Skip to main content

Prerequisites

Use Python 3.10 or later. Set SILMARIL_API_KEY and SILMARIL_API_URL from your deployment access.

Install

Classify your first request

Create one client per protected system and reuse it. Label each call with the boundary it checks.
For tool output, pass the tool name as well.

Expected result

A benign request logs prediction=BENIGN and its score. When the effective mode is block, a malicious request raises FirewallBlockedException. Its result holds the full verdict. In shadow or warn mode the call returns the result instead, so route on result.prediction. Your deployment sets the mode unless the client or call sets mode. Outcome meanings and recommended actions are in the outcome taxonomy. SilmarilApiError means the API returned a non-2xx response after retries. Network failures raise the underlying requests exception. Neither is a verdict, so decide whether that boundary fails open or closed. LangChain and LangGraph handlers for this client are documented in Framework SDKs.

Async classify

Install async support before using AsyncFirewall.
Share one AsyncFirewall across tasks on one event loop for the service lifetime and close it at shutdown. Cancellation stops the calling task’s request. Async calls raise the same block exceptions as the synchronous client. For a synchronous off-thread fallback, create one Firewall per worker thread.

Shadow mode

Shadow mode returns results instead of raising block exceptions, so you can measure would-block decisions while traffic continues. Per-call overrides let one boundary enforce before you change the client default.
The last call passes shadow_mode=False, so that call enforces.

Errors

Direct calls raise FirewallBlockedException when a block is enforced. It carries score, threshold, and the full result.
Read exc.result for the verdict, or use shadow mode when you need the result without a block exception. Outcome meanings and recommended actions are in the outcome taxonomy.