Prerequisites
Use Go 1.22 or later. SetSILMARIL_API_KEY and SILMARIL_API_URL from your deployment access.
Install
Classify your first request
Create one client per protected system and reuse it. Label each call with the boundary it checks, and check each call’s error before making the next one.context.Background(). For tool output, pass the tool name as well, and handle its error the same way.
Expected result
A benign request logsprediction=BENIGN and its score. When the effective mode is block, a malicious request returns *firewall.FirewallBlockedError. Its Result field holds the full verdict. In shadow or warn mode the call returns the result instead, so route on result.Prediction. Your deployment sets the mode unless the client or call sets Mode. Outcome meanings and recommended actions are in the outcome taxonomy.
Any other error means the call did not produce a verdict. That includes *firewall.APIError for a non-2xx API response, and a network, timeout, or context error. Decide whether that boundary fails open or closed.
Concurrent requests
Reuse one client across goroutines. EachClassify or ClassifyBatch call takes a context, so canceling one call also stops its retry wait. Caller-owned metadata, callbacks, and custom transports must be safe for concurrent access.
Shadow mode
Shadow mode returns results instead of blocking errors, so you can measure would-block decisions while traffic continues. Per-call options can enforce one boundary before you change the client default.WithShadowMode(false), so that call enforces. OnClassify can run on overlapping calls. Synchronize any shared state it touches.
Errors
Enforced blocks return*firewall.FirewallBlockedError, which carries Score, Threshold, and Result.
blocked.Result for the verdict, or use shadow mode when you need the result without a blocking error. Outcome meanings and recommended actions are in the outcome taxonomy.