API reference

All endpoints are JSON over HTTPS. Authenticate with Authorization: Bearer <key>. Member keys (agy_live_…) call the gateway; admin keys (agy_admin_…) manage the workspace.

Gateway — POST /api/v1/chat

curl https://YOUR-DEPLOYMENT/api/v1/chat \
  -H "Authorization: Bearer agy_live_..." \
  -H "Content-Type: application/json" \
  -d '{"model":"@cf/meta/llama-3.2-3b-instruct",
       "messages":[{"role":"user","content":"Reply to jane@acme.io about her refund"}]}'

200 response (redacted request):

{
  "decision": "redact",
  "reasons": ["sensitive_data_redacted"],
  "findings": { "input": { "EMAIL": 1 }, "output": {} },
  "sent_to_model": [{ "role": "user", "content": "Reply to [EMAIL_1] about her refund" }],
  "choices": [{ "index": 0, "message": { "role": "assistant", "content": "..." } }],
  "usage": { "estimated_tokens": 61, "estimated_cost_usd": 0.000024 },
  "audit": { "seq": 42, "hash": "9c1f..." }
}

Blocked requests return 403 with error.code = "policy_violation" and the reasons. Every request, allowed or not, gets an audit entry. Response headers: x-aegisly-decision, x-aegisly-audit-seq.

StatusCodeMeaning
401unauthorizedMissing, invalid or revoked key
403policy_violationBlocked term, secret/PII in block mode, model not allowed, prompt too long
429plan_quota_exceeded / key_budget_exceededMonthly plan quota or per-key budget reached

Workspace (admin key)

MethodPathDescription
POST/api/signupCreate workspace {workspace, email} → admin + member keys (no auth)
GET/api/meWorkspace, plan, policy, month usage
PUT/api/policy{piiMode, secretsMode, blockedTerms[], maxPromptChars, allowedModels[], scanOutput}
POST/api/scanDry-run the policy on {text} without calling a model
GET / POST/api/keysList keys with usage / create {label, monthly_budget_usd?}
DELETE/api/keys/:idRevoke a key
GET/api/audit?limit=50Latest audit entries
GET/api/audit/verifyRecompute the hash chain → {valid, checked, head}
GET/api/audit/export.csvFull audit export
POST/api/billing/checkout{plan} → Stripe Checkout URL (or sandbox switch when Stripe is not configured)

Detectors

PII: EMAIL, PHONE, CREDIT_CARD (Luhn-validated), US_SSN, BR_CPF (check digits validated), IBAN, IP_ADDRESS. Secrets: AWS_ACCESS_KEY, API_KEY (sk-/pk-/rk- style), GITHUB_TOKEN, JWT, PRIVATE_KEY.

Detection is pattern-based and deterministic: fast and auditable, but not a guarantee. Names and free-text identifiers are not detected in this version.