Classify a batch
Return a Firewall verdict for each independent event in input order.
texts. For conversation-aware checks, use ordered single-event requests with the same metadata.conversationId. Batch classification neither reads nor updates conversation history.
Use your provisioned SILMARIL_API_URL as the full request URL. Inspect prediction and optional governance.action for every item in predictions before consuming it.
Authorizations
API key provisioned for your deployment.
Body
Independent events. Batch and input-size limits depend on your deployment.
11One hook per text, in input order. Length must match texts.
Boundary being checked. Use the SDK hook labels shown here.
user_input, system_prompt, tool_call, tool_response, llm_output, unknown One tool name or null per text. Length must match texts.
One metadata object or null per text. Length must match texts.
JSON metadata for this event. SDKs add request identity under silmaril. A conversationId connects ordered single-event calls when conversation history is supported. Batch metadata does not connect events into a sequence.
One concrete resource or null per text, where supported. Length must match texts.
Concrete governance resource, where supported. id must not be blank. mcp_tool requires parent_id; other resource kinds must omit parent_id.
Resource-catalog revision, where supported by the deployment.
1Scoring override for legacy runtimes. Cascade uses its configured decision policy. Use the returned prediction as the verdict.
0 <= x <= 1Score calibration for legacy runtimes. Support depends on your deployment.
0.01 <= x <= 10Response
One verdict per text in the predictions array, in input order. Malicious or governance-blocked items still return HTTP 200.
One verdict per text, in input order.