curl --request POST \
--url https://api.mnemom.ai/v1/policies/evaluate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"agent_id": "<string>",
"tools": [
{
"name": "<string>"
}
],
"context": "cicd",
"dry_run": false
}
'import requests
url = "https://api.mnemom.ai/v1/policies/evaluate"
payload = {
"agent_id": "<string>",
"tools": [{ "name": "<string>" }],
"context": "cicd",
"dry_run": False
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_id: '<string>',
tools: [{name: '<string>'}],
context: 'cicd',
dry_run: false
})
};
fetch('https://api.mnemom.ai/v1/policies/evaluate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.mnemom.ai/v1/policies/evaluate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_id' => '<string>',
'tools' => [
[
'name' => '<string>'
]
],
'context' => 'cicd',
'dry_run' => false
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.mnemom.ai/v1/policies/evaluate"
payload := strings.NewReader("{\n \"agent_id\": \"<string>\",\n \"tools\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"context\": \"cicd\",\n \"dry_run\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.mnemom.ai/v1/policies/evaluate")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"agent_id\": \"<string>\",\n \"tools\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"context\": \"cicd\",\n \"dry_run\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.mnemom.ai/v1/policies/evaluate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_id\": \"<string>\",\n \"tools\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"context\": \"cicd\",\n \"dry_run\": false\n}"
response = http.request(request)
puts response.read_body{
"verdict": "pass",
"violations": [
{
"type": "forbidden",
"tool": "<string>",
"capability": "<string>",
"rule": "<string>",
"reason": "<string>",
"severity": "low"
}
],
"warnings": [
{
"tool": "<string>",
"message": "<string>"
}
],
"card_gaps": [
{
"capability": "<string>",
"missing_card_field": "<string>",
"suggestion": "<string>"
}
],
"coverage": 0.5
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}Evaluate an agent's derived policy against tools
Evaluate a list of tools against the policy DERIVED from the agent’s published canonical alignment card (capabilities + enforcement + escalation triggers).
curl --request POST \
--url https://api.mnemom.ai/v1/policies/evaluate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"agent_id": "<string>",
"tools": [
{
"name": "<string>"
}
],
"context": "cicd",
"dry_run": false
}
'import requests
url = "https://api.mnemom.ai/v1/policies/evaluate"
payload = {
"agent_id": "<string>",
"tools": [{ "name": "<string>" }],
"context": "cicd",
"dry_run": False
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_id: '<string>',
tools: [{name: '<string>'}],
context: 'cicd',
dry_run: false
})
};
fetch('https://api.mnemom.ai/v1/policies/evaluate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.mnemom.ai/v1/policies/evaluate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_id' => '<string>',
'tools' => [
[
'name' => '<string>'
]
],
'context' => 'cicd',
'dry_run' => false
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.mnemom.ai/v1/policies/evaluate"
payload := strings.NewReader("{\n \"agent_id\": \"<string>\",\n \"tools\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"context\": \"cicd\",\n \"dry_run\": false\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.mnemom.ai/v1/policies/evaluate")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"agent_id\": \"<string>\",\n \"tools\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"context\": \"cicd\",\n \"dry_run\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.mnemom.ai/v1/policies/evaluate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_id\": \"<string>\",\n \"tools\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"context\": \"cicd\",\n \"dry_run\": false\n}"
response = http.request(request)
puts response.read_body{
"verdict": "pass",
"violations": [
{
"type": "forbidden",
"tool": "<string>",
"capability": "<string>",
"rule": "<string>",
"reason": "<string>",
"severity": "low"
}
],
"warnings": [
{
"tool": "<string>",
"message": "<string>"
}
],
"card_gaps": [
{
"capability": "<string>",
"missing_card_field": "<string>",
"suggestion": "<string>"
}
],
"coverage": 0.5
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
}
}Authorizations
Supabase JWT token in Authorization: Bearer header
Body
Agent whose canonical alignment card the policy is derived from. Must have a published canonical card, and the caller must be a member of the agent's org (else 404, the same answer as an agent that does not exist).
Non-empty list of tools to evaluate against the agent's derived policy.
1Show child attributes
Show child attributes
Evaluation surface/context (default "cicd").
When true, the evaluation result is not persisted to policy_evaluations.
Response
Policy evaluation result
Result of evaluating a CLPI policy against a set of tools or traces.
Overall evaluation verdict
pass, warn, fail List of policy violations detected
Show child attributes
Show child attributes
Non-blocking warnings about potential issues
Show child attributes
Show child attributes
Gaps between the policy and the alignment card
Show child attributes
Show child attributes
Fraction of tools covered by the policy (0.0 to 1.0)
0 <= x <= 1