# jes > Open-source guardrails for AI agents Every page below is Markdown. Append `.md` to any docs URL to get its source, or read https://docs.getjes.dev/llms-full.txt for all pages in one file. ## Docs - [Introduction](https://docs.getjes.dev/index.md): jes is an open-source Python library that guards AI agents with any decision model on the TypeSafe API, such as Jev or Laya, checking every prompt, tool call, tool result, and reply. - [Why jes](https://docs.getjes.dev/why-jes.md): Why jes checks agent steps with a decision model, such as Jev or Laya, instead of an LLM judge — latency, cost, and why the checked text can't hijack the check. - [How jes works](https://docs.getjes.dev/concepts.md): What happens inside one check — transforms on your machine, judgments by a decision model such as Jev, and the result you branch on and forward. - [Built-in policies](https://docs.getjes.dev/built-in-policies.md): The policies that ship with jes — core policies in jes.policies and recipes in jes.recipes — and where to go to write your own. ## Core classes - [Core classes](https://docs.getjes.dev/classes.md): The handful of jes classes you work with, what each one is for, and how they fit together in a check. - [Guard and AsyncGuard](https://docs.getjes.dev/classes/guard.md): What a Guard is for — the one object your app talks to. It holds your policies, model, and limits, and checks each step of an agent. - [Policies](https://docs.getjes.dev/classes/policies.md): What a policy is — one rule a guard applies. The three kinds (transforms, sensitive-data policies, judgments), how each works, and how you build them. - [Questions and thresholds](https://docs.getjes.dev/classes/questions.md): What YesNo, Choice, Score, and Threshold are for — the typed question a judgment asks the decision model, and the line where an answer becomes a flag or a block. - [Result](https://docs.getjes.dev/classes/result.md): What every jes check returns — the ok flag to act on, the onward text to forward, and the findings, scores, and usage that explain it. - [Redactions](https://docs.getjes.dev/classes/redactions.md): What a jes Redactions store is — one conversation's private memory of the personal data hidden from the model, so replies can be restored. - [Message and History](https://docs.getjes.dev/classes/history.md): What Message and History are for — earlier turns you pass to a check so judgments see the conversation, and how jes sanitizes, fits, and flags them. - [Limits](https://docs.getjes.dev/classes/limits.md): What jes Limits are — the resource budget for one check, what each cap protects against, and what happens when one is crossed. - [Backend](https://docs.getjes.dev/classes/backend.md): The bridge between jes and a decision model — what a backend does, the three ways to pass model=, and how to write your own. - [FakeBackend](https://docs.getjes.dev/classes/fake-backend.md): A scripted backend for tests and offline runs — how it picks answers, and how to assert on what a check asked. - [Errors](https://docs.getjes.dev/classes/errors.md): The jes exception family — which error means what, why bad setup raises while bad input blocks, and which errors to catch. ## Protect your coding agent - [Agent setup](https://docs.getjes.dev/agents.md): Run jes from Claude Code, Codex, Hermes, OpenCode, OpenClaw, or Pi hooks with uvx. Log in once, pick your guards, install the hook. - [Claude Code](https://docs.getjes.dev/agents/claude-code.md): Check Claude Code prompts, tool calls, tool results, and replies with jes hooks. - [Codex](https://docs.getjes.dev/agents/codex.md): Check Codex prompts, tool calls, tool results, and replies with jes hooks. - [Hermes](https://docs.getjes.dev/agents/hermes.md): Check Hermes prompts and tool calls with jes shell hooks. - [OpenCode](https://docs.getjes.dev/agents/opencode.md): Check OpenCode prompts, tool calls, and tool results with the jes plugin. - [OpenClaw](https://docs.getjes.dev/agents/openclaw.md): Check OpenClaw prompts, tool calls, tool results, and replies with the jes plugin. - [Pi](https://docs.getjes.dev/agents/pi.md): Check Pi prompts, tool calls, and tool results with the jes extension. - [Guard config](https://docs.getjes.dev/agents/config.md): Every key in ~/.config/jes/config.json, the file that picks which guards the agent hooks run. - [Hook protocol](https://docs.getjes.dev/agents/hook-protocol.md): The stdin and stdout JSON of `jes hook`, the host-neutral hook command. Use it to add jes to an agent that has no built-in adapter. ## Protect your AI app - [Installation](https://docs.getjes.dev/getting-started/installation.md): Install the jes Python library, set your TypeSafe key, and add the extras for PII, secrets, encryption, regexes, and token limits. - [Quickstart](https://docs.getjes.dev/getting-started/quickstart.md): Run a first jes check in Python, then guard one conversation with reversible PII placeholders. Works with TypeSafe, OpenRouter, or Ollama. - [The five checks](https://docs.getjes.dev/guides/checks.md): When to call check_input, check_untrusted, check_tool_call, check_tool_result, and check_output, and what to forward from each. - [Tool calls and agents](https://docs.getjes.dev/guides/tool-calls.md): Check the tool name and arguments a model chooses, and the tool's response, with check_tool_call, check_tool_result, and allowed_tools. - [Multi-turn conversations](https://docs.getjes.dev/guides/multi-turn.md): Keep one Redactions store per conversation, pass history, and restore PII placeholders