Skip to content

Overview

DeepIntShield’s /genai endpoint accepts the supported Google GenAI request shapes. Use it when your application needs native GenAI clients and response objects. The common OpenAI client remains the primary cross-provider inference path in SDK 2.8.3.

Terminal window
pip install "deepintshield[genai]==2.8.3"
export DEEPINTSHIELD_BASE_URL="https://app.deepintshield.com"
export DEEPINTSHIELD_VIRTUAL_KEY="sk-ds-your-virtual-key"
from deepintshield import DeepintShield
with DeepintShield.from_env() as shield:
with shield.genai() as client:
response = client.models.generate_content(
model="gemini/gemini-2.5-flash",
contents="Hello!",
config={"automatic_function_calling": {"disable": True}},
)
print(response.text)

This returns a native google.genai.Client. Close it independently of the parent SDK client. The text example disables local automatic function calling because it supplies no Python callable tools. This setting does not disable gateway-side MCP tools attached by policy.

import os
from google import genai
from google.genai.types import HttpOptions
origin = os.environ["DEEPINTSHIELD_BASE_URL"].rstrip("/")
with genai.Client(
api_key=os.environ["DEEPINTSHIELD_VIRTUAL_KEY"],
http_options=HttpOptions(base_url=origin + "/genai", api_version="v1beta"),
) as client:
response = client.models.generate_content(
model="gemini/gemini-2.5-flash",
contents="Hello!",
config={"automatic_function_calling": {"disable": True}},
)
print(response.text)

Use the current @google/genai client and its httpOptions object. The URL is the integration root; the SDK adds the API version and model action. See Google’s HTTP options reference.

Terminal window
npm install @google/genai
import { GoogleGenAI } from "@google/genai";
const ai = new GoogleGenAI({
apiKey: process.env.DEEPINTSHIELD_VIRTUAL_KEY,
httpOptions: {
baseUrl: "https://app.deepintshield.com/genai",
apiVersion: "v1beta",
},
});
const response = await ai.models.generateContent({
model: "gemini/gemini-2.5-flash",
contents: "Hello!",
});
console.log(response.text);

Use provider/model-id for explicit routing: gemini/gemini-2.5-flash, openai/gpt-4o-mini, or a supported Anthropic/Vertex model. Choose a model configured for your account and key. The gateway translates supported content and tools; GenAI-only features do not become available on every provider.

Bare model names follow the GenAI route’s configured/default selection. Prefer a prefix when your workspace has multiple providers. Model methods, file/cache resources and errors retain operation-specific limits.

The raw action URL uses a colon: POST /genai/v1beta/models/gemini/gemini-2.5-flash:generateContent. Streaming uses :streamGenerateContent. Native clients construct these paths.

For Python, iterate client.models.generate_content_stream(...) for a supported model. Native async methods live under client.aio; use awaited calls and an async client context. Do not confuse native async I/O with the separate gateway async job API.

Inspect finish reasons and safety/refusal outcomes as well as text. An interrupted connection is not a completed response. Output guardrail inspection is incremental and cannot recall text already delivered. See streaming responses.

For Python callable tools, keep automatic function calling enabled and use client.chats.create(model=..., config={"tools": [your_function]}), then chat.send_message(...) or chat.send_message_stream(...). Native async chat methods are available through client.aio.chats.

Local callable execution and gateway MCP execution have different ownership. With DeepIntShield Agentic instrumentation enabled, local tools also need the configured agent identity, enrollment and policy authorization. Follow Agentic governance and MCP filtering for the respective controls.

Files, cached content and optional wrappers

Section titled “Files, cached content and optional wrappers”
  • Files and batch describes supported native resource operations. Uploading a file does not make its content available to the gateway’s attachment inspector.
  • shield.genai_cached() is an opt-in cache-aware wrapper; shield.genai() remains the native client. See provider prompt caching.
  • Named cached-content resources, model/account scope and lifecycle methods have protocol-specific requirements.
  • Native provider exceptions own HTTP decoding. Direct DeepIntShield helper failures use the SDK error catalog.

Use HttpOptions(headers=...) in Python or httpOptions.headers in JavaScript. Pass the gateway virtual key as api_key/apiKey in normal usage. Direct provider keys require administrator-enabled key management configuration; they are not needed for this integration.

See providers and frameworks for dependency sets, client options and the common inference path.