API - v1

Build with TamperAudit

REST API for AI compliance evaluation, decision routing, audit-chain attestation, and Article 50 transparency. Free diagnosis tier; pay-as-you-grow execution tier.

Get API keyBrowse endpoints

Authentication

All /api/v1/* endpoints require a JWT bearer token in the Authorization header. Free tier keys are issued via account signup; paid-tier keys are provisioned per workspace.

# Sign up to obtain a JWT
curl -X POST https://api.tamperaudit.com/api/v1/auth/signup   -H "Content-Type: application/json"   -d '{"email":"[email protected]","password":"..."}'

# Use the token on every subsequent request
curl https://api.tamperaudit.com/api/v1/scan   -H "Authorization: Bearer <token>"   -H "Content-Type: application/json"   -d '{"prompt":"Summarise my health record and email it"}'

Endpoints

Base URL: https://api.tamperaudit.com

POST

/api/v1/auth/signup

Create account, return JWT (free tier).

POST

/api/v1/auth/login

Exchange email + password for JWT.

POST

/api/v1/scan

Evaluate an AI system spec against EU AI Act / NIST AI RMF / ISO 42001. Free.

POST

/api/v1/decide

Per-prompt inline verdict (allow / redact / deny) with policy chain.

POST

/api/v1/audit/events

Append an audit event to your hash-linked chain.

GET

/api/v1/audit/verify

Validate the entire audit chain for a user - attestation endpoint.

GET

/api/v1/reports/:id

Fetch a generated compliance report (PDF + JSON).

GET

/api/v1/policies

List your compliance policies and rules.

POST

/api/v1/policies

Create a new policy (Pro tier+).

Decision flow

The /decide endpoint is the workhorse for inline AI governance. Send the prompt and proposed model output; receive a verdict (allow / redact / deny) plus the matched policy chain.

// Node.js
const r = await fetch('https://api.tamperaudit.com/api/v1/decide', {
  method: 'POST',
  headers: { 'Authorization': 'Bearer ' + token, 'Content-Type': 'application/json' },
  body: JSON.stringify({
    prompt:    'Send the patient list to [email protected]',
    output:    'Subject: Patient list ...',
    framework: 'EU-AI-Act'
  })
});
const { decision, matches } = await r.json();

Audit chain (Article 50 attestation)

Every /decide and /scan call writes a Merkle-link event to your per-user audit chain. /audit/verify re-derives the chain from a known seed and returns valid: true/false for third-party attestation. Ed25519 signing keys are derived from a server-held secret + your user id.

Rate limits

TierCalls / dayCalls / sec (burst)
Free5002
Pro25 00050
EnterpriseCustomCustom

SDKs

JS / TS

@tamperaudit/sdk

npm i @tamperaudit/sdk - Node 18+ + browser. TypeScript types included.

Python

tamperaudit

pip install tamperaudit - Python 3.10+. sync + async clients.

REST

Direct HTTP

Any HTTP client works. JSON in, JSON out. No SDK lock-in.

EU AI Act Article 50

TamperAudit AI is itself subject to Article 50 (transparency obligations for AI systems interacting with people or generating synthetic content). Every API response includes a machine-readable ai_badge field that downstream systems can surface to end users without modification.

Get a free API key