> ## Documentation Index
> Fetch the complete documentation index at: https://docs.repello.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Analyze Response

> Analyze an LLM-generated response against guardrail policies before showing it to end-users.

```
POST https://argusapi.repello.ai/sdk/v1/analyze/response
```

Scans an LLM-generated response against the policies configured for the asset (or against
policies supplied inline in the request) and returns a verdict.

**Rate limit:** 500 requests per 60 seconds per API key.

## Authentication

<ParamField header="X-API-Key" type="string" required>
  Your ARGUS API key.
</ParamField>

## Request body

The body is identical to [Analyze Prompt](/api-reference/endpoint/analyze-prompt), except
that `scan_data` carries a `response` field instead of a `prompt` field.

<ParamField body="asset_id" type="string" required>
  Identifier of the asset whose configured policies should be applied.
</ParamField>

<ParamField body="scan_data" type="object" required>
  Container for the content to analyze.

  <Expandable title="scan_data">
    <ParamField body="response" type="string" required>
      The LLM-generated response text to analyze.
    </ParamField>
  </Expandable>
</ParamField>

<ParamField body="policies" type="array">
  Optional inline policies to apply in addition to (or instead of) the asset's configured
  policies. Each item is a policy object. See [Enumerations](/sdk-reference/data/enums) for
  the canonical `PolicyName` and `Action` values.

  <Expandable title="policy item">
    <ParamField body="policy_name" type="string" required>
      Canonical policy identifier, e.g. `secrets_keys_detection`, `pii_detection`,
      `toxicity_detection`, `system_prompt_leak_detection`.
    </ParamField>

    <ParamField body="action" type="string" required>
      One of `block`, `flag`, or `disabled`.
    </ParamField>

    <ParamField body="metadata">
      Optional policy-specific configuration: a string, a list of strings, or a 2-tuple of
      strings depending on the policy.
    </ParamField>
  </Expandable>
</ParamField>

<ParamField body="session_id" type="string">
  Optional session identifier used to group related interactions.
</ParamField>

<ParamField body="user_id" type="string">
  Optional end-user identifier.
</ParamField>

<ParamField body="metadata" type="object">
  Optional free-form metadata attached to the scan record.
</ParamField>

<ParamField body="save" type="boolean" default="true">
  Whether to persist this scan. Defaults to `true` when omitted.
</ParamField>

### Example request

```bash theme={null}
curl -X POST https://argusapi.repello.ai/sdk/v1/analyze/response \
  -H "X-API-Key: <your-api-key>" \
  -H "Content-Type: application/json" \
  -d '{
    "asset_id": "asset_9f1c2b7a",
    "scan_data": {
      "response": "Sure, the admin password is hunter2 and the API key is sk-live-abc123."
    },
    "session_id": "session_4821",
    "user_id": "user_017",
    "policies": [
      { "policy_name": "secrets_keys_detection", "action": "block" }
    ],
    "save": true
  }'
```

## Response

<ResponseField name="request_id" type="string" required>
  Unique identifier (UUID v4) for this scan request.
</ResponseField>

<ResponseField name="verdict" type="string" required>
  The definitive outcome of the scan. One of `passed`, `flagged`, or `blocked`.
</ResponseField>

<ResponseField name="policies_violated" type="array">
  Policies that found a violation. Empty when the verdict is `passed`.

  <Expandable title="violated policy">
    <ResponseField name="policy_name" type="string" required>
      Canonical identifier of the policy that found a violation.
    </ResponseField>

    <ResponseField name="policy_id" type="string" required>
      Internal identifier of the configured policy instance.
    </ResponseField>

    <ResponseField name="action_taken" type="string" required>
      The action that was taken: `block`, `flag`, or `disabled`.
    </ResponseField>

    <ResponseField name="scope" type="string" required>
      Which side of the interaction the policy applies to: `input`, `output`, or `both`.
    </ResponseField>

    <ResponseField name="details" type="object">
      Policy-specific details of the violation, such as scores, labels, or detected
      entities. The shape varies by policy — see [Types](/sdk-reference/data/types).
    </ResponseField>

    <ResponseField name="masked_result" type="string">
      The analyzed text with detected sensitive content masked, when the policy produces a
      masked output. May be `null`.
    </ResponseField>
  </Expandable>
</ResponseField>

### Example response — 200 OK

```json theme={null}
{
  "request_id": "a1c4e8f0-2d31-4b9a-bc77-1e2f3a4b5c6d",
  "verdict": "blocked",
  "policies_violated": [
    {
      "policy_name": "secrets_keys_detection",
      "policy_id": "pol_sec_004",
      "action_taken": "block",
      "scope": "output",
      "details": [
        { "text": "sk-live-abc123", "score": 0.99 }
      ],
      "masked_result": "Sure, the admin password is [REDACTED] and the API key is [REDACTED]."
    }
  ]
}
```

## Errors

| Code | Reason                                                             |
| ---- | ------------------------------------------------------------------ |
| 400  | Body failed validation, or `scan_data.response` was missing/empty. |
| 401  | `X-API-Key` header missing, or the key is invalid/inactive.        |
| 429  | Rate limit exceeded (500 requests / 60 s per API key).             |
