Skip to main content

Project logo

any-guardrail

Docs Linting Unit Tests Integration Tests

Python 3.11+ PyPI Discord

A single interface to use different guardrail models.

any-guardrail provides a unified interface for AI safety guardrails, for example, letting you detect toxic content, jailbreak attempts, and other risks in LLM inputs and outputs. Switch between different guardrail providers, both encoder-based (discriminative) and decoder-based (generative) models like Llama Guard and ShieldGemma, without changing your code.

Some guardrails are extremely customizable, which any-guardrail fully exposes. See the complete list of supported providers and customization examples in our docs.

Why any-guardrail?

  • Unified API: Switch between evergrowing list of guardrail providers
  • Production-ready: Built for real-world LLM applications
  • Flexible: Use encoder-based (fast) or decoder-based (customizable) models

Quickstart

Requirements

  • Python 3.11 or newer

Installation

Install with pip:

pip install any-guardrail

Basic Usage

AnyGuardrail provides a seamless interface for interacting with the guardrail models. It allows you to see a list of all the supported guardrails, and to instantiate each supported guardrail. Here is a full example:

from any_guardrail import AnyGuardrail, GuardrailName, GuardrailOutput

# Initialize guardrail
guardrail = AnyGuardrail.create(GuardrailName.DEEPSET)

# Validate input before sending to your LLM
result: GuardrailOutput = guardrail.validate("How do I hack into a system?")

if not result.valid:
    print(f"Blocked: {result.explanation}")
else:
    # Safe to proceed with LLM call
    response = your_llm(user_input)

Every guardrail returns the same GuardrailOutput shape, so you can swap models without changing application code:

result.valid       # bool verdict — True means the content passed
result.score       # risk score in ~[0, 1], higher = more likely violating (when available)
result.categories  # per-category results: CategoryResult(name, description, triggered, score, severity)
result.explanation # human-readable rationale (judge reasoning, raw generation)
result.action      # provider-recommended action (e.g. "block"), advisory; None if none
result.usage       # provenance: model_id, latency_ms, token counts
result.extra       # guardrail-specific structured extras; result.raw holds the backend payload

flagged = [c.name for c in result.categories if c.triggered]

A machine-readable JSON Schema for this output is published in the repo (generated from the Pydantic models). Reference it at the stable raw URL, pinning a release tag for a specific version:

https://raw.githubusercontent.com/mozilla-ai/any-guardrail/main/schemas/guardrail_output.schema.json

Prompts, policies, rubrics & criteria

Generative and judge guardrails run against a prompt template and often need a policy, rubric, or criteria. any-guardrail lets you discover and override the default prompt, and fetch author-published policies/rubrics/criteria — all without loading a model:

from any_guardrail import AnyGuardrail, GuardrailName

# Inspect a guardrail's default prompt template
AnyGuardrail.get_prompt(GuardrailName.SELENE).segments["user"]

# Fetch a ready-made author-published policy and use it directly
policy = AnyGuardrail.get_policy(GuardrailName.SHIELD_GEMMA, "dangerous_content")
guard = AnyGuardrail.create(GuardrailName.SHIELD_GEMMA, policy=policy)

See the Prompts & content guide. The catalogs are exported to schemas/guardrail_prompts.json and schemas/guardrail_content.json.

Documentation

Full guides at docs link

Troubleshooting

Some of the models on HuggingFace require extra permissions to use. To do this, you'll need to create a HuggingFace profile and manually go through the permissions. Then, you'll need to download the HuggingFace Hub and login. One way to do this is:

pip install --upgrade huggingface_hub

hf auth login

More information can be found here: HuggingFace Hub

Contributing to any-guardrail

The guardrail space is ever growing. If there is a guardrail that you'd like us to support, please see our CONTRIBUTING.md for details.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

any_guardrail-0.7.2.tar.gz (511.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

any_guardrail-0.7.2-py3-none-any.whl (243.7 kB view details)

Uploaded Python 3

File details

Details for the file any_guardrail-0.7.2.tar.gz.

File metadata

  • Download URL: any_guardrail-0.7.2.tar.gz
  • Upload date:
  • Size: 511.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for any_guardrail-0.7.2.tar.gz
Algorithm Hash digest
SHA256 fd421eccfdffa48bc55abfe1fb78f385390b475facb187d099218cda2e2905ce
MD5 639358918e418d3f9305df5fa0752132
BLAKE2b-256 1a7f7b519f3bec2bf427cddff078ee0e30f50e7a5a3e81405b95455d9a067137

See more details on using hashes here.

Provenance

The following attestation bundles were made for any_guardrail-0.7.2.tar.gz:

Publisher: release.yaml on mozilla-ai/any-guardrail

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file any_guardrail-0.7.2-py3-none-any.whl.

File metadata

  • Download URL: any_guardrail-0.7.2-py3-none-any.whl
  • Upload date:
  • Size: 243.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for any_guardrail-0.7.2-py3-none-any.whl
Algorithm Hash digest
SHA256 495df37823eace6135c284d5f29966c0964ef9ca57e0f02b238a93584db8661f
MD5 cc550a2fcc394eddb44c34131a5b9bd4
BLAKE2b-256 b1527c7af5ab9dc4988155bebbf1eee0a521c115aff6d13d608f0302bc35005e

See more details on using hashes here.

Provenance

The following attestation bundles were made for any_guardrail-0.7.2-py3-none-any.whl:

Publisher: release.yaml on mozilla-ai/any-guardrail

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.7.7

2 files

0.7.6

2 files

0.7.5

2 files

0.7.4

2 files

0.7.3

2 files

This release

0.7.2 This release

2 files

0.7.1

2 files

0.7.0

2 files

0.6.4

2 files

0.6.3

2 files

0.6.2

2 files

0.6.1

2 files

0.6.0

2 files

0.5.1

2 files

0.5.0

2 files

0.4.1

2 files

0.4.0

2 files

0.3.2

2 files

0.3.1

2 files

0.3.0

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.1

2 files

0.1.0

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page