Filters

Browse Praxis AI filters and open their generated configuration reference.
On this page

Praxis AI registers AI-specific filters into the Praxis filter pipeline. The generated filter reference is the authoritative inventory of filter names, descriptions, and configuration documentation.

For pipeline execution, filter traits, body access, conditional execution, filter chains, and core filters, see the Praxis core filter documentation.

Organization

AI filters are organized across two crates:

apis/src/                 Provider API integrations
  anthropic/              Anthropic Messages API
  openai/                 OpenAI Responses and Conversations APIs
  classifier/             Shared request classification
  store/                  Response and conversation persistence

filters/src/              Cross-provider behavior
  agentic/                MCP and A2A
  guardrails/             AI content guardrails
  inference/              Model routing
  prompt_enrich/          Prompt injection
  token_usage/            Token counting and headers

Praxis AI also inherits all base proxy filters from Praxis core through FilterRegistry::with_builtins(). This includes routing, load balancing, headers, credential injection, JSON-RPC parsing, CORS, compression, IP ACLs, and other general proxy behavior. Those filters are intentionally documented in the Praxis core filter reference, not duplicated here.

Registration

In-tree AI filters are registered by praxis_ai_filters::register_ai_filters. Downstream consumers that only need AI filters (for example an Envoy ExtProc) can depend on praxis-ai-filters without the proxy crate:

use praxis_filter::FilterRegistry;

let mut registry = FilterRegistry::with_builtins();
praxis_ai_filters::register_ai_filters(&mut registry);
// Or: let registry = praxis_ai_filters::build_ai_registry();

praxis-ai-proxy builds the full registry in three ownership layers:

let mut registry = FilterRegistry::with_builtins();
praxis_ai_filters::register_ai_filters(&mut registry);
register_external_filters(&mut registry); // proxy-only

This keeps core filters, in-tree AI filters, and auto-discovered extensions at clear ownership boundaries. External filter auto-discovery stays proxy-only.

Pipelines that use OpenAI store or rehydrate filters must also install the response-store extension:

pipeline.add_pipeline_extension(
    Box::new(praxis_ai_apis::store::ResponseStoreRegistry::new()),
);

The AI proxy does this in server/src/pipelines.rs. Other hosts (such as ExtProc) must do the same.


a2a

Extracts A2A protocol metadata from JSON-RPC request bodies and promotes method, family, task ID, streaming detection, and version to request headers, filter results, and durable metadata for routing.

ai_guardrails

Calls an external AI guardrail provider to evaluate request and response bodies. The provider determines whether content should be passed, blocked, or redacted.

anthropic_messages_format

Classifies Anthropic Messages API requests and promotes routing facts to headers, metadata, and filter results.

anthropic_messages_protocol

Normalizes Anthropic Messages protocol headers for native backends.

anthropic_messages_to_chat_completions

Transforms Anthropic Messages API requests to Chat Completions-compatible request bodies and transforms compatible responses back.

anthropic_messages_to_chat_completions_stream

Transforms streaming SSE responses between the Chat Completions and Anthropic Messages formats, processing each chunk as it arrives.

anthropic_validate

Validates Anthropic Messages request bodies for proxy-owned JSON envelope requirements.

anthropic_web_search

Executes server-owned WebSearch tool calls in an Anthropic Messages loop.

aws_sigv4_sign

Signs outbound requests to AWS services using SigV4.

azure_ad

Injects an Azure AD (Entra ID) bearer token into outbound requests.

callout_credentials

Establishing filter that captures typed per-user callout secrets from ingress headers.

credential_inject

Replaces caller credentials with the upstream credential selected by intelligent_route or provider_route.

Extensions

Extend Praxis AI with custom filters using the Praxis core filter interfaces and registration model.

external_metering

Integrates with an external metering service for pre-request balance checks and post-response token usage reporting.