in complete replies. - [Thresholds and scores](https://docs.getjes.dev/guides/thresholds.md): What a violation score is, how Threshold blocks and flags, and why jes publishes no default thresholds. - [Write your own policy](https://docs.getjes.dev/guides/custom-policies.md): Build your own jes policies — a judge() question for the decision model, a regex() or substrings() pattern, or a policy class of your own — and test them offline. - [The judge](https://docs.getjes.dev/guides/judge.md): How jes sends judgment questions to a TypeSafe decision model, such as Jev or Laya, through LangChain — model names, pinning, the question mapping, confidence, failures, and bringing your own backend. - [OpenRouter](https://docs.getjes.dev/guides/openrouter.md): Run Jev through OpenRouter, so one OPENROUTER_API_KEY pays for both the jes judge and your app's chat model. - [Ollama](https://docs.getjes.dev/guides/ollama.md): Run jes fully on your machine with tev1, a local decision model served by Ollama, and a local chat model next to it. - [Where checked text goes](https://docs.getjes.dev/guides/where-text-goes.md): Which parts of jes run locally, what is sent to TypeSafe, and what the agent hooks store on disk. - [Failures and limits](https://docs.getjes.dev/guides/failures-and-limits.md): How on_backend_error, deadlines, and resource caps affect decision, complete, and ok. - [Limitations](https://docs.getjes.dev/guides/limitations.md): What jes does not do, in the library and in the agent hooks. ## Cookbooks - [Cookbooks](https://docs.getjes.dev/cookbook.md): The jes examples/ course, 15 lessons. Each has a hosted version (jev.py) and a local Ollama version (local.py), and two lessons also run through OpenRouter. - [Your first check](https://docs.getjes.dev/cookbook/one-check.md): A Guard, one policy, a threshold, ok and onward. - [The model call](https://docs.getjes.dev/cookbook/model-call.md): Guard one model call at its three trust boundaries: the input, a retrieved page, and the reply. - [Tool calls](https://docs.getjes.dev/cookbook/tool-calls.md): Check a tool call before it runs, and its result before the model reads it. - [PII across one conversation](https://docs.getjes.dev/cookbook/pii-conversation.md): Keep PII away from the model and give it back to the user. - [Secrets and a canary](https://docs.getjes.dev/cookbook/secrets-canary.md): Hide secrets from the model and catch a leaked canary. - [Topics and toxicity](https://docs.getjes.dev/cookbook/topics-toxicity.md): Deny a topic and block toxic messages. - [Your own question](https://docs.getjes.dev/cookbook/custom-questions.md): Ask your own yes/no, choice, and score questions with judge(). - [Recipes](https://docs.getjes.dev/cookbook/recipes.md): Ready-made recipes from the catalog. - [Async](https://docs.getjes.dev/cookbook/async-check.md): Run checks concurrently with AsyncGuard. - [When the model fails](https://docs.getjes.dev/cookbook/failures.md): Fail closed or open when the decision model is down. - [OpenAI SDK tool loop](https://docs.getjes.dev/cookbook/openai-sdk.md): Guard an OpenAI Responses API tool loop written out by hand. - [OpenAI Agents SDK](https://docs.getjes.dev/cookbook/openai-agents-sdk.md): jes as OpenAI Agents SDK guardrails. - [A LangChain agent](https://docs.getjes.dev/cookbook/langchain-agent.md): One middleware guards a LangChain agent. - [A LangGraph agent](https://docs.getjes.dev/cookbook/langgraph-agent.md): A LangGraph agent with a check at every trust boundary. - [A Deep Agent](https://docs.getjes.dev/cookbook/deep-agents.md): Guard a Deep Agent and the subagent it hands work to. ## API reference - [API reference](https://docs.getjes.dev/reference.md): Every public name in jes, grouped by module. - [Guard and AsyncGuard](https://docs.getjes.dev/reference/guard.md): Reference for jes.Guard, jes.AsyncGuard, and jes.Limits — constructor arguments, limits, and the five check methods. - [Policies](https://docs.getjes.dev/reference/policies.md): Reference for jes.policies — core transforms, sensitive-data policies, core judgments, judge(), and the policy protocols. - [Questions and thresholds](https://docs.getjes.dev/reference/questions.md): Reference for YesNo, Choice, Score, their answer types, violation_score, and Threshold. - [jes.backend](https://docs.getjes.dev/reference/backend.md): Reference for jes.backend — TypeSafe, ModelSpec, resolve_model, Request, Reply, and the backend protocols. - [Recipes](https://docs.getjes.dev/reference/recipes.md): Reference for jes.recipes — pre-made, unevaluated policy factories and their signatures. - [Results](https://docs.getjes.dev/reference/results.md): Reference for Result, Finding, Span, ScoreResult, Usage, Message, State, and the type aliases a check reports. - [Redactions](https://docs.getjes.dev/reference/redactions.md): Reference for jes.Redactions — the per-conversation store of PII placeholders. - [Errors](https://docs.getjes.dev/reference/errors.md): Reference for the jes exception types. - [Testing](https://docs.getjes.dev/reference/testing.md): Reference for jes.testing — FakeBackend and Rule, for testing guards and policies offline. ## Project - [Changelog](https://docs.getjes.dev/changelog.md): Release notes for every jes version. ## Agent tools - [jes agent skill](https://docs.getjes.dev/skills/jes/SKILL.md): SKILL.md for coding agents that write or review code using jes. - [jes docs MCP server](https://mcp.getjes.dev/mcp): MCP server for these docs. Add it to Claude Code, Cursor, or VS Code.