idrequired | SuspensionId |
|---|
organizationrequired | Ref | nullSet when an organization is suspended.
|
|---|
userrequired | Ref | nullSet when a user is suspended.
|
|---|
reasonrequired | stringA short reason, such as signals for one a policy made.
|
|---|
noterequired | string | null |
|---|
created_byrequired | Actor |
|---|
created_atrequired | Timestamp |
|---|
expires_atrequired | string (date-time) | null |
|---|
lifted_atrequired | string (date-time) | null |
|---|
lifted_byrequired | Actor | null |
|---|
SuspensionCreate
Names exactly one of organization_id and user_id.
Example
{
"user_id": "user_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"reason": "abuse",
"note": "Scraping answers at volume.",
"expires_at": "2026-10-09T00:00:00.000Z"
}
SuspensionList
SystemPrompt
A system prompt the team declared as its app's own. Its text isn't kept.
objectrequired | "system_prompt" |
|---|
idrequired | SystemPromptId |
|---|
namerequired | string | null |
|---|
fingerprintrequired | stringThe keyed hash of the prompt's text, as requests' prompts are hashed.
|
|---|
created_atrequired | Timestamp |
|---|
SystemPromptCreate
textrequired | stringThe prompt, exactly as the app sends it, several system blocks joined by line breaks. Only its fingerprint is kept.
|
|---|
name | string | null |
|---|
SystemPromptList
Policy
objectrequired | "policy" |
|---|
idrequired | PolicyId |
|---|
namerequired | string |
|---|
descriptionrequired | string | null |
|---|
matchrequired | Match |
|---|
settingsrequired | Settings |
|---|
versionrequired | integer |
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
Example
{
"object": "policy",
"id": "policy_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
},
"version": 1,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
PolicyCreate
namerequired | string |
|---|
description | string |
|---|
matchrequired | Match |
|---|
settingsrequired | Settings |
|---|
Example
{
"name": "Free plan",
"description": "Tighter limits and EU-only routing for the free plan.",
"match": {"plan": "free"},
"settings": {
"routing": {"regions": ["eu"]},
"limits": {
"requests": [{"per": "user", "period": "minute", "amount": 20}],
"spend": [{"per": "user", "period": "day", "amount": "0.50"}]
},
"guardrails": {
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {"action": "pseudonymize", "mode": "enforce"}
}
}
}
PolicyUpdate
name | string |
|---|
description | string | null |
|---|
match | MatchReplaces the whole match, never merges into it: a field left out no longer selects.
|
|---|
settings | Settings |
|---|
Example
{
"settings": {
"limits": {
"spend": [{"per": "user", "period": "day", "amount": "1.00"}]
}
}
}
PolicyList
PolicyVersion
objectrequired | "policy_version" |
|---|
policy_idrequired | PolicyId |
|---|
versionrequired | integer |
|---|
namerequired | string |
|---|
matchrequired | Match |
|---|
settingsrequired | Settings |
|---|
deletedrequired | booleanTrue for the version that deleted the policy.
|
|---|
created_byrequired | Actor |
|---|
created_atrequired | Timestamp |
|---|
PolicyVersionList
Match
Selects requests by their Alectura-* headers. Every field given must hold, and an omitted field matches anything. {} matches every request.
Example
{"organization": "globex"}
MatchValue
A value, any of a list of values, or null for requests that don't send the header.
ExternalId | ExternalId[] | null
Settings
Each setting combines across matching policies by the rule in its description, and every rule only tightens. A setting no matching policy sets takes its default.
routing | RoutingSettings |
|---|
retention | RetentionSettings |
|---|
limits | LimitSettings |
|---|
guardrails | GuardrailSettings |
|---|
uninspected | "allow" | "block"What to do with content nothing can inspect, such as images. block wins. Default allow, with the content recorded as uninspected.
|
|---|
abuse | objectWhat happens when a signal flags a user or organization for abuse.
