Sessions
Check Content
POST
/
api
/
session
/
check
cURL
curl --request POST \
--url https://eu.whitecircle.com/api/session/check \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'whitecircle-version: <whitecircle-version>' \
--data @- <<EOF
{
"deployment_id": "your-deployment-id",
"external_session_id": "user-session-123",
"include_context": true,
"messages": [
{
"content": "Hello, can you help me with something?",
"metadata": {
"message": {
"id": "msg-123"
},
"user": {
"email": "user@example.com",
"id": "user-456"
}
},
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"metadata": {
"assistant": {
"latency": 1.2,
"model_name": "gpt-4o-mini"
}
},
"role": "assistant"
}
],
"metadata": {
"session": {
"timestamp": "2025-12-01T10:00:00Z"
}
}
}
EOFimport requests
url = "https://eu.whitecircle.com/api/session/check"
payload = {
"deployment_id": "your-deployment-id",
"external_session_id": "user-session-123",
"include_context": True,
"messages": [
{
"content": "Hello, can you help me with something?",
"metadata": {
"message": { "id": "msg-123" },
"user": {
"email": "user@example.com",
"id": "user-456"
}
},
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"metadata": { "assistant": {
"latency": 1.2,
"model_name": "gpt-4o-mini"
} },
"role": "assistant"
}
],
"metadata": { "session": { "timestamp": "2025-12-01T10:00:00Z" } }
}
headers = {
"whitecircle-version": "<whitecircle-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'whitecircle-version': '<whitecircle-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
deployment_id: 'your-deployment-id',
external_session_id: 'user-session-123',
include_context: true,
messages: [
{
content: 'Hello, can you help me with something?',
metadata: {message: {id: 'msg-123'}, user: {email: 'user@example.com', id: 'user-456'}},
role: 'user'
},
{
content: [{text: 'Of course! I\'d be happy to help you.', type: 'text'}],
metadata: {assistant: {latency: 1.2, model_name: 'gpt-4o-mini'}},
role: 'assistant'
}
],
metadata: {session: {timestamp: '2025-12-01T10:00:00Z'}}
})
};
fetch('https://eu.whitecircle.com/api/session/check', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://eu.whitecircle.com/api/session/check",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'deployment_id' => 'your-deployment-id',
'external_session_id' => 'user-session-123',
'include_context' => true,
'messages' => [
[
'content' => 'Hello, can you help me with something?',
'metadata' => [
'message' => [
'id' => 'msg-123'
],
'user' => [
'email' => 'user@example.com',
'id' => 'user-456'
]
],
'role' => 'user'
],
[
'content' => [
[
'text' => 'Of course! I\'d be happy to help you.',
'type' => 'text'
]
],
'metadata' => [
'assistant' => [
'latency' => 1.2,
'model_name' => 'gpt-4o-mini'
]
],
'role' => 'assistant'
]
],
'metadata' => [
'session' => [
'timestamp' => '2025-12-01T10:00:00Z'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"whitecircle-version: <whitecircle-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://eu.whitecircle.com/api/session/check"
payload := strings.NewReader("{\n \"deployment_id\": \"your-deployment-id\",\n \"external_session_id\": \"user-session-123\",\n \"include_context\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"metadata\": {\n \"message\": {\n \"id\": \"msg-123\"\n },\n \"user\": {\n \"email\": \"user@example.com\",\n \"id\": \"user-456\"\n }\n },\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"metadata\": {\n \"assistant\": {\n \"latency\": 1.2,\n \"model_name\": \"gpt-4o-mini\"\n }\n },\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"session\": {\n \"timestamp\": \"2025-12-01T10:00:00Z\"\n }\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("whitecircle-version", "<whitecircle-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://eu.whitecircle.com/api/session/check")
.header("whitecircle-version", "<whitecircle-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"deployment_id\": \"your-deployment-id\",\n \"external_session_id\": \"user-session-123\",\n \"include_context\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"metadata\": {\n \"message\": {\n \"id\": \"msg-123\"\n },\n \"user\": {\n \"email\": \"user@example.com\",\n \"id\": \"user-456\"\n }\n },\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"metadata\": {\n \"assistant\": {\n \"latency\": 1.2,\n \"model_name\": \"gpt-4o-mini\"\n }\n },\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"session\": {\n \"timestamp\": \"2025-12-01T10:00:00Z\"\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://eu.whitecircle.com/api/session/check")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["whitecircle-version"] = '<whitecircle-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"deployment_id\": \"your-deployment-id\",\n \"external_session_id\": \"user-session-123\",\n \"include_context\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"metadata\": {\n \"message\": {\n \"id\": \"msg-123\"\n },\n \"user\": {\n \"email\": \"user@example.com\",\n \"id\": \"user-456\"\n }\n },\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"metadata\": {\n \"assistant\": {\n \"latency\": 1.2,\n \"model_name\": \"gpt-4o-mini\"\n }\n },\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"session\": {\n \"timestamp\": \"2025-12-01T10:00:00Z\"\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"flagged": true,
"internal_session_id": "123e4567-e89b-12d3-a456-426614174000",
"external_session_id": "user-session-001",
"policies": {
"70289e06-9111-463e-b121-7247c2b7bfbd": {
"flagged": false,
"flagged_source": [],
"name": "No PII Sharing"
},
"a4a91875-1e54-42d7-b9b0-a75dfebeb057": {
"flagged": true,
"flagged_source": [
"text"
],
"name": "Drugs"
}
}
}This is the core endpoint for content moderation and analytics — send your content using the OpenAI-like message format and receive instant feedback on policy violations. Metrics are computed for each request in the background.
