Sessions
Sessions remember token mappings so that repeated PII values are processed faster. This is especially useful in multi-turn conversations where the same names, emails, or IDs appear across messages.
How sessions work
Each request can include an X-NoPII-Session-Id header. If omitted, NoPII generates a UUID and returns it in the response header.
| Aspect | Detail |
|---|---|
| Header | X-NoPII-Session-Id |
| Auto-generated | Yes - if not provided, a UUID is generated and returned in the response |
| Scope | Per-session token/plaintext cache |
| TTL | 1 hour |
Using sessions
Capture the session ID from the first response and include it in subsequent requests:
python
import openai
client = openai.OpenAI(base_url="https://api.nopii.co")
# First request - NoPII generates a session ID
response = client.chat.completions.create(
model="gpt-4o",
messages=[{"role": "user", "content": "Review the file for John Smith"}],
extra_headers={} # no session ID needed
)
# Capture session ID from response headers
session_id = response.headers.get("x-nopii-session-id")
# Subsequent requests - reuse the session ID
response = client.chat.completions.create(
model="gpt-4o",
messages=[
{"role": "user", "content": "Review the file for John Smith"},
{"role": "assistant", "content": response.choices[0].message.content},
{"role": "user", "content": "What's John Smith's address?"},
],
extra_headers={"X-NoPII-Session-Id": session_id}
)Best practices
- 1.Reuse session IDs across conversation turns. This avoids redundant processing for PII that was already tokenized.
- 2.Use one session per conversation. Don't share sessions across unrelated conversations - this keeps caches focused and memory-efficient.
- 3.Let sessions expire naturally. The 1-hour TTL is designed to cover typical conversation durations. Don't try to extend sessions indefinitely.
Sessions and GDPR
When tokens are purged via the GDPR token purge API, NoPII automatically removes those tokens from all active sessions. This prevents purged PII from being served from the session cache after deletion.
Related
- Streaming - Sessions also apply to streaming requests
- API Reference - Full header and endpoint documentation