# OpenAI Guardrails (slim) > OpenAI's open-source Python library that wraps the OpenAI client and runs configured checks on inputs, outputs and tool calls, including moderation, jailbreak, prompt injection, personal data, URL and off-topic checks. It is labelled a preview. - Full: https://www.anchorterminal.com/tools/openai-guardrails.md (~6,750 tokens) · this version ~1,430 tokens · JSON https://www.anchorterminal.com/tools/openai-guardrails.json · canonical https://www.anchorterminal.com/tools/openai-guardrails - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 69.5/100 · rank #175 of 842 · #4 in Guardrails & safety filters · not agent-ready · confidence medium** Assessment: MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless `raise_guardrail_errors=True` is set. ## Facts - Kind: Agent framework · vendor: OpenAI · category: Guardrails & safety filters · legal entity: OpenAI (as named in the LICENSE copyright line and the PyPI author field) · provenance 87/100 - Local only (HTTP): pypi `openai-guardrails`, npm `@openai/guardrails` - Auth: API key · pricing: Free · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Packages: `openai-guardrails` 0.3.3 on PyPI, `@openai/guardrails` 0.3.0 on npm - Languages: Python 3.11 to 3.14. TypeScript on Node.js 22.13 or later - Status: Preview, per the README title - Clients: `GuardrailsOpenAI`, `GuardrailsAsyncOpenAI`, `GuardrailsAzureOpenAI`, `GuardrailsAsyncAzureOpenAI`, and `GuardrailAgent` for the OpenAI Agents SDK - Wrapped calls: `chat.completions.create`, `responses.create` and `responses.parse` - Stages: Pre-flight (before the model call), input (in parallel with it) and output - Checks: Keyword Filter, Competitors, Moderation, URL Filter, Secret Keys, Contains PII, Hallucination Detection, Jailbreak, Prompt Injection Detection, NSFW Text, Off Topic Prompts, Custom Prompt Check - Configuration: One versioned JSON file, a dict or a JSON string. A wizard at https://guardrails.openai.com/ exports the file - On a violation: Raises `GuardrailTripwireTriggered`, or returns results on `response.guardrail_results` with `suppress_tripwire=True` - On a check error: Passes by default. `raise_guardrail_errors=True` raises - Command line: `guardrails validate ` and `guardrails-evals` for labelled datasets - Telemetry: None found in the source (searched 2026-10-08). Calls to api.openai.com carry `safety_identifier` `openai-guardrails-python` - Releases in 90 days: 3 (0.3.0 on 2026-07-21, 0.3.2 on 2026-08-21, 0.3.3 on 2026-09-10) - Scores: Reliability 73, Performance pending, Schema & documentation 66, Agent ergonomics 73, Security & auth 59, Payments & pricing 60, Task success pending, Maintenance & community 89, Transparency & trust 76 · total over the 7 assessed categories - Why: Reliability, Local-software reading. · Schema & documentation, Framework reading. · Agent ergonomics, Framework reading. · Security & auth, Framework reading. · Payments & pricing, Self-hosted rule. · Maintenance & community, 0.3.3 on 10 September 2026, 28 days before the check (30). · Transparency & trust, MIT licence in the repository and on PyPI (30). - Sources: 19, open questions: 6, both in the full twin - Capabilities: guard.injection, guard.pii, guard.moderation, guard.policy, guard.self-host - JSON: https://www.anchorterminal.com/api/v1/tools/openai-guardrails.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/openai-guardrails.svg` or a link to https://www.anchorterminal.com/tools/openai-guardrails from a page on openai.com or one of its subdomains, or the README of github.com/openai/openai-guardrails-python, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pass `raise_guardrail_errors=True` to the client. The default treats a check that failed to run as passed 2. Run `python -m spacy download en_core_web_sm` before using Contains PII, or client initialisation fails 3. Catch `GuardrailTripwireTriggered`, and append a user message to history only after the call returns without it 4. Use `block=true` for Contains PII in the output stage. Masking works only in the pre-flight stage 5. Keep `stream=False` where output must be checked before it is shown, and budget one extra model call per LLM-based check ## Connect ```bash pip install openai-guardrails python -m spacy download en_core_web_sm # only for Contains PII ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | NVIDIA NeMo Guardrails | B | 68.4 | guard.injection, guard.pii, guard.moderation, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/nemo-guardrails.min.md | | Lakera Guard (Check Point AI Guardrails) | C | 59.6 | guard.injection, guard.pii, guard.moderation, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/lakera-guard.min.md | | Guardrails AI | D | 49.6 | guard.injection, guard.pii, guard.moderation, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/guardrails-ai.min.md | | Google Cloud Model Armor | BB | 77.9 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/google-model-armor.min.md | | Amazon Bedrock Guardrails | BB | 74.8 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)