curl --request POST \
--url https://use.hoop.dev/api/ai/session-analyzer/rules \
--header 'Content-Type: application/json' \
--data '
{
"connection_names": [
"pgdemo",
"mysql-prod"
],
"name": "block-dangerous-queries",
"risk_evaluation": {
"high_risk_action": "block_execution",
"low_risk_action": "allow_execution",
"medium_risk_action": "allow_execution"
},
"agentic": false,
"approval_ttl_sec": 600,
"custom_prompt": "Treat any query that touches the payments schema as high risk.",
"description": "Blocks high-risk SQL commands",
"pending_ttl_sec": 900,
"reviewers_groups": [
"dba-leads"
],
"sidecar_spec": {},
"sidecar_targets": [
{
"listener_name": "appdb",
"sidecar_id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7"
}
]
}
'import requests
url = "https://use.hoop.dev/api/ai/session-analyzer/rules"
payload = {
"connection_names": ["pgdemo", "mysql-prod"],
"name": "block-dangerous-queries",
"risk_evaluation": {
"high_risk_action": "block_execution",
"low_risk_action": "allow_execution",
"medium_risk_action": "allow_execution"
},
"agentic": False,
"approval_ttl_sec": 600,
"custom_prompt": "Treat any query that touches the payments schema as high risk.",
"description": "Blocks high-risk SQL commands",
"pending_ttl_sec": 900,
"reviewers_groups": ["dba-leads"],
"sidecar_spec": {},
"sidecar_targets": [
{
"listener_name": "appdb",
"sidecar_id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7"
}
]
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
connection_names: ['pgdemo', 'mysql-prod'],
name: 'block-dangerous-queries',
risk_evaluation: {
high_risk_action: 'block_execution',
low_risk_action: 'allow_execution',
medium_risk_action: 'allow_execution'
},
agentic: false,
approval_ttl_sec: 600,
custom_prompt: 'Treat any query that touches the payments schema as high risk.',
description: 'Blocks high-risk SQL commands',
pending_ttl_sec: 900,
reviewers_groups: ['dba-leads'],
sidecar_spec: {},
sidecar_targets: [{listener_name: 'appdb', sidecar_id: '15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7'}]
})
};
fetch('https://use.hoop.dev/api/ai/session-analyzer/rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://use.hoop.dev/api/ai/session-analyzer/rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'connection_names' => [
'pgdemo',
'mysql-prod'
],
'name' => 'block-dangerous-queries',
'risk_evaluation' => [
'high_risk_action' => 'block_execution',
'low_risk_action' => 'allow_execution',
'medium_risk_action' => 'allow_execution'
],
'agentic' => false,
'approval_ttl_sec' => 600,
'custom_prompt' => 'Treat any query that touches the payments schema as high risk.',
'description' => 'Blocks high-risk SQL commands',
'pending_ttl_sec' => 900,
'reviewers_groups' => [
'dba-leads'
],
'sidecar_spec' => [
],
'sidecar_targets' => [
[
'listener_name' => 'appdb',
'sidecar_id' => '15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://use.hoop.dev/api/ai/session-analyzer/rules"
payload := strings.NewReader("{\n \"connection_names\": [\n \"pgdemo\",\n \"mysql-prod\"\n ],\n \"name\": \"block-dangerous-queries\",\n \"risk_evaluation\": {\n \"high_risk_action\": \"block_execution\",\n \"low_risk_action\": \"allow_execution\",\n \"medium_risk_action\": \"allow_execution\"\n },\n \"agentic\": false,\n \"approval_ttl_sec\": 600,\n \"custom_prompt\": \"Treat any query that touches the payments schema as high risk.\",\n \"description\": \"Blocks high-risk SQL commands\",\n \"pending_ttl_sec\": 900,\n \"reviewers_groups\": [\n \"dba-leads\"\n ],\n \"sidecar_spec\": {},\n \"sidecar_targets\": [\n {\n \"listener_name\": \"appdb\",\n \"sidecar_id\": \"15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://use.hoop.dev/api/ai/session-analyzer/rules")
.header("Content-Type", "application/json")