Fields suspend_at | numberSuspend the user when a signal's score reaches this; an organization is never suspended automatically. The lowest wins. Default: never.
|
|---|
|
|---|
RoutingSettings
connections | ("own" | "environment")[]Whose connections may serve a request, in order. own is the organization's own connections: an organization that owns any is served by them alone, so a request none of them can serve is refused with no_allowed_connection, while one that owns none, or a request without an organization, is served by the environment's. environment is the environment's, so [own, environment] falls back to them. Across policies, the members every policy allows, in the order of the most specific policy that sets it. Default ["own"]. A policy lists at least one; an effective policy's list is empty when its policies allow nothing in common.
|
|---|
regions | ProviderRegion[]Where a provider may process a request, in order of preference. Across policies, the members every policy allows, in the order of the most specific policy that sets it. Default: the environment's own region. A policy lists at least one; an effective policy's list is empty when its policies allow nothing in common, and then refuses every request.
|
|---|
models | string[]The models a request may use; an id without a date matches every dated version. Across policies, the intersection. Default: any model an active connection serves.
|
|---|
data_terms | objectThe data terms a connection must declare (Connection.data_terms) to serve a request. A connection whose terms are undeclared doesn't meet a requirement. When no connection that meets them serves the model, the request is refused with no_allowed_connection. Default: any terms.
Fields retention | "any" | "zero"zero: only connections whose provider keeps nothing it's sent. Across policies, zero wins. Content retention none doesn't imply it.
|
|---|
training | "any" | "no"no: only connections whose provider doesn't train on what it's sent. Across policies, no wins.
|
|---|
|
|---|
Example
{
"connections": ["own", "environment"],
"regions": ["eu", "global"],
"models": ["claude-sonnet-5-5", "claude-haiku-4-5"],
"data_terms": {"retention": "zero", "training": "no"}
}
RetentionSettings
content | "none" | "team" | "7d" | "30d" | "90d" | "365d"How long a request's content is kept. Across policies, the earliest in this list. Default none. team means held by the team rather than by Alectura: in the environment's content store (/content_store), for as long as the team keeps it. Until the environment has an active content store, team keeps no content, as none. Records are kept 400 days whatever this says.
|
|---|
LimitSettings
For each pair of per and period, the lowest amount among matching policies wins; limits for different pairs all apply. requests and tokens take a minute or a day, and spend a day, a week or a month. A limit over a minute refuses with 429; over a day, week or month, with 402. Periods are calendar periods in UTC, and weeks start on Monday.
max_output_tokens | integerLowers a request's maximum output to this, and sets it when the request doesn't. The lowest wins.
|
|---|
requests | object[]Each item perrequired | LimitScope |
|---|
periodrequired | "minute" | "day" |
|---|
amountrequired | integer |
|---|
|
|---|
tokens | object[]Input and output tokens together.
Each item perrequired | LimitScope |
|---|
periodrequired | "minute" | "day" |
|---|
amountrequired | integer |
|---|
|
|---|
spend | object[]Estimated cost at list prices, in USD.
|
|---|
Example
{
"requests": [{"per": "user", "period": "minute", "amount": 60}],
"spend": [
{"per": "user", "period": "day", "amount": "2.00"},
{
"per": "organization",
"period": "month",
"amount": "500.00"
}
]
}
LimitScope
A request without a user or organization isn't counted against limits for it.
"user" | "organization"
GuardrailSettings
Across policies: each guardrail's action and mode take the strictest value, in the order listed for each; parts and kinds the union; exclusions the intersection. A guardrail no matching policy sets doesn't run.
secrets | objectCredentials and private keys. In the request, redact replaces each with [redacted:kind] and block refuses it with blocked_by_guardrail. In the answer (output), streamed or not, redact redacts the same way, holding back the text a secret could still be growing into across deltas, and block cuts the answer with cut_by_guardrail.
|
|---|
personal_data | objectPersonal data of the kinds selected. In the request, pseudonymize replaces each value with a pseudonym, [[kind:hash8]], which the answer gets back as the value; redact replaces it with [redacted:kind]; block refuses the request. In the answer (output), redact redacts what the answer holds and block cuts it with cut_by_guardrail; under pseudonymize the answer's pseudonyms are restored and personal data the answer adds is recorded, since a pseudonym would reach the client in its place. person_name, street_address and date_of_birth are found in English text without a model (crates/guard/accuracy/README.md has how well).
Fields actionrequired | "record" | "pseudonymize" | "redact" | "block" |
|---|
moderequired | GuardrailMode |
|---|
parts | Parts |
|---|
kinds | ("email" | "phone" | "card_number" | "iban" | "ip_address" | "national_id" | "person_name" | "street_address" | "date_of_birth")[] |
|---|
exclusions | string[]Exact values never treated as personal data, such as the team's support address.
|
|---|
|
|---|
prompt_injection | objectInstructions that try to take over the model, in the request's parts, tool results included. It judges the request, not the answer, so its parts can't name output.
|
|---|
illegal_content | objectRequests for help with a crime, judged by a local model over the parts selected, tool results included. block refuses the request before the provider sees it, with blocked_by_guardrail; flag records the finding and lets it through. The kinds are MLCommons' hazard categories that are crimes wherever the request comes from, with illegal conventional weapons joined to chemical, biological, radiological, nuclear and explosive ones in weapons. It judges the request before the provider sees it, not the answer, so its parts can't name output. Its measured precision and recall per kind are published; start in monitor mode.
