Classify an event
Return a Firewall verdict for one complete event.
text. For multiple independent events, use batch classification.
Use your provisioned SILMARIL_API_URL as the full request URL. Inspect prediction and optional governance.action before consuming the event.
Authorizations
API key provisioned for your deployment.
Body
One complete event to classify. Input-size limits depend on your deployment.
1"Summarize this release note."
Boundary being checked. Use the SDK hook labels shown here.
user_input, system_prompt, tool_call, tool_response, llm_output, unknown "user_input"
Tool name when checking a tool call or tool response.
"read_file"
JSON metadata for this event. SDKs add request identity under silmaril. A conversationId connects ordered single-event calls when conversation history is supported. Batch metadata does not connect events into a sequence.
Concrete governance resource, where supported. id must not be blank. mcp_tool requires parent_id; other resource kinds must omit parent_id.
Resource-catalog revision for deployments supporting concrete governance identities.
1Scoring override for legacy runtimes. Cascade uses its configured decision policy. Use the returned prediction as the verdict.
0 <= x <= 1Score calibration for legacy runtimes. Support depends on your deployment.
0.01 <= x <= 10Response
One verdict. A malicious or governance-blocked result still returns HTTP 200.
Authoritative verdict. Also check governance.action when present.
BENIGN, MALICIOUS Classification score. Use prediction for the verdict instead of recomputing it from score.
0 <= x <= 1Threshold reported by the deployment.
0 <= x <= 1Optional outcome detail. A missing or unknown malicious outcome should be blocked by default in Block mode.
benign, information_disclosure, secret_exposure, control_abuse, system_compromise, service_disruption Optional scores keyed by harmful outcome. Available keys depend on the deployment.
Optional scores keyed by harmful outcome. Available keys depend on the deployment.
Optional detection counts keyed by harmful outcome.
Optional governance decision. Older deployments may omit this field.