xAI Grok integration
Mask personal data before it reaches xAI Grok
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results
- Streaming responses
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
The xAI API is OpenAI-compatible, which makes Grok easy to add to an existing application and just as easy to send it the same customer data the rest of the stack handles.
Routing Grok traffic through Maskflare applies the same rules you use for every other provider: sensitive values are masked before the request leaves, and restored in the answer when restoration is on.
Set up xAI Grok with Maskflare
Requests go to /v1/xai on your Maskflare gateway instead of the provider.
from openai import OpenAI
client = OpenAI(
base_url="https://YOUR_GATEWAY_HOST/v1/xai",
api_key="mf_live_...", # a Maskflare key
)
reply = client.chat.completions.create(
model="grok-4",
messages=[{"role": "user", "content": "Classify this ticket from j.smith@example.com"}],
)What gets masked
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results
- Streaming responses
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
Good to know
- A rule set to block stops the request before it reaches the provider and returns HTTP 403 with the matching rule keys, never the values.
- Store the provider key once in the Maskflare console, or keep sending it per request in pass-through mode.
- No code change option: the Maskflare forward proxy inspects traffic to api.x.ai with the same rules.
Frequently asked questions
Do I need a separate SDK for Grok?
No. Use the OpenAI SDK or any OpenAI-compatible client with the base URL set to your gateway's /v1/xai route.
Do Grok requests share rules with other providers?
Yes. Rules are set per environment, so the same API key applies the same masking to xAI, OpenAI, Anthropic, and every other provider.
What happens when a rule blocks a request?
The request is refused before it reaches xAI, with HTTP 403 and the keys of the rules that matched.
Other providers
See it on your own data
Book a 30-minute demo.
Bring your hardest prompts.
We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.