nemoguardrails
NeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.
Decision gist · record as of 2026-08-14
Yes, if you are building LLM-based conversational applications and need safety controls. The library is actively maintained, has no known vulnerabilities, supports current Python versions, and low install friction. The 18 dependencies are standard ecosystem packages. Permissive licensing allows commercial use. Main consideration: evaluate whether the guardrails configuration overhead and async-first design fit your application architecture.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10, 3.11, 3.12, or 3.13.
- Guardrails configuration folder with config.yml, config.py, and actions.py must be provided.
- Low install friction with a pure-Python wheel.
License · maintenance · safety
LICENSE.md (permissive) — Permissive license (Apache-2.0 primary with Other/Proprietary noted in classifiers). No restrictions on commercial use or modification; review LICENSE.md for any dual-licensing details if proprietary clauses apply.
last release 2026-07-01 (44 days) · last repo commit 2026-08-14 · 6,951 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 407,191 downloads/mo, #6,888 on PyPI
Alternatives
Verify before relying
from nemoguardrails import LLMRails, RailsConfig
config = RailsConfig.from_path("PATH/TO/CONFIG")
rails = LLMRails(config)
completion = rails.generate(
messages=[{"role": "user", "content": "Hello world!"}]
)- Performance overhead of guardrails layer relative to direct LLM calls
- Compatibility with specific LLM providers beyond those listed in documentation
- Memory footprint with all 18 runtime dependencies loaded
What it is and what it does
NeMo Guardrails is an NVIDIA open-source library that inserts a programmable control layer between your application code and an LLM. It lets you define rules—called rails—that shape how the LLM responds: rejecting unsafe inputs, preventing jailbreaks and prompt injections, enforcing topic boundaries, masking sensitive data, and steering conversations along predefined paths. The library supports five rail types (input, dialog, retrieval, execution, output) and works with multiple LLM providers.
You configure guardrails via YAML and Python files in a standard folder structure, then instantiate an LLMRails object and call generate() or generate_async() instead of the LLM directly. The API mirrors OpenAI's Chat Completions format, so integration requires minimal code changes. It's async-first internally but exposes both sync and async methods, and includes built-in protections against common LLM vulnerabilities like jailbreaks and hallucinations.
Use it for
- Add fact-checking and output moderation to retrieval-augmented generation (RAG) systems
- Build domain-specific chatbots that stay on topic and follow predefined conversation flows
- Protect custom LLM endpoints from jailbreaks and prompt injection attacks
- Mask sensitive data (PII, credentials) in user input before the LLM sees it
- Enforce authentication and support workflows in conversational applications
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building LLM-based conversational applications and need safety controls.
The library is actively maintained, has no known vulnerabilities, supports current Python versions, and low install friction. The 18 dependencies are standard ecosystem packages. Permissive licensing allows commercial use. Main consideration: evaluate whether the guardrails configuration overhead and async-first design fit your application architecture.
Install
nemoguardrails on PyPI
Before you install
Low install friction with a pure-Python wheel. Active maintenance with recent release (44 days old) and 6951 repository stars. Requires Python 3.10–3.13; 18 runtime dependencies including aiohttp, pydantic, and onnxruntime add moderate weight but are standard ecosystem packages.
Requires Python 3.10, 3.11, 3.12, or 3.13. Guardrails configuration folder with config.yml, config.py, and actions.py must be provided.
License in practice
Permissive license (Apache-2.0 primary with Other/Proprietary noted in classifiers). No restrictions on commercial use or modification; review LICENSE.md for any dual-licensing details if proprietary clauses apply.
Quickstart
from nemoguardrails import LLMRails, RailsConfig
config = RailsConfig.from_path("PATH/TO/CONFIG")
rails = LLMRails(config)
completion = rails.generate(
messages=[{"role": "user", "content": "Hello world!"}]
)
Verify before relying
- Performance overhead of guardrails layer relative to direct LLM calls
- Compatibility with specific LLM providers beyond those listed in documentation
- Memory footprint with all 18 runtime dependencies loaded
Package facts
| License | LICENSE.md permissive |
| Python support | Supports the current Python release <3.14,>=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 18 packagesaiohttpaiohttp-retrydataclasses-jsonfastembedhttpxjinja2jsonschemalarknest-asyncioonnxruntimepandasprompt-toolkitprotobufpydanticpyyamlrichsimpleevaltyper |
| Maintenance | Actively maintained 44 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 407,191 / month, #6,888 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseLicense :: Other/Proprietary LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13 |
Evidence: nemoguardrails-0.23.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “llm safety guardrails”
- nemoguardrailsAdds programmable guardrails to LLM-based conversational applications…
- datarobot-moderationsEnforces content moderation on LLM prompts and responses using…
- guardrails-aiGuardrails is a Python framework that validates and constrains LLM…
Give your agent the search over MCP, or paste the wish link into any chat.
More Artificial Intelligence packages
LiteLLM provides a unified Python interface to call 100+ LLM providers (OpenAI, Anthropic, Gemini, Bedrock, Azure, and others) using OpenAI-compatible API format, available as both a Python SDK and a self-hosted AI Gateway proxy server.
Install it if you need to work with multiple LLM providers or want to centralize LLM routing in your organization.
Client library and CLI tool for downloading, uploading, and managing models, datasets, and repositories on the Hugging Face Hub platform.
Install it if you work with Hugging Face Hub models or datasets.
LangChain provides a framework for building agents and LLM-powered applications by composing language models, tools, and memory through a unified API that abstracts over multiple model providers.
hf-xet provides chunk-based deduplication and efficient file transfer for the Hugging Face Hub, enabling faster uploads and downloads of large files with local disk caching.
Tokenizers converts raw text into token sequences for NLP models, with support for training custom vocabularies and using pre-built tokenizers (BPE, WordPiece) optimized for speed via Rust.
Transformers provides a unified framework for loading, fine-tuning, and running state-of-the-art pretrained models across text, vision, audio, video, and multimodal tasks using PyTorch, JAX, or TensorFlow.
Install it if you need to run or train any transformer-based model for NLP, vision, audio, or multimodal tasks.
See also datarobot-moderations · openai-guardrails · nemo-toolkit · nemo-relay · guardrails-ai · nvidia-nat-core · data-designer-engine · guardrails-ai-types · nemo-gym · guardrails-hub-types