API reference
All endpoints are JSON over HTTPS. Authenticate with Authorization: Bearer <key>. Member keys (agy_live_…) call the gateway; admin keys (agy_admin_…) manage the workspace.
Gateway — POST /api/v1/chat
curl https://YOUR-DEPLOYMENT/api/v1/chat \
-H "Authorization: Bearer agy_live_..." \
-H "Content-Type: application/json" \
-d '{"model":"@cf/meta/llama-3.2-3b-instruct",
"messages":[{"role":"user","content":"Reply to jane@acme.io about her refund"}]}'
200 response (redacted request):
{
"decision": "redact",
"reasons": ["sensitive_data_redacted"],
"findings": { "input": { "EMAIL": 1 }, "output": {} },
"sent_to_model": [{ "role": "user", "content": "Reply to [EMAIL_1] about her refund" }],
"choices": [{ "index": 0, "message": { "role": "assistant", "content": "..." } }],
"usage": { "estimated_tokens": 61, "estimated_cost_usd": 0.000024 },
"audit": { "seq": 42, "hash": "9c1f..." }
}
Blocked requests return 403 with error.code = "policy_violation" and the reasons. Every request, allowed or not, gets an audit entry. Response headers: x-aegisly-decision, x-aegisly-audit-seq.
| Status | Code | Meaning |
|---|---|---|
| 401 | unauthorized | Missing, invalid or revoked key |
| 403 | policy_violation | Blocked term, secret/PII in block mode, model not allowed, prompt too long |
| 429 | plan_quota_exceeded / key_budget_exceeded | Monthly plan quota or per-key budget reached |
Workspace (admin key)
| Method | Path | Description |
|---|---|---|
| POST | /api/signup | Create workspace {workspace, email} → admin + member keys (no auth) |
| GET | /api/me | Workspace, plan, policy, month usage |
| PUT | /api/policy | {piiMode, secretsMode, blockedTerms[], maxPromptChars, allowedModels[], scanOutput} |
| POST | /api/scan | Dry-run the policy on {text} without calling a model |
| GET / POST | /api/keys | List keys with usage / create {label, monthly_budget_usd?} |
| DELETE | /api/keys/:id | Revoke a key |
| GET | /api/audit?limit=50 | Latest audit entries |
| GET | /api/audit/verify | Recompute the hash chain → {valid, checked, head} |
| GET | /api/audit/export.csv | Full audit export |
| POST | /api/billing/checkout | {plan} → Stripe Checkout URL (or sandbox switch when Stripe is not configured) |
Detectors
PII: EMAIL, PHONE, CREDIT_CARD (Luhn-validated), US_SSN, BR_CPF (check digits validated), IBAN, IP_ADDRESS. Secrets: AWS_ACCESS_KEY, API_KEY (sk-/pk-/rk- style), GITHUB_TOKEN, JWT, PRIVATE_KEY.
Detection is pattern-based and deterministic: fast and auditable, but not a guarantee. Names and free-text identifiers are not detected in this version.