Fields actionrequired | "flag" | "block" |
|---|
moderequired | GuardrailMode |
|---|
parts | Parts |
|---|
kinds | ("violent_crimes" | "non_violent_crimes" | "sex_crimes" | "child_sexual_exploitation" | "weapons")[] |
|---|
|
|---|
Example
{
"secrets": {"action": "redact", "mode": "enforce"},
"personal_data": {
"action": "pseudonymize",
"mode": "enforce",
"parts": ["user", "tool_result"],
"kinds": ["email", "phone"],
"exclusions": ["support@acme.example"]
},
"prompt_injection": {"action": "cut", "mode": "enforce", "parts": ["tool_result"]},
"illegal_content": {"action": "block", "mode": "monitor"}
}
GuardrailMode
monitor records what the guardrail would do; enforce does it. enforce wins.
"monitor" | "enforce"
Parts
The parts of a request a guardrail inspects. Default all of them that the guardrail reads. Only secrets and personal_data read output; a policy that names it for another guardrail is refused with 422 validation_failed.
Part[]
Part
output is the provider's answer, streamed or not; the rest are the request's input.
"system" | "user" | "assistant" | "tool_call" | "tool_result" | "output"
EffectivePolicy
objectrequired | "effective_policy" |
|---|
identityrequired | objectFields organizationrequired | string | null |
|---|
userrequired | string | null |
|---|
planrequired | string | null |
|---|
|
|---|
policiesrequired | PolicyRef[]The matching policies, at their current versions.
|
|---|
settingsrequired | SettingsThe settings as they apply. One no matching policy sets shows at its default: routing to the environment's region on ["own"] connections, retention none and uninspected: allow; a guardrail or a limit no policy sets is absent, since its default is to do nothing.
|
|---|
sourcesrequired | map<string, PolicyId[]>For each setting, by its dotted path, the policies that decided its value. A setting that no policy sets is absent, and takes its default.
|
|---|
PolicyRef
idrequired | PolicyId |
|---|
versionrequired | integer |
|---|
Provider
gemini is the Gemini API, in its own format. simulator answers inside the gateway with recorded responses, in the region of the environment's cell, so no provider is reached or paid: any team may connect it to try Alectura, and outside the demo team each environment may send it a burst of 20 requests and 60 a minute, past which a request no other connection can serve is refused 429 rate_limited.
"openai" | "anthropic" | "bedrock" | "gemini" | "simulator"
ConnectionState
Only an active connection routes. A connection is activated only after its test passes.
"draft" | "active" | "disabled"
DataTerms
What the provider's terms for this account say, as declared by whoever made the connection. Undeclared counts as retaining. Prompt caching in memory isn't retention.
retentionrequired | "undeclared" | "zero" | "retains" |
|---|
trainingrequired | "undeclared" | "no" | "yes" |
|---|
Credential
Write-only. Reading a connection returns only CredentialHint.
object | object
CredentialHint
typerequired | "api_key" | "aws_role" |
|---|
hintrequired | stringThe last four characters of a key, or a role's name.
|
|---|
Owner
object | object
Connection
objectrequired | "connection" |
|---|
idrequired | ConnectionId |
|---|
namerequired | string |
|---|
providerrequired | Provider |
|---|
ownerrequired | Owner |
|---|
base_urlrequired | "https://api.openai.com/v1" | "https://eu.api.openai.com/v1" | "https://api.anthropic.com" | "https://generativelanguage.googleapis.com" | nullFor OpenAI, Anthropic and Gemini.
|
|---|
aws_regionrequired | string | null |
|---|
inference_profilerequired | "us" | "eu" | "apac" | "au" | "global" | nullFor Bedrock, a cross-region inference profile, or null for the region's own endpoint.
|
|---|
regionrequired | ProviderRegionWhere the endpoint promises to process requests. Derived, never set.
|
|---|
modelsrequired | string[]The models it serves, by the ids clients send.