Each policy in the
The last message’s role determines which policies are evaluated:
Role strings with postfixes (e.g.,
Using
How It Works
- You submit content as one or more messages
- White Circle analyzes the content against all policies in your deployment
- You receive a response indicating which (if any) policies got flagged
Each check is associated with a session. Sessions help you track content over time and enable features like context merging.
Policies and metrics are evaluated against only the last message in the
messages array. All preceding messages provide context for the evaluation but are not themselves checked for violations.Request Overview
| Field | Type | Required | Description |
|---|---|---|---|
messages | array | ✓ | Array of messages to analyze |
deployment_id | string | ✓ | The deployment ID to check against |
external_session_id | string | Your custom tracking ID | |
include_context | boolean | Automatically include previous messages. Defaults to true if external_session_id is provided. See Context Merging. | |
metadata | object | Session-level metadata. See Metadata |
Response Overview
| Field | Description |
|---|---|
flagged | true if any policy was violated |
internal_session_id | System-generated UUID for this session |
external_session_id | Your custom tracking ID (if provided) |
policies | Map of policy IDs to their violation statuses |
policies object includes:
name— Human-readable policy nameflagged— Whether this specific policy was violatedflagged_source— Array of content types that triggered the violation:["text"],["image"], or["text", "image"]when both text and image violated
Message Roles
The API uses OpenAI-compatible message format. Each message must have arole field:
| Role | Description |
|---|---|
system | System prompts or instructions |
user | User-created content |
assistant | AI-generated content |
tool | Tool/function call outputs |
developer | Developer-level instructions |
| Last message role | Policies applied |
|---|---|
user, system, developer, tool | input + any policies |
assistant | output + any policies |
"user-12345", "assistant-v2") are normalized to their base role.
Send both user and assistant messages to detect violations in either direction, whether they’re harmful requests from users or problematic responses from your AI.
Content Types
White Circle supports different content formats within a message:image_url and input_image content parts are not supported. To include images in a session, use artifact content parts.Text
Plain text content in string format
Images
Images inline or by reference via artifact content parts
Artifacts
Standalone content checks for images, with pre-check and reference support
Advanced Features
Context Merging
Send only new messages and let White Circle automatically merge them with the previous session context
Metadata
Attach user information, timestamps, and custom data to enable risk scoring and analytics
Session Tracking
Useexternal_session_id to track content using your own identifiers. This can be any string that makes sense for your application:
| Use Case | Example external_session_id |
|---|---|
| Chat conversation | "conversation-a1b2c3d4" |
| User session | "user-123-session-456" |
| Support ticket | "ticket-2024-001234" |
| Document review | "doc-review-draft-v2" |
| Thread/channel | "slack-channel-C04ABCD-thread-1234" |
{
"deployment_id": "your-deployment-id",
"external_session_id": "user-123-conversation-456",
"messages": [...]
}
external_session_id allows you to:
- Retrieve results later via Retrieving Results
- Use context merging to send incremental updates
- Enable Risk Scoring by associating sessions with users
Authorizations
API Key required. Format: Bearer wc-your-api-key
Headers
API Version
Body
application/json
Array of chat messages to analyze for policy violations
Hide child attributes
Hide child attributes
Hide child attributes
Hide child attributes
Hide child attributes
Hide child attributes
City name
Example:
"San Francisco"
Full country name
Example:
"United States"
ISO 3166-1 alpha-2 country code (e.g., 'US', 'GB')
Example:
"US"
User's IP address for geolocation lookup
Example:
"8.8.8.8"
Latitude coordinate
Example:
37.7749
Longitude coordinate
Example:
-122.4194
State/province name or code
Example:
"California"
The deployment ID to check against
Optional external identifier for tracking this session
Include previous conversation context. Defaults to true if external_session_id is provided
Optional list of specific policy IDs to check against. If omitted, all deployment policies are used
Response
Success
⌘I
cURL
curl --request POST \
--url https://eu.whitecircle.com/api/session/check \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'whitecircle-version: <whitecircle-version>' \
--data @- <<EOF
{
"deployment_id": "your-deployment-id",
"external_session_id": "user-session-123",
"include_context": true,
"messages": [
{
"content": "Hello, can you help me with something?",
"metadata": {
"message": {
"id": "msg-123"
},
"user": {
"email": "user@example.com",
"id": "user-456"
}
},
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"metadata": {
"assistant": {
"latency": 1.2,
"model_name": "gpt-4o-mini"
