Scan up to 32 items in one round-trip
curl --request POST \
--url https://api.blindsight.example.com/api/runtime-security/scan/batch \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"items": [
{
"text": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
]
}
'import requests
url = "https://api.blindsight.example.com/api/runtime-security/scan/batch"
payload = { "items": [
{
"text": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
] }
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
items: [
{
text: '<string>',
direction: 'input',
source_app: '<string>',
provider: '<string>',
model: '<string>',
metadata: {}
}
]
})
};
fetch('https://api.blindsight.example.com/api/runtime-security/scan/batch', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.blindsight.example.com/api/runtime-security/scan/batch",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'items' => [
[
'text' => '<string>',
'direction' => 'input',
'source_app' => '<string>',
'provider' => '<string>',
'model' => '<string>',
'metadata' => [
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.blindsight.example.com/api/runtime-security/scan/batch"
payload := strings.NewReader("{\n \"items\": [\n {\n \"text\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.blindsight.example.com/api/runtime-security/scan/batch")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"items\": [\n {\n \"text\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.blindsight.example.com/api/runtime-security/scan/batch")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"items\": [\n {\n \"text\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"results": [
{
"uuid": "<string>",
"injection": {
"score": 0.5,
"meta": {}
},
"pii": {
"count": 1,
"categories": [
"<string>"
],
"findings": [
{
"type": "<string>",
"subtype": "<string>",
"score": 0.5,
"snippet": "<string>",
"start": 1,
"end": 1,
"extra": {}
}
]
},
"redacted_text": "<string>",
"latency_ms": 1,
"text_length": 1,
"blocked_reason": "<string>"
}
]
}{
"detail": {
"code": "QUOTA_EXCEEDED",
"message": "<string>",
"usage": {
"used": 123,
"limit": 123,
"period_end": "2023-11-07T05:31:56Z"
},
"upgrade_url": "<string>"
}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "<string>"
}Scan
Scan up to 32 items in one round-trip
Each item costs one license call (same as individual scans). If quota runs out mid-batch, the entire request fails with 402 and no scoring runs.
POST
/
api
/
runtime-security
/
scan
/
batch
Scan up to 32 items in one round-trip
curl --request POST \
--url https://api.blindsight.example.com/api/runtime-security/scan/batch \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"items": [
{
"text": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
]
}
'import requests
url = "https://api.blindsight.example.com/api/runtime-security/scan/batch"
payload = { "items": [
{
"text": "<string>",
"direction": "input",
"source_app": "<string>",
"provider": "<string>",
"model": "<string>",
"metadata": {}
}
] }
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
items: [
{
text: '<string>',
direction: 'input',
source_app: '<string>',
provider: '<string>',
model: '<string>',
metadata: {}
}
]
})
};
fetch('https://api.blindsight.example.com/api/runtime-security/scan/batch', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.blindsight.example.com/api/runtime-security/scan/batch",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'items' => [
[
'text' => '<string>',
'direction' => 'input',
'source_app' => '<string>',
'provider' => '<string>',
'model' => '<string>',
'metadata' => [
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.blindsight.example.com/api/runtime-security/scan/batch"
payload := strings.NewReader("{\n \"items\": [\n {\n \"text\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.blindsight.example.com/api/runtime-security/scan/batch")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"items\": [\n {\n \"text\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.blindsight.example.com/api/runtime-security/scan/batch")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"items\": [\n {\n \"text\": \"<string>\",\n \"direction\": \"input\",\n \"source_app\": \"<string>\",\n \"provider\": \"<string>\",\n \"model\": \"<string>\",\n \"metadata\": {}\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"results": [
{
"uuid": "<string>",
"injection": {
"score": 0.5,
"meta": {}
},
"pii": {
"count": 1,
"categories": [
"<string>"
],
"findings": [
{
"type": "<string>",
"subtype": "<string>",
"score": 0.5,
"snippet": "<string>",
"start": 1,
"end": 1,
"extra": {}
}
]
},
"redacted_text": "<string>",
"latency_ms": 1,
"text_length": 1,
"blocked_reason": "<string>"
}
]
}{
"detail": {
"code": "QUOTA_EXCEEDED",
"message": "<string>",
"usage": {
"used": 123,
"limit": 123,
"period_end": "2023-11-07T05:31:56Z"
},
"upgrade_url": "<string>"
}
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "<string>"
}Authorizations
ApiKeyAuthBlindsightKeyAuthSessionCookieAuth
Blindsight workspace API key (ak_live_…). Use this header for the
scan API and the OpenAI proxy routes. The required permission
scope is runtime_security.scan for scan endpoints,
runtime_security.view for read-only analytics, and
runtime_security.manage for configuration changes.
Body
application/json
Required array length:
1 - 32 elementsShow child attributes
Show child attributes
Response
All items scored
Show child attributes
Show child attributes
Scan an LLM response before returning it to the userScan an agent tool invocation before executing it
⌘I

