Parameters
See plugin common configurations for configuration options available to all plugins.
access_key_id
Aliyun access key ID.
access_key_secret
Aliyun secret access key. The value is encrypted before being stored.
region_id
Aliyun region ID.
endpoint
Aliyun endpoint.
check_request
If true, moderate the request content.
check_response
If true, moderate non-streaming and streaming LLM response content according to
stream_check_mode.request_check_service
Location where Aliyun should moderation the requests.
request_check_length_limit
Request content length limit, in character count. If exceeded, the content will be sent in chunks.
For instance, if the request content has 250 characters and the
request_check_length_limitis set to100, then the content will be sent in 3 requests to Aliyun.response_check_service
Location where Aliyun should moderation the responses.
response_check_length_limit
Response content length limit, in character count. If exceeded, the content will be sent in chunks.
For instance, if the response content has 250 characters and the
response_check_length_limitis set to100, then the content will be sent in 3 requests to Aliyun.risk_level_bar
vaild vaule:
none,low,medium,high, ormaxIf the evaluated risk level is lower than the
risk_level_bar, the request/response will be passed through to upstream LLM / client respectively.deny_code
vaild vaule:
between 200 and 599 inclusive
HTTP status returned when content is denied before response headers are sent. The default
200returns a provider-compatible refusal; set a4xxvalue to expose moderation as an HTTP error. After streaming starts, the status cannot be changed.deny_message
Message returned when request or response content is denied. If unset, the plugin uses Aliyun's moderation advice.
timeout
vaild vaule:
greater than or equal to 1
Timeout in milliseconds.
stream_check_mode
vaild vaule:
realtimeorfinal_packetStreaming check mode, which specifies how to handle content moderation for streaming (SSE) responses.
realtimeperforms incremental, batched moderation checks while the response is streaming. If a violation is detected, the stream is immediately interrupted with a denial message.final_packetevaluates the complete response after the LLM finishes and appends the calculated risk level to the data field of the SSE messages.stream_check_cache_size
vaild vaule:
greater than or equal to 1
Max characters per moderation batch in
realtimemode.stream_check_interval
vaild vaule:
greater than or equal to 0.1
Seconds between batch checks in
realtimemode.keepalive
If true, enable HTTP keepalive to Aliyun.
keepalive_pool
vaild vaule:
greater than or equal to 1
Maximum number of connections in the keepalive pool.
keepalive_timeout
vaild vaule:
greater than or equal to 1000
Keepalive timeout in milliseconds.
ssl_verify
If true, enable SSL verification.
fail_mode
vaild vaule:
skip,warn, orerrorBehavior when the plugin receives a request it cannot moderate, such as non-AI traffic on a Consumer binding or a request that did not pass through AI Proxy. With
skip, the request passes unchecked. Withwarn, it passes unchecked and a warning is logged. Witherror, the plugin rejects it with the applicable HTTP 400 or 500 response. None of these outcomes means moderation succeeded.Introduced in API7 Enterprise 3.9.14 and APISIX 3.18.0.
request_check_mode
vaild vaule:
lastorallWhich turn messages in the request to moderate for roles selected by
request_check_roles. Withlast, only the latest consecutive block of selecteduserandtoolmessages is moderated. Withall, every selecteduserandtoolmessage is moderated. Thesystemrole is always checked on every request when selected.Introduced in API7 Enterprise 3.9.16 and 3.10.3, and APISIX 3.18.0.
request_check_roles
vaild vaule:
user,tool, orsystemMessage roles to moderate on the request side.
userandtoolfollowrequest_check_mode;systemis checked on every request because system content can be affected by malicious tool-call arguments.In APISIX, selecting
systemalso coversdevelopermessages, which is the role OpenAI uses in place ofsystemon newer models and on the Responses API. There is no separatedeveloperentry. API7 Enterprise 3.9.18 and 3.10.5 use the same behavior; earlier API7 Enterprise versions did not moderatedevelopermessages.Tool-result moderation applies to OpenAI-compatible formats where tool output is represented as a distinct
toolrole or item.Introduced in API7 Enterprise 3.9.16 and 3.10.3, and APISIX 3.18.0.