| Method | Path | Response |
|---|---|---|
| GET | /health |
JSON: status, version, service, codename (shape may extend) |
| GET | /ready |
JSON: readiness |
Primary JSON body (recommended):
{
"conversation": [
{ "role": "user", "content": "..." },
{ "role": "assistant", "content": "..." }
]
}Legacy fields are accepted with aliases: text, message, content, input, prompt; optional tool_trace / tool_calls; optional session_id.
Response (typical):
{
"violation": false,
"confidence": 0.0,
"decision": "allow",
"risk_score": 0.0,
"reason_codes": [],
"detail": null,
"version": "...",
"mini_rescue": false,
"mini_entropy": null
}violation:trueif blocked.confidence:0.0–1.0; implementations cap “allow” confidence at≤ 0.5so harnesses that inferviolationfromconfidence > 0.5remain consistent.
The service accepts POST on:
/v1/classify,/v1/classify//classify,/classify//api/v1/classify,/api/classify/(root)/{any_path}— catch-all POST for proxy path quirks
GET / returns service metadata and lists these routes.
Default 8080 (Dockerfile / uvicorn).