credential_injection
On this page
Injects per-cluster API credentials into upstream requests.
Configuration Notes
For each configured cluster, injects a header (e.g. Authorization: Bearer sk-...), replacing any client-provided value for that header to prevent credential forwarding.
Credentials are resolved at construction time (inline values or environment variables). The filter matches on the cluster name selected by the router filter earlier in the pipeline.
Scoping is per-cluster: a request routed to a cluster with no configured entry is left untouched, so a client-supplied header (e.g. Authorization) is forwarded to that cluster unchanged. This filter is not a general credential stripper; pair it with an explicit header-removal filter if every cluster must have client credentials stripped. The injected secret itself is only ever applied to the cluster it is configured for.
On the response path the injected header is stripped before the response reaches the client, so a gateway-managed credential never leaks even if the upstream echoes it back.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
clusters | ClusterCredentialConfig[] | yes | Per-cluster credential injection rules. |
clusters[].name | string | yes | Cluster name this rule applies to. |
clusters[].env_var | string | no | Environment variable name containing the credential. Resolved at filter construction time. Mutually exclusive with value. |
clusters[].header | string | yes | Header name to inject (e.g. "Authorization", "x-api-key"). |
clusters[].header_prefix | string | no | Optional prefix prepended to the credential value before injection (e.g. "Bearer "). |
clusters[].strip_client_credential | bool | no | Deprecated: injection always replaces any client-provided value for the header. Retained for config compatibility. |
clusters[].value | string (secret) | no | Literal credential value. Mutually exclusive with env_var. Wrapped in [SecretString] to prevent accidental logging. |
Example
filter: credential_injection
clusters:
- name: provider-a
header: Authorization
env_var: PROVIDER_A_API_KEY
header_prefix: "Bearer "
strip_client_credential: true
- name: internal
header: x-api-key
value: "internal-secret"