{"_id":"@axiorank/ai-sdk","_rev":"3-ec832b78630055dbe44a53de21b4e315","name":"@axiorank/ai-sdk","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@axiorank/ai-sdk","version":"0.1.0","keywords":["axiorank","ai","vercel-ai-sdk","ai-sdk","middleware","wraplanguagemodel","guardrails","llm","security","gateway","prompt-injection","secrets-detection","pii","redaction","agent-security"],"author":{"name":"AxioRank"},"license":"MIT","_id":"@axiorank/ai-sdk@0.1.0","maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"homepage":"https://axiorank.com","bugs":{"url":"https://github.com/frostyhand/AxioRank/issues"},"dist":{"shasum":"3ee057764319ab0a6b277ea90c83984ea07d131d","tarball":"https://registry.npmjs.org/@axiorank/ai-sdk/-/ai-sdk-0.1.0.tgz","fileCount":9,"integrity":"sha512-8X6778tjK1/8Bt83WoQpeA+2OLZ2+ww0m0Z+FVdClojZFmbtH3t3a3oUIeLPrG2p6Aai6LNd5waTnyDJ/G1OOQ==","signatures":[{"sig":"MEYCIQCmodqDN9tZuuFmecPJ85wBE0sJy9e2vPoVaQZFJiTEOgIhAKoQW7myrM6z0DViX6Y9a+1kpl9ZFYk2bH9vnTP5IMhW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":380234},"main":"./dist/index.cjs","type":"module","_from":"file:axiorank-ai-sdk-0.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"_resolved":"/private/var/folders/tj/sd2_mky164g410jm_lcgy8wh0000gn/T/41027c28820dd8b9f6a08092ac8b47cf/axiorank-ai-sdk-0.1.0.tgz","_integrity":"sha512-8X6778tjK1/8Bt83WoQpeA+2OLZ2+ww0m0Z+FVdClojZFmbtH3t3a3oUIeLPrG2p6Aai6LNd5waTnyDJ/G1OOQ==","repository":{"url":"git+https://github.com/frostyhand/AxioRank.git","type":"git","directory":"packages/ai-sdk"},"_npmVersion":"10.9.8","description":"AxioRank guardrail middleware for the Vercel AI SDK. Inspect and redact prompts, completions, and proposed tool calls on every generateText and streamText.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.0","tsup":"^8.3.5","vite":"^8.0.16","vitest":"^4.1.8","typescript":"^6.0.3","@types/node":"^22.10.0","@axiorank/sdk":"0.18.0","@ai-sdk/provider":"^4.0.0"},"peerDependencies":{"ai":"^7.0.0"},"_npmOperationalInternal":{"tmp":"tmp/ai-sdk_0.1.0_1783516737476_0.33639422241678685","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@axiorank/ai-sdk","version":"0.2.0","keywords":["axiorank","ai","vercel-ai-sdk","ai-sdk","middleware","wraplanguagemodel","guardrails","llm","security","gateway","prompt-injection","secrets-detection","pii","redaction","agent-security"],"author":{"name":"AxioRank"},"license":"MIT","_id":"@axiorank/ai-sdk@0.2.0","maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"homepage":"https://axiorank.com","bugs":{"url":"https://github.com/frostyhand/AxioRank/issues"},"dist":{"shasum":"88d3b83ac5383e73bafaab1e3587041dab99b677","tarball":"https://registry.npmjs.org/@axiorank/ai-sdk/-/ai-sdk-0.2.0.tgz","fileCount":9,"integrity":"sha512-5FMDbAortsKAIgiPN+AZMdJ+neq35NXEFqM6hExZXl5FwZsIbuVjtFVGEGjyP+IrunmPM/zEdWupXh4Pfyh7ZQ==","signatures":[{"sig":"MEYCIQDfn1eUFiue3oG+Fk2bTsKcFR4x51zaxK9M0KKstQpEZQIhAJskD/Gi4HGyOhF0oL00wt7ijEXXyRZvbdqchgqW8uN4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":546182},"main":"./dist/index.cjs","type":"module","_from":"file:axiorank-ai-sdk-0.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"_resolved":"/private/var/folders/tj/sd2_mky164g410jm_lcgy8wh0000gn/T/065dccc93185d56b576dafbe2542a72e/axiorank-ai-sdk-0.2.0.tgz","_integrity":"sha512-5FMDbAortsKAIgiPN+AZMdJ+neq35NXEFqM6hExZXl5FwZsIbuVjtFVGEGjyP+IrunmPM/zEdWupXh4Pfyh7ZQ==","repository":{"url":"git+https://github.com/frostyhand/AxioRank.git","type":"git","directory":"packages/ai-sdk"},"_npmVersion":"10.9.8","description":"AxioRank guardrail middleware for the Vercel AI SDK. Inspect and redact prompts, completions, and proposed tool calls on every generateText and streamText.