Get access
Silmaril provisions an API key and a classify URL for your deployment. Book a call to arrange access, then setSILMARIL_API_KEY and SILMARIL_API_URL in your service environment.
SILMARIL_API_URL is the complete classify URL, including any deployment path prefix and /classify. Use the supplied value as-is. Hosted and self-hosted deployments use the same request format.
Classify events
Send JSON with thex-api-key header to POST /classify.
Batch items are independent. For conversation-aware checks, send ordered single-event requests with the same
metadata.conversationId, waiting for each verdict before sending the next event.
Handle the verdict
A successful HTTP response contains a verdict even when it is malicious. Checkprediction and the optional governance.action before consuming the event. In Block mode, stop a malicious or governance-blocked event. In Warn or Shadow mode, record the would-block decision and continue according to your application policy.
prediction is the authoritative BENIGN or MALICIOUS verdict. The score and optional outcome fields add detail. Use firewall outcomes to route malicious results.
A non-2xx response or network failure means no verdict was returned. Your application decides whether that boundary fails open or closed.