Check Session
curl --request POST \
--url https://eu.whitecircle.com/api/protect/check \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'whitecircle-version: <whitecircle-version>' \
--data @- <<EOF
{
"external_id": "user-session-123",
"include_context": true,
"include_policy_names": true,
"messages": [
{
"content": "Hello, can you help me with something?",
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"role": "assistant"
}
],
"metadata": {
"model": {
"name": "gpt-4.1",
"price_per_1m_tokens": 0.1
},
"user": {
"id": "abcd-1234"
}
}
}
EOFimport requests
url = "https://eu.whitecircle.com/api/protect/check"
payload = {
"external_id": "user-session-123",
"include_context": True,
"include_policy_names": True,
"messages": [
{
"content": "Hello, can you help me with something?",
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"role": "assistant"
}
],
"metadata": {
"model": {
"name": "gpt-4.1",
"price_per_1m_tokens": 0.1
},
"user": { "id": "abcd-1234" }
}
}
headers = {
"whitecircle-version": "<whitecircle-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'whitecircle-version': '<whitecircle-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
external_id: 'user-session-123',
include_context: true,
include_policy_names: true,
messages: [
{content: 'Hello, can you help me with something?', role: 'user'},
{
content: [{text: 'Of course! I\'d be happy to help you.', type: 'text'}],
role: 'assistant'
}
],
metadata: {model: {name: 'gpt-4.1', price_per_1m_tokens: 0.1}, user: {id: 'abcd-1234'}}
})
};
fetch('https://eu.whitecircle.com/api/protect/check', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://eu.whitecircle.com/api/protect/check",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'external_id' => 'user-session-123',
'include_context' => true,
'include_policy_names' => true,
'messages' => [
[
'content' => 'Hello, can you help me with something?',
'role' => 'user'
],
[
'content' => [
[
'text' => 'Of course! I\'d be happy to help you.',
'type' => 'text'
]
],
'role' => 'assistant'
]
],
'metadata' => [
'model' => [
'name' => 'gpt-4.1',
'price_per_1m_tokens' => 0.1
],
'user' => [
'id' => 'abcd-1234'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"whitecircle-version: <whitecircle-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://eu.whitecircle.com/api/protect/check"
payload := strings.NewReader("{\n \"external_id\": \"user-session-123\",\n \"include_context\": true,\n \"include_policy_names\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"model\": {\n \"name\": \"gpt-4.1\",\n \"price_per_1m_tokens\": 0.1\n },\n \"user\": {\n \"id\": \"abcd-1234\"\n }\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("whitecircle-version", "<whitecircle-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://eu.whitecircle.com/api/protect/check")
.header("whitecircle-version", "<whitecircle-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"external_id\": \"user-session-123\",\n \"include_context\": true,\n \"include_policy_names\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"model\": {\n \"name\": \"gpt-4.1\",\n \"price_per_1m_tokens\": 0.1\n },\n \"user\": {\n \"id\": \"abcd-1234\"\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://eu.whitecircle.com/api/protect/check")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["whitecircle-version"] = '<whitecircle-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"external_id\": \"user-session-123\",\n \"include_context\": true,\n \"include_policy_names\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"model\": {\n \"name\": \"gpt-4.1\",\n \"price_per_1m_tokens\": 0.1\n },\n \"user\": {\n \"id\": \"abcd-1234\"\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"external_id": "user-session-001",
"internal_id": "123e4567-e89b-12d3-a456-426614174000",
"violation": true,
"violations": {
"123e4567-e89b-12d3-a456-426614174000": {
"name": "NSFW",
"violation": true,
"violation_source": [
"image"
]
},
"70289e06-9111-463e-b121-7247c2b7bfbd": {
"name": "No PII Sharing",
"violation": false,
"violation_source": []
},
"a4a91875-1e54-42d7-b9b0-a75dfebeb057": {
"name": "Drugs",
"violation": true,
"violation_source": [
"text"
]
}
}
}image_url and input_image content parts are not supported. To submit images, use the artifact API or a newer session API version with artifact content parts.Authorizations
API Key required. Format: Bearer wc-your-api-key
Headers
API Version
Body
Optional external identifier for tracking this session. Useful for correlating results with your own systems
Include previous conversation context associated with the same external_id. Default: false.
Include human-readable policy names in the response. Default: false.
Optional list of specific policy IDs to check. If omitted, all deployment policies are used.
