OpenAI integration
Mask personal data before it reaches the OpenAI API
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results, across Chat Completions, the Responses API, and any other OpenAI endpoint
- Streaming responses, with masked values restored in streamed text and tool-call arguments
- Embeddings inputs, masked deterministically so the same value always embeds the same way
- Batch input files uploaded through the Files API, masked line by line
Most OpenAI integrations send whatever the user typed, plus whatever the application retrieved, straight to the API. Support tickets, CRM records, and documents pulled in by retrieval carry names, emails, IBANs, and API keys that were never meant to leave.
Maskflare sits on the request path. Change the SDK's base URL and authenticate with a Maskflare key: each request is scanned with your rules, sensitive values are replaced with mf_mask_ tokens before OpenAI sees them, and with response restoration on for the key, the real values are put back in the answer.
Set up OpenAI with Maskflare
Requests go to /v1/openai on your Maskflare gateway instead of the provider.
from openai import OpenAI
client = OpenAI(
base_url="https://YOUR_GATEWAY_HOST/v1/openai",
api_key="mf_live_...", # a Maskflare key
)
reply = client.chat.completions.create(
model="gpt-4o",
messages=[{"role": "user", "content": "Reply to ada@example.com about invoice 4471"}],
)What gets masked
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results, across Chat Completions, the Responses API, and any other OpenAI endpoint
- Streaming responses, with masked values restored in streamed text and tool-call arguments
- Embeddings inputs, masked deterministically so the same value always embeds the same way
- Batch input files uploaded through the Files API, masked line by line
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
Good to know
- A rule set to block stops the request before it reaches the provider and returns HTTP 403 with the matching rule keys, never the values.
- Store the provider key once in the Maskflare console, or keep sending it per request in pass-through mode.
- Large batch uploads through the multi-part Uploads API are refused, because they can't be masked line by line; upload batch files through the Files API instead.
- No code change option: the Maskflare forward proxy inspects traffic to api.openai.com with the same rules.
Frequently asked questions
Does Maskflare work with the OpenAI Responses API?
Yes. The gateway masks every endpoint under /v1/openai, including the Responses API, and can restore values in its streamed and non-streamed output.
Will masking break function calling?
No. Tool and function-call arguments are scanned like any other text, and with restoration on, arguments the model returns are restored before your code runs the tool.
What about embeddings and RAG?
Embeddings inputs are masked deterministically: the same value always becomes the same token, so similarity search still works on masked text without the real value ever reaching OpenAI.
Does it cover employees using ChatGPT?
Yes, through the forward proxy with browser data loss prevention turned on. Prompts typed into ChatGPT on the web are masked with the same rules as API traffic.
Other providers
See it on your own data
Book a 30-minute demo.
Bring your hardest prompts.
We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.