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.0","tsup":"^8.3.5","vite":"^8.0.16","vitest":"^4.1.8","typescript":"^6.0.3","@types/node":"^22.10.0","@axiorank/sdk":"0.19.0","@ai-sdk/provider":"^4.0.0"},"peerDependencies":{"ai":"^7.0.0"},"_npmOperationalInternal":{"tmp":"tmp/ai-sdk_0.2.0_1783919082362_0.9811706450865991","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@axiorank/ai-sdk","version":"0.2.1","description":"AxioRank guardrail middleware for the Vercel AI SDK. Inspect and redact prompts, completions, and proposed tool calls on every generateText and streamText.","license":"MIT","homepage":"https://axiorank.com","bugs":{"url":"https://axiorank.com/support"},"author":{"name":"AxioRank"},"type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"sideEffects":false,"keywords":["axiorank","ai","vercel-ai-sdk","ai-sdk","middleware","wraplanguagemodel","guardrails","llm","security","gateway","prompt-injection","secrets-detection","pii","redaction","agent-security"],"scripts":{"build":"tsup","dev":"tsup --watch","typecheck":"tsc --noEmit","test":"vitest run"},"publishConfig":{"access":"public"},"peerDependencies":{"ai":"^7.0.0"},"devDependencies":{"@ai-sdk/provider":"^4.0.0","@axiorank/sdk":"workspace:*","@types/node":"^22.10.0","ai":"^7.0.0","tsup":"^8.3.5","typescript":"^6.0.3","vite":"^8.0.16","vitest":"^4.1.8"},"_id":"@axiorank/ai-sdk@0.2.1","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-tW+3AtZEAD8lm0tgNfjr2NnS6wOj7uilXLGKvYBKMO7hRDHPK/bVgS3g3Qj/JbUaEEYCu9TkR967X2k9qbmYLg==","shasum":"96e9009943d3cb49670f7190a1184d78a0ed275a","tarball":"https://registry.npmjs.org/@axiorank/ai-sdk/-/ai-sdk-0.2.1.tgz","fileCount":9,"unpackedSize":546017,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEKId0haPoHAZv8ZTdD5a4MSUgJp1XEHpBu8TCFaKt4iAiEAjyQIlX4RmiITGIYUIHmTSfLRTnZTp5qx4UymJYNsSfE="}]},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"directories":{},"maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ai-sdk_0.2.1_1785415298562_0.7566711114196609"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-08T13:18:57.297Z","modified":"2026-07-30T12:41:39.617Z","0.1.0":"2026-07-08T13:18:57.685Z","0.2.0":"2026-07-13T05:04:42.526Z","0.2.1":"2026-07-30T12:41:38.769Z"},"bugs":{"url":"https://axiorank.com/support"},"author":{"name":"AxioRank"},"license":"MIT","homepage":"https://axiorank.com","keywords":["axiorank","ai","vercel-ai-sdk","ai-sdk","middleware","wraplanguagemodel","guardrails","llm","security","gateway","prompt-injection","secrets-detection","pii","redaction","agent-security"],"description":"AxioRank guardrail middleware for the Vercel AI SDK. Inspect and redact prompts, completions, and proposed tool calls on every generateText and streamText.","maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"readme":"# @axiorank/ai-sdk\n\nAxioRank guardrail middleware for the [Vercel AI SDK](https://ai-sdk.dev). One\n`wrapLanguageModel` call governs every `generateText`, `streamText`, and\n`generateObject` through a model: the prompt is inspected before it is sent, the\ncompletion is inspected and optionally redacted before your app sees it, and the\ntool calls the model proposes are inspected before the SDK executes them.\n\nIt catches leaked secrets, prompt injection, PII, and destructive tool calls,\nusing the same detectors and risk scoring as the rest of AxioRank, the security\ngateway for AI agents.\n\n## Install\n\n```bash\nnpm install @axiorank/ai-sdk ai\n```\n\n`ai` (v7 or later) is a peer dependency.\n\n## Quickstart\n\n```ts\nimport { wrapLanguageModel } from \"ai\";\nimport { openai } from \"@ai-sdk/openai\";\nimport { createAxioRankMiddleware } from \"@axiorank/ai-sdk\";\n\nconst model = wrapLanguageModel({\n  model: openai(\"gpt-4o\"),\n  middleware: createAxioRankMiddleware({ apiKey: process.env.AXIORANK_KEY }),\n});\n\n// governed: prompt, completion, and proposed tool calls are all inspected\nconst { text } = await generateText({ model, prompt: \"...\" });\n```\n\nStreaming works the same way:\n\n```ts\nconst { textStream } = await streamText({ model, prompt: \"...