# Portkey AI Gateway — Velaru Fuse Hop (fail-closed guardrail)

August 2026 · Nisaba LLC

Wire Velaru **public fuse existence** into Portkey's `default.webhook` guardrail. No partnership. No Velaru account for the gateway operator beyond optional API key for KILL.

---

## What this does

| Portkey default | Velaru |
|-----------------|--------|
| Webhook timeout → **fail-open** (`verdict: true`) | You must set **`deny: true`** on the guardrail |
| Logs only | **DEAD fuse → `verdict: false` + restraint receipt + `verify_url`** |
| No public mortality | Stranger verify at `https://velaru.xyz/verify` |

---

## Velaru endpoint

```http
POST https://velaru.xyz/api/v1/fuse/hop
Content-Type: application/json

{
  "fuse_id": "fuse_velaru_demo_live",
  "action": "chatComplete",
  "scope": "invoke"
}
```

**Always HTTP 200.** Policy deny is `verdict: false`, never 400.

On deny:

```json
{
  "ok": true,
  "verdict": false,
  "state": "DEAD",
  "receipt_id": "…",
  "entry_id": "…",
  "verify_url": "https://velaru.xyz/verify?entry_id=…",
  "message": "DEAD fuse/fuse_velaru_demo_dead"
}
```

Lookup (no hop): `GET https://velaru.xyz/api/v1/fuse/lookup?q={fuse_id}`

Spec: `GET https://velaru.xyz/.well-known/velaru.json`

---

## Option A — Direct hop (simplest)

Use when every request carries a stable `fuse_id` in Portkey metadata.

**Portkey config JSON:**

```json
{
  "input_guardrails": [{
    "default.webhook": {
      "webhookURL": "https://velaru.xyz/api/v1/fuse/hop",
      "headers": { "Content-Type": "application/json" },
      "timeout": 5000
    },
    "deny": true
  }]
}
```

**Limitation:** Portkey posts its own webhook body shape, not your JSON. Use **Option B** for production.

---

## Option B — Thin adapter (recommended)

Deploy a 20-line adapter that maps Portkey → Velaru hop:

```javascript
// POST /portkey/velaru-guardrail
export default async function handler(req, res) {
  const meta = req.body?.metadata || {};
  const fuseId = meta.fuse_id || meta.velaru_fuse_id || process.env.VELARU_FUSE_ID;
  if (!fuseId) {
    return res.json({ verdict: false, data: { reason: "UNSIGNED — no fuse_id in metadata" } });
  }
  const hop = await fetch("https://velaru.xyz/api/v1/fuse/hop", {
    method: "POST",
    headers: { "Content-Type": "application/json" },
    body: JSON.stringify({ fuse_id: fuseId, action: req.body?.requestType || "invoke" }),
  }).then(r => r.json());
  return res.json({
    verdict: !!hop.verdict,
    data: {
      velaru: hop,
      verify_url: hop.verify_url,
      explanation: hop.message,
    },
  });
}
```

**Portkey config:**

```json
{
  "input_guardrails": [{
    "default.webhook": {
      "webhookURL": "https://YOUR_ADAPTER/portkey/velaru-guardrail",
      "headers": { "Authorization": "Bearer YOUR_SECRET" },
      "timeout": 5000
    },
    "deny": true
  }]
}
```

Pass fuse id on each request:

```http
x-portkey-metadata: {"fuse_id":"fuse_YOUR_TENANT"}
```

---

## Option C — Kong / IBM ContextForge (same primitive)

| Gateway | Hook | Velaru call |
|---------|------|-------------|
| Kong AI Gateway | pre-function / MCP passthrough | Return 403 when hop `verdict: false` |
| IBM ContextForge | `tool_pre_invoke` enforce | POST hop before tool runs |
| TrueFoundry | `mcp_pre_tool` | Same hop; card **Velaru** not Verra |

---

## Demo fuse ids (public)

| Fuse | State | URL |
|------|-------|-----|
| `fuse_velaru_demo_live` | LIVE | https://velaru.xyz/fuse/fuse_velaru_demo_live |
| `fuse_velaru_demo_dead` | DEAD | https://velaru.xyz/fuse/fuse_velaru_demo_dead |
| `fuse_velaru_drill` | Drill | https://velaru.xyz/fuse/fuse_velaru_drill |

Drill: `POST https://velaru.xyz/fuse/fuse_velaru_demo_dead/drill` → BLOCK + CHARGE URL.

---

## Smoke test (curl)

```bash
# DEAD → deny + verify_url
curl -s -X POST https://velaru.xyz/api/v1/fuse/hop \
  -H 'Content-Type: application/json' \
  -d '{"fuse_id":"fuse_velaru_demo_dead","action":"invoke"}' | jq .

# LIVE → allow
curl -s -X POST https://velaru.xyz/api/v1/fuse/hop \
  -H 'Content-Type: application/json' \
  -d '{"fuse_id":"fuse_velaru_demo_live","action":"invoke"}' | jq .

# UNSIGNED lookup
curl -s 'https://velaru.xyz/api/v1/fuse/lookup?q=random-brand.example' | jq .
```

---

## Links

- Portkey BYOG: https://portkey.ai/docs/integrations/guardrails/bring-your-own-guardrails
- Velaru integrate: https://velaru.xyz/integrate
- x402 + bazaar: https://velaru.xyz/docs/tap-ado-x402-bazaar.md
- Publish checklist: https://velaru.xyz/export/publish-batch-paste.txt

— Nisaba LLC (Velaru) · hello@velaru.xyz