.body("{\n \"connection_names\": [\n \"pgdemo\",\n \"mysql-prod\"\n ],\n \"name\": \"block-dangerous-queries\",\n \"risk_evaluation\": {\n \"high_risk_action\": \"block_execution\",\n \"low_risk_action\": \"allow_execution\",\n \"medium_risk_action\": \"allow_execution\"\n },\n \"agentic\": false,\n \"approval_ttl_sec\": 600,\n \"custom_prompt\": \"Treat any query that touches the payments schema as high risk.\",\n \"description\": \"Blocks high-risk SQL commands\",\n \"pending_ttl_sec\": 900,\n \"reviewers_groups\": [\n \"dba-leads\"\n ],\n \"sidecar_spec\": {},\n \"sidecar_targets\": [\n {\n \"listener_name\": \"appdb\",\n \"sidecar_id\": \"15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://use.hoop.dev/api/ai/session-analyzer/rules")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"connection_names\": [\n \"pgdemo\",\n \"mysql-prod\"\n ],\n \"name\": \"block-dangerous-queries\",\n \"risk_evaluation\": {\n \"high_risk_action\": \"block_execution\",\n \"low_risk_action\": \"allow_execution\",\n \"medium_risk_action\": \"allow_execution\"\n },\n \"agentic\": false,\n \"approval_ttl_sec\": 600,\n \"custom_prompt\": \"Treat any query that touches the payments schema as high risk.\",\n \"description\": \"Blocks high-risk SQL commands\",\n \"pending_ttl_sec\": 900,\n \"reviewers_groups\": [\n \"dba-leads\"\n ],\n \"sidecar_spec\": {},\n \"sidecar_targets\": [\n {\n \"listener_name\": \"appdb\",\n \"sidecar_id\": \"15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"agentic": false,
"approval_ttl_sec": 600,
"connection_names": [
"pgdemo",
"mysql-prod"
],
"created_at": "2024-07-25T15:56:35.317601Z",
"custom_prompt": "Treat any query that touches the payments schema as high risk.",
"description": "Blocks high-risk SQL commands",
"id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7",
"managed_by": "hoop",
"name": "block-dangerous-queries",
"pending_ttl_sec": 900,
"reviewers_groups": [
"dba-leads"
],
"risk_evaluation": {
"high_risk": {
"action": "require_access_request",
"access_request_rule_name": "prod-approvals"
},
"high_risk_action": "block_execution",
"low_risk": {
"action": "require_access_request",
"access_request_rule_name": "prod-approvals"
},
"low_risk_action": "allow_execution",
"medium_risk": {
"action": "require_access_request",
"access_request_rule_name": "prod-approvals"
},
"medium_risk_action": "allow_execution"
},
"sidecar_spec": {},
"sidecar_targets": [
{
"listener_name": "appdb",
"sidecar_id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7"
}
],
"updated_at": "2024-07-25T15:56:35.317601Z"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}Create AI Session Analyzer Rule
Create a new AI session analyzer rule
curl --request POST \
--url https://use.hoop.dev/api/ai/session-analyzer/rules \
--header 'Content-Type: application/json' \
--data '
{
"connection_names": [
"pgdemo",
"mysql-prod"
],
"name": "block-dangerous-queries",
"risk_evaluation": {
"high_risk_action": "block_execution",
"low_risk_action": "allow_execution",
"medium_risk_action": "allow_execution"
},
"agentic": false,
"approval_ttl_sec": 600,
"custom_prompt": "Treat any query that touches the payments schema as high risk.",
"description": "Blocks high-risk SQL commands",
"pending_ttl_sec": 900,
"reviewers_groups": [
"dba-leads"
],
"sidecar_spec": {},
"sidecar_targets": [
{
"listener_name": "appdb",
"sidecar_id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7"
}
]
}
'import requests
url = "https://use.hoop.dev/api/ai/session-analyzer/rules"
payload = {
"connection_names": ["pgdemo", "mysql-prod"],
"name": "block-dangerous-queries",
"risk_evaluation": {
"high_risk_action": "block_execution",
"low_risk_action": "allow_execution",
"medium_risk_action": "allow_execution"
},
"agentic": False,
"approval_ttl_sec": 600,
"custom_prompt": "Treat any query that touches the payments schema as high risk.",
"description": "Blocks high-risk SQL commands",
"pending_ttl_sec": 900,
"reviewers_groups": ["dba-leads"],
"sidecar_spec": {},
"sidecar_targets": [
{
"listener_name": "appdb",
"sidecar_id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7"
}
]
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
connection_names: ['pgdemo', 'mysql-prod'],
name: 'block-dangerous-queries',
risk_evaluation: {
high_risk_action: 'block_execution',
low_risk_action: 'allow_execution',
medium_risk_action: 'allow_execution'
