Skip to main content
Silmaril middleware runs in your application around the gateway model. It inspects calls made through that wrapped model.

Prerequisites

  • Install and configure the TypeScript SDK.
  • Set AI_GATEWAY_API_KEY for your Vercel AI Gateway account, or use Vercel’s supported deployment authentication.
  • Set SILMARIL_API_KEY and SILMARIL_API_URL to your provisioned Silmaril classify credentials.

Install the AI SDK

Wrap the gateway model

Use a model available to your gateway account. The example starts in shadow mode, so would-block decisions do not interrupt model calls.

Verify and enforce

Confirm both input and output classifications appear in Silmaril. The middleware checks input, and the explicit classify call checks generated text before it is returned. When ready to enforce, set shadowMode to false and handle FirewallBlockedException before returning a response to the caller. See TypeScript error handling. Handle gateway authentication, model, and network errors separately. A failed request is not a benign verdict.

Coverage

With AI SDK 6, use the explicit output check above instead of relying on the middleware’s scanOutput option. This example protects generated text. Classify tool-call arguments before executing a tool, and buffer streaming output until classification finishes when blocking before delivery is required. Every protected call must use the wrapped model and the output check. Configuring middleware in one application does not enable a gateway-wide guardrail for other applications or unwrapped calls.