|
|---|
data_termsrequired | DataTerms |
|---|
credentialrequired | CredentialHint |
|---|
aws_external_idrequired | string | nullFor an aws_role credential, the external id the role's trust policy must require.
|
|---|
staterequired | ConnectionState |
|---|
cooling_down_untilrequired | string (date-time) | nullSet while repeated failures keep the connection out of routing.
|
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
Example
{
"object": "connection",
"id": "conn_01J9ZQ6V8D3K4M5N6P7Q8R9S0T",
"name": "OpenAI EU",
"provider": "openai",
"owner": {"type": "environment"},
"base_url": "https://eu.api.openai.com/v1",
"aws_region": null,
"inference_profile": null,
"region": "eu",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "hint": "Qk3x"},
"aws_external_id": null,
"state": "draft",
"cooling_down_until": null,
"created_at": "2026-09-29T14:02:11.482Z",
"updated_at": "2026-09-29T14:02:11.482Z"
}
ConnectionCreate
namerequired | string |
|---|
providerrequired | Provider |
|---|
owner | Owner |
|---|
base_url | "https://api.openai.com/v1" | "https://eu.api.openai.com/v1" | "https://api.anthropic.com" | "https://generativelanguage.googleapis.com" |
|---|
aws_region | string |
|---|
inference_profile | "us" | "eu" | "apac" | "au" | "global" | null |
|---|
modelsrequired | string[] |
|---|
data_terms | DataTerms |
|---|
credential | CredentialRequired, except for the simulator, which reaches no provider and needs no key.
|
|---|
Example
{
"name": "OpenAI EU",
"provider": "openai",
"base_url": "https://eu.api.openai.com/v1",
"models": ["gpt-5", "gpt-5-mini"],
"data_terms": {"retention": "zero", "training": "no"},
"credential": {"type": "api_key", "api_key": "sk-proj-…"}
}
ConnectionUpdate
ConnectionList
ConnectionTest
objectrequired | "connection_test" |
|---|
connection_idrequired | ConnectionId |
|---|
passedrequired | booleanTrue when every check passed.
|
|---|
checksrequired | object[]Each item namerequired | stringWhat was checked, such as credential, model:gpt-5, stream or usage.
|
|---|
passedrequired | boolean |
|---|
reasonrequired | string | nullWhy it failed, such as invalid_credential, model_unavailable, invalid_stream, missing_usage or region_not_allowed.
|
|---|
messagerequired | string | null |
|---|
upstream_status | integer | nullThe provider's HTTP status, when it answered.
|
|---|
|
|---|
created_atrequired | Timestamp |
|---|
ContentStore
Where team-held content goes: an S3 bucket in the team's own AWS account, reached through a role there whose trust policy allows Alectura's account with external_id. Content packs, attachments and pseudonyms are written under prefix, sealed with each organization's key, and read through the same role. Their lifecycle is the bucket's.
objectrequired | "content_store" |
|---|
bucketrequired | string |
|---|
regionrequired | string |
|---|
prefixrequired | stringWhat every key starts with: empty, or ending in /.
|
|---|
role_arnrequired | string |
|---|
external_idrequired | stringWhat the role's trust policy must require as sts:ExternalId.
|
|---|
staterequired | "draft" | "active"Only an active store takes content. A store becomes active when its test passes.
|
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
ContentStoreSet
bucketrequired | string |
|---|
regionrequired | stringThe bucket's AWS region, which must be in the environment's region, so content never leaves it.
|
|---|
prefix | string |
|---|
role_arnrequired | string |
|---|
ContentStoreTest
objectrequired | "content_store_test" |
|---|
passedrequired | boolean |
|---|
messagerequired | string | nullWhy it failed, such as the role that couldn't be assumed or the key that couldn't be written.
|
|---|
content_storerequired | ContentStore |
|---|
ApiKeyType
Sending keys call the gateway; management keys call this API.