},
agentic: false,
approval_ttl_sec: 600,
custom_prompt: 'Treat any query that touches the payments schema as high risk.',
description: 'Blocks high-risk SQL commands',
pending_ttl_sec: 900,
reviewers_groups: ['dba-leads'],
sidecar_spec: {},
sidecar_targets: [{listener_name: 'appdb', sidecar_id: '15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7'}]
})
};
fetch('https://use.hoop.dev/api/ai/session-analyzer/rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://use.hoop.dev/api/ai/session-analyzer/rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'connection_names' => [
'pgdemo',
'mysql-prod'
],
'name' => 'block-dangerous-queries',
'risk_evaluation' => [
'high_risk_action' => 'block_execution',
'low_risk_action' => 'allow_execution',
'medium_risk_action' => 'allow_execution'
],
'agentic' => false,
'approval_ttl_sec' => 600,
'custom_prompt' => 'Treat any query that touches the payments schema as high risk.',
'description' => 'Blocks high-risk SQL commands',
'pending_ttl_sec' => 900,
'reviewers_groups' => [
'dba-leads'
],
'sidecar_spec' => [
],
'sidecar_targets' => [
[
'listener_name' => 'appdb',
'sidecar_id' => '15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://use.hoop.dev/api/ai/session-analyzer/rules"
payload := strings.NewReader("{\n \"connection_names\": [\n \"pgdemo\",\n \"mysql-prod\"\n ],\n \"name\": \"block-dangerous-queries\",\n \"risk_evaluation\": {\n \"high_risk_action\": \"block_execution\",\n \"low_risk_action\": \"allow_execution\",\n \"medium_risk_action\": \"allow_execution\"\n },\n \"agentic\": false,\n \"approval_ttl_sec\": 600,\n \"custom_prompt\": \"Treat any query that touches the payments schema as high risk.\",\n \"description\": \"Blocks high-risk SQL commands\",\n \"pending_ttl_sec\": 900,\n \"reviewers_groups\": [\n \"dba-leads\"\n ],\n \"sidecar_spec\": {},\n \"sidecar_targets\": [\n {\n \"listener_name\": \"appdb\",\n \"sidecar_id\": \"15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://use.hoop.dev/api/ai/session-analyzer/rules")
.header("Content-Type", "application/json")
.body("{\n \"connection_names\": [\n \"pgdemo\",\n \"mysql-prod\"\n ],\n \"name\": \"block-dangerous-queries\",\n \"risk_evaluation\": {\n \"high_risk_action\": \"block_execution\",\n \"low_risk_action\": \"allow_execution\",\n \"medium_risk_action\": \"allow_execution\"\n },\n \"agentic\": false,\n \"approval_ttl_sec\": 600,\n \"custom_prompt\": \"Treat any query that touches the payments schema as high risk.\",\n \"description\": \"Blocks high-risk SQL commands\",\n \"pending_ttl_sec\": 900,\n \"reviewers_groups\": [\n \"dba-leads\"\n ],\n \"sidecar_spec\": {},\n \"sidecar_targets\": [\n {\n \"listener_name\": \"appdb\",\n \"sidecar_id\": \"15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://use.hoop.dev/api/ai/session-analyzer/rules")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"connection_names\": [\n \"pgdemo\",\n \"mysql-prod\"\n ],\n \"name\": \"block-dangerous-queries\",\n \"risk_evaluation\": {\n \"high_risk_action\": \"block_execution\",\n \"low_risk_action\": \"allow_execution\",\n \"medium_risk_action\": \"allow_execution\"\n },\n \"agentic\": false,\n \"approval_ttl_sec\": 600,\n \"custom_prompt\": \"Treat any query that touches the payments schema as high risk.\",\n \"description\": \"Blocks high-risk SQL commands\",\n \"pending_ttl_sec\": 900,\n \"reviewers_groups\": [\n \"dba-leads\"\n ],\n \"sidecar_spec\": {},\n \"sidecar_targets\": [\n {\n \"listener_name\": \"appdb\",\n \"sidecar_id\": \"15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"agentic": false,
"approval_ttl_sec": 600,
"connection_names": [
"pgdemo",
"mysql-prod"
],
"created_at": "2024-07-25T15:56:35.317601Z",
"custom_prompt": "Treat any query that touches the payments schema as high risk.",
"description": "Blocks high-risk SQL commands",
"id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7",
"managed_by": "hoop",
"name": "block-dangerous-queries",
"pending_ttl_sec": 900,
"reviewers_groups": [
"dba-leads"
],
"risk_evaluation": {
"high_risk": {
