Security

14 configurations in Security for Praxis.

Configurations in Security.

Configurations

  • Basic Auth — Authenticate requests using HTTP Basic Authentication (RFC 7617)
  • Cors — Spec-compliant CORS filter with preflight handling, origin validation, and credential support
  • Credential Injection — Injects per-cluster API credentials into upstream requests
  • Csrf — Cross-site request forgery protection via origin validation
  • Downstream Read Timeout — Protects against slow client attacks by limiting how long the proxy waits for data from downstream clients
  • Forwarded Headers — Injects X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host into upstream requests
  • Guardrails Per Model — Runs body-inspecting guardrails only for a model selected from the request body
  • Guardrails — Reject requests that match header or body inspection rules
  • Ip Acl — Allow or deny requests by source IP/CIDR
  • Peer Identity Trust — Validates downstream mTLS peer identity against a set of trusted peers
  • Policy Assertions — Projects policy-derived identity into request headers and removes credentials that should not reach the upstream
  • Policy Http — Generic-HTTP authorization for non-MCP traffic using the Praxis Policy Engine
  • Policy Llm — Authorizes body-addressed inference requests against llm: policy routes
  • Policy — Embeds the Praxis Policy Engine in-process to enforce multi-source identity, APL route policy, RFC 8693 OAuth 2.0 token exchange, field redaction, session taint, audit emission, and (under body_access: read_write) request / response body rewriting

Basic Auth

Authenticate requests using HTTP Basic Authentication (RFC 7617)

Cors

Spec-compliant CORS filter with preflight handling, origin validation, and credential support

Credential Injection

Injects per-cluster API credentials into upstream requests

Csrf

Cross-site request forgery protection via origin validation

Downstream Read Timeout

Protects against slow client attacks by limiting how long the proxy waits for data from downstream clients

Forwarded Headers

Injects X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host into upstream requests

Guardrails

Reject requests that match header or body inspection rules

Guardrails Per Model

Runs body-inspecting guardrails only for a model selected from the request body

Ip Acl

Allow or deny requests by source IP/CIDR

Peer Identity Trust

Validates downstream mTLS peer identity against a set of trusted peers

Policy

Embeds the Praxis Policy Engine in-process to enforce multi-source identity, APL route policy, RFC 8693 OAuth 2.0 token exchange, field redaction, session taint, audit emission, and (under body_access: read_write) request / response body rewriting

Policy Assertions

Projects policy-derived identity into request headers and removes credentials that should not reach the upstream

Policy Http

Generic-HTTP authorization for non-MCP traffic using the Praxis Policy Engine

Policy Llm

Authorizes body-addressed inference requests against llm: policy routes