Quickstart

Put Verexa in front of your first LLM call in a few minutes.

Verexa checks every prompt before it reaches your model and every reply before it reaches your user. In this guide you create an API key, install an SDK, guard an OpenAI client and watch the verdicts arrive in the dashboard.

  • Redact PII such as emails, phone numbers and card numbers before the model sees them
  • Block leaks of secrets, your system prompt and data hidden in markdown links
  • Flag prompt injection and jailbreak attempts so you can review them

Create an API key

Sign in to the dashboard, open Settings → API keys and create a key. A key belongs to one project and one environment, so its checks and events land in the right place without extra configuration. Set it in your environment along with the API URL:

Environment
export VEREXA_API_KEY="vx_live_..."export VEREXA_BASE_URL="https://api.verexa.dev"
Verexa fails open
Without a valid key or a reachable API, every check returns allow with degraded: true and the SDK logs one warning, so your app keeps working. Set failMode: "closed" (fail_mode="closed" in Python, FailMode: verexa.FailClosed in Go) to block instead.

Install the SDK

pip install verexa

The SDKs have no runtime dependencies. Python needs 3.10 or later and Go needs 1.22 or later.

Guard your OpenAI client

Wrap the OpenAI client you already have. Every chat.completions.create and responses.create call is then checked twice: the prompt before it is sent, and the reply before it is returned. Both checks share one trace id.

Wrap the OpenAI client
from openai import OpenAIfrom verexa import wrap_openaiclient = wrap_openai(OpenAI())completion = client.chat.completions.create(    model="gpt-4o",    messages=[{"role": "user", "content": "How do I reset my password?"}],)print(completion.choices[0].message.content)
Streamed replies reach your code as they arrive and are checked once the stream ends. A blocking verdict raises at that point, so treat it as a signal to retract the reply.

Try a redaction

Send a message that contains an email address. Verexa replaces it before the request leaves your process, so the model only ever sees [redacted email].

Send PII through the guard
completion = client.chat.completions.create(    model="gpt-4o",    messages=[{"role": "user", "content": "Repeat after me: my email is jane.doe@example.com"}],)print(completion.choices[0].message.content)

Handle a blocked turn

When a verdict is block, the wrapped call raises instead of returning. A blocked prompt never reaches the provider, and a blocked reply never reaches your user. With the default policy, replies that leak a secret or your system prompt are blocked.

Catch a blocked turn
from verexa import GuardBlockedErrortry:    completion = client.chat.completions.create(model="gpt-4o", messages=messages)    print(completion.choices[0].message.content)except GuardBlockedError as err:    # err.phase is "input" or "output"; err.response is the full verdict    print(f"Blocked on {err.phase}: {err}")

A flag verdict does not stop the turn. It is recorded so you can review it.

Check text from any model

If you do not use the OpenAI client, call the guard yourself. Check the prompt, call your model with the text Verexa returns, then check the reply with the same trace id.

Check input and output
from verexa import create_guard, random_trace_idguard = create_guard()trace_id = random_trace_id()verdict = guard.check_input(user_message, trace_id=trace_id)if verdict.action == "block":    returnprompt = verdict.text if verdict.action == "redact" else user_messagereply = call_your_model(prompt)checked = guard.check_output(reply, trace_id=trace_id, system_prompt=SYSTEM_PROMPT)if checked.action == "block":    returnsend(checked.text if checked.action == "redact" else reply)

Every SDK is a thin client over one endpoint, so you can also call the API directly:

Check a prompt over HTTP
curl https://api.verexa.dev/v1/check \  -H "Authorization: Bearer $VEREXA_API_KEY" \  -H "Content-Type: application/json" \  -d '{"traceId": "t_quickstart", "phase": "input", "text": "my email is jane.doe@example.com"}'
Response (trimmed)
{  "action": "redact",  "score": 1,  "detectors": [    { "detectorId": "prompt.instruction_override", "score": 0, "action": "allow" },    { "detectorId": "prompt.unicode_obfuscation", "score": 0, "action": "allow" },    { "detectorId": "text.pii", "score": 1, "action": "redact" }  ],  "text": "my email is [redacted email]",  "latencyMs": 0.05,  "degraded": false}

See it in the dashboard

Open Events in the dashboard. Each turn appears as one trace with its input and output checks, the detectors that fired and the action taken.

Next steps