"action": "require_access_request",
"access_request_rule_name": "prod-approvals"
},
"high_risk_action": "block_execution",
"low_risk": {
"action": "require_access_request",
"access_request_rule_name": "prod-approvals"
},
"low_risk_action": "allow_execution",
"medium_risk": {
"action": "require_access_request",
"access_request_rule_name": "prod-approvals"
},
"medium_risk_action": "allow_execution"
},
"sidecar_spec": {},
"sidecar_targets": [
{
"listener_name": "appdb",
"sidecar_id": "15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7"
}
],
"updated_at": "2024-07-25T15:56:35.317601Z"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}{
"message": "the error description"
}Body
The request body resource
Connection names this rule applies to
["pgdemo", "mysql-prod"]
Unique name for the rule
"block-dangerous-queries"
Risk evaluation actions per level
Show child attributes
Show child attributes
When true, the analyzer runs an agentic tool-calling loop over past sessions and resource metadata before classifying.
false
Seconds an approval lasts from the approval, 60 to 604800. The same rules as pending_ttl_sec
600
Optional extra instructions appended to the default system prompt
"Treat any query that touches the payments schema as high risk."
Optional description
"Blocks high-risk SQL commands"
Seconds a held statement's review may wait for a decision, 60 to 604800. Control plane, read only while sidecar_spec holds under its own approval rule. Absent keeps, 0 clears
900
ReviewersGroups are the groups whose members may release a statement this rule holds for approval. Absent keeps the groups already set; with none set the admin group reviews.
A control plane field, read only while sidecar_spec holds a statement.
["dba-leads"]
SidecarSpec is this rule in the SIDECAR's own vocabulary, which the gateway's fields above do not share: a trigger, risk actions spelled allow / warn / block / defer, and the per-lane cost overrides. It IS the analyzer block the listener receives.
A control plane field. A gateway has no sidecars and refuses it.
SidecarTargets names the sidecar LISTENERS that must run this analysis. One block per listener: two rules bound to one listener is refused rather than merged.
A POINTER because absent and empty are different instructions: absent leaves the bindings exactly as they are, and [] unbinds the rule from every sidecar. Without that distinction any write that did not mention the field -- a script fixing a typo, the gateway's own UI, an MCP call -- would silently unbind a rule from the whole fleet.
Show child attributes
Show child attributes
Response
Created
When true, the analyzer runs an agentic tool-calling loop over past sessions and resource metadata before classifying.
false
Seconds an approval lasts from the approval. Present as pending_ttl_sec is
600
Connection names this rule applies to
["pgdemo", "mysql-prod"]
The time the resource was created
"2024-07-25T15:56:35.317601Z"
Optional extra instructions appended to the default system prompt
"Treat any query that touches the payments schema as high risk."
Optional description
"Blocks high-risk SQL commands"
The resource identifier
"15B5A2FD-0706-4A47-B1CF-B93CCFC5B3D7"
Set to "hoop" when the rule is materialized and lifecycle-managed by a protection profile; managed rules are read-only through this API
"hoop"
Unique name for the rule
"block-dangerous-queries"
Seconds a held statement's review may wait for a decision. Present only in a control plane, while the rule holds and the limit is set
900
The groups whose members may release a statement this rule holds. Present only in a control plane, while the rule holds.
["dba-leads"]
Risk evaluation actions per level
Show child attributes
Show child attributes
SidecarSpec is this rule in the sidecar's own vocabulary; see the request type. Present only in a control plane.
The sidecar listeners this rule is bound to, and therefore distributed to
Show child attributes
Show child attributes
The time the resource was updated
"2024-07-25T15:56:35.317601Z"
Was this page helpful?