Skip to main content
Everything in the Deploy section covers AI your people use. This section covers AI your code calls — LLM API calls from services, pipelines, and agents, which no browser extension or endpoint agent can see. Both feed one registry.

The two halves

An asset detected by two independent channels is more trustworthy than one detected by a single channel — that idea is formalised in confidence scoring.

Two ways to instrument code

Python SDK

Drop-in replacement for the OpenAI and Anthropic clients. Richest metadata — business unit, use case, owner, data classification — because you declare it at construction.

AI Gateway

An HTTP proxy. Point OPENAI_BASE_URL at it and every call is captured with no application changes. Less business context, but nothing to integrate.
Most teams use both: the gateway for blanket coverage of everything that already exists, the SDK on the services where the business context actually matters.

What it captures

The SDK is fail-open by design. If the collector is unreachable, your LLM call still succeeds — telemetry buffers locally and retries. A discovery tool must never become a dependency of the thing it is discovering.

Current status

Be aware of what is and is not available yet:
Because the hosted API is not live, every example in this section points at a collector you run, typically http://localhost:8000. Nothing here depends on a Prompt Shields–hosted endpoint.

Where to start

1

Stand up a collector

Docker Compose brings up PostgreSQL with pgvector and the collector. See Self-hosting.
2

Instrument one service

Pick a single service with real business context and wrap its client. See Python SDK.
3

Add the gateway for breadth

Route everything else through the proxy to find what you didn’t know about. See AI Gateway.
4

Read the registry

Query assets, vendors, models, data flows, and risks over HTTP. See Registry API.