}
},
"role": "assistant"
}
],
"metadata": {
"session": {
"timestamp": "2025-12-01T10:00:00Z"
}
}
}
EOFimport requests
url = "https://eu.whitecircle.com/api/session/check"
payload = {
"deployment_id": "your-deployment-id",
"external_session_id": "user-session-123",
"include_context": True,
"messages": [
{
"content": "Hello, can you help me with something?",
"metadata": {
"message": { "id": "msg-123" },
"user": {
"email": "user@example.com",
"id": "user-456"
}
},
"role": "user"
},
{
"content": [
{
"text": "Of course! I'd be happy to help you.",
"type": "text"
}
],
"metadata": { "assistant": {
"latency": 1.2,
"model_name": "gpt-4o-mini"
} },
"role": "assistant"
}
],
"metadata": { "session": { "timestamp": "2025-12-01T10:00:00Z" } }
}
headers = {
"whitecircle-version": "<whitecircle-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'whitecircle-version': '<whitecircle-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
deployment_id: 'your-deployment-id',
external_session_id: 'user-session-123',
include_context: true,
messages: [
{
content: 'Hello, can you help me with something?',
metadata: {message: {id: 'msg-123'}, user: {email: 'user@example.com', id: 'user-456'}},
role: 'user'
},
{
content: [{text: 'Of course! I\'d be happy to help you.', type: 'text'}],
metadata: {assistant: {latency: 1.2, model_name: 'gpt-4o-mini'}},
role: 'assistant'
}
],
metadata: {session: {timestamp: '2025-12-01T10:00:00Z'}}
})
};
fetch('https://eu.whitecircle.com/api/session/check', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://eu.whitecircle.com/api/session/check",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'deployment_id' => 'your-deployment-id',
'external_session_id' => 'user-session-123',
'include_context' => true,
'messages' => [
[
'content' => 'Hello, can you help me with something?',
'metadata' => [
'message' => [
'id' => 'msg-123'
],
'user' => [
'email' => 'user@example.com',
'id' => 'user-456'
]
],
'role' => 'user'
],
[
'content' => [
[
'text' => 'Of course! I\'d be happy to help you.',
'type' => 'text'
]
],
'metadata' => [
'assistant' => [
'latency' => 1.2,
'model_name' => 'gpt-4o-mini'
]
],
'role' => 'assistant'
]
],
'metadata' => [
'session' => [
'timestamp' => '2025-12-01T10:00:00Z'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"whitecircle-version: <whitecircle-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://eu.whitecircle.com/api/session/check"
payload := strings.NewReader("{\n \"deployment_id\": \"your-deployment-id\",\n \"external_session_id\": \"user-session-123\",\n \"include_context\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"metadata\": {\n \"message\": {\n \"id\": \"msg-123\"\n },\n \"user\": {\n \"email\": \"user@example.com\",\n \"id\": \"user-456\"\n }\n },\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"metadata\": {\n \"assistant\": {\n \"latency\": 1.2,\n \"model_name\": \"gpt-4o-mini\"\n }\n },\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"session\": {\n \"timestamp\": \"2025-12-01T10:00:00Z\"\n }\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("whitecircle-version", "<whitecircle-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://eu.whitecircle.com/api/session/check")
.header("whitecircle-version", "<whitecircle-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"deployment_id\": \"your-deployment-id\",\n \"external_session_id\": \"user-session-123\",\n \"include_context\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"metadata\": {\n \"message\": {\n \"id\": \"msg-123\"\n },\n \"user\": {\n \"email\": \"user@example.com\",\n \"id\": \"user-456\"\n }\n },\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"metadata\": {\n \"assistant\": {\n \"latency\": 1.2,\n \"model_name\": \"gpt-4o-mini\"\n }\n },\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"session\": {\n \"timestamp\": \"2025-12-01T10:00:00Z\"\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://eu.whitecircle.com/api/session/check")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["whitecircle-version"] = '<whitecircle-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"deployment_id\": \"your-deployment-id\",\n \"external_session_id\": \"user-session-123\",\n \"include_context\": true,\n \"messages\": [\n {\n \"content\": \"Hello, can you help me with something?\",\n \"metadata\": {\n \"message\": {\n \"id\": \"msg-123\"\n },\n \"user\": {\n \"email\": \"user@example.com\",\n \"id\": \"user-456\"\n }\n },\n \"role\": \"user\"\n },\n {\n \"content\": [\n {\n \"text\": \"Of course! I'd be happy to help you.\",\n \"type\": \"text\"\n }\n ],\n \"metadata\": {\n \"assistant\": {\n \"latency\": 1.2,\n \"model_name\": \"gpt-4o-mini\"\n }\n },\n \"role\": \"assistant\"\n }\n ],\n \"metadata\": {\n \"session\": {\n \"timestamp\": \"2025-12-01T10:00:00Z\"\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"flagged": true,
"internal_session_id": "123e4567-e89b-12d3-a456-426614174000",
"external_session_id": "user-session-001",
"policies": {
"70289e06-9111-463e-b121-7247c2b7bfbd": {
"flagged": false,
"flagged_source": [],
"name": "No PII Sharing"
},
"a4a91875-1e54-42d7-b9b0-a75dfebeb057": {
"flagged": true,
"flagged_source": [
"text"
],
"name": "Drugs"
}
}
}