Prerequisites
Use Node.js 20 or later. SetSILMARIL_API_KEY and SILMARIL_API_URL from your deployment access.
Install
Classify your first request
Create one client per protected system and reuse it. Label each call with the boundary it checks.Expected result
A benign request logsBENIGN, its score, and allow. Direct classify calls return a result in every mode. They do not throw on a block. Treat the request as blocked when prediction is MALICIOUS or governance.action is block, then route it with firewall outcomes.
A rejected promise means the call did not produce a verdict. That includes SilmarilApiError for a non-2xx API response, and a network, timeout, or abort error. Decide whether that boundary fails open or closed.
Vercel, LangChain, and LangGraph integrations that wrap this client are documented in Framework SDKs.
Concurrent requests
Reuse one client for concurrent calls in a JavaScript runtime, with a hook on each call. Passsignal to classify or classifyBatch to cancel one request and its retry wait. Create a client in each worker thread.
request.signal is the caller’s AbortSignal.
Shadow mode
Shadow mode reports would-block decisions with the same thresholds while traffic continues. Framework adapters inherit the client setting and can override it when a surface is ready to enforce.Errors
Framework adapters throwFirewallBlockedException when a malicious or governance-block decision is enforced. The exception carries score and threshold.
generateText and model come from the Vercel integration. Rethrow any error that is not a firewall block.