API Reference

NoPII exposes drop-in proxy endpoints for OpenAI and Anthropic. The request and response formats are identical to the upstream providers - NoPII only modifies message content to tokenize and detokenize PII.

Base URL: https://api.nopii.co

Providers: OpenAI, Anthropic, xAI, DeepSeek, Mistral, Gemini, Groq, Together, Fireworks. All OpenAI-compatible providers use /chat/completions. See Supported Providers for details.

Authentication

NoPII uses drop-in authentication - it identifies your account by the LLM API key already present in the request. No NoPII-specific API keys or headers are needed.

ProviderHeaderFormat
OpenAIAuthorizationBearer sk-...
Anthropicx-api-keysk-ant-...

Your API key must be registered in the admin console before use. The key is passed through to the LLM provider - NoPII never stores it.

OpenAI Chat Completions

POST /chat/completions

Proxies to the OpenAI Chat Completions API with automatic PII tokenization.

Headers

HeaderRequiredDescription
AuthorizationYesBearer token - your OpenAI API key
Content-TypeYesapplication/json
X-NoPII-Session-IdNoSession ID for token cache continuity
traceparentNoW3C Trace Context header for distributed tracing

Request body

Standard OpenAI Chat Completions request. The messages[].content field is sanitized before forwarding. Supports "stream": true.

Example

bash
curl -X POST https://api.nopii.co/chat/completions \
  -H "Authorization: Bearer sk-your-openai-key" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-4o",
    "messages": [
      {"role": "user", "content": "Summarize the case for John Smith, SSN 123-45-6789"}
    ]
  }'

Response

Standard OpenAI response format. Assistant message content is detokenized (tokens replaced with original PII). Includes X-NoPII-Session-Id response header.

Anthropic Messages

POST /v1/messages

Proxies to the Anthropic Messages API with automatic PII tokenization.

Headers

HeaderRequiredDescription
x-api-keyYesYour Anthropic API key
anthropic-versionNoDefaults to 2023-06-01 - passed through
Content-TypeYesapplication/json
X-NoPII-Session-IdNoSession ID for token cache continuity
traceparentNoW3C Trace Context header for distributed tracing

Request body

Standard Anthropic Messages request. Both the system field (string or content block array) and messages[].content are sanitized. Supports "stream": true.

Example

bash
curl -X POST https://api.nopii.co/v1/messages \
  -H "x-api-key: sk-ant-your-key" \
  -H "anthropic-version: 2023-06-01" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "claude-sonnet-4-20250514",
    "max_tokens": 1024,
    "messages": [
      {"role": "user", "content": "Draft a letter for Jane Doe at 123 Main St"}
    ]
  }'

Response

Standard Anthropic response format. Text content blocks are detokenized. Includes X-NoPII-Session-Id response header.

Health checks

GET /healthz

Liveness probe. Returns {"status": "ok"}

GET /readyz

Readiness probe. Returns {"status": "ready"}

Debug mode

Debug mode can be enabled per tenant in the admin console. When enabled, NoPII logs the full sanitized request body and raw LLM response body for each proxy call. These are visible in the request log detail view.

Debug mode is intended for troubleshooting only. Disable it in production to avoid logging overhead.

Related