Verexa checks every prompt before it reaches your model and every reply before it reaches your user. In this guide you create an API key, install an SDK, guard an OpenAI client and watch the verdicts arrive in the dashboard.
- Redact PII such as emails, phone numbers and card numbers before the model sees them
- Block leaks of secrets, your system prompt and data hidden in markdown links
- Flag prompt injection and jailbreak attempts so you can review them
Create an API key
Sign in to the dashboard, open Settings → API keys and create a key. A key belongs to one project and one environment, so its checks and events land in the right place without extra configuration. Set it in your environment along with the API URL:
export VEREXA_API_KEY="vx_live_..."export VEREXA_BASE_URL="https://api.verexa.dev"allow with degraded: true and the SDK logs one warning, so your app keeps working. Set failMode: "closed" (fail_mode="closed" in Python, FailMode: verexa.FailClosed in Go) to block instead.Install the SDK
pip install verexaThe SDKs have no runtime dependencies. Python needs 3.10 or later and Go needs 1.22 or later.
Guard your OpenAI client
Wrap the OpenAI client you already have. Every chat.completions.create and responses.create call is then checked twice: the prompt before it is sent, and the reply before it is returned. Both checks share one trace id.
from openai import OpenAIfrom verexa import wrap_openaiclient = wrap_openai(OpenAI())completion = client.chat.completions.create( model="gpt-4o", messages=[{"role": "user", "content": "How do I reset my password?"}],)print(completion.choices[0].message.content)Try a redaction
Send a message that contains an email address. Verexa replaces it before the request leaves your process, so the model only ever sees [redacted email].
completion = client.chat.completions.create( model="gpt-4o", messages=[{"role": "user", "content": "Repeat after me: my email is jane.doe@example.com"}],)print(completion.choices[0].message.content)Handle a blocked turn
When a verdict is block, the wrapped call raises instead of returning. A blocked prompt never reaches the provider, and a blocked reply never reaches your user. With the default policy, replies that leak a secret or your system prompt are blocked.
from verexa import GuardBlockedErrortry: completion = client.chat.completions.create(model="gpt-4o", messages=messages) print(completion.choices[0].message.content)except GuardBlockedError as err: # err.phase is "input" or "output"; err.response is the full verdict print(f"Blocked on {err.phase}: {err}")A flag verdict does not stop the turn. It is recorded so you can review it.
Check text from any model
If you do not use the OpenAI client, call the guard yourself. Check the prompt, call your model with the text Verexa returns, then check the reply with the same trace id.
from verexa import create_guard, random_trace_idguard = create_guard()trace_id = random_trace_id()verdict = guard.check_input(user_message, trace_id=trace_id)if verdict.action == "block": returnprompt = verdict.text if verdict.action == "redact" else user_messagereply = call_your_model(prompt)checked = guard.check_output(reply, trace_id=trace_id, system_prompt=SYSTEM_PROMPT)if checked.action == "block": returnsend(checked.text if checked.action == "redact" else reply)Every SDK is a thin client over one endpoint, so you can also call the API directly:
curl https://api.verexa.dev/v1/check \ -H "Authorization: Bearer $VEREXA_API_KEY" \ -H "Content-Type: application/json" \ -d '{"traceId": "t_quickstart", "phase": "input", "text": "my email is jane.doe@example.com"}'{ "action": "redact", "score": 1, "detectors": [ { "detectorId": "prompt.instruction_override", "score": 0, "action": "allow" }, { "detectorId": "prompt.unicode_obfuscation", "score": 0, "action": "allow" }, { "detectorId": "text.pii", "score": 1, "action": "redact" } ], "text": "my email is [redacted email]", "latencyMs": 0.05, "degraded": false}See it in the dashboard
Open Events in the dashboard. Each turn appears as one trace with its input and output checks, the detectors that fired and the action taken.
Next steps
- Core concepts: actions, profiles, traces and failure modes
- Policies: turn detectors on or off and run them in monitor mode
- SDK guides for Python, TypeScript and Go
- API reference: every endpoint and field