API reference · Trust Fabric
Ask the live policy engine about a hypothetical call
POST /fabric/policy/evaluate
Last reviewed 2026-10-03
POST /fabric/policy/evaluate
Preview a policy decision without making the call.
Sends the same input document shape the gateway's own request path sends -- a preview that asks a differently-shaped question would answer a different question and be worse than no preview at all.
Request body
EvaluateRequest (required)
| Field | Type | Meaning |
|---|---|---|
service required | string | min length 1 · max length 128 |
path | string | max length 512 · default "/" |
method | string | max length 10 · default "POST" |
tier | string or null | |
entitled | boolean | default true |
Responses
| Status | Meaning | Body |
|---|---|---|
200 | Successful Response | JSON |
422 | Validation Error | HTTPValidationError |
401 | No key, or a key that is not valid | JSON detail |
429 | Rate limit for your plan reached; retry after the Retry-After seconds | JSON detail |
Try it
This call changes data in the account the key belongs to.
The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.
Code
curl -sS -X POST 'https://cainstudio.online/fabric/policy/evaluate' \
-H "X-API-Key: $CAIN_API_KEY" \
-H 'Content-Type: application/json' \
-d '{"service": "service", "path": "/", "method": "POST", "entitled": true}'import json, os, urllib.request
req = urllib.request.Request('https://cainstudio.online/fabric/policy/evaluate', method='POST',
headers={"X-API-Key": os.environ["CAIN_API_KEY"], "Content-Type": "application/json"},
data=json.dumps({
"service": "service",
"path": "/",
"method": "POST",
"entitled": True
}).encode())
with urllib.request.urlopen(req, timeout=60) as r:
print(r.status, json.load(r))const res = await fetch("https://cainstudio.online/fabric/policy/evaluate", {
method: "POST",
headers: {
"X-API-Key": process.env.CAIN_API_KEY!,
"Content-Type": "application/json",
},
body: JSON.stringify({
"service": "service",
"path": "/",
"method": "POST",
"entitled": true
}),
});
console.log(res.status, await res.json());Schemas used
HTTPValidationError · ValidationError · EvaluateRequest
← What would happen to my recent traffic under different enforcement · all 79 Trust Fabric calls · The latest proof run: every claim, executed →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem