{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "openai-guardrails",
    "name": "OpenAI Guardrails",
    "vendor": "OpenAI",
    "vendorUrl": "https://openai.com",
    "kind": "framework",
    "category": "guardrails",
    "summary": "OpenAI's open-source Python library that wraps the OpenAI client and runs configured checks on inputs, outputs and tool calls, including moderation, jailbreak, prompt injection, personal data, URL and off-topic checks. It is labelled a preview.",
    "url": "https://www.anchorterminal.com/tools/openai-guardrails",
    "markdownUrl": "https://www.anchorterminal.com/tools/openai-guardrails.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openai-guardrails.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openai-guardrails.json",
    "repo": "https://github.com/openai/openai-guardrails-python",
    "license": "MIT",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "pypi",
        "name": "openai-guardrails"
      },
      {
        "registry": "npm",
        "name": "@openai/guardrails"
      }
    ],
    "auth": "api-key",
    "authNotes": "No credential of its own. The wrapped client takes an OpenAI API key from `OPENAI_API_KEY` or the constructor, an Azure OpenAI key through `GuardrailsAzureOpenAI`, or the key of any OpenAI-compatible endpoint set with `base_url`, such as a local Ollama server (https://openai.github.io/openai-guardrails-python/quickstart/).",
    "pricing": "free",
    "pricingNotes": "Free under the MIT licence, with no hosted or paid edition and no account of its own. The README states that Guardrails calls paid OpenAI APIs. Each LLM-based check is one extra model call billed at OpenAI's rates, the moderation check is documented as no cost, and the keyword, URL, secret key and personal data checks run locally (https://github.com/openai/openai-guardrails-python).",
    "priceSummary": "Free · OSS",
    "where": "library",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the README or docs (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 259,
      "npmWeekly": 18502,
      "pypiWeekly": 104530,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://openai.github.io/openai-guardrails-python/",
    "capabilities": [
      "guard.injection",
      "guard.pii",
      "guard.moderation",
      "guard.policy",
      "guard.self-host"
    ],
    "tags": [
      "official",
      "framework",
      "open-source",
      "self-hosted",
      "local",
      "python",
      "typescript",
      "free",
      "preview",
      "openai-compatible"
    ],
    "lastRelease": "2026-09-10",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 69.5,
      "grade": "B",
      "agentReady": false,
      "rank": 175,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 73,
        "maintenance": 89,
        "payments": 60,
        "reliability": 73,
        "schema": 66,
        "security": 59,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 73,
          "points": 14.6,
          "reason": "Local-software reading. Installs from PyPI as `openai-guardrails`, Python 3.11 to 3.14 stated (20). Public CI runs ruff, mypy, pyright and the test suite on four Python versions, and the CI run on main passed on 8 October 2026 (25). No open issues and 11 closed in total, though four were closed together on 18 August 2026 after three to ten months (20 of 25). Semver tags, but CHANGELOG.md starts at 0.3.3 and no release note marks a breaking change. RELEASING.md says breaking changes bump the minor version before 1.0 (8 of 15). Version 0.3.3 and the README title reads Preview (0)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 66,
          "points": 10.73,
          "reason": "Framework reading. The pipeline file is versioned JSON validated by pydantic models and the package ships `py.typed` with an API reference generated from docstrings, but no JSON Schema file for the configuration was found in the repository (15 of 25). `llms.txt` on the docs site returns 404 (0). Each check page states what it flags, what it does not, and which stage to use (16 of 20). Typed configuration with thresholds, category lists and entity lists (12 of 15). Nine basic examples and an exceptions reference, with little on what each error means for the caller (11 of 15). Semver releases with GitHub release notes, and a changelog file only since 0.3.3 (12 of 15). The docs deploy workflow failed on main on 8 October 2026."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 73,
          "points": 11.86,
          "reason": "Framework reading. `GuardrailsOpenAI` replaces `OpenAI` with one config argument, and results sit on `response.guardrail_results` (22 of 25). Confidence thresholds, `max_turns`, `include_reasoning` off by default and `suppress_tripwire` control what comes back, and `total_guardrail_token_usage` reports the cost (15 of 20). Typed exceptions carry the check name and stage, but a check that fails to run is reported as not triggered unless `raise_guardrail_errors=True` (12 of 20). Checks are stateless and safe to repeat, each LLM-based check is an extra model call, and streaming can show output before an output check trips (12 of 20). Python and TypeScript packages, few required parameters, and a spaCy model to install by hand for Contains PII (12 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 59,
          "points": 10.33,
          "reason": "Framework reading. No credential of its own. It uses the OpenAI API key, or the key of whichever compatible endpoint is set, from the environment or the constructor (10 of 30). The prompt injection check runs before and after each tool call in the Agents SDK and can reject or halt, but there is no human approval step, and check failures pass by default (10 of 20). Jailbreak and prompt injection detection are the product, with a published benchmark in which the default model scores 0.000 recall at a 1 per cent false positive rate (13 of 15). Per-call results with check name, stage, confidence and token usage, and no log sink of its own (9 of 15). SECURITY.md points to OpenAI's coordinated disclosure policy, security.txt names a Bugcrowd contact, CodeQL and Dependabot are configured, releases use PyPI trusted publishing with attestations, and the repository has no published advisories (17 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Self-hosted rule. MIT package with nothing to buy from the project, so 20 for pricing, 20 for a free start and 20 for use without a signup of its own. No payment protocol (0). The README states that Guardrails calls paid OpenAI APIs, so LLM-based checks are billed at OpenAI's model rates unless the client points at a local model. The moderation check page says that call has no cost."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 89,
          "points": 7.79,
          "reason": "0.3.3 on 10 September 2026, 28 days before the check (30). Three PyPI releases in the last 90 days, 0.3.0 on 21 July, 0.3.2 on 21 August and 0.3.3 (20). All 11 issues are closed and bug reports from 2025 were answered within days, but four were closed in bulk on 18 August 2026, outside pull requests are refused by policy, and nothing was released from 15 December 2025 to 21 July 2026 (15 of 25). Current official packages on PyPI and npm (15). Dependabot, CodeQL and CI on four Python versions, with the docs deploy failing on 8 October (9 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 65, provenance 87",
          "reason": "MIT licence in the repository and on PyPI (30). The README says the developer is responsible for storage of blocked content and that the library calls OpenAI APIs, and each check page says whether it uses a model, but no page lists which checks send text off the machine, and OpenAI's API terms and privacy policy answered 403 to us today so were not read (15 of 30). No deprecation policy. RELEASING.md states that breaking changes bump the minor version before 1.0 (8 of 20). No telemetry was found in the source. Requests to api.openai.com carry `safety_identifier` set to `openai-guardrails-python`, which is described in a source docstring and not in the docs, with no switch found (12 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Framework reading. `GuardrailsOpenAI` replaces `OpenAI` with one config argument, and results sit on `response.guardrail_results` (22 of 25). Confidence thresholds, `max_turns`, `include_reasoning` off by default and `suppress_tripwire` control what comes back, and `total_guardrail_token_usage` reports the cost (15 of 20). Typed exceptions carry the check name and stage, but a check that fails to run is reported as not triggered unless `raise_guardrail_errors=True` (12 of 20). Checks are stateless and safe to repeat, each LLM-based check is an extra model call, and streaming can show output before an output check trips (12 of 20). Python and TypeScript packages, few required parameters, and a spaCy model to install by hand for Contains PII (12 of 15).",
          "maintenance": "0.3.3 on 10 September 2026, 28 days before the check (30). Three PyPI releases in the last 90 days, 0.3.0 on 21 July, 0.3.2 on 21 August and 0.3.3 (20). All 11 issues are closed and bug reports from 2025 were answered within days, but four were closed in bulk on 18 August 2026, outside pull requests are refused by policy, and nothing was released from 15 December 2025 to 21 July 2026 (15 of 25). Current official packages on PyPI and npm (15). Dependabot, CodeQL and CI on four Python versions, with the docs deploy failing on 8 October (9 of 10).",
          "payments": "Self-hosted rule. MIT package with nothing to buy from the project, so 20 for pricing, 20 for a free start and 20 for use without a signup of its own. No payment protocol (0). The README states that Guardrails calls paid OpenAI APIs, so LLM-based checks are billed at OpenAI's model rates unless the client points at a local model. The moderation check page says that call has no cost.",
          "reliability": "Local-software reading. Installs from PyPI as `openai-guardrails`, Python 3.11 to 3.14 stated (20). Public CI runs ruff, mypy, pyright and the test suite on four Python versions, and the CI run on main passed on 8 October 2026 (25). No open issues and 11 closed in total, though four were closed together on 18 August 2026 after three to ten months (20 of 25). Semver tags, but CHANGELOG.md starts at 0.3.3 and no release note marks a breaking change. RELEASING.md says breaking changes bump the minor version before 1.0 (8 of 15). Version 0.3.3 and the README title reads Preview (0).",
          "schema": "Framework reading. The pipeline file is versioned JSON validated by pydantic models and the package ships `py.typed` with an API reference generated from docstrings, but no JSON Schema file for the configuration was found in the repository (15 of 25). `llms.txt` on the docs site returns 404 (0). Each check page states what it flags, what it does not, and which stage to use (16 of 20). Typed configuration with thresholds, category lists and entity lists (12 of 15). Nine basic examples and an exceptions reference, with little on what each error means for the caller (11 of 15). Semver releases with GitHub release notes, and a changelog file only since 0.3.3 (12 of 15). The docs deploy workflow failed on main on 8 October 2026.",
          "security": "Framework reading. No credential of its own. It uses the OpenAI API key, or the key of whichever compatible endpoint is set, from the environment or the constructor (10 of 30). The prompt injection check runs before and after each tool call in the Agents SDK and can reject or halt, but there is no human approval step, and check failures pass by default (10 of 20). Jailbreak and prompt injection detection are the product, with a published benchmark in which the default model scores 0.000 recall at a 1 per cent false positive rate (13 of 15). Per-call results with check name, stage, confidence and token usage, and no log sink of its own (9 of 15). SECURITY.md points to OpenAI's coordinated disclosure policy, security.txt names a Bugcrowd contact, CodeQL and Dependabot are configured, releases use PyPI trusted publishing with attestations, and the repository has no published advisories (17 of 20).",
          "transparency": "MIT licence in the repository and on PyPI (30). The README says the developer is responsible for storage of blocked content and that the library calls OpenAI APIs, and each check page says whether it uses a model, but no page lists which checks send text off the machine, and OpenAI's API terms and privacy policy answered 403 to us today so were not read (15 of 30). No deprecation policy. RELEASING.md states that breaking changes bump the minor version before 1.0 (8 of 20). No telemetry was found in the source. Requests to api.openai.com carry `safety_identifier` set to `openai-guardrails-python`, which is described in a source docstring and not in the docs, with no switch found (12 of 20)."
        },
        "sources": [
          {
            "what": "repository, README, licence and source tree (shallow clone)",
            "url": "https://github.com/openai/openai-guardrails-python",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://github.com/openai/openai-guardrails-python/blob/main/CHANGELOG.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://github.com/openai/openai-guardrails-python/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy",
            "url": "https://github.com/openai/openai-guardrails-python/blob/main/SECURITY.md",
            "seen": "2026-10-08"
          },
          {
            "what": "CI workflow and runs on main",
            "url": "https://github.com/openai/openai-guardrails-python/actions",
            "seen": "2026-10-08"
          },
          {
            "what": "issues and pull requests",
            "url": "https://github.com/openai/openai-guardrails-python/issues?q=is%3Aissue",
            "seen": "2026-10-08"
          },
          {
            "what": "contribution policy",
            "url": "https://github.com/openai/openai-guardrails-python/blob/main/CONTRIBUTING.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release process",
            "url": "https://github.com/openai/openai-guardrails-python/blob/main/.github/RELEASING.md",
            "seen": "2026-10-08"
          },
          {
            "what": "quickstart, with error handling modes",
            "url": "https://openai.github.io/openai-guardrails-python/quickstart/",
            "seen": "2026-10-08"
          },
          {
            "what": "streaming and blocking behaviour",
            "url": "https://openai.github.io/openai-guardrails-python/streaming_output/",
            "seen": "2026-10-08"
          },
          {
            "what": "jailbreak check and benchmark",
            "url": "https://openai.github.io/openai-guardrails-python/ref/checks/jailbreak/",
            "seen": "2026-10-08"
          },
          {
            "what": "prompt injection detection check",
            "url": "https://openai.github.io/openai-guardrails-python/ref/checks/prompt_injection_detection/",
            "seen": "2026-10-08"
          },
          {
            "what": "Contains PII check",
            "url": "https://openai.github.io/openai-guardrails-python/ref/checks/pii/",
            "seen": "2026-10-08"
          },
          {
            "what": "safety identifier source",
            "url": "https://github.com/openai/openai-guardrails-python/blob/main/src/guardrails/utils/safety_identifier.py",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI package and release dates",
            "url": "https://pypi.org/pypi/openai-guardrails/json",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI downloads",
            "url": "https://pypistats.org/api/packages/openai-guardrails/recent",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package",
            "url": "https://registry.npmjs.org/@openai/guardrails/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript repository",
            "url": "https://github.com/openai/openai-guardrails-js",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://openai.com/.well-known/security.txt",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: https://openai.com/policies/services-agreement/ and https://openai.com/policies/privacy-policy/ answered HTTP 403 to our reader on 8 October 2026, so the terms and privacy policy that cover the OpenAI API calls the checks make were not read and `provenance.terms` and `provenance.privacy` are left out.",
          "unchecked: https://openai.com/security/disclosure/ answered HTTP 403, so the disclosure policy and any bounty scope for this package were not read.",
          "unchecked: https://guardrails.openai.com/ is drawn by script, so the configuration wizard and whatever terms it links were not read.",
          "Whether `safety_identifier` can be turned off for calls to api.openai.com. No switch was found in the source.",
          "Why no release was published between 15 December 2025 and 21 July 2026.",
          "The tag v0.3.1 exists in the repository and no 0.3.1 is on PyPI."
        ]
      },
      "negative": 0,
      "verdict": "MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless `raise_guardrail_errors=True` is set.",
      "bestFor": "Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code.",
      "strengths": [
        "MIT licence, source on GitHub, and three PyPI releases in the 90 days to 8 October 2026 (0.3.0, 0.3.2, 0.3.3)",
        "Twelve built-in checks set in one versioned JSON file across pre-flight, input and output stages",
        "`GuardrailAgent` runs the prompt injection check before and after every tool call in the OpenAI Agents SDK",
        "CI runs ruff, mypy, pyright and tests on Python 3.11 to 3.14, with CodeQL, Dependabot and SHA-pinned actions",
        "The jailbreak page publishes ROC AUC, precision, recall and latency per model on a 4,000-conversation sample"
      ],
      "weaknesses": [
        "By default a check that fails to run returns `tripwire_triggered=False`, so the request continues. Strict mode is opt-in",
        "The README titles the package a preview, the version is 0.3.3, and no release was published between 15 December 2025 and 21 July 2026",
        "With `stream=True` the output checks run alongside the stream, and the docs say violating content may appear briefly",
        "The docs' own table gives the default jailbreak model, `gpt-4.1-mini`, a recall of 0.000 at a 1 per cent false positive rate",
        "LLM-based checks add a billed model call each. The docs list a median of 1,538 ms for `gpt-4.1-mini` on the jailbreak check",
        "Pull requests from non-collaborators are not accepted, and CHANGELOG.md starts at 0.3.3"
      ],
      "agentNotes": [
        "Pass `raise_guardrail_errors=True` to the client. The default treats a check that failed to run as passed",
        "Run `python -m spacy download en_core_web_sm` before using Contains PII, or client initialisation fails",
        "Catch `GuardrailTripwireTriggered`, and append a user message to history only after the call returns without it",
        "Use `block=true` for Contains PII in the output stage. Masking works only in the pre-flight stage",
        "Keep `stream=False` where output must be checked before it is shown, and budget one extra model call per LLM-based check"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 69.5
        }
      ],
      "editorialScores": {
        "ergonomics": 73,
        "maintenance": 89,
        "payments": 60,
        "reliability": 73,
        "schema": 66,
        "security": 59,
        "transparency": 65
      },
      "provenanceScore": 87
    },
    "connect": {
      "install": "pip install openai-guardrails\npython -m spacy download en_core_web_sm   # only for Contains PII"
    },
    "letme": {
      "capability": "https://letme.dev/guard.injection",
      "tool": "https://letme.dev/openai-guardrails"
    },
    "sameCompany": [
      "openai-api",
      "openai-embeddings",
      "openai-moderation",
      "openai-image-api",
      "openai-sora",
      "openai-agents-sdk",
      "openai-decisions-api",
      "openai-codex"
    ],
    "notable": [
      "The README is titled OpenAI Guardrails: Python (Preview). The latest release is 0.3.3 on 10 September 2026 (https://github.com/openai/openai-guardrails-python)",
      "Twelve built-in checks. Keyword Filter, Competitors, Moderation, URL Filter, Secret Keys, Contains PII, Hallucination Detection, Jailbreak, Prompt Injection Detection, NSFW Text, Off Topic Prompts and Custom Prompt Check (https://github.com/openai/openai-guardrails-python#available-guardrails)",
      "Default error handling is documented as fail-safe mode. A check that fails to run, for example on an invalid model name, returns `tripwire_triggered=False`. `raise_guardrail_errors=True` raises instead (https://openai.github.io/openai-guardrails-python/quickstart/)",
      "With `stream=True`, output checks run in parallel with the stream and the docs state that violating content may briefly appear before a check triggers (https://openai.github.io/openai-guardrails-python/streaming_output/)",
      "The jailbreak page reports a 4,000-conversation benchmark. `gpt-4.1` scores ROC AUC 0.999 and the default `gpt-4.1-mini` 0.928, with recall of 0.000 at a 1 per cent false positive rate and a median time to complete of 1,538 ms (https://openai.github.io/openai-guardrails-python/ref/checks/jailbreak/)",
      "Contains PII uses Presidio with a spaCy model the user installs, adds CVV and BIC/SWIFT recognisers, and can look inside Base64, URL-encoded and hex strings (https://openai.github.io/openai-guardrails-python/ref/checks/pii/)",
      "Calls to api.openai.com carry `safety_identifier` set to `openai-guardrails-python`. Azure and custom endpoints do not receive it (https://github.com/openai/openai-guardrails-python/blob/main/src/guardrails/utils/safety_identifier.py)",
      "Pull requests are limited to repository collaborators. Others are asked to open issues (https://github.com/openai/openai-guardrails-python/blob/main/CONTRIBUTING.md)",
