Scan File
curl --request POST \
--url https://api.your-blindsight.com/api/runtime-security/scan/file \
--header 'Content-Type: application/json' \
--data '
{
"data": "<string>",
"filename": "<string>",
"media_type": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
'import requests
url = "https://api.your-blindsight.com/api/runtime-security/scan/file"
payload = {
"data": "<string>",
"filename": "<string>",
"media_type": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
data: '<string>',
filename: '<string>',
media_type: '<string>',
direction: 'input',
source_app: '<string>',
provider: '<string>',
model: '<string>',
metadata: {}
})
};
fetch('https://api.your-blindsight.com/api/runtime-security/scan/file', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.your-blindsight.com/api/runtime-security/scan/file",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'data' => '<string>',
'filename' => '<string>',
'media_type' => '<string>',
'direction' => 'input',
'source_app' => '<string>',
'provider' => '<string>',
'model' => '<string>',
'metadata' => [
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.your-blindsight.com/api/runtime-security/scan/file"
payload := strings.NewReader("{\n \"data\": \"<string>\",\n \"filename\": \"<string>\",\n \"media_type\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.your-blindsight.com/api/runtime-security/scan/file")
.header("Content-Type", "application/json")
.body("{\n \"data\": \"<string>\",\n \"filename\": \"<string>\",\n \"media_type\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.your-blindsight.com/api/runtime-security/scan/file")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"data\": \"<string>\",\n \"filename\": \"<string>\",\n \"media_type\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n}"
response = http.request(request)
puts response.read_body{
"uuid": "<string>",
"verdict": "<string>",
"injection": {},
"pii": {},
"redacted": true,
"redacted_count": 123,
"data": "<string>",
"kind": "<string>",
"extracted_chars": 123,
"latency_ms": 123,
"media_type": "<string>",
"filename": "<string>",
"blocked_reason": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}runtime-security
Scan File
Extract text from an uploaded file, scan it, and (when redaction is needed) rewrite the file in place so the bytes returned to the caller carry placeholders instead of the original PII/secrets.
The desktop agent calls this for file/document blocks it finds in proxied LLM requests, its own detection stack only sees plain message text, so without this path nothing inside an uploaded spreadsheet/PDF is inspected.
POST
/
api
/
runtime-security
/
scan
/
file
Scan File
curl --request POST \
--url https://api.your-blindsight.com/api/runtime-security/scan/file \
--header 'Content-Type: application/json' \
--data '
{
"data": "<string>",
"filename": "<string>",
"media_type": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
'import requests
url = "https://api.your-blindsight.com/api/runtime-security/scan/file"
payload = {
"data": "<string>",
"filename": "<string>",
"media_type": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
data: '<string>',
filename: '<string>',
media_type: '<string>',
direction: 'input',
source_app: '<string>',
provider: '<string>',
model: '<string>',
metadata: {}
})
};
fetch('https://api.your-blindsight.com/api/runtime-security/scan/file', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.your-blindsight.com/api/runtime-security/scan/file",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'data' => '<string>',
'filename' => '<string>',
'media_type' => '<string>',
'direction' => 'input',
'source_app' => '<string>',
'provider' => '<string>',
'model' => '<string>',
'metadata' => [
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.your-blindsight.com/api/runtime-security/scan/file"
payload := strings.NewReader("{\n \"data\": \"<string>\",\n \"filename\": \"<string>\",\n \"media_type\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.your-blindsight.com/api/runtime-security/scan/file")
.header("Content-Type", "application/json")
.body("{\n \"data\": \"<string>\",\n \"filename\": \"<string>\",\n \"media_type\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.your-blindsight.com/api/runtime-security/scan/file")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"data\": \"<string>\",\n \"filename\": \"<string>\",\n \"media_type\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n}"
response = http.request(request)
puts response.read_body{
"uuid": "<string>",
"verdict": "<string>",
"injection": {},
"pii": {},
"redacted": true,
"redacted_count": 123,
"data": "<string>",
"kind": "<string>",
"extracted_chars": 123,
"latency_ms": 123,
"media_type": "<string>",
"filename": "<string>",
"blocked_reason": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Headers
Body
application/json
Base64-encoded file bytes to scan.
Maximum string length:
512MIME hint, e.g. application/pdf. Sniffed if absent.
Maximum string length:
255Pattern:
^(input|output)$Maximum string length:
128Maximum string length:
32Maximum string length:
128Response
Successful Response