"sending" | "management"
ApiKeyState
"active" | "disabled" | "expired" | "revoked"
Permission
"send" | "read" | "read_content" | "manage"
ApiKey
objectrequired | "api_key" |
|---|
idrequired | ApiKeyId |
|---|
namerequired | string |
|---|
typerequired | ApiKeyType |
|---|
permissionsrequired | Permission[]send alone for a sending key; any of the others for a management key.
|
|---|
labelrequired | stringThe key with all but its prefix and last six characters masked.
|
|---|
staterequired | ApiKeyState |
|---|
expires_atrequired | string (date-time) | null |
|---|
previous_secret_expires_atrequired | string (date-time) | nullAfter a rotation, when the old secret stops working.
|
|---|
created_byrequired | Actor |
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
ApiKeyWithSecret
ApiKey & object
ApiKeyCreate
namerequired | string |
|---|
type | ApiKeyType |
|---|
permissions | ("read" | "read_content" | "manage")[]For a management key; a sending key always has send alone.
|
|---|
expires_at | Timestamp |
|---|
ApiKeyUpdate
name | string |
|---|
state | "active" | "disabled" |
|---|
expires_at | string (date-time) | null |
|---|
ApiKeyList
Verdict
"passed" | "modified" | "blocked" | "cut"
Guardrail
"secrets" | "personal_data" | "prompt_injection" | "illegal_content"
ContentVersion
What the client sent; what the provider received; what the provider sent back; what the client received.
"client_request" | "provider_request" | "provider_response" | "client_response"
ConnectionRef
Request
objectrequired | "request" |
|---|
idrequired | RequestId |
|---|
staterequired | "pending" | "completed" | "interrupted"pending while the request is still running; interrupted if its end never arrived because the gateway task serving it stopped.
|
|---|
created_atrequired | Timestamp |
|---|
completed_atrequired | string (date-time) | null |
|---|
organizationrequired | Ref | null |
|---|
userrequired | Ref | null |
|---|
planrequired | string | null |
|---|
conversation_idrequired | ConversationId | null |
|---|
api_key_idrequired | ApiKeyId |
|---|
endpointrequired | "openai.chat_completions" | "openai.responses" | "anthropic.messages" | "gemini.generate_content" | nullNull for a request refused before its path named an endpoint.
|
|---|
modelrequired | string | nullThe model the request asked for; null for a request refused before its body was read.
|
|---|
streamrequired | boolean |
|---|
statusrequired | integer | nullThe HTTP status the client received; null while pending.
|
|---|
verdictrequired | Verdict |
|---|
refusalrequired | object | nullOur refusal or cut, if there was one.
|
|---|
connectionrequired | ConnectionRef | nullThe connection that served the request, if any did.
|
|---|
attemptsrequired | object[]Every connection tried, in order.
Each item connectionrequired | ConnectionRef |
|---|
started_atrequired | Timestamp |
|---|
statusrequired | integer | nullThe provider's HTTP status; null if it never answered.
|
|---|
errorrequired | string | nullWhy the attempt failed, such as provider_timeout or the provider's own error code.
|
|---|
duration_msrequired | number |
|---|
|
|---|
policiesrequired | PolicyRef[]The policies that matched, at their versions then.
|
|---|
findingsrequired | Finding[] |
|---|
coveragerequired | object[]For each block, the detectors that ran on it, or why none did. A request that reached a provider ends with one more entry, part output, for the answer: read by the guardrails that select output, or not_selected. Findings in the answer name that entry's block.
Each item blockrequired | integer |
|---|
partrequired | Part |
|---|
modalityrequired | "text" | "image" | "audio" | "video" | "file" | "reasoning" |
|---|
inspected_byrequired | Guardrail[] |
|---|
reasonrequired | "images_uninspected" | "audio_uninspected" | "video_uninspected" | "files_uninspected" | "uninspectable" | "encrypted" | "not_selected" | nullWhy no detector ran, or null when one did. images_uninspected, audio_uninspected and video_uninspected: no detector reads that modality. files_uninspected: a file with no text layer a detector reads, or one the body only points at. uninspectable: a part the gateway doesn't read. encrypted: signed or encrypted provider content, which passes through byte for byte. not_selected: no guardrail that runs selects the block's part.
|
|---|
|
|---|
usagerequired | Usage | null |
|---|
costrequired | Money | null |
|---|
timingsrequired | objectFields overhead_msrequired | numberTime the gateway added, excluding the provider.
|
|---|
first_byte_msrequired | number | null |
|---|
duration_msrequired | number | null |
|---|
|
|---|
contentrequired | objectFields retainedrequired | boolean |
|---|
retentionrequired | "none" | "team" | "7d" | "30d" | "90d" | "365d" |
|---|
expires_atrequired | string (date-time) | null |
|---|
reasonrequired | string | nullWhy content wasn't kept, such as retention_none.
|
|---|
|
|---|
Usage
input_tokensrequired | integerInput tokens not read from or written to the cache.
