Secrets Detection Configuration
Options
| Option | Default | Description |
|---|---|---|
enabled | true | Enable secrets detection |
action | redact | Action when secrets found |
entities | Private keys | Secret types to detect |
max_scan_chars | 200000 | Max characters to scan (0 = unlimited) |
log_detected_types | true | Log detected types (never logs content) |
redact_placeholder | <SECRET_REDACTED_{N}> | Placeholder format for redaction |
Actions
| Action | Description |
|---|---|
redact | Replace secrets with placeholders, restore in response (default) |
block | Return HTTP 400, request never reaches LLM |
route_local | Route to local LLM (requires route mode) |