openai_response_store

Persists Responses API responses to the configured response store backend.
On this page

Persists Responses API responses to the configured response store backend.

Configuration

FieldTypeRequiredDescription
backendsqlite | postgresyesStorage backend to use.
database_urlstring (secret)yesDatabase connection URL. Wrapped in [SecretString] to prevent accidental logging of credentials.
responses_tablestringyesTable name for response records.
conversations_tablestringyesTable name for conversation message records.
ssl_modeSslModenoTLS mode for PostgreSQL connections. Only valid when backend is postgres. Overrides any sslmode parameter in the connection URL.
ssl_root_certstring (secret)noPath to a PEM-encoded root CA certificate for PostgreSQL TLS verification. Only valid when backend is postgres and the effective SSL mode is verify-ca or verify-full.
ssl_client_certstring (secret)noPath to a PEM-encoded client certificate for mutual TLS with PostgreSQL. Only valid when backend is postgres and the effective SSL mode is verify-ca or verify-full. Must be configured together with ssl_client_key. Enables certificate authentication so the server does not challenge for a password.
ssl_client_keystring (secret)noPath to the PEM-encoded private key for ssl_client_cert. Only valid when backend is postgres. Must be an unencrypted PKCS#8 key (mode 0600) and configured together with ssl_client_cert. The native-tls backend (OpenSSL on Linux, Security.framework on macOS) accepts PKCS#8 only; convert a SEC1/PKCS#1 key with openssl pkcs8 -topk8 -nocrypt.
require_certificate_authenticationboolnoEnforce the certificate-authentication compliance profile for PostgreSQL. When enabled, the filter fails to start unless ssl_mode is verify-full, both ssl_client_cert and ssl_client_key are set, and no password reaches the connection (rejecting a password in database_url, TLS parameters in database_url, and the PGPASSWORD environment variable). It also rejects non-addressing connection parameters in database_url (application_name, options/options[...], statement-cache-capacity), which the certificate-authentication rebuild would silently drop; set such defaults on the database role instead (ALTER ROLE ... SET ...). The ssl_client_key file must also be owner-only (mode 0600, enforced on Unix). This keeps application-side password cryptography off the connection path. The PostgreSQL server must independently use a cert rule in pg_hba.conf; the proxy cannot enforce that server-side requirement.
allow_private_database_urlboolnoAllow PostgreSQL URLs that target local-sensitive addresses. By default, DNS names, localhost, loopback, private, link-local, cloud metadata, unspecified, and Unix socket targets are rejected. This opt-in is intended for local development and tests.
poolPoolConfignoConnection pool tuning options. When omitted, sqlx defaults apply (max_connections = 10, idle_timeout = 600s, acquire_timeout = 30s).
compressionStoreCompressionConfignoOptional payload compression for stored JSON columns. When omitted, payloads are stored uncompressed. Reads auto-detect the format, so enabling compression keeps existing uncompressed records readable.

Example

filter: openai_response_store
backend: postgres
database_url: postgres://praxis:[email protected]/praxis
responses_table: openai_responses
conversations_table: openai_conversation_messages
allow_private_database_url: true