Skip to main content

Use Hosted Rivaro

Your first request through Rivaro Cloud in about 5 minutes. Walk through the Connect Agent wizard, point your SDK at Rivaro, see the request in the dashboard.

Rivaro sits between your AI application and the AI provider (OpenAI, Anthropic, Azure, Bedrock, Vertex, etc.). It intercepts every request, scans for violations (PII, prompt injection, data exfiltration, tool abuse, etc.), enforces your policies, and forwards the request to the provider. Your app gets back the same response it would normally — enforcement is transparent.

Want to evaluate locally first?

This guide walks through Rivaro Cloud — the hosted product with a multi-user dashboard, persistent AARM receipt chain, and full Connect Agent wizard. To run Rivaro on your laptop with Docker (no signup, no email), see Run Rivaro Locally instead.

Step 1: Open the Connect Agent wizard​

In the Rivaro dashboard, go to Agents and click Connect Agent. Pick the provider you want to govern (OpenAI, Anthropic, Azure OpenAI, Bedrock, Vertex AI, MCP, etc.).

The Create Agent wizard opens. Only the first two steps are required to start sending traffic — the rest can be filled in later.

1a. Role​

The first step asks: what will this agent do? Pick a role preset (Customer Service, Engineering Assistant, BI Analyst, etc.) or Custom for full manual control. Roles pre-configure detectors and policy rules so you don't start from scratch.

1b. Connect​

Give the agent a name (e.g. "Production Customer Support"). The wizard pre-fills sensible defaults for endpoints based on the provider you picked. Open Advanced Connection Settings if you need to override endpoints, or — for MCP — choose between gateway (proxy with tool chain) and tool (standalone MCP tool) modes and discover tools from your MCP server.

Click Continue. Rivaro creates an AppContext, a detection key, and applies the role's policy rules in one step.

1c. (Optional) Confirm Policy, Detectors, Policy Rules, Enforcement, Governance, Risk Profile​

If you picked a role preset, the wizard will offer to walk you through the remaining steps to refine:

  • Confirm Policy — review the rules the role applied
  • Detectors — enable/disable risk categories (Critical Control Risks, Identity & Access, Behavior & Evasion, Governance & Visibility)
  • Policy Rules — per-detector action overrides (BLOCK, REDACT, STEP_UP, LOG, ALERT)
  • Enforcement — pick a preset (Conservative, Balanced, Permissive) or edit the risk-band thresholds directly
  • Governance — owner, department, purpose, data classification
  • Risk Profile — risk level, intended use, out-of-scope uses, known limitations, compliance frameworks (GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001, ISO 42001, NIST AI RMF, EU AI Act)

You can skip these now and come back later via the agent's settings — the agent will work with the role's defaults.

Step 2: Copy the connection details​

After you finish the Connect step, the wizard moves into the Connect Traffic phase and shows you:

  • Your detection key (e.g. detect_live_aBcDeFg...) — only fully visible here, copy it now
  • The proxy base URL for your org (e.g. https://your-org.rivaro.ai/v1)
  • A copyable SDK snippet specific to your provider

Keep that tab open. The wizard will poll for your first request and confirm the connection automatically.

Step 3: Change your base URL​

Point your AI SDK at your Rivaro proxy instead of the provider directly. That's the only code change.

OpenAI (Python)​

Before:

from openai import OpenAI

client = OpenAI(api_key="sk-your-openai-key")

After:

from openai import OpenAI

client = OpenAI(
api_key="sk-your-openai-key",
base_url="https://your-org.rivaro.ai/v1",
default_headers={
"x-detection-key": "detect_live_your_key_here"
}
)

OpenAI (Node.js)​

Before:

import OpenAI from 'openai';

const client = new OpenAI({ apiKey: 'sk-your-openai-key' });

After:

import OpenAI from 'openai';

const client = new OpenAI({
apiKey: 'sk-your-openai-key',
baseURL: 'https://your-org.rivaro.ai/v1',
defaultHeaders: {
'x-detection-key': 'detect_live_your_key_here'
}
});

Anthropic (Python)​

Before:

from anthropic import Anthropic

client = Anthropic(api_key="sk-ant-your-key")

After:

from anthropic import Anthropic

client = Anthropic(
api_key="sk-ant-your-key",
base_url="https://your-org.rivaro.ai",
default_headers={
"x-detection-key": "detect_live_your_key_here"
}
)

Step 4: Make a request​

Use your SDK exactly as you normally would. Rivaro handles enforcement transparently:

response = client.chat.completions.create(
model="gpt-4",
messages=[{"role": "user", "content": "Hello, world!"}]
)

print(response.choices[0].message.content)

If enforcement allows the request, you get the provider's response back unchanged. If a policy blocks the request, you'll get an error response from Rivaro (see Error responses below).

Step 5: Connection verified​

Switch back to the wizard tab. Once your first request arrives, the wizard advances automatically to the Agent is Live phase — usage count and last-used timestamp update in real time. From there you can jump straight to the policy editor or close the wizard and head to the agent dashboard.

The same request shows up in the dashboard activity feed with:

  • Detections — what Rivaro found (PII, prompt injection, etc.)
  • Policy action — what happened (allowed, logged, blocked, redacted, step-up)
  • Risk classification — severity, risk domain, risk category
note

If you picked a permissive role preset and skipped the optional steps, Rivaro will mostly log rather than block — useful for seeing what your agent does before turning enforcement up. Switch to the Conservative or Balanced enforcement preset, or edit per-detector actions, when you're ready to enforce.

Error responses​

When Rivaro itself rejects a request (not the AI provider), you'll get:

HTTP StatusMeaningExample
401Detection key missing or invalid{"error": "Detection key required for proxy endpoints."}
403Model not in allowed list{"error": "The requested model is not permitted."}
429Rate limit exceeded{"error": "Rate limit exceeded"}
451Request blocked by policy{"error": "Request blocked by enforcement policy"}

Errors from the AI provider (e.g. invalid provider API key, quota exceeded) are passed through in the provider's own format.

Streaming​

Streaming works out of the box. Use stream=True (Python) or stream: true (Node.js) as you normally would. Rivaro streams chunks back in real time with enforcement applied.

stream = client.chat.completions.create(
model="gpt-4",
messages=[{"role": "user", "content": "Explain quantum computing"}],
stream=True
)

for chunk in stream:
print(chunk.choices[0].delta.content or "", end="")

What's next​