Filter Reference

Built-in filters organized by protocol and category.
On this page

Built-in filters organized by protocol and category.

HTTP / Observability

FilterFeatureDescription
access_log-Logs structured access records for each request and response.
cloud_eventscloud-events-filterGenerate structured CloudEvents and ship them to a configured HTTP endpoint.
request_id-Ensures every request carries a correlation ID.
trace_context-Propagates W3C Trace Context and x-request-id correlation.

HTTP / Payload Processing

FilterFeatureDescription
compression-Enables Pingora’s built-in response compression when present in a filter chain.
grpc_web-Translates gRPC-Web calls to native gRPC and back.
json_body-Rewrites JSON request bodies with JSON Pointer add, remove, replace, and extract, and response bodies with remove and extract.
json_body_field-Extracts top-level fields from a JSON request body and promotes their values to request headers using [StreamBuffer] mode.
json_rpc-Extracts JSON-RPC 2.0 envelope metadata from request bodies and promotes method, id, and kind to request headers and filter results for routing.

HTTP / Security

FilterFeatureDescription
basic_authbasic-auth-filterHTTP Basic Authentication filter (RFC 7617).
cors-Spec-compliant CORS filter implementing origin validation, preflight handling, and response header injection.
credential_injection-Injects per-cluster API credentials into upstream requests.
csrf-CSRF protection filter that validates request origins against a trusted allowlist.
forwarded_headers-Injects X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host headers into upstream requests.
guardrails-Rejects requests matching string, regex, or PII rules against headers and/or body content.
ip_acl-IP-based access control filter.
peer_identity_trustspiffeValidates that the downstream mTLS peer identity matches a configured trusted peer before allowing the request to continue.
policypolicy-engineEmbeds the Praxis Policy Engine in-process to enforce multi-source identity, APL route policy, RFC 8693 token exchange, field redaction, session taint, audit emission, and (under body_access: read_write) request / response body rewriting. Content scanning is a host plugin the engine dispatches, not a bundled one.

HTTP / Traffic Management

FilterFeatureDescription
circuit_breaker-Rejects requests to clusters whose circuit is open.
endpoint_selector-Selects an upstream endpoint from a trusted mutation source.
grpc_detection-Detects the gRPC variant from the request content-type header and records it for branch-chain routing and observability.
grpc_timeout-Honours the grpc-timeout request header as a real deadline.
iterative_request_routeriterative-request-routerFramework-level filter for iterative sub-request execution.
load_balancer-Selects an upstream endpoint using the cluster’s configured strategy.
rate_limit-Token bucket rate limiter that rejects excess traffic with 429.
redirect-Returns a redirect response without contacting any upstream.
router-Routes requests to clusters based on path prefix and host header.
static_response-Returns a fixed response without contacting any upstream.
sticky_sessions-Sticky sessions HTTP filter.
timeout-Enforces a maximum end-to-end latency from request receipt to response headers.

HTTP / Transformation

FilterFeatureDescription
grpc_status-Answers proxy-generated errors in the shape gRPC clients expect.
headers-Adds, sets, or removes headers on upstream requests and downstream responses.
path_rewrite-Rewrites the request path before forwarding to the upstream.
url_rewrite-Rewrites request URLs using regex substitution and query parameter manipulation before the request reaches upstream.

TCP / Observability

FilterFeatureDescription
tcp_access_log-Logs TCP connection events.

TCP / Traffic Management

FilterFeatureDescription
sni_router-Routes TCP connections by SNI hostname.
tcp_load_balancer-Selects an upstream TCP endpoint using the cluster’s configured strategy.