> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://hiddenlayer.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://hiddenlayer.ferndocs.com/_mcp/server.

# Prompt Analyzer

POST https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer
Content-Type: application/json

Analyze LLM Prompt and Response

Reference: https://hiddenlayer.ferndocs.com/api-reference/llm-proxy-api/prompt-analyzer/create

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.hiddenlayer.ai` (ProdUs, default)
- `https://api.eu.hiddenlayer.ai` (ProdEu)

## Request

### Body (application/json)

This endpoint expects a PromptAnalyzerRequest.

- `prompt` (string, required)
- `output` (string, optional)
- `model` (string, optional)

## Response

### 200

Successful Prompt Analyzer response

- `response` (HiddenLayerPromptAnalyzerResponseMetadata, optional)
- `provider` (string, optional)
- `model` (string, optional)
- `verdict` (boolean, optional) — The overall verdict of the analysis
- `categories` (HiddenLayerAnalysisCategories, optional) — The analysis detection categories
- `results` (HiddenLayerAnalysisResults, optional) — The analysis results
- `policy` (HiddenLayerAnalysisPolicy, optional) — The policy used during analysis
- `frameworks` (HiddenLayerAnalysisFrameworks, optional) — The framework labels identified during analysis
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the request
- `upstream_elapsed_ms` (double, optional) — The time in milliseconds the upstream LLM took to process the request

## Types

### HiddenLayerPromptAnalyzerResponseMetadata

- `provider` (string, optional)
- `model` (string, optional)
- `prompt` (string, optional)
- `output` (string, optional)
- `unmodified_prompt` (string, optional)
- `unmodified_output` (string, optional)

### HiddenLayerAnalysisCategories

The analysis detection categories

- `unsafe_input` (boolean, optional) — The input is unsafe
- `unsafe_output` (boolean, optional) — The output is unsafe
- `prompt_injection` (boolean, optional) — The input contains prompt injection
- `input_dos` (boolean, optional) — The input contains a denial of service attack
- `input_pii` (boolean, optional) — The input contains personally identifiable information
- `output_pii` (boolean, optional) — The output contains personally identifiable information
- `input_code` (boolean, optional) — The input contains code
- `output_code` (boolean, optional) — The output contains code
- `guardrail` (boolean, optional) — The input activated the upstream guardrails
- `input_language` (boolean, optional) — The input contains a disallowed language

### HiddenLayerAnalysisResults

The analysis results

- `input_block_list_results` (HiddenLayerAnalysisResultsInputBlockListResults, optional) — The input block list results
- `prompt_injection_classifier_results` (list of HiddenLayerAnalysisResultsPromptInjectionClassifierResultsItems, optional)
- `input_dos_results` (HiddenLayerAnalysisResultsInputDosResults, optional) — The input denial of service results
- `input_pii_results` (HiddenLayerAnalysisResultsInputPiiResults, optional) — The input personally identifiable information results
- `output_pii_results` (HiddenLayerAnalysisResultsOutputPiiResults, optional) — The output personally identifiable information results
- `input_code_results` (HiddenLayerAnalysisResultsInputCodeResults, optional) — The input code results
- `output_code_results` (HiddenLayerAnalysisResultsOutputCodeResults, optional) — The output code results
- `guardrail_results` (HiddenLayerAnalysisResultsGuardrailResults, optional) — The guardrail results
- `input_url_results` (HiddenLayerAnalysisResultsInputUrlResults, optional) — The input URL results
- `output_url_results` (HiddenLayerAnalysisResultsOutputUrlResults, optional) — The output URL results
- `input_language_results` (HiddenLayerAnalysisResultsInputLanguageResults, optional) — The input language results

### HiddenLayerAnalysisPolicy

The policy used during analysis

- `block_unsafe` (boolean, optional, default: false) — Block unsafe input and output
- `block_unsafe_input` (boolean, optional, default: false) — Block unsafe input
- `block_unsafe_output` (boolean, optional) — Block unsafe output
- `skip_prompt_injection_detection` (boolean, optional) — Skip prompt injection detection
- `block_prompt_injection` (boolean, optional) — Block prompt injection
- `prompt_injection_scan_type` (enum, optional, default: quick) — The type of prompt injection scan to use
  - Allowed values: `quick`, `full`
- `skip_input_pii_detection` (boolean, optional) — Skip input personally identifiable information detection
- `skip_output_pii_detection` (boolean, optional) — Skip output personally identifiable information detection
- `block_input_pii` (boolean, optional) — Block input personally identifiable information
- `block_output_pii` (boolean, optional) — Block output personally identifiable information
- `redact_input_pii` (boolean, optional) — Redact input personally identifiable information
- `redact_output_pii` (boolean, optional) — Redact output personally identifiable information
- `redact_type` (enum, optional, default: entity) — The type of redaction to use
  - Allowed values: `entity`, `strict`
- `entity_type` (enum, optional, default: strict) — The type of entity to redact
  - Allowed values: `strict`, `all`
- `skip_input_code_detection` (boolean, optional) — Skip input code detection
- `skip_output_code_detection` (boolean, optional) — Skip output code detection
- `block_input_code_detection` (boolean, optional) — Block input code detection
- `block_output_code_detection` (boolean, optional) — Block output code detection
- `skip_guardrail_detection` (boolean, optional) — Skip guardrail detection
- `block_guardrail_detection` (boolean, optional) — Block guardrail detection
- `skip_input_url_detection` (boolean, optional) — Skip input URL detection
- `skip_output_url_detection` (boolean, optional) — Skip output URL detection
- `skip_input_dos_detection` (boolean, optional) — Skip input denial of service detection
- `block_input_dos_detection` (boolean, optional) — Block input denial of service detection
- `input_dos_detection_threshold` (double, optional, default: 4096) — The threshold for input denial of service detection

