Skip to main content

chox-sdk

Python SDK for Chox — AI governance proxy. Evaluate AI tool calls before execution to prevent unintended financial operations, data deletions, and other risky actions.

Why Chox?

As AI agents gain access to external APIs (Stripe, Slack, SQL), they need governance. Chox sits between your agent and those APIs to:

  • Evaluate every tool call (financial operations, data deletions, message sends, etc.)
  • Classify the action type and risk level
  • Return a verdict — allow, block, escalate, or warn — before the agent proceeds
  • Log all activity for audit trails

This SDK wraps the POST /api/v1/evaluate endpoint with a clean API, automatic retry on network failures (fail-open), and precise type hints.

Install

pip install chox-sdk

Quickstart

from chox import ChoxClient

chox = ChoxClient(
    base_url="https://chox.example.com",
    token="chox_token_...",
)

# Evaluate before a risky operation
verdict = chox.evaluate(
    tool="stripe.create_charge",
    arguments={"amount": 5000, "currency": "USD"},
    context={"user_id": "user_123"},
)

if verdict.verdict == "allow":
    # Safe to proceed
    stripe.Charge.create(amount=5000, currency="USD")
elif verdict.verdict == "block":
    raise ValueError(f"Action blocked: {verdict.reason}")
elif verdict.verdict == "escalate":
    # Requires human approval
    send_to_approval_queue(verdict.reason)

Configuration

chox = ChoxClient(
    base_url="https://chox.example.com",  # Required: Your Chox gateway URL
    token="chox_token_...",               # Required: Caller token or admin key
    fail_open=True,                       # Optional: Default True. If Chox is unreachable, return allow verdict
    timeout=5.0,                          # Optional: Default 5.0 seconds. Request timeout
)

Authentication

  • Caller token (chox_token_...): Use this in production. Tied to a specific AI system in Chox, can only evaluate with that token.
  • Admin key (chox_admin_...): Use this for setup/testing. Can manage projects, integrations, and callers, but not recommended for ongoing agent evaluation.

Verdicts

The evaluate() method returns an EvaluateResponse dataclass with these fields:

from chox import EvaluateResponse

verdict: EvaluateResponse = chox.evaluate(...)

# Fields:
verdict.request_id          # Unique request ID for audit logging
verdict.verdict             # "allow" | "block" | "escalate" | "warn"
verdict.action_type         # "read" | "write" | "delete" | "financial" | "unknown"
verdict.risk_score          # 0 (safe) to 1 (critical)
verdict.reason              # Human-readable explanation
verdict.evaluated_at        # ISO 8601 timestamp

Verdict meanings:

  • allow — Safe to proceed
  • block — Blocked by policy; do not proceed
  • escalate — Requires human approval (e.g., large transfer)
  • warn — Proceed with caution; log prominently

Error Handling

from chox import ChoxClient, ChoxError, ChoxNetworkError

chox = ChoxClient(base_url="...", token="...")

try:
    verdict = chox.evaluate(tool="stripe.create_charge")
except ChoxError as e:
    # API returned non-2xx status
    print(f"Chox API error {e.status}: {e.body}")
except ChoxNetworkError as e:
    # Network timeout or unreachable
    print(f"Network error: {e}")
    if e.cause:
        print(f"Caused by: {e.cause}")

Note: If fail_open=True (default), network errors and timeouts return an allow verdict instead of raising, so your agent never gets blocked by Chox being temporarily down.

API Reference

Evaluate

verdict = chox.evaluate(
    tool: str,                              # Dot-notation tool name, e.g., "stripe.create_charge"
    arguments: dict[str, Any] | None = None,  # Tool arguments as JSON
    caller_token: str | None = None,       # Optional override caller token
    context: dict[str, Any] | None = None, # Optional context (user_id, session, etc.)
)

Projects

chox.projects.create(name=..., slug=...)   # Create a project; returns raw admin key once
chox.projects.get()                        # Get authenticated project

Callers (AI Systems)

chox.callers.create(name=..., description="")  # Register an AI system; returns raw token once
chox.callers.list()                            # List all callers
chox.callers.delete(id)                        # Remove a caller

Integrations

chox.integrations.create(                  # Register an external API
    name="stripe",
    integration_type="http",              # "http" or "mcp"
    destination_url="https://api.stripe.com",
)
chox.integrations.list()                   # List all integrations
chox.integrations.delete(id)               # Remove an integration

Logs

chox.logs.list(                            # Query evaluation logs
    caller_id=None,
    integration=None,
    action_type=None,
    start=None,     # ISO 8601 timestamp
    end=None,       # ISO 8601 timestamp
    limit=None,
    offset=None,
)
chox.logs.get(id)                          # Get a specific log entry

Stats

chox.stats.actions(start=None, end=None)      # Breakdown by action type
chox.stats.hourly(start=None, end=None)       # Hourly activity counts
chox.stats.integrations(start=None, end=None) # Per-integration traffic
chox.stats.total()                            # Total request count

Type Hints

This SDK is fully typed for use with mypy, pyright, and other type checkers.

from chox import ChoxClient, EvaluateResponse

chox: ChoxClient = ChoxClient(base_url="...", token="...")
verdict: EvaluateResponse = chox.evaluate(tool="stripe.create_charge")

# Type checker catches mismatches:
if verdict.verdict == "invalid":  # ✗ mypy: Type '"invalid"' is not assignable to '"allow" | "block" | "escalate" | "warn"'
    pass

License

MIT

Metadata

Release files for chox-ai-sdk 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for chox-ai-sdk 0.1.0
File Size Uploaded
chox_ai_sdk-0.1.0.tar.gz 16.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for chox-ai-sdk 0.1.0
File Interpreter ABI Platform
chox_ai_sdk-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 28.2 kB

Release files / chox_ai_sdk-0.1.0.tar.gz

Download URL chox_ai_sdk-0.1.0.tar.gz
Size 16.4 kB
Tags Source
SHA-256 checksum
How to use checksums
16c5948fe4d7d51c9d8df306c15eb86340ba57832d4809aed483d45772ef9988
BLAKE2b-256 checksum
How to use checksums
9fa12abd4c9cd93fde24a8b66af2cdd63cfd9cfaa1cfe3f390bf07e6154ab210
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release files / chox_ai_sdk-0.1.0-py3-none-any.whl

Download URL chox_ai_sdk-0.1.0-py3-none-any.whl
Size 11.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9e87b4f4cfdf1b20982dfd5b7184b37c9220bc5303710ee32a3a4c83638c6041
BLAKE2b-256 checksum
How to use checksums
7e140da6869bab3d4ebfe2251918625c290271ea76a737f47d6e2c5ddd523070
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page