> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zespan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Run a guardrails check

> Evaluate text against the authenticated project's enabled guardrails at runtime. Returns whether the text is allowed, the per-guardrail results, and any modified (e.g. redacted) text. Requires `x-api-key`.




## OpenAPI

````yaml /api-reference/openapi.yaml post /v1/guardrails/check
openapi: 3.1.0
info:
  title: Zespan Public API
  version: 1.0.0
  description: >
    The Zespan Public API covers the endpoints that customers call directly or
    through the Zespan SDKs: trace ingestion (native and OpenTelemetry), prompt
    management, datasets and dataset runs, and the runtime guardrails check.

    All endpoints authenticate with a project API key sent in the `x-api-key`
    header. Create and manage API keys from the project settings in the Zespan
    dashboard.
servers:
  - url: https://api.zespan.com
    description: Zespan production API
security:
  - ApiKeyAuth: []
tags:
  - name: Ingestion
    description: Send traces and events to Zespan.
  - name: OpenTelemetry
    description: OTLP-compatible ingestion endpoints.
  - name: Prompts
    description: Manage versioned prompts and their labels, tags, and folders.
  - name: Datasets
    description: Read datasets and manage dataset runs used for experiments and scoring.
  - name: Guardrails
    description: Runtime guardrail evaluation.
paths:
  /v1/guardrails/check:
    post:
      tags:
        - Guardrails
      summary: Run a guardrails check
      description: >
        Evaluate text against the authenticated project's enabled guardrails at
        runtime. Returns whether the text is allowed, the per-guardrail results,
        and any modified (e.g. redacted) text. Requires `x-api-key`.
      operationId: guardrailsCheck
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - text
                - phase
              properties:
                text:
                  type: string
                  minLength: 1
                  maxLength: 50000
                  example: My card number is 4111 1111 1111 1111.
                phase:
                  type: string
                  enum:
                    - pre
                    - post
                  description: Whether this is checking input (`pre`) or output (`post`).
                traceId:
                  type: string
                spanId:
                  type: string
                model:
                  type: string
                  example: gpt-4o
                operation:
                  type: string
                estimatedCost:
                  type: number
                inputTokens:
                  type: integer
                agentName:
                  type: string
                  maxLength: 200
                toolName:
                  type: string
                  maxLength: 200
                recentToolCalls:
                  type: array
                  maxItems: 100
                  items:
                    type: object
                    properties:
                      toolName:
                        type: string
                        maxLength: 200
                      args:
                        type: string
                        maxLength: 10000
      responses:
        '200':
          description: Guardrail evaluation result.
          content:
            application/json:
              schema:
                type: object
                properties:
                  allowed:
                    type: boolean
                    example: false
                  results:
                    type: array
                    items:
                      $ref: '#/components/schemas/GuardrailResult'
                  modifiedText:
                    type: string
                    nullable: true
                    example: My card number is [REDACTED].
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    GuardrailResult:
      type: object
      properties:
        guardrailSlug:
          type: string
          example: pii-detection
        passed:
          type: boolean
          example: false
        action:
          type: string
          enum:
            - allowed
            - blocked
            - redacted
            - warned
        reason:
          type: string
          nullable: true
          example: Detected credit card number
        modifiedText:
          type: string
          nullable: true
        latencyMs:
          type: integer
          example: 12
    Error:
      type: object
      properties:
        error:
          type: string
          description: Human-readable error message.
          example: Unauthorized
        code:
          type: string
          description: Machine-readable error code, when present.
          example: rate_limit_exceeded
      required:
        - error
  responses:
    Unauthorized:
      description: Missing or invalid API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Project API key. Manage keys in the Zespan dashboard under project
        settings.

````