### HiddenLayerAnalysisFrameworks

The framework labels identified during analysis

- `mitre` (list of HiddenLayerAnalysisFrameworksMitreItems, optional)
- `owasp` (list of HiddenLayerAnalysisFrameworksOwaspItems, optional)
- `owasp:2025` (list of HiddenLayerAnalysisFrameworksOwasp2025Items, optional)

### HiddenLayerAnalysisResultsInputBlockListResults

The input block list results

- `verdict` (boolean, optional) — The verdict of the input block list analysis
- `matches` (list of string, optional)
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the input block list

### HiddenLayerAnalysisResultsPromptInjectionClassifierResultsItems

- `version` (double, optional) — The version of the prompt injection classifier
- `verdict` (boolean, optional) — The verdict of the prompt injection classifier
- `probabilities` (list of double, optional)
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the prompt injection classifier
- `allow_override` (string, optional) — The allow override applied to the prompt
- `block_override` (string, optional) — The block override applied to the prompt

### HiddenLayerAnalysisResultsInputDosResults

The input denial of service results

- `verdict` (boolean, optional) — The verdict of the input denial of service analysis
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the input denial of service
- `embeddings_length` (double, optional) — The length of the embeddings analyzed

### HiddenLayerAnalysisResultsInputPiiResults

The input personally identifiable information results

- `verdict` (boolean, optional) — The verdict of the input personally identifiable information analysis
- `entities` (list of string, optional)
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the input personally identifiable information

### HiddenLayerAnalysisResultsOutputPiiResults

The output personally identifiable information results

- `verdict` (boolean, optional) — The verdict of the output personally identifiable information analysis
- `entities` (list of string, optional)
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the output personally identifiable information

### HiddenLayerAnalysisResultsInputCodeResults

The input code results

- `verdict` (boolean, optional) — The verdict of the input code analysis
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the input code

### HiddenLayerAnalysisResultsOutputCodeResults

The output code results

- `verdict` (boolean, optional) — The verdict of the output code analysis
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the output code

### HiddenLayerAnalysisResultsGuardrailResults

The guardrail results

- `verdict` (boolean, optional) — The verdict of the guardrail analysis
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the guardrail
- `refusal_classifier_results` (HiddenLayerAnalysisResultsGuardrailResultsRefusalClassifierResults, optional) — The refusal classifier results

### HiddenLayerAnalysisResultsInputUrlResults

The input URL results

- `urls` (list of string, optional)
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the guardrail

### HiddenLayerAnalysisResultsOutputUrlResults

The output URL results

- `urls` (list of string, optional)
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the guardrail

### HiddenLayerAnalysisResultsInputLanguageResults

The input language results

- `verdict` (boolean, optional) — The verdict of the input language analysis
- `language` (string, optional) — Language detected in the input
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the input language detection

### HiddenLayerAnalysisFrameworksMitreItems

The MITRE Atlas framework labels identified during analysis

- `name` (string, optional) — The name of the MITRE Atlas framework label
- `label` (string, optional) — The label of the MITRE Atlas framework label

### HiddenLayerAnalysisFrameworksOwaspItems

The OWASP framework labels identified during analysis

- `name` (string, optional) — The name of the OWASP framework label
- `label` (string, optional) — The label of the OWASP framework label

### HiddenLayerAnalysisFrameworksOwasp2025Items

The OWASP:2025 framework labels identified during analysis

- `name` (string, optional) — The name of the OWASP:2025 framework label
- `label` (string, optional) — The label of the OWASP:2025 framework label

### HiddenLayerAnalysisResultsGuardrailResultsRefusalClassifierResults

The refusal classifier results

- `version` (double, optional) — The version of the refusal classifier
- `verdict` (boolean, optional) — The verdict of the refusal classifier
- `probabilities` (list of double, optional)
- `elapsed_ms` (double, optional) — The time in milliseconds it took to process the refusal classifier