Filter Reference

AI filters provided by Praxis AI. For base proxy filters (router, load balancer, headers, CORS, etc.), see the Praxis core filter reference.

gcp_adc

Injects a GCP OAuth2 access token into outbound requests.

http_callout

Calls an external HTTP service during request processing and feeds its response into branch-chain evaluation.

identity_header_guard

Captures request headers matching a configured prefix into filter_metadata and removes them from the upstream request.

intelligent_route

Selects an upstream cluster from a site/capability descriptor by matching either an inference model name or MCP tool name.

llmisvc_model_provider_resolver

Rewrites publisher-ID body model values to the short model name for LLMISvc / KServe routing; the routing header is left unchanged.

mcp

Extracts MCP JSON-RPC method, tool, resource, prompt, version, and session metadata into filter-visible request fields.

model_to_header

Promotes the JSON “model” field from the request body to a request header.

openai_agentic_loop

Agentic loop controller for the Responses API pipeline.

openai_chat_completions_to_azureai_chat_completions

Transforms requests targeting Azure OpenAI deployments into standard Chat Completions-compatible form and normalizes responses back.

openai_chat_completions_to_vertexai_gemini

Transforms OpenAI Chat Completions requests into Vertex AI Gemini generateContent format and translates responses back.

openai_client_tool_compat

Lowers rich client-owned tool declarations to private function tools for a function-only Responses backend and restores the typed items on the way back.

openai_conversations

Serve OpenAI Conversations API endpoints locally through the configured response store.

openai_doc_extract

Converts input_file content parts to input_text for backends that do not support input_file natively (e.g. vLLM, llm-d).

openai_file_resolve

Resolves file_id and file_url references in Responses API input by fetching content from a Files API or remote URL via ApiClient and inlining the base64-encoded content in the provider-native field.

openai_file_search_callout

Dispatches the loop owner’s pending file-search assignments against a vector store API compatible backend.

openai_mcp_dispatch

Executes MCP tool calls against upstream MCP servers within the Responses API agentic loop.

openai_mcp_tool_resolve

Resolves MCP tool entries from the Responses API tools array into concrete tool definitions by calling tools/list on each upstream MCP server.

openai_operation

Classifies supported OpenAI operations from the request head.

openai_response_store

Persists Responses API responses to the configured response store backend.

openai_responses_compact

Summarizes conversation history when the token count exceeds a configured threshold.

openai_responses_format

Classifies AI API request bodies and promotes routing facts to headers, metadata, and filter results without mutating the body.

openai_responses_model_rewrite

Rewrites the model field in Responses and Chat Completions request bodies.

openai_responses_proxy

Rebuilds the request body from ResponsesState when present.

openai_responses_rehydrate

Validates previous_response_id by fetching the stored response, confirming its status is “completed”, and populating ResponsesState with the full conversation history (stored turns + current input).

openai_responses_request

Processes the Responses create request body once and initializes state.

openai_responses_validate

Validates and enriches Responses API requests.

openai_stream_events

Composes the current IRR execution into one logical Responses stream.

openai_tool_parse

Parses tool definitions and tool_choice from Responses API request bodies and promotes routing facts to metadata and filter results without mutating the body.

openai_web_search

Web search filter for model-driven web_search_call dispatch.

project_state_owner_headers

Projects a normalized [StateOwner] into destination-specific HTTP headers.

prompt_enrich

Injects statically configured messages into the messages array of OpenAI-compatible chat completion request bodies.

provider_route

Exact provider-local mapping from an authenticated intelligent routing selection to a private backend cluster.

responses_to_chat_completions

Translates canonical Responses create requests for a Chat Completions backend.

state_owner

Establishes a normalized [StateOwner] from trusted identity sources.

time_to_first_token

Measures time-to-first-token for streaming AI responses.

token_count

Extracts token usage from AI inference responses and writes unified counts to [filter_metadata].

token_rate_limit

Token-denominated rate limiter: reserves an estimated cost at admission, reconciles against actual usage after the response completes.

token_usage_headers

Injects Praxis-Token-Input, Praxis-Token-Output, and Praxis-Token-Total headers into downstream responses when token usage data is present in [filter_metadata].