- Keeping system prompts out of stored traces while still tracing the request.
- Excluding user-submitted content from logs to meet data-handling requirements.
- Redacting model output from traces without changing what the caller receives.
security parameter controls what gets written to stored traces. It does not change the live request or response: the caller always receives the full, unmasked output. Only the copy persisted to trace storage is affected.
security is set per request. There is no workspace, project, or API-key default, so a request that sends no security block is traced in full unless a workspace-level mask applies. To mask every request without repeating the field, enable Trace Scrubbing for the workspace, subject to the routes listed under Coverage. To attach the field automatically instead, set it as a default on the SDK client.Comparison to Trace Scrubbing
Trace Data Masking (this page) and Trace Scrubbing both decide what the AI Gateway writes to a stored trace. They mask the same fields with the same code, so what differs is not what gets masked but where the mask is set and who can change it. What is the same- Both accept
input,output,system,metadata,variables, orall. - Both blank or remove those fields from the stored trace only. The live request, the response, the payload the provider receives, and the data Guardrails and Evaluators check are untouched.
- A request that sends both is merged: the masks add up, and neither side removes a mask the other set.
Which to use:
security.mask suits a caller protecting its own traffic, at the cost of sending the field on every request. trace_scrubbing suits a policy that must hold for everyone, because an admin sets it once for the workspace, a rule, or a gateway and no caller can opt out.
Quick Start
Configuration
An unrecognized value in
mask is rejected with a 400 error.
What each value masks
Coverage
security is supported on the AI Gateway’s request endpoints: responses, chat/completions, completions, embeddings, images/generations, images/variations, ocr, rerank, speech, transcriptions, and translations, and on deployments/invoke.
Three endpoints ignore the field: /classify does not accept it, and images/edits and moderations accept it without applying it. To mask /classify traces, set the Trace Scrubbing plugin on the workspace or on a routing rule. No placement masks images/edits, moderations, and the /responses WebSocket and /responses/compact routes traces, Trace Scrubbing included: their spans record no masking options, so ingest-time masking passes over them.
security is unrelated to the PII Redaction plugin, which rewrites sensitive values in the live request and response, and to Guardrails, which can block a request outright. It changes only what is written to trace storage; see Comparison to Trace Scrubbing for the plugin that writes the same masks from a wider set of places.