Web Search Scoped Credentials
A scoped-credentials variant of full-flow-agentic.yaml
Category: Setup-dependent integration
Task: A scoped-credentials variant of full-flow-agentic.yaml
Prerequisites: The external service, credentials, or certificates referenced by this configuration.
Run it: Use ghcr.io/praxis-proxy/ai:0.5.0 and follow the container quickstart to mount and start the configuration.
This configuration comes from the selected release. The example has not been run here; external services are not bundled.
Download the source file.
Companion resources from the same snapshot:
# Anthropic Messages Web Search with Per-User Callout Credentials + Owner Attribution
#
# A scoped-credentials variant of full-flow-agentic.yaml. Accepts Anthropic
# Messages requests with hosted web search against a native Messages backend,
# and demonstrates PR1 of issue #880:
#
# * state_owner maps trusted ingress identity headers (x-auth-tenant /
# x-auth-user) into a normalized owner the web-search callout projects
# into its nested provider subrequest.
# * callout_credentials captures a PER-USER provider key from the trusted
# ingress header x-user-brave-key into the `brave_search` slot and strips
# the header so it never reaches an upstream. anthropic_web_search stages
# that per-user secret as the Brave `x-subscription-token` on the provider
# callout instead of the shared api_key. A request missing the header fails
# closed with a 401 authentication_error before any provider callout runs.
#
# Both filters run in the OUTER chain (before the iterative_request_router):
# core threads their extensions into every IRR step, and the ingress header is
# stripped before the IRR clones request headers.
#
# curl -N http://127.0.0.1:8080/v1/messages \
# -H 'content-type: application/json' \
# -H 'x-auth-tenant: acme' -H 'x-auth-user: alice' \
# -H 'x-user-brave-key: $ALICE_BRAVE_KEY' \
# -d '{"model":"openai/gpt-oss-20b","max_tokens":1024,"stream":true,"messages":[{"role":"user","content":"Use web search to look up potato, then summarize in one sentence."}],"tools":[{"name":"WebSearch","description":"Search the web","input_schema":{"type":"object","properties":{"query":{"type":"string"}},"required":["query"]}}]}'
listeners:
- name: anthropic-full-flow-agentic
address: "127.0.0.1:8080"
filter_chains: [full-flow-agentic]
filter_chains:
- name: full-flow-agentic
filters:
- filter: state_owner
# Deployment-specific trusted ingress identity. The authentication
# boundary must overwrite these and prevent clients from spoofing them.
mode: trusted_headers
tenant:
header: x-auth-tenant
issuer:
static: urn:example:gateway
subject:
header: x-auth-user
- filter: callout_credentials
# Capture the per-user Brave key from a trusted ingress header into the
# `brave_search` slot and strip the header so it never reaches an
# upstream. anthropic_web_search stages this per-user secret instead of
# the shared api_key below.
#
# SECURITY: each source_header is trusted-boundary-owned. The
# authentication boundary MUST unconditionally delete then set every
# source_header on every request, so a client cannot spoof another
# user's credential by supplying the header itself.
credentials:
- slot: brave_search
source_header: x-user-brave-key
- filter: anthropic_messages_format
on_invalid: reject
- filter: anthropic_validate
- filter: iterative_request_router
initial_step: inference
max_iterations: 6
timeout_ms: 90000
steps:
- name: inference
filters:
- filter: anthropic_web_search
provider: brave
api_key: ${WEB_SEARCH_API_KEY}
# Require the per-user Brave key captured into the `brave_search`
# slot by callout_credentials. A request without it fails closed
# with a 401 authentication_error before any provider callout.
user_credential: brave_search
default_context_size: medium
timeout_ms: 10000
# Each Brave provider callout executes through this outbound
# chain; the filtered-subrequest executor enforces destination
# authority, DNS/SSRF, TLS/SNI, and Host centrally.
outbound_chain:
name: anthropic-web-search-outbound
filters:
- filter: request_id
- filter: anthropic_messages_protocol
default_version: "2023-06-01"
- filter: router
routes:
- path_prefix: "/v1/messages"
cluster: messages-backend
- filter: load_balancer
clusters:
- name: messages-backend
endpoints: ["127.0.0.1:8000"]
on_result:
- filter: anthropic_web_search
key: action
value: loop
next: inference
- default: true
done: true
insecure_options:
allow_private_endpoints: true # example proxies to local backends