|
|---|
output_tokensrequired | integerOutput tokens, reasoning included.
|
|---|
cache_read_input_tokensrequired | integer |
|---|
cache_creation_input_tokensrequired | integer |
|---|
reasoning_tokensrequired | integer | null |
|---|
estimatedrequired | booleanTrue when the provider reported no usage and the gateway counted.
|
|---|
rawrequired | object | nullThe provider's usage object, as it sent it.
|
|---|
Finding
objectrequired | "finding" |
|---|
idrequired | FindingId |
|---|
guardrailrequired | Guardrail |
|---|
kindrequired | stringWhat the detector found, such as aws_access_key, email, instruction_override or weapons.
|
|---|
actionrequired | "record" | "redact" | "pseudonymize" | "block" | "flag" | "cut" |
|---|
moderequired | GuardrailMode |
|---|
appliedrequired | booleanFalse in monitor mode, where the action is only recorded.
|
|---|
blockrequired | integer |
|---|
partrequired | Part |
|---|
RequestList
ContentRead
objectrequired | "content_read" |
|---|
request_idrequired | RequestId |
|---|
versionrequired | ContentVersion | null |
|---|
attachmentrequired | string | nullThe attachment's hash, when one was read.
|
|---|
readerrequired | Actor |
|---|
FindingsSummary
objectrequired | "findings_summary" |
|---|
fromrequired | Timestamp |
|---|
torequired | Timestamp |
|---|
groupsrequired | object[]Each item guardrailrequired | Guardrail |
|---|
kindrequired | string |
|---|
actionrequired | string |
|---|
moderequired | GuardrailMode |
|---|
countrequired | integer |
|---|
requestsrequired | integerDistinct requests, each counted once however often a block was resent.
|
|---|
samplesrequired | RequestId[] |
|---|
|
|---|
Disposition
objectrequired | "disposition" |
|---|
idrequired | DispositionId |
|---|
finding_idrequired | FindingId |
|---|
labelrequired | "false_positive" | "confirmed" |
|---|
noterequired | string | null |
|---|
created_byrequired | Actor |
|---|
created_atrequired | Timestamp |
|---|
DispositionCreate
labelrequired | "false_positive" | "confirmed" |
|---|
note | string |
|---|
DispositionList
Totals
requestsrequired | integer |
|---|
verdictsrequired | objectFields passedrequired | integer |
|---|
modifiedrequired | integer |
|---|
blockedrequired | integer |
|---|
cutrequired | integer |
|---|
|
|---|
errorsrequired | integerRequests whose provider failed.
|
|---|
input_tokensrequired | integer |
|---|
output_tokensrequired | integer |
|---|
costrequired | Money |
|---|
findingsrequired | objectFields secretsrequired | integer |
|---|
personal_datarequired | integer |
|---|
prompt_injectionrequired | integer |
|---|
illegal_contentrequired | integer |
|---|
|
|---|
organizationsrequired | integer |
|---|
usersrequired | integer |
|---|
modelsrequired | map<string, integer>The requests a provider served, by the model they asked for.
|
|---|
providersrequired | map<string, integer>The requests a provider served, by that provider.
|
|---|
Summary
SummaryList
SignalState
"open" | "dismissed" | "actioned"
Signal
objectrequired | "signal" |
|---|
idrequired | SignalId |
|---|
kindrequired | stringWhat was observed, such as injection_attempts, illegal_content, secret_probing, shared_template, topic_variety (far more conversations in an hour than the app's users hold) or shim_shape (requests whose parameters and client software the app's own traffic doesn't have, as an OpenAI-compatible shim's).
|
|---|
organizationrequired | Ref | null |
|---|
userrequired | Ref | null |
|---|
scorerequired | number |
|---|
windowrequired | object |
|---|
evidencerequired | objectFields requestsrequired | RequestId[] |
|---|
featuresrequired | map<string, number> |
|---|
|
|---|
staterequired | SignalState |
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
SignalList
EventType
"organization.created" | "organization.updated" | "organization.deleted" | "user.created" | "user.updated" | "system_prompt.created" | "system_prompt.deleted" | "user.suspended" | "user.unsuspended" | "organization.suspended" | "organization.unsuspended" | "signal.detected" | "policy.created" | "policy.updated" | "policy.deleted" | "connection.created" | "connection.updated" | "connection.deleted" | "api_key.created" | "api_key.updated" | "api_key.revoked" | "webhook_endpoint.disabled" | "webhook_endpoint.test" | "request.blocked" | "request.cut" | "request.content_read" | "limit.threshold_crossed" | "replay.completed" | "replay.failed" | "evidence_pack.completed" | "evidence_pack.failed" | "assessment.completed" | "assessment.failed"
Event
objectrequired | "event" |
|---|
idrequired | EventId |
|---|
eventrequired | EventType |
|---|
datarequired | objectThe object the event is about, as it was then.
