Skip to main content

Parameters

See plugin common configurations for configuration options available to all plugins.

  • access_key_id

    string

    required


    Aliyun access key ID.

  • access_key_secret

    string

    required


    Aliyun secret access key. The value is encrypted before being stored.

  • region_id

    string

    required


    Aliyun region ID.

  • endpoint

    string

    required


    Aliyun endpoint.

  • check_request

    boolean

    default: true


    If true, moderate the request content.

  • check_response

    boolean

    default: false


    If true, moderate the response content.

  • request_check_service

    string

    default: llm_query_moderation


    Location where Aliyun should moderation the requests.

  • request_check_length_limit

    number

    default: 2000


    Request content length limit, in character count. If exceeded, the content will be sent in chunks.

    For instance, if the request content has 250 characters and the request_check_length_limit is set to 100, then the content will be sent in 3 requests to Aliyun.

  • response_check_service

    string

    default: llm_response_moderation


    Location where Aliyun should moderation the responses.

  • response_check_length_limit

    number

    default: 5000


    Response content length limit, in character count. If exceeded, the content will be sent in chunks.

    For instance, if the response content has 250 characters and the response_check_length_limit is set to 100, then the content will be sent in 3 requests to Aliyun.

  • risk_level_bar

    string

    default: high

    vaild vaule:

    none, low, medium, high, or max


    If the evaluated risk level is lower than the risk_level_bar, the request/response will be passed through to upstream LLM / client respectively.

  • deny_code

    integer

    default: 200

    vaild vaule:

    between 200 and 599 inclusive


    Rejection HTTP status code.

  • deny_message

    string


    Rejection message.

  • timeout

    integer

    default: 10000

    vaild vaule:

    greater than or equal to 1


    Timeout in milliseconds.

  • stream_check_mode

    string

    default: final_packet

    vaild vaule:

    realtime or final_packet


    Streaming check mode, which specifies how to handle content moderation for streaming (SSE) responses.

    realtime performs incremental, batched moderation checks while the response is streaming. If a violation is detected, the stream is immediately interrupted with a denial message.

    final_packet evaluates the complete response after the LLM finishes and appends the calculated risk level to the data field of the SSE messages.

  • stream_check_cache_size

    integer

    default: 128

    vaild vaule:

    greater than or equal to 1


    Max characters per moderation batch in realtime mode.

  • stream_check_interval

    number

    default: 3

    vaild vaule:

    greater than or equal to 0.1


    Seconds between batch checks in realtime mode.

  • keepalive

    boolean

    default: true


    If true, enable HTTP keepalive to Aliyun.

  • keepalive_pool

    integer

    default: 30

    vaild vaule:

    greater than or equal to 1


    Maximum number of connections in the keepalive pool.

  • keepalive_timeout

    integer

    default: 60000

    vaild vaule:

    greater than or equal to 1000


    Keepalive timeout in milliseconds.

  • ssl_verify

    boolean

    default: true


    If true, enable SSL verification.

  • fail_mode

    string

    default: skip

    vaild vaule:

    skip, warn, or error


    Behavior when the plugin is bound to a Consumer and receives a request whose format it does not recognize, such as a non-AI request. With skip, the unrecognized request is passed through unchecked. With warn, the request is passed through and a warning is logged. With error, the request is rejected with HTTP 400.

    Available in API7 Enterprise from version 3.9.14.

  • request_check_mode

    string

    default: last

    vaild vaule:

    last or all


    Which turn messages in the request to moderate for roles selected by request_check_roles. With last, only the latest consecutive block of selected user and tool messages is moderated. With all, every selected user and tool message is moderated. The system role is always checked on every request when selected.

    Available in API7 Enterprise 3.9.16+ or 3.10.3+.

  • request_check_roles

    array[string]

    default: ["user"]

    vaild vaule:

    user, tool, or system


    Message roles to moderate on the request side. user and tool follow request_check_mode; system is checked on every request because system content can be affected by malicious tool-call arguments.

    Tool-result moderation applies to OpenAI-compatible formats where tool output is represented as a distinct tool role or item.

    Available in API7 Enterprise 3.9.16+ or 3.10.3+.