## Examples

**Request**

```json
{
  "prompt": "Hello World",
  "output": "Hello, how can I help you today?",
  "model": "mistral-tiny"
}
```

**Response**

```json
{
  "response": {
    "provider": "string",
    "model": "string",
    "prompt": "string",
    "output": "string",
    "unmodified_prompt": "string",
    "unmodified_output": "string"
  },
  "provider": "string",
  "model": "string",
  "verdict": true,
  "categories": {
    "unsafe_input": true,
    "unsafe_output": true,
    "prompt_injection": true,
    "input_dos": true,
    "input_pii": true,
    "output_pii": true,
    "input_code": true,
    "output_code": true,
    "guardrail": true,
    "input_language": true
  },
  "results": {
    "input_block_list_results": {
      "verdict": true,
      "matches": [
        "badToken"
      ],
      "elapsed_ms": 10
    },
    "prompt_injection_classifier_results": [
      {
        "version": 1,
        "verdict": true,
        "probabilities": [
          1
        ],
        "elapsed_ms": 100
      }
    ],
    "input_dos_results": {
      "verdict": true,
      "elapsed_ms": 1.1,
      "embeddings_length": 1.1
    },
    "input_pii_results": {
      "verdict": true,
      "entities": [
        "PHONE_NUMBER"
      ],
      "elapsed_ms": 20
    },
    "output_pii_results": {
      "verdict": true,
      "entities": [
        "LOCATION"
      ],
      "elapsed_ms": 20
    },
    "input_code_results": {
      "verdict": true,
      "elapsed_ms": 1.1
    },
    "output_code_results": {
      "verdict": true,
      "elapsed_ms": 1.1
    },
    "guardrail_results": {
      "verdict": true,
      "elapsed_ms": 1.1,
      "refusal_classifier_results": {
        "version": 1.1,
        "verdict": true,
        "probabilities": [
          1.1
        ],
        "elapsed_ms": 1.1
      }
    },
    "input_url_results": {
      "urls": [
        "string"
      ],
      "elapsed_ms": 1.1
    },
    "output_url_results": {
      "urls": [
        "string"
      ],
      "elapsed_ms": 1.1
    },
    "input_language_results": {
      "verdict": true,
      "language": "string",
      "elapsed_ms": 1.1
    }
  },
  "policy": {
    "block_unsafe": false,
    "block_unsafe_input": false,
    "block_unsafe_output": true,
    "skip_prompt_injection_detection": true,
    "block_prompt_injection": true,
    "prompt_injection_scan_type": "quick",
    "skip_input_pii_detection": true,
    "skip_output_pii_detection": true,
    "block_input_pii": true,
    "block_output_pii": true,
    "redact_input_pii": true,
    "redact_output_pii": true,
    "redact_type": "entity",
    "entity_type": "strict",
    "skip_input_code_detection": true,
    "skip_output_code_detection": true,
    "block_input_code_detection": true,
    "block_output_code_detection": true,
    "skip_guardrail_detection": true,
    "block_guardrail_detection": true,
    "skip_input_url_detection": true,
    "skip_output_url_detection": true,
    "skip_input_dos_detection": true,
    "block_input_dos_detection": true,
    "input_dos_detection_threshold": 4096
  },
  "frameworks": {
    "mitre": [
      {
        "name": "LLM Prompt Injection",
        "label": "AML.T0051"
      }
    ],
    "owasp": [
      {
        "name": "Prompt Injection",
        "label": "LLM01"
      }
    ],
    "owasp:2025": [
      {
        "name": "Prompt Injection",
        "label": "LLM01:2025"
      }
    ]
  },
  "elapsed_ms": 1.1,
  "upstream_elapsed_ms": 1.1
}
```

**SDK Code**

```python
import requests

url = "https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer"

payload = {
    "prompt": "Hello World",
    "output": "Hello, how can I help you today?",
    "model": "mistral-tiny"
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"prompt":"Hello World","output":"Hello, how can I help you today?","model":"mistral-tiny"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer"

	payload := strings.NewReader("{\n  \"prompt\": \"Hello World\",\n  \"output\": \"Hello, how can I help you today?\",\n  \"model\": \"mistral-tiny\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"prompt\": \"Hello World\",\n  \"output\": \"Hello, how can I help you today?\",\n  \"model\": \"mistral-tiny\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"prompt\": \"Hello World\",\n  \"output\": \"Hello, how can I help you today?\",\n  \"model\": \"mistral-tiny\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer', [
  'body' => '{
  "prompt": "Hello World",
  "output": "Hello, how can I help you today?",
  "model": "mistral-tiny"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"prompt\": \"Hello World\",\n  \"output\": \"Hello, how can I help you today?\",\n  \"model\": \"mistral-tiny\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "prompt": "Hello World",
  "output": "Hello, how can I help you today?",
  "model": "mistral-tiny"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.hiddenlayer.ai/api/v1/submit/prompt-analyzer")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```