Skip to main content

Portkey AI Gateway

A Portkey guardrail plugin. Add your Alice API key once under Integrations, create an Evaluate check with your application id, and attach it as an input or output guardrail in any Portkey config. Portkey enforces the verdict: block, mask the flagged spans, or record and pass.

Status: Beta · Evaluates: Prompts, Responses, Tool calls · Vendor: Portkey

Requests (beforeRequestHook) and responses (afterRequestHook).

Setup​

Configuration: apiKey (Integrations page, encrypted), apiBase (optional), appId (check parameter, required), timeout (ms, default 5000)

  1. Portkey, Integrations: open Alice and paste your Alice API key (created in WonderSuite under Account Settings). This is the plugin credential apiKey; leave apiBase blank unless you run a private deployment.
  2. Portkey, Guardrails, Create: search for Evaluate under Alice, add it, and set Application to your appId (the UUID from Application Inventory). Optionally set the timeout in ms.
  3. Save the guardrail and copy its id.
  4. Add the id to input_guardrails and/or output_guardrails in a Portkey Config, then call the gateway with that Config.

Example​

guardrail check (Portkey UI, Guardrails > Create > Evaluate)

{
"id": "alice.evaluate",
"parameters": { "appId": "payments-bot" }
}

attach the guardrail id to a Config

{
"input_guardrails": ["guardrails-id-xxx"],
"output_guardrails": ["guardrails-id-xxx"]
}

call through the gateway with that Config

portkey = Portkey(
api_key="PORTKEY_API_KEY",
config="pc-***" # Supports a string config id or a config object
)

plugins/alice/manifest.json (credentials + parameters schema)

{
"id": "alice",
"description": "Alice (https://alice.io) — policy-based guardrails for prompts and model responses. Blocks, masks or records content against the policies configured for your application.",
"credentials": {
"type": "object",
"properties": {
"apiKey": {
"type": "string",
"label": "Alice API key",
"description": "Your Alice API key. Create one in WonderSuite under Account Settings.",
"encrypted": true
},
"apiBase": {
"type": "string",
"label": "API base URL",
"description": "Base URL of the Alice API. Leave blank for https://api.alice.io; set it only if you run a private deployment."
}
},
"required": ["apiKey"]
},
"functions": [
{
"name": "Evaluate",
"id": "evaluate",
"supportedHooks": ["beforeRequestHook", "afterRequestHook"],
"type": "guardrail",
"description": [
{
"type": "subHeading",
"text": "Evaluate the prompt or the model response against the Alice policies configured for your application, and enforce the verdict: block it, mask the flagged spans, or record a detection and let it through."
}
],
"parameters": {
"type": "object",
"properties": {
"appId": {
"type": "string",
"label": "Application",
"description": [
{
"type": "subHeading",
"text": "The application whose policies apply. Its UUID from your Application Inventory, or your own id for it if you set one. Alice configures policies per application and a project usually holds several, so this decides which policy set a request is measured against."
}
]
},
"timeout": {
"type": "number",
"label": "Timeout (ms)",
"description": [
{
"type": "subHeading",
"text": "How long to wait for Alice before giving up. A timeout is reported as a check error, so `failOnError` decides whether the request proceeds."
}
]
}
},
"required": ["appId"]
}
}
]
}

Good to know​

A check with no appId fails rather than guessing. Any failure, including timeouts, is a check error, so failOnError decides whether the request proceeds. Block works on streams; mask does not rewrite streamed text.