net/http middleware adapter for [guard-core-go](https://github.com/Guard-Core/guard-core-go). Translates `*http.Request` into the guardcore request surface, runs the engine, and translates verdicts to exact HTTP responses. Works with the stdlib mux, chi, httprouter, gorilla, and anything speaking `func(http.Handler) http.Handler`.
Website · Docs · Playground · Dashboard · Discord
Guard Core is the Python engine. Framework adapters are thin wrappers that translate native request/response types into Guard Core's protocols. The telemetry agents ship security events and metrics to the monitoring backend. Parallel engine implementations exist for Go, PHP, TypeScript (on npm), and Rust (on crates.io) - all ports of the same reference semantics, conformance-tested against the shared adversarial corpus.
| Package | Role | PyPI |
|---|---|---|
| guard-core | Framework-agnostic security engine | |
| guard-agent | Telemetry agent | |
| fastapi-guard | FastAPI / Starlette adapter | |
| flaskapi-guard | Flask adapter | |
| djapi-guard | Django adapter | |
| tornadoapi-guard | Tornado adapter |
Go modules published via GitHub releases. Production-ready.
| Package | Role | Release |
|---|---|---|
| guard-core-go | Go engine | |
| nethttp-guard | net/http adapter | |
| gin-guard | Gin adapter | |
| echo-guard | Echo (v4) adapter | |
| fiber-guard | Fiber (v3) adapter | |
| guard-agent-go | Telemetry agent |
Published on Packagist under the rennf93 vendor. Production-ready.
| Package | Role | Packagist |
|---|---|---|
| guard-core-php | PHP engine | |
| laravel-guard | Laravel adapter | |
| symfony-guard | Symfony adapter | |
| psr15-guard | PSR-15 adapter | |
| slim-guard | Slim 4 adapter | |
| guard-agent-php | Telemetry agent |
Published under the @guardcore npm scope; source in the guard-core-ts monorepo. Production-ready.
| Package | Role | npm |
|---|---|---|
| @guardcore/core | Core engine | |
| @guardcore/express | Express adapter | |
| @guardcore/nestjs | NestJS adapter | |
| @guardcore/fastify | Fastify adapter | |
| @guardcore/hono | Hono (edge) adapter | |
| guardagent | Telemetry agent |
Published on crates.io. Production-ready.
| Package | Role | crates.io |
|---|---|---|
| guard-core-engine | Core engine crate | |
| guard-core-rs | Facade crate (consumer entry point) | |
| actix-guard-rs | Actix Web adapter | |
| axum-guard-rs | Axum adapter | |
| tower-guard-rs | Tower adapter | |
| rocket-guard-rs | Rocket adapter | |
| guard-agent-rs | Telemetry agent |
| Package | Role | PyPI |
|---|---|---|
| guard-core-mcp | MCP server: config validation, docs search, detection sandbox |
- The full guard-core-go engine pipeline over net/http requests: rate limiting, IP policy, payload inspection across 19 attack categories, auto-banning
- Security headers and behavioral response rules applied on the pass-through path, with CORS merge
- Bounded body buffering with replay for downstream handlers
- Fail-closed on engine malfunction - a broken engine never turns into an open gate
📚 Documentation - full technical documentation for this package.
🛡️ Guard Core - the engine's reference documentation.
🤖 Monitoring Agent Integration - monitor your Guard instance with a monitoring agent.
go get github.com/rennf93/nethttp-guard@v1.4.0 github.com/rennf93/guard-core-go/v4@v4.3.2
package main
import (
"log"
"net/http"
guardcore "github.com/rennf93/guard-core-go/v4/guardcore"
nethttp "github.com/rennf93/nethttp-guard"
)
func main() {
cfg := guardcore.DefaultSecurityConfig()
engine, err := guardcore.NewEngine(cfg)
if err != nil {
log.Fatal(err)
}
if err := engine.Initialize(); err != nil {
log.Fatal(err)
}
guard, err := nethttp.New(engine)
if err != nil {
log.Fatal(err)
}
mux := http.NewServeMux()
mux.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) {
_, _ = w.Write([]byte("ok"))
})
log.Fatal(http.ListenAndServe(":8080", guard(mux)))
}Options: nethttp.WithMaxBodyBytes(n) bounds the body bytes the engine scans (default 262144), nethttp.WithLogger(l) swaps the fail-closed logger. Route-level configuration uses engine.Routes.Register plus nethttp.WithRouteID(ctx, id) on the request context.
Every engine SecurityConfig field is reachable through this adapter: global tuning (behavior rules with BehaviorScanResponseBody and the inspect-bytes budget, the geo lifecycle with IPInfoToken/OnGeoEvent, CORS, security headers, custom error bodies) goes through the SecurityConfig you hand to guardcore.NewEngine, per-route detection exclusions and per-route behavior/IP rules through engine.Routes.Register. On every pass-through response the adapter merges Engine.ResponseHeaders() with Engine.CORSResponseHeaders(req) and reports the response (status plus the leading inspect-budget bytes of the body when BehaviorScanResponseBody is on) to Engine.ProcessResponse for the behavioral return rules. See docs/configuration.md.
Engine malfunctions fail closed with a 500. Detection covers at most the first MaxBodyBytes of the body; payloads beyond the bound are not scanned, and the full body still reaches your handler untouched.
The middleware consumes the core as a normal module dependency, currently pinned to the guard-core-go master surface (v4.0.5-0.20260926230539-e39ac203568b, the behavior-rules / geo-lifecycle / route-detection-exclusions wave); no replace directive is used or needed. For cross-repo work on the core itself, add a temporary local replace line in your own checkout and drop it before committing.
Integration tests run against real Redis:
REDIS_HOST=127.0.0.1 go test -tags integration ./...
MIT