|
|---|
actorrequired | Actor | nullWho caused it, or null when traffic did.
|
|---|
environment_idrequired | EnvironmentId |
|---|
created_atrequired | Timestamp |
|---|
EventList
LimitThreshold
objectrequired | "limit_threshold" |
|---|
limitrequired | objectFields kindrequired | "requests" | "tokens" | "spend" |
|---|
perrequired | LimitScope |
|---|
periodrequired | "minute" | "day" | "week" | "month" |
|---|
amountrequired | stringAs a decimal string for every kind.
|
|---|
|
|---|
organizationrequired | Ref | null |
|---|
userrequired | Ref | null |
|---|
thresholdrequired | 80 | 95 | 100The percentage crossed; 100 when the limit starts refusing.
|
|---|
usedrequired | string |
|---|
resets_atrequired | Timestamp |
|---|
WebhookEndpointState
"enabled" | "disabled"
WebhookEndpoint
WebhookEndpointWithSecret
WebhookEndpoint & object
WebhookEndpointCreate
urlrequired | string (uri) |
|---|
events | EventType[]The events it receives; empty for every event, including types added later. webhook_endpoint.test goes only to the endpoint tested, so it can't be listed.
|
|---|
WebhookEndpointUpdate
WebhookEndpointList
DeliveryState
"pending" | "succeeded" | "failed"
Delivery
One event sent to one endpoint. It is tried at once, then after 1 minute, 10 minutes, 1 hour and 12 hours; after the fifth failure it has failed, and the endpoint is disabled.
objectrequired | "delivery" |
|---|
idrequired | DeliveryId |
|---|
webhook_endpoint_idrequired | WebhookEndpointId |
|---|
event_idrequired | EventId |
|---|
eventrequired | EventType |
|---|
staterequired | DeliveryState |
|---|
attemptsrequired | object[]Each item atrequired | Timestamp |
|---|
statusrequired | integer | null |
|---|
duration_msrequired | number |
|---|
errorrequired | string | nullSuch as timeout, connection_refused or tls_error.
|
|---|
|
|---|
next_attempt_atrequired | string (date-time) | null |
|---|
created_atrequired | Timestamp |
|---|
DeliveryList
JobState
"queued" | "running" | "completed" | "failed"
Replay
objectrequired | "replay" |
|---|
idrequired | ReplayId |
|---|
staterequired | JobState |
|---|
policyrequired | objectThe draft that was replayed.
|
|---|
fromrequired | Timestamp |
|---|
torequired | Timestamp |
|---|
progressrequired | number |
|---|
resultrequired | object | nullWhat would have changed. Null until completed.
|
|---|
errorrequired | string | null |
|---|
created_byrequired | Actor |
|---|
created_atrequired | Timestamp |
|---|
completed_atrequired | string (date-time) | null |
|---|
ReplayCreate
A new draft (match and settings), or changes to an existing policy (policy_id with either).
EvidencePack
objectrequired | "evidence_pack" |
|---|
idrequired | EvidencePackId |
|---|
staterequired | JobState |
|---|
organization_idrequired | OrganizationId |
|---|
fromrequired | Timestamp |
|---|
torequired | Timestamp |
|---|
errorrequired | string | null |
|---|
created_byrequired | Actor |
|---|
created_atrequired | Timestamp |
|---|
completed_atrequired | string (date-time) | null |
|---|
expires_atrequired | string (date-time) | nullWhen the files are deleted, per the organization's retention.
|
|---|
EvidencePackCreate
Assessment
objectrequired | "assessment" |
|---|
idrequired | AssessmentId |
|---|
namerequired | string |
|---|
staterequired | "awaiting_upload" | "queued" | "running" | "completed" | "failed" |
|---|
formatrequired | AssessmentFormat |
|---|
uploadrequired | object | nullWhere to upload the logs, while the assessment awaits them.
|
|---|
progressrequired | object | nullWhere the assessment is while it is queued or running, as of its last checkpoint: null until it has read its first part of the upload, and once it ends.
