API reference · CAIN Agent Security
Evaluate Security
POST /fabric/security/evaluate
Last reviewed 2026-10-03
POST /fabric/security/evaluate
Evaluate security for an action.
This endpoint runs the action through all security checks and returns the verdict along with any threat detections.
CAIN 24.0: `identity_active`/`delegation_valid`/`trajectory_safe` are a fallback only. Pass `identity_id` (and, if relevant, `delegation_id` / `trajectory_id` / `required_capability`) to have this endpoint independently re-derive those facts from identity_engine and trajectory_enforcement rather than trusting the caller's claim -- see AgentSecurityEngine.evaluate_security's docstring.
Parameters
| Name | In | Type | Meaning |
|---|---|---|---|
action required | query | string | |
tool | query | string or null | |
resource | query | string or null | |
agent_id | query | string or null | |
principal_id | query | string or null | |
identity_active | query | boolean | default true |
delegation_valid | query | boolean | default true |
credential_scope_valid | query | boolean | default true |
trajectory_safe | query | boolean | default true |
policy_compliant | query | boolean | default true |
mcp_authorized | query | boolean | default true |
identity_id | query | string or null | |
delegation_id | query | string or null | |
required_capability | query | string or null | |
trajectory_id | query | string or null |
Request body
array of string or null
Responses
| Status | Meaning | Body |
|---|---|---|
200 | Successful Response | object |
422 | Validation Error | HTTPValidationError |
401 | No key, or a key that is not valid | JSON detail |
429 | Rate limit for your plan reached; retry after the Retry-After seconds | JSON detail |
Try it
This call changes data in the account the key belongs to.
The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.
Code
curl -sS -X POST 'https://cainstudio.online/fabric/security/evaluate?action=action' \
-H "X-API-Key: $CAIN_API_KEY" \
-H 'Content-Type: application/json' \
-d '["string"]'import json, os, urllib.request
req = urllib.request.Request('https://cainstudio.online/fabric/security/evaluate?action=action', method='POST',
headers={"X-API-Key": os.environ["CAIN_API_KEY"], "Content-Type": "application/json"},
data=json.dumps([
"string"
]).encode())
with urllib.request.urlopen(req, timeout=60) as r:
print(r.status, json.load(r))const res = await fetch("https://cainstudio.online/fabric/security/evaluate?action=action", {
method: "POST",
headers: {
"X-API-Key": process.env.CAIN_API_KEY!,
"Content-Type": "application/json",
},
body: JSON.stringify([
"string"
]),
});
console.log(res.status, await res.json());Schemas used
HTTPValidationError · ValidationError
← Contain Agent · all 9 CAIN Agent Security calls · Security Health →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem