Core concepts
Policy sets
A policy set is your rules under a name: one piece of text that can hold several rules.
await policies.save('uploads', `
1) No nudity or sexually explicit imagery.
2) No weapons shown, unless holstered on a uniformed guard.
`);
- A check names one set. Content is blocked if any rule in the set applies.
- Save once, check many times. Saving takes a while, so do it when you deploy. Checks are fast, so do them on every request.
- Sets are independent. Keep a strict set for one part of your product and a looser one for another.
- Saving again overwrites. Running the same
save()on every deploy is fine. - A set can't contradict itself. If one rule allows what another blocks, the save is refused and the message names both rules. An exception inside one rule ("unless holstered…") is fine.
Verdicts
| You check | Verdicts |
|---|---|
| Text | block, pass |
| An image | block, pass, unknown |
unknown means the image couldn't answer the question: too dark, too cropped or
too blurry. Don't treat it as a pass. Use isSafe, which is true only for
pass:
if (!isSafe(result)) await reject();
Projects and API keys
Your organization can have several projects, for example one for staging and one for production. Each project has its own API keys and its own policy sets. A key only reaches the policy sets in its own project.
- Anyone in the organization can create and revoke keys. A key is shown once. Revoking it stops it working at once.
- Admins and Owners create, rename and delete projects. Deleting a project deletes its keys and policy sets.
- Each project has a rate limit on requests per minute.
- Credit belongs to the organization and is shared by all its projects. See Credit and billing.