\" });\n```\n\n## Try it with no key\n\nLeave the API key off and the middleware runs the detectors in-process (no\nsignup, no network) as an advisory guard:\n\n```ts\nconst model = wrapLanguageModel({\n  model: openai(\"gpt-4o\"),\n  middleware: createAxioRankMiddleware(), // local mode\n});\n```\n\n## What it inspects\n\n| Surface | When | Default action on a block |\n| --- | --- | --- |\n| Prompt | Before the model is called | Return a refusal (the model is never called) |\n| Completion | After the model responds | Redact (hosted policy) or replace with a refusal |\n| Tool calls | On the calls the model proposes | Strip the denied call so the SDK never runs it |\n\nA denied call is handled gracefully by default (`onDeny: \"block\"`): the surface\nis refused, redacted, or stripped, and generation continues. Set\n`onDeny: \"throw\"` to raise `AxioRankDeniedError` instead.\n\n## Hosted vs local\n\n* **Hosted** (an API key is present): calls the AxioRank gateway, so your\n  workspace's real policy applies, every call lands in the audit log, and the\n  gateway can return a redacted completion. Enable model I/O enforcement in your\n  workspace settings so prompt and completion governance is active; otherwise the\n  gateway inspects but does not block them.\n* **Local** (no API key): runs the bundled detectors in-process against the\n  default posture. Advisory and block-on-deny only (no policy, no redaction).\n\n## Streaming\n\n`streamText` forwards tokens as they arrive, so a secret that appears mid-stream\nwould reach the client before it could be caught. The `stream` option controls\nthe trade-off:\n\n* `\"buffer\"` (default): accumulate the streamed text, inspect it, then release\n  it. Redaction and blocking are correct, at the cost of some first-token\n  latency.\n* `\"passthrough\"`: stream tokens live and inspect at the end for audit only. It\n  cannot retract text that has already been sent, so it never redacts.\n\n## Options\n\n```ts\ncreateAxioRankMiddleware({\n  apiKey,            // else AXIORANK_API_KEY, then AXIORANK_KEY\n  baseUrl,           // else AXIORANK_BASE_URL, then https://app.axiorank.com\n  mode,              // \"hosted\" | \"local\" (auto: hosted when a key is present)\n  onDeny,            // \"block\" (default) | \"throw\"\n  failOpen,          // default true: an AxioRank outage never breaks your app\n  inspectPrompts,    // default true\n  inspectCompletions,// default true\n  inspectToolCalls,  // default true\n  stream,            // \"buffer\" (default) | \"passthrough\"\n  refusal,           // text substituted for a blocked prompt or completion\n  onDecision,        // (phase, verdict) => void, for logging and metrics\n  timeoutMs,         // default 10000\n  model,             // model label sent to the gateway (defaults to the call's id)\n});\n```\n\n## Relationship to `@axiorank/sdk`\n\nThis middleware guards the **model**: its prompts, its completions, and the tool\ncalls it proposes. To guard tool **execution** (the code your tools actually\nrun), use `guardTools` from `@axiorank/sdk/vercel`. The two are complementary and\ncompose:\n\n```ts\nimport { AxioRank } from \"@axiorank/sdk\";\nimport { guardTools } from \"@axiorank/sdk/vercel\";\nimport { createAxioRankMiddleware } from \"@axiorank/ai-sdk\";\n\nconst axio = new AxioRank({ apiKey: process.env.AXIORANK_KEY });\n\nconst model = wrapLanguageModel({\n  model: openai(\"gpt-4o\"),\n  middleware: createAxioRankMiddleware({ apiKey: process.env.AXIORANK_KEY }),\n});\n\nawait generateText({\n  model,\n  tools: guardTools(myTools, axio),\n  prompt: \"...\",\n});\n```\n\n`AxioRankDeniedError` is re-exported here and is the same class `@axiorank/sdk`\nthrows, so a single `catch` handles both.\n\n## Links\n\n* [axiorank.com](https://axiorank.com)\n* [Documentation](https://axiorank.com/docs)\n* [Support](https://axiorank.com/support)\n","readmeFilename":"README.md"}