Configure Prompt Guard.
Checking account…
Use Google or email to sign in. Save a policy, create a key, then connect your server-side API client.
1. Review and save your policy
Loading saved policy…
Existing settings load before editing is enabled. Private terms: up to 50 entries, 3–120 characters each.
2. Create a proxy key
100 hosted requests are free. Your selected AI provider charges separately. Rotating the proxy key immediately revokes the old key.
POST https://workflow-inspector.com/api/tools/ai-proxy/v1/chat/completions Authorization: Bearer YOUR_PROMPT_GUARD_KEY X-Upstream-API-Key: YOUR_PROVIDER_KEY Idempotency-Key: UNIQUE_REQUEST_ID
Text-only, non-streaming requests. See the quickstart and coverage.
3. Employee keys (optional)
Each key uses your central policy and shared quota. Restrict providers, set an expiry and revoke access individually.
Add "provider":"anthropic" or "provider":"gemini" to your JSON request and use a model ID supported by that provider. The default is OpenAI. Requests still require text-only messages.
Subscription and access
$19/month for 10,000 hosted text requests per UTC month. No overage charges. Quota exhaustion blocks requests. Plus applicable tax. Cancel anytime.
Revoking access stops the tool and removes stored credentials. It does not cancel billing; use Manage subscription to cancel renewal. Cancellation keeps paid access until the displayed period end. For account or retained-data deletion, contact support; revocation is not account deletion.
Recent operations
Last 100 metadata events, retained up to 30 days. No prompts or model responses are recorded.
Latest 1,000 retained events, signed with Ed25519. This verifies snapshot integrity, not completeness or compliance certification.
4. Connect and troubleshoot
You supply your own OpenAI, Anthropic or Gemini key on each server-side request. Provider usage is billed separately. Never paste a provider key into a URL, public browser bundle or this page. Protection applies only to requests routed through Prompt Guard.
The local scanner is free and makes no provider calls. A successful local scan checks policy behavior, not provider credentials or a live connection.
- INVALID_KEY / 401
- Use an unexpired Prompt Guard key; check whether it was rotated or revoked.
- PROVIDER_FORBIDDEN / 403
- Choose a provider permitted for the employee key.
- POLICY_BLOCKED / 422
- Your policy blocked the request. No model call was made.
- QUOTA_EXHAUSTED / 402
- Check the displayed allowance and billing status. Requests stay blocked when the quota is exhausted.
- PROVIDER_REJECTED / 429 or 502
- Check the selected provider's credentials, model access, rate limit and billing. Provider errors are sanitized.
- DUPLICATE_REQUEST / 409 or uncertain timeout
- Inspect recent operations before retrying. Do not automatically send a new request ID: a provider may already have processed the first request.
Get support: include the error code and request ID only. Never send API keys or raw sensitive prompts.