|
|---|
errorrequired | string | null |
|---|
created_byrequired | Actor |
|---|
created_atrequired | Timestamp |
|---|
completed_atrequired | string (date-time) | null |
|---|
AssessmentFormat
The provider formats are one request per line, with its response, in the provider's own format, wrapped with timestamp, user, organization and plan (and model for Gemini, whose request leaves it out). bedrock_invocation_logs_jsonl is Bedrock's model invocation logs as Bedrock writes them, the user, organization and plan taken from each invocation's requestMetadata (user, organization, plan), or the user from an Anthropic body's metadata.user_id. An upload is at most 5 GiB. The metadata formats carry no prompts: each row is timestamp, user, organization, plan, model, input_tokens, output_tokens, ip_hash and system_prompt_hash, as a JSON object per line or as CSV under a header line naming the columns. timestamp, user and model are required. The hashes can be any stable hash the prospect chooses. Signals that read what users wrote (shared templates, prompt injection, secrets) are reported as unavailable for a metadata assessment.
"openai_chat_jsonl" | "openai_responses_jsonl" | "anthropic_messages_jsonl" | "gemini_generate_content_jsonl" | "bedrock_invocation_logs_jsonl" | "metadata_jsonl" | "metadata_csv"
AssessmentReport
A completed assessment's report (J5.3): the users analyzed, the suspicious ones and their share of tokens, the cost estimated at list prices, and the most suspicious users, each signal naming lines of the upload behind it.
objectrequired | "assessment_report" |
|---|
assessment_idrequired | AssessmentId |
|---|
namerequired | string |
|---|
formatrequired | AssessmentFormat |
|---|
fromrequired | string (date-time) | nullThe earliest accepted row's time, or null when no row was accepted.
|
|---|
torequired | string (date-time) | nullThe latest accepted row's time, or null when no row was accepted.
|
|---|
generated_atrequired | Timestamp |
|---|
rowsrequired | objectFields readrequired | integerLines that weren't blank.
|
|---|
acceptedrequired | integer |
|---|
rejectedrequired | map<string, integer> |
|---|
|
|---|
users_analyzedrequired | integer |
|---|
suspicious_usersrequired | integer |
|---|
tokensrequired | objectFields totalrequired | integer |
|---|
suspiciousrequired | integer |
|---|
|
|---|
suspicious_token_sharerequired | number |
|---|
estimated_costrequired | objectIn US dollars, at list prices.
|
|---|
usersrequired | object[]The most suspicious users, most suspicious first.
Each item userrequired | stringThe user's id as the upload names it.
|
|---|
organizationrequired | string | null |
|---|
planrequired | string | null |
|---|
scorerequired | number |
|---|
requestsrequired | integer |
|---|
tokensrequired | integer |
|---|
estimated_costrequired | Decimal |
|---|
signalsrequired | object[]Each item kindrequired | stringAs a signal's kind, such as shared_template.
|
|---|
scorerequired | number |
|---|
linesrequired | integer[]Lines of the upload behind the signal.
|
|---|
|
|---|
|
|---|
unavailable_signalsrequired | string[]Signals the assessment couldn't look for: those that read what users wrote, for a metadata assessment. Empty for the provider formats.
|
|---|
AssessmentCreate
Role
"admin" | "developer" | "viewer"
Team
TeamUpdate
Member
objectrequired | "member" |
|---|
idrequired | MemberId |
|---|
emailrequired | string (email) |
|---|
namerequired | string | null |
|---|
rolerequired | Role |
|---|
staterequired | "invited" | "active" |
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
MemberUpdate
InvitationCreate
emailrequired | string (email) |
|---|
rolerequired | Role |
|---|
MemberList
Project
ProjectCreate
ProjectUpdate
ProjectList
Environment
objectrequired | "environment" |
|---|
idrequired | EnvironmentId |
|---|
project_idrequired | ProjectId |
|---|
namerequired | string |
|---|
regionrequired | Region |
|---|
productionrequired | booleanProduction environments' keys say live; the rest say test.
|
|---|
api_base_urlrequired | string |
|---|
gateway_base_urlrequired | string |
|---|
created_atrequired | Timestamp |
|---|
updated_atrequired | Timestamp |
|---|
EnvironmentCreate
project_idrequired | ProjectId |
|---|
namerequired | string |
|---|
regionrequired | Region |
|---|
productionrequired | boolean |
|---|
EnvironmentUpdate
EnvironmentList