Anthropic Claude integration
Mask personal data before it reaches Claude
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results, including the system prompt and tool_use input
- Streaming Messages API responses, with masked values restored in streamed text and tool input
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
Claude is often chosen for long documents: contracts, case files, support histories. Those are exactly the inputs most likely to carry personal data, and a single request can contain thousands of names, addresses, and account numbers.
With Maskflare in front of the Messages API, every request is scanned before it leaves. Sensitive values become mf_mask_ tokens, Claude works on the masked text, and with response restoration on, the answer comes back with the real values in place.
Set up Anthropic Claude with Maskflare
Requests go to /v1/anthropic on your Maskflare gateway instead of the provider.
from anthropic import Anthropic
client = Anthropic(
base_url="https://YOUR_GATEWAY_HOST/v1/anthropic",
api_key="mf_live_...", # a Maskflare key
)
message = client.messages.create(
model="claude-sonnet-4-5",
max_tokens=1024,
messages=[{"role": "user", "content": "Summarize this case note for patient Jan de Vries"}],
)What gets masked
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results, including the system prompt and tool_use input
- Streaming Messages API responses, with masked values restored in streamed text and tool input
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
Good to know
- A rule set to block stops the request before it reaches the provider and returns HTTP 403 with the matching rule keys, never the values.
- If a rule blocks content mid-stream, the stream ends with an Anthropic-format error event, so the SDK reports it like any other API error.
- Store the provider key once in the Maskflare console, or keep sending it per request in pass-through mode.
- No code change option: the Maskflare forward proxy inspects traffic to api.anthropic.com with the same rules.
Frequently asked questions
Does Maskflare support Claude streaming?
Yes. Streamed Messages API responses are masked, and with response restoration on for the API key, tokens in streamed text and tool input are swapped back as the events arrive.
Does the system prompt get scanned?
Yes. The whole request body is scanned, so the system prompt, every message, and tool results are covered, not just the last user turn.
Can Claude still reason about masked values?
Yes. Each value becomes a stable token, so the same customer is the same token throughout the conversation and Claude can refer to them consistently.
Which Anthropic key do I use?
Send a Maskflare key in place of the Anthropic key. Your Anthropic key is stored once in the console, or passed per request in pass-through mode.
Other providers
See it on your own data
Book a 30-minute demo.
Bring your hardest prompts.
We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.