Basic Auth
Authenticate requests using HTTP Basic Authentication (RFC 7617)
Configurations in Security.
Authenticate requests using HTTP Basic Authentication (RFC 7617)
Spec-compliant CORS filter with preflight handling, origin validation, and credential support
Injects per-cluster API credentials into upstream requests
Cross-site request forgery protection via origin validation
Protects against slow client attacks by limiting how long the proxy waits for data from downstream clients
Injects X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host into upstream requests
Reject requests that match header or body inspection rules
Runs body-inspecting guardrails only for a model selected from the request body
Allow or deny requests by source IP/CIDR
Validates downstream mTLS peer identity against a set of trusted peers
Embeds the Praxis Policy Engine in-process to enforce multi-source identity, APL route policy, RFC 8693 OAuth 2.0 token exchange, field redaction, session taint, audit emission, and (under body_access: read_write) request / response body rewriting
Projects policy-derived identity into request headers and removes credentials that should not reach the upstream
Generic-HTTP authorization for non-MCP traffic using the Praxis Policy Engine
Authorizes body-addressed inference requests against llm: policy routes