      "A TypeScript package, `@openai/guardrails` 0.3.0, is published from a separate repository and needs Node.js 22.13 or later (https://github.com/openai/openai-guardrails-js)",
      "`openai-guardrails` had 104,530 PyPI downloads in the week to 8 October 2026 (https://pypistats.org/api/packages/openai-guardrails/recent)"
    ],
    "area": "models",
    "details": [
      {
        "label": "Packages",
        "value": "`openai-guardrails` 0.3.3 on PyPI, `@openai/guardrails` 0.3.0 on npm"
      },
      {
        "label": "Languages",
        "value": "Python 3.11 to 3.14. TypeScript on Node.js 22.13 or later"
      },
      {
        "label": "Status",
        "value": "Preview, per the README title"
      },
      {
        "label": "Clients",
        "value": "`GuardrailsOpenAI`, `GuardrailsAsyncOpenAI`, `GuardrailsAzureOpenAI`, `GuardrailsAsyncAzureOpenAI`, and `GuardrailAgent` for the OpenAI Agents SDK"
      },
      {
        "label": "Wrapped calls",
        "value": "`chat.completions.create`, `responses.create` and `responses.parse`"
      },
      {
        "label": "Stages",
        "value": "Pre-flight (before the model call), input (in parallel with it) and output"
      },
      {
        "label": "Checks",
        "value": "Keyword Filter, Competitors, Moderation, URL Filter, Secret Keys, Contains PII, Hallucination Detection, Jailbreak, Prompt Injection Detection, NSFW Text, Off Topic Prompts, Custom Prompt Check"
      },
      {
        "label": "Configuration",
        "value": "One versioned JSON file, a dict or a JSON string. A wizard at https://guardrails.openai.com/ exports the file"
      },
      {
        "label": "On a violation",
        "value": "Raises `GuardrailTripwireTriggered`, or returns results on `response.guardrail_results` with `suppress_tripwire=True`"
      },
      {
        "label": "On a check error",
        "value": "Passes by default. `raise_guardrail_errors=True` raises"
      },
      {
        "label": "Command line",
        "value": "`guardrails validate \u003cconfig\u003e` and `guardrails-evals` for labelled datasets"
      },
      {
        "label": "Telemetry",
        "value": "None found in the source (searched 2026-10-08). Calls to api.openai.com carry `safety_identifier` `openai-guardrails-python`"
      },
      {
        "label": "Releases in 90 days",
        "value": "3 (0.3.0 on 2026-07-21, 0.3.2 on 2026-08-21, 0.3.3 on 2026-09-10)"
      }
    ],
    "provenance": {
      "legalEntity": "OpenAI (as named in the LICENSE copyright line and the PyPI author field)",
      "domain": "openai.com",
      "domainRegistered": "2007-01-19",
      "domainNote": "A library, not a service. The code is on github.com under the openai organisation, the docs on openai.github.io and the configuration wizard on guardrails.openai.com.",
      "endpointOnVendorDomain": null,
      "terms": "",
      "privacy": "",
      "statusPage": "",
      "changelog": "https://github.com/openai/openai-guardrails-python/blob/main/CHANGELOG.md",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The library is governed by the MIT licence in the repository. The model and moderation calls it makes are OpenAI API calls on the user's own key, under OpenAI's API terms.",
        "https://openai.com/policies/services-agreement/ and https://openai.com/policies/privacy-policy/ answered HTTP 403 to us on 8 October 2026, so the terms and privacy fields are left out as unread.",
        "https://openai.com/.well-known/security.txt is PGP-signed and lists a Bugcrowd contact, a disclosure address and a policy link. It has no Expires line. The copy at cdn.openai.com/security.txt that SECURITY.md links carries an Expires date of 17 January 2024.",
        "No status page applies to the library. The OpenAI API it calls has one at https://status.openai.com.",
        "RDAP gives 19 January 2007 as the registration date of openai.com. The repository was created on 9 April 2025 and the first PyPI release is dated 6 October 2025."
      ],
      "score": 87,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "OpenAI (as named in the LICENSE copyright line and the PyPI author field)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "openai.com, registered 2007-01-19 (19 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "nothing hosted, so the MIT licence stands in",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "nothing hosted, not scored",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/openai-guardrails.json"
  }
}
