Documentation

Bind a hosted security profile to each deployment, then scan input, retrieval, tools, and output.

1. Request Flow

  1. Create a security deployment and generate a deployment-scoped API key.
  2. Create one Axiom session for each end-user conversation.
  3. Scan user input and retrieved content before the model call.
  4. Guard proposed tool calls before execution.
  5. Scan model output before releasing it to the user.

2. Environment

Generate a key in the dashboard and store it server-side only.

  • API keys use the ax_live_ prefix.
  • The plaintext key is shown once after generation.
  • Do not send the key to browser code or mobile clients.
  • Never put API keys in query params; use the Authorization header.
  • Use the production scanner URL shown below.
# .env
AXIOM_API_KEY=ax_live_your_generated_key
AXIOM_API_BASE=https://api.axiomsecurity.dev

3. Inspect a Scan Decision

This request inspects a decision; it does not execute a model or release a response. Use the protected flow below to enforce decisions in your application.

curl -X POST "https://api.axiomsecurity.dev/v1/scan/input" \
  -H "Authorization: Bearer $AXIOM_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"content":"Review this customer request"}'

4. Protected Input and Output

Install the supplied Axiom SDK bundle on your server. Your application supplies the approved response map, buffered model call, review routing and conversation termination callbacks. Incomplete scans do not release a normal model response. Guard retrieval and tool execution separately when those boundaries are in scope.

import { AxiomClient, runProtectedTurn } from "@axiom/sdk";

const axiom = new AxiomClient({
  apiKey: process.env.AXIOM_API_KEY!,
  baseUrl: "https://api.axiomsecurity.dev",
  failurePolicy: { input: "closed", output: "closed", retrieval: "closed", tool: "closed" },
  timeouts: { scanMs: 60000, toolGuardMs: 3000 },
});
// Reuse this handle for one end-user chat, never across unrelated users.
const conversation = axiom.conversation();

const result = await runProtectedTurn({
  input: userMessage,
  approvedResponses,
  scanInput: (text) => conversation.scanInput(text),
  generate: generateBufferedResponse,
  scanOutput: (text) => conversation.scanOutput(text),
  requireCompleteProtection: true,
  streaming: false,
  onReview: routeReview,
  onTerminate: closeConversation,
});
if (result.status === "displayed") {
  displayToUser(result.displayedText);
}

5. Key Management

  • GenerateCreate keys from the dashboard. The website stores only a SHA-256 hash.
  • StoreSave the plaintext key in your server environment when it is shown.
  • RevokeRevoke keys from the dashboard when they are rotated or no longer needed.