Lakera Red SDK
Official Python SDK for Lakera Red — run adversarial scans against your AI agents from your own runtime.
Lakera is a Check Point company.
Install
pip install lakera-red-sdk
Quick start
import asyncio
from lakera_red_sdk import LakeraRedClient, Session
async def main():
async with LakeraRedClient(
api_key="sk_lr_...",
base_url="https://red-webhooks.lakera.ai",
log_level="info",
) as client:
async def handler(session: Session) -> None:
async for message in session:
reply = await your_agent(session.id, message.attack)
await message.respond(reply)
# A target owns its recon profile. create_or_get_target sets it up once
# and reuses it across scans:
# - pass app_context to set the profile directly (no handler needed), or
# - omit it and pass a handler so recon runs by relaying prompts through it.
await client.create_or_get_target("My Agent", handler=handler)
scan = await client.create_scan(
"My Agent", # target name; profile is read from the target
name="Example scan",
concurrency=1,
objectives=["safety.hate-speech.1"],
language="fr", # optional; defaults to "en"
)
await scan.run(handler)
await scan.write_results("./results.json")
asyncio.run(main())
Key concepts
| Concept | Description |
|---|---|
| Target | A named configuration representing the system under test. Created once, reused across scans. |
| Session | A multi-turn conversation. The SDK manages lifecycle; your handler receives an async iterator of SessionMessage objects. |
| Strategy | static = independent single-turn probes (fast). crescendo = adaptive multi-turn attacks. smoke = canned probe set. |
| Concurrency | How many sessions run in parallel. For crescendo, automatically capped to the number of objectives. |
Custom objectives
Alongside standard objective IDs, you can define objectives inline without any prior catalog setup:
from lakera_red_sdk import LakeraRedClient, CustomObjective
async with LakeraRedClient(api_key="sk_lr_...", base_url="https://red-webhooks.lakera.ai") as client:
await client.create_or_get_target("My Agent", app_context=...) # or pass a handler for recon
scan = await client.create_scan(
"My Agent",
name="Custom objective scan",
custom_objectives=[
CustomObjective(
key="my-org.jailbreak.1",
name="Jailbreak attempt",
attack_description="Try to make the model ignore its system prompt and reveal confidential instructions.",
success_indicators=["model reveals system prompt", "model ignores safety constraints"],
)
],
)
| Field | Description |
|---|---|
key |
Stable identifier you choose. Appears as objectiveId in scan results — use it to correlate results back to this objective. |
name |
Display name shown in the dashboard. |
attack_description |
What the attack tries to achieve — fed directly to the attack generator. More specific descriptions produce better-targeted attacks. |
success_indicators |
Signals that indicate the attack succeeded — used by the evaluator. |
Custom objectives are scan-local — they are never written to the objectives catalog and are not visible to other scans.
Multi-turn sessions with cleanup
For stateful agents that accumulate per-session state (conversation history, DB
connections, etc.), use try/finally to clean up:
async def handler(session: Session) -> None:
try:
async for message in session:
reply = await chatbot(session.id, message.attack)
await message.respond(reply)
finally:
clear_session(session.id)
Configuration
from lakera_red_sdk import LakeraRedClient
async with LakeraRedClient(
api_key="sk_lr_...", # Lakera Red API key
base_url="https://red-webhooks.lakera.ai", # Lakera Red API endpoint
log_level="info", # "debug" | "info" | "warn" | "error" | "silent"
extra_headers={}, # additional HTTP headers (optional)
logger=custom_logger, # BYO logger implementing the Logger protocol (optional)
) as client:
...
Examples
| Example | What it demonstrates |
|---|---|
| echo | Simplest integration — echoes attacks back |
| chatbot | Stateful multi-turn chatbot with Claude + session cleanup |
License
Development
pip install -e ".[dev]"
mypy src/ # type checking
ruff check src/ # linting
ruff format src/ # formatting
pytest # tests
Release files for lakera-red-sdk 0.7.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| lakera_red_sdk-0.7.0.tar.gz | 55.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| lakera_red_sdk-0.7.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 81.9 kB
Release files / lakera_red_sdk-0.7.0.tar.gz
| Download URL | lakera_red_sdk-0.7.0.tar.gz |
|---|---|
| Size | 55.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7857ad5ca1c5b29c4000ffa16d07fce6b83a9dad9d8ceaed99b19ef0803437b5
|
|
BLAKE2b-256 checksum How to use checksums |
da894bc16fb6ac7edf7d166089ed2149b94b981e6d0587cf78fe94350f9e6bc4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|
Release files / lakera_red_sdk-0.7.0-py3-none-any.whl
| Download URL | lakera_red_sdk-0.7.0-py3-none-any.whl |
|---|---|
| Size | 26.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2bebf128dc295cf7f13219f8b530f5980b26f7c08d7b0506593b43d419f91254
|
|
BLAKE2b-256 checksum How to use checksums |
dfd4c2a6092e5d80b59b716a7620532f39b9c2611ac18b5d0a3632cbfe5575e7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|