Skip to content
GET/api/v1/uba/outliers

Get user-behavior-analytics outliers

Returns end-user outliers for an org, computed by the `compute_user_outliers` SQL function over `gateway_proxy_logs`. Per `end_user_id` it reports call count and cost with their org-wide z-scores, blocked count and blocked rate vs the org p95, distinct models used, average latency, firewall hits across ALL categories (the field is named injectionHits but the SQL sums every firewall hit, not only prompt injection), `flagReasons`, a `severity` of critical/high/medium/low, and first/last seen — plus a `bySeverity` summary. It is API-usage analytics only: there is no login-location, source-IP or time-of-day signal. `?orgId` is required; `?windowDays` defaults to 7 and is clamped to 1–90. Returns 501 `MIGRATION_PENDING` if migration 20260429 has not been applied.

Authentication

Send Authorization: Bearer YOUR_API_KEY on every request. Generate API keys at /dashboard/settings/api-keys.

Response

200 example

{
  "success": true
}

All status codes

200Outliers.
400(no description)
401(no description)
403Forbidden — the credential is valid but lacks the API-key scope, member role, or plan entitlement this operation requires.
429(no description)
500Internal Server Error — DB_ERROR.
501Not Implemented — MIGRATION_PENDING.

Code samples

cURL

curl -X GET \
  https://evalguard.ai/api/v1/uba/outliers \
  -H "Authorization: Bearer $EVALGUARD_API_KEY"

TypeScript

// The TypeScript SDK (@evalguard/sdk) exposes TYPED methods — runEval,
// getEval, runSecurityScan, checkFirewall, … — not a generic request().
// For an arbitrary endpoint, call it directly:

const res = await fetch("https://evalguard.ai/api/v1/uba/outliers", {
  method: "GET",
  headers: { Authorization: `Bearer ${process.env.EVALGUARD_API_KEY}` },
});
console.log(res.status, await res.json());

Python

# The Python SDK (pip install evalguardai) exposes TYPED methods on
# EvalGuardClient — run_eval, get_eval, … — not a generic request().
# For an arbitrary endpoint, call it directly:

import os
import requests

headers = {"Authorization": f"Bearer {os.environ['EVALGUARD_API_KEY']}"}

response = requests.request("GET", "https://evalguard.ai/api/v1/uba/outliers", headers=headers)
print(response.status_code, response.json())

Go

package main

import (
	"context"
	"fmt"
	"net/http"
	"os"
)

func main() {
	req, _ := http.NewRequestWithContext(context.Background(), "GET", "https://evalguard.ai/api/v1/uba/outliers", nil)
	req.Header.Set("Authorization", "Bearer "+os.Getenv("EVALGUARD_API_KEY"))
	resp, err := http.DefaultClient.Do(req)
	if err != nil { panic(err) }
	defer resp.Body.Close()
	fmt.Println(resp.Status)
}

Errors

400401403429500501

Other Security endpoints