Service surfaces
Warden provides the free /api/demo/scan,
/api/demo/examples, /api/demo/gauntlet,
/api/demo/gauntlet/stats,
/api/demo/gauntlet/breakers,
/api/demo/gauntlet/breakers/{certificate_id},
POST /api/feedback,
GET /api/threat-intel/v1/summary,
/api/badges, /badge/{audit_id},
/apa/log, and /health routes. Production
POST /scan and POST /audit are protected
by the x402 terms returned by the live endpoint.
Security decision boundary
Warden applies implemented deterministic scanners and analyzers and returns ALLOW, SANITIZE, or BLOCK. ALLOW means no implemented detector fired for that request. It does not establish that content, an agent, an endpoint, a transaction, or a linked resource is safe. You remain responsible for approval policy, wallet controls, and the action taken after a verdict.
Gauntlet submissions
An ALLOW result from /api/demo/gauntlet creates a
pending candidate, not a confirmed bypass. Human review determines
whether the declared attack intent is genuine. By submitting, you
permit the Warden operator to retain and analyze the claim and, if
confirmed, prepare a redacted reproducer and add only that
reproducer to the held-out benchmark. A confirmed bypass also
receives a public signed WARDEN BREAKER certificate and a
hash-chained transparency-log entry. That first confirmed
reproducer remains held out and is not copied into training.
Training use is a separate opt-in. It requires explicit training-use consent confirming the submitter has rights to grant that use, followed by a separate second human review of a distinct redacted training reproducer. Promotion is bound to the confirmed WARDEN BREAKER certificate, records first-party provenance and consent evidence, and rejects overlap with training, held-out, or built-in material.
Public finder credit requires a supplied handle and explicit consent to publish that exact handle. Without that consent, a certificate must be anonymous. A certificate proves that Warden recorded the credit; it does not prove the submitter controls or owns the named account. No payment or reward is promised.
Do not place secrets, personal information, unlawful content, or payloads you lack permission to share into a Gauntlet claim.
Opt-in feedback
Feedback is a separate action and is never inferred from a scan.
By calling POST /api/feedback, you confirm that the
submitted reproducer is redacted, that you are authorized to share
it, and that Warden may retain it for review. Do not submit an
original private payload, credentials, personal information,
wallet material, or content you lack permission to share.
Submission does not promise detector changes, publication, or inclusion in a dataset. There is no automatic learning path. A human reviewer may promote and publish the redacted reproducer in exactly one training or held-out dataset only after category, consent, duplicate, and cross-dataset checks. Once promoted, the redacted reproducer may remain in that dataset beyond the pending feedback-retention period.
Public threat-intelligence output contains only aggregate cells with at least five accepted records. Smaller groups are absent from published cells, totals, and observation timing. The output excludes submitted text and record-level identifiers. Counts are self-reported and scanner-equivalent duplicates are collapsed; they are not a measurement of attack prevalence, detector accuracy, or the safety of any agent or endpoint.
Badges and registry records
A verified badge signature establishes the integrity of the displayed Warden record. A badge is point-in-time evidence for the fixed audit battery and target observed on its issue date. It is not a certification, ownership proof, continuous monitor, warranty, or statement about attacks the audit did not test.
Payments and marketplace activity
The live x402 challenge controls the payment terms for a production call. Successful settlement is recorded on a public chain. A raw x402 call does not create an OKX task and cannot itself support task-linked feedback; use the guided hire flow when a reviewable task is required. Do not self-pay or self-review to create misleading marketplace activity.
Availability and limits
The /api/demo/* routes use a dedicated public-demo
rate-limit budget, while /scan and
/audit use the paid-route budget.
POST /api/feedback uses a separate feedback budget.
GET /api/threat-intel/v1/summary uses a separate read
budget. The current application does not apply that limiter to
/health, /api/badges, or
/badge/{audit_id}. Availability, marketplace listing
state, corpus content, and service metadata may change. The status
page distinguishes current browser reachability from historical
uptime, which is not measured.
Disclaimer and independence
The service is provided as-is for security workflow support. To the extent permitted by law, no warranty of uninterrupted operation, merchantability, fitness for a particular purpose, or complete attack detection is made. Warden does not provide legal, financial, custody, or investment advice.
Warden is an independent service listed on OKX.AI and does not claim endorsement by OKX or OKLink.
Read the Privacy summary for payload handling, retention, public records, and operational metadata.