ZeroLeaksDocs

AI SDK integration

Use Shield with the OpenAI-compatible provider or guard another model with Shield middleware.

Call Shield as a classifier

Use @ai-sdk/openai-compatible to send a request to Shield's chat-completions endpoint:

bun add ai @ai-sdk/openai-compatible
import { createOpenAICompatible } from "@ai-sdk/openai-compatible";
import { generateText } from "ai";

const shield = createOpenAICompatible({
  name: "zeroleaks-shield",
  baseURL: "https://api.zeroleaks.ai/v1",
  apiKey: process.env.ZEROLEAKS_API_KEY,
});

const result = await generateText({
  model: shield("shield"),
  prompt: "Untrusted text to classify",
});

if (result.text.startsWith("unsafe")) {
  // Hold this input for review.
}

streamText works with the same provider. Shield finishes inference before streaming its verdict. It returns safe or unsafe\nprompt_injection, not a conversational answer.

A generic chat client may not expose Shield's coverage extension. If your acceptance policy checks coverage, use the Shield SDK for typed coverage, including requireFullCoverage.

Guard another model with middleware

Use the hosted detector with Shield's AI SDK middleware:

bun add ai @ai-sdk/openai @zeroleaks/shield
import { openai } from "@ai-sdk/openai";
import { createHostedDetector } from "@zeroleaks/shield";
import { shieldLanguageModelMiddleware } from "@zeroleaks/shield/ai-sdk";
import { generateText, wrapLanguageModel } from "ai";

const shield = createHostedDetector({
  apiKey: process.env.ZEROLEAKS_API_KEY,
  model: "shield",
  requireFullCoverage: true,
});

const model = wrapLanguageModel({
  model: openai("gpt-4.1-mini"),
  middleware: shieldLanguageModelMiddleware({
    detect: shield.options(),
    scanToolResults: shield.options(),
  }),
});

const response = await generateText({
  model,
  prompt: "A user's message",
});

The wrapper waits for hosted checks of user messages and tool results before forwarding the request. For retrieved documents added through another path, call the detector explicitly where the documents enter the agent's context. Check the provider coverage for the content shapes each integration reads.

A flagged input raises InjectionDetectedError under the default blocking policy. A failed hosted check raises an API error. Handle these separately from successful model output; do not convert either into a safe verdict.

Custom deployments

Set baseURL on the provider, or use baseURL or endpoint in createHostedDetector. See self-hosting.

These integrations call your configured endpoint directly. OpenAI protocol compatibility does not imply an AI Gateway catalog listing.

On this page