Models
Prompt guard · xjp-guard-1
Checks a piece of text and answers with booleans only: harmful content, prompt injection, and whether it is allowed.
Contract
The model id is xjp-guard-1, listed by GET /v1/models with kind guard. It is not a chat model, and /v1/chat/completions with this id returns 400.
Example call
curl https://router.xiaojins.com/v1/workflows/guard \
-H "Authorization: Bearer $XJP_KEY" -H "content-type: application/json" \
-d '{"input": "text to check"}'{"allowed": true, "nsfw": false, "injection": false, "judge_error": false,
"model": "xjp-guard-1", "id": "guard_...", "usage": {"units": 2, "est_tokens": 12}}The four booleans
nsfw- The text is harmful content (sexual, graphic violence, clearly illegal help, and similar).
injection- The text tries to instruct or jailbreak an AI system, or to steer this check itself.
allowed- True only when both nsfw and injection are false and judge_error is false.
judge_error- The check could not be completed, so the answer is a refusal (allowed=false). The HTTP status stays 200 and error_code is one of timeout, upstream, parse, unavailable.
The response never contains judge text, reasons, scores, or the upstream model name. The response header x-xjp-guard-version is the prompt version.
Limits
input is required and must not be blank; unknown fields and stream: true return 400. Text beyond 8,000 characters is cut off before checking. Calls time out after 15 seconds.
Billing
- You are charged by how much text the judge reads. est_tokens counts over at most the first 8,000 characters: Chinese, Japanese, Korean, and full-width characters count as 1 token each, and every other character as a quarter token, rounded up.
- units = 1 + ceil(est_tokens / 400), and one unit is 0.003 USD. usage.units and usage.est_tokens report what was charged.
- User credit wallets pay 1 credit per unit. A judge_error costs nothing.
| Input | est_tokens | units | Price (USD) |
|---|---|---|---|
| One English sentence (48 characters) | 12 | 2 | 0.006 |
| English, 2,000 characters | 500 | 3 | 0.009 |
| Chinese, 2,000 characters | 2,000 | 6 | 0.018 |
| English, 8,000 characters | 2,000 | 6 | 0.018 |
| Chinese, 8,000 characters | 8,000 | 21 | 0.063 |
Privacy
The text you send is relayed to a third-party model provider for judging. Router does not store the text or the judge's reply, does not log them (logs keep only the length and a short hash prefix), and returns only the booleans above. Do not send text you may not share with a third-party processor.
Not available in mainland China
The mainland (CN) deployment has no judge route and always answers with judge_error and error_code unavailable, plus the header x-xjp-guard-unavailable: cn.