Response
Success
Unique internal identifier for this check
Whether any policy violations were detected
Map of policy IDs to policy status objects containing violation and optional name
Hide child attributes
Hide child attributes
Hide child attributes
Hide child attributes
Whether a violation was detected for this policy
Sources where violations were detected (includes only triggered violations)
text, image Human-readable policy name (only present if include_policy_names=true)
{
"name": "No PII Sharing",
"violation": true,
"violation_source": ["text"]
}
Optional external identifier provided by client
curl --request POST \
--url https://eu.whitecircle.com/api/protect/check \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'whitecircle-version: <whitecircle-version>' \
--data @- <<EOF
{
"external_id": "user-session-123",
"include_context": true,
"include_policy_names": true,
"messages": [
{
"content": "Hello, can you help me with something?",
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"role": "assistant"
}
],
"metadata": {
"model": {
"name": "gpt-4.1",
"price_per_1m_tokens": 0.1
},
"user": {
"id": "abcd-1234"
}
}
}
EOFimport requests
url = "https://eu.whitecircle.com/api/protect/check"
payload = {
"external_id": "user-session-123",
"include_context": True,
"include_policy_names": True,
"messages": [
{
"content": "Hello, can you help me with something?",
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"role": "assistant"
}
],
"metadata": {
"model": {
"name": "gpt-4.1",
"price_per_1m_tokens": 0.1
},
"user": { "id": "abcd-1234" }
}
}
headers = {
"whitecircle-version": "<whitecircle-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'whitecircle-version': '<whitecircle-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
external_id: 'user-session-123',
include_context: true,
include_policy_names: true,
messages: [
{content: 'Hello, can you help me with something?', role: 'user'},
{
content: [{text: 'Of course! I\'d be happy to help you.', type: 'text'}],
role: 'assistant'
}
],
metadata: {model: {name: 'gpt-4.1', price_per_1m_tokens: 0.1}, user: {id: 'abcd-1234'}}
})
};
fetch('https://eu.whitecircle.com/api/protect/check', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://eu.whitecircle.com/api/protect/check",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'external_id' => 'user-session-123',
'include_context' => true,
'include_policy_names' => true,
'messages' => [
[
'content' => 'Hello, can you help me with something?',
'role' => 'user'
],
[
'content' => [
[
'text' => 'Of course! I\'d be happy to help you.',
'type' => 'text'
]
],
'role' => 'assistant'
]
],
'metadata' => [
'model' => [
'name' => 'gpt-4.1',
'price_per_1m_tokens' => 0.1
],
'user' => [
'id' => 'abcd-1234'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"whitecircle-version: <whitecircle-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://eu.whitecircle.com/api/protect/check"
payload := strings.NewReader("{\n \"external_id\": \"user-session-123\",\n \"include_context\": true,\n \"include_policy_names\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"model\": {\n \"name\": \"gpt-4.1\",\n \"price_per_1m_tokens\": 0.1\n },\n \"user\": {\n \"id\": \"abcd-1234\"\n }\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("whitecircle-version", "<whitecircle-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://eu.whitecircle.com/api/protect/check")
.header("whitecircle-version", "<whitecircle-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"external_id\": \"user-session-123\",\n \"include_context\": true,\n \"include_policy_names\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"model\": {\n \"name\": \"gpt-4.1\",\n \"price_per_1m_tokens\": 0.1\n },\n \"user\": {\n \"id\": \"abcd-1234\"\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://eu.whitecircle.com/api/protect/check")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["whitecircle-version"] = '<whitecircle-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"external_id\": \"user-session-123\",\n \"include_context\": true,\n \"include_policy_names\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"model\": {\n \"name\": \"gpt-4.1\",\n \"price_per_1m_tokens\": 0.1\n },\n \"user\": {\n \"id\": \"abcd-1234\"\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"external_id": "user-session-001",
"internal_id": "123e4567-e89b-12d3-a456-426614174000",
"violation": true,
"violations": {
"123e4567-e89b-12d3-a456-426614174000": {
"name": "NSFW",
"violation": true,
"violation_source": [
"image"
]
},
"70289e06-9111-463e-b121-7247c2b7bfbd": {
"name": "No PII Sharing",
"violation": false,
"violation_source": []
},
"a4a91875-1e54-42d7-b9b0-a75dfebeb057": {
"name": "Drugs",
"violation": true,
"violation_source": [
"text"
]
}
}
}