中文

Models

Prompt guard · xjp-guard-1

Checks a piece of text and answers with booleans only: harmful content, prompt injection, and whether it is allowed.

Contract

The model id is xjp-guard-1, listed by GET /v1/models with kind guard. It is not a chat model, and /v1/chat/completions with this id returns 400.

Example call

curl https://router.xiaojins.com/v1/workflows/guard \
  -H "Authorization: Bearer $XJP_KEY" -H "content-type: application/json" \
  -d '{"input": "text to check"}'
{"allowed": true, "nsfw": false, "injection": false, "judge_error": false,
 "model": "xjp-guard-1", "id": "guard_...", "usage": {"units": 2, "est_tokens": 12}}

The four booleans

nsfw
The text is harmful content (sexual, graphic violence, clearly illegal help, and similar).
injection
The text tries to instruct or jailbreak an AI system, or to steer this check itself.
allowed
True only when both nsfw and injection are false and judge_error is false.
judge_error
The check could not be completed, so the answer is a refusal (allowed=false). The HTTP status stays 200 and error_code is one of timeout, upstream, parse, unavailable.

The response never contains judge text, reasons, scores, or the upstream model name. The response header x-xjp-guard-version is the prompt version.

Limits

input is required and must not be blank; unknown fields and stream: true return 400. Text beyond 8,000 characters is cut off before checking. Calls time out after 15 seconds.

Billing

  • You are charged by how much text the judge reads. est_tokens counts over at most the first 8,000 characters: Chinese, Japanese, Korean, and full-width characters count as 1 token each, and every other character as a quarter token, rounded up.
  • units = 1 + ceil(est_tokens / 400), and one unit is 0.003 USD. usage.units and usage.est_tokens report what was charged.
  • User credit wallets pay 1 credit per unit. A judge_error costs nothing.
Inputest_tokensunitsPrice (USD)
One English sentence (48 characters)1220.006
English, 2,000 characters50030.009
Chinese, 2,000 characters2,00060.018
English, 8,000 characters2,00060.018
Chinese, 8,000 characters8,000210.063

Privacy

The text you send is relayed to a third-party model provider for judging. Router does not store the text or the judge's reply, does not log them (logs keep only the length and a short hash prefix), and returns only the booleans above. Do not send text you may not share with a third-party processor.

Not available in mainland China

The mainland (CN) deployment has no judge route and always answers with judge_error and error_code unavailable, plus the header x-xjp-guard-unavailable: cn.