Google Gemini integration
Mask personal data before it reaches Google Gemini
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results, including system instructions and function-call arguments
- streamGenerateContent responses, with masked values restored in streamed text and function calls
- Embeddings inputs, masked deterministically
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
Gemini's long context makes it easy to send a whole mailbox export or a full customer file in one call. That convenience is also the exposure: everything in the context window leaves your environment.
Maskflare masks it first. Requests to the Gemini API go through your Maskflare gateway, sensitive values are replaced with tokens, and with response restoration on, Gemini's answer comes back with the real values.
Set up Google Gemini with Maskflare
Requests go to /v1/gemini on your Maskflare gateway instead of the provider.
from google import genai
from google.genai import types
client = genai.Client(
api_key="mf_live_...", # a Maskflare key
http_options=types.HttpOptions(base_url="https://YOUR_GATEWAY_HOST/v1/gemini"),
)
response = client.models.generate_content(
model="gemini-2.5-flash",
contents="Draft a follow-up to maria.rossi@example.it",
)What gets masked
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results, including system instructions and function-call arguments
- streamGenerateContent responses, with masked values restored in streamed text and function calls
- Embeddings inputs, masked deterministically
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
Good to know
- A rule set to block stops the request before it reaches the provider and returns HTTP 403 with the matching rule keys, never the values.
- Store the provider key once in the Maskflare console, or keep sending it per request in pass-through mode.
- No code change option: the Maskflare forward proxy inspects traffic to generativelanguage.googleapis.com with the same rules.
Frequently asked questions
Does this work with the Gemini API or Vertex AI?
The gateway's Gemini route forwards to the Gemini API at generativelanguage.googleapis.com. Vertex AI endpoints are not a supported route.
Is Gemini streaming supported?
Yes. streamGenerateContent responses are masked, and with response restoration on, tokens in streamed text and function calls are restored as they arrive.
How is the Maskflare key sent?
In the same place the SDK sends a Gemini key: the x-goog-api-key header or the key query parameter. Maskflare recognises its own keys by their mf_ prefix.
Are images masked?
No. Images aren't read as text, so text inside an image, such as a photographed document, isn't masked. Masking applies to the text in the request.
Other providers
See it on your own data
Book a 30-minute demo.
Bring your hardest prompts.
We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.