Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
token-proxy — A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing sensitive data outbound and restoring it inbound. Built with FastAPI + httpx. | Kitploit
Tools/GitHubGitHub/zolderio/token-proxy
Defensive ToolsEncryption/Decryption ToolsData ExfiltrationCloud SecurityPrivacyThreat IntelligenceAPI SecurityAI SecurityLog Analysis
GitHubzolderio/token-proxy

token-proxy

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing sensitive data outbound and restoring it inbound. Built with FastAPI + httpx.

281245 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

llm-token-proxy

A transparent PII redaction proxy for LLM API traffic. Sits between your application and the LLM provider, pseudonymizing sensitive data on the way out and restoring it on the way back.

Your LLM never sees real names, emails, IPs, or domains — it works entirely with structured pseudonyms like [email protected]. Your application gets back the original values, transparently.

Why

When using LLMs for security operations, incident response, or any task involving real customer data, you risk sending PII to third-party APIs. This proxy solves that by:

  • Replacing real PII with deterministic, structured pseudonyms before it reaches the LLM
  • Restoring original values in the response before it reaches your application
  • Maintaining consistency within a session (same input always maps to the same pseudonym)
  • Working transparently — no code changes needed in your application

Quickstart

# 1. Create your config
cp config.json.example config.json
# Edit config.json with your internal domains, known entities, etc.

# 2. Run with Docker
docker build -t llm-token-proxy .
docker run -p 8090:8080 -v ./config.json:/app/config.json llm-token-proxy

# 3. Point your application at the proxy
export ANTHROPIC_BASE_URL=http://localhost:8090/session/my-session/

That's it. Your Anthropic API calls now go through the proxy with PII redacted.

How It Works

Token Proxy Typical Flow

Typical flow: Application → Token Proxy (PII redaction) → LLM API (pseudonyms only) → Token Proxy (restore originals) → Application

Detection Pipeline (3 passes)

  1. Regex — emails, IP addresses, domains, and config-driven patterns (known persons, orgs, hostnames)
  2. NER — spaCy named entity recognition catches person and organization names that regex misses
  3. Username extraction — bare email local parts (e.g., admin from [email protected])

Pseudonym Format

Entity TypeInternal ExampleExternal Example
Email[email protected][email protected]
Domaindomain-internal-001.comdomain-external-001.net
IP10.99.99.1 (RFC1918)ASN-aware donor IP (see below)
Personperson_internal_001person_external_001
Orgorg_internal_001org_external_001
Hostnamehost_001host_001

Pseudonyms are deterministic within a session — the same real value always maps to the same pseudonym.

Context-preserving IP pseudonymization

When an LLM is analyzing security logs, the hosting provider and geolocation of an IP address matters — a login from a Hetzner IP in Germany tells a different story than one from a residential ISP in the US. Naive replacement with documentation-range IPs (e.g., 198.51.100.x) destroys this context.

With the optional MaxMind GeoLite2-ASN database, the proxy replaces real IPs with a different IP from the same ASN and subnet. The LLM sees a real-looking IP that resolves to the same hosting provider and approximate geography — but it's not the actual address.

  • A Hetzner IP gets replaced with a different Hetzner IP from the same prefix
  • A Cloudflare IP stays a Cloudflare IP
  • Internal/RFC1918 IPs always map to 10.99.99.x (no ASN context to preserve)
  • Without the GeoIP database, external IPs fall back to 198.51.100.x (documentation range)

The donor IP is chosen deterministically via HMAC with a per-session salt, so the same real IP always maps to the same donor within a session, but different sessions produce different mappings.

Configuration

The proxy ships with an empty config.json — no built-in word lists or domain-specific assumptions. The included config.json.example is tuned for security operations with Microsoft Sentinel and Entra ID (8,000+ KQL table/column names, Graph API permission terms, security reference domains). If that matches your use case, copy what you need from it. If you're using the proxy for a different domain (healthcare, legal, finance, etc.), start from the empty config and build your own lists.

config.json

{
  "internal_domains": ["yourcompany.com"],
  "partner_domains": ["partnercorp.com"],
  "internal_ip_ranges": ["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"],
  "known_persons": ["John Smith"],
  "known_orgs": ["YourCompany"],
  "known_hostnames": ["DC01", "FS01"],
  "ner_enabled": true,
  "ner_skiplist": [],
  "redaction_enabled": true
}
  • internal_domains — domains classified as "internal" (get _internal_ pseudonyms)
  • partner_domains — domains classified as "partner"
  • internal_ip_ranges — CIDR ranges for internal IP classification
  • known_persons/orgs/hostnames — regex-matched entities (guaranteed detection)
  • ner_enabled — toggle spaCy NER (requires spacy + en_core_web_sm)
  • ner_skiplist — terms the NER model should ignore (reduces false positives)
  • redaction_enabled — master toggle; when false, proxy becomes pure pass-through
  • pseudonymize_domains — when false, domains pass through unmodified (emails, IPs, names are still redacted). Useful when domain names carry important context for the LLM (e.g., distinguishing outlook.com from protonmail.com) and are not considered sensitive.

Environment Variables

VariableDefaultPurpose
ANTHROPIC_API_BASEhttps://api.anthropic.comUpstream Anthropic API URL
TOKEN_PROXY_CONFIG_PATH/app/config.jsonPath to config file
LOG_LEVELinfoLogging level
GEOIP_ASN_DB_PATH/app/data/GeoLite2-ASN.mmdbMaxMind GeoLite2-ASN database (optional)

Runtime Configuration API

Manage whitelists and toggle redaction without restarting:

# View all whitelists
curl http://localhost:8090/token-proxy/config/whitelist

# Add terms to NER skiplist (reduces false positives)
curl -X POST http://localhost:8090/token-proxy/config/whitelist \
  -H "Content-Type: application/json" \
  -d '{"category": "ner_skiplist", "values": ["EvoSTS", "Hetzner"]}'

# Add domains to allowlist (never pseudonymize these)
curl -X POST http://localhost:8090/token-proxy/config/whitelist \
  -H "Content-Type: application/json" \
  -d '{"category": "domain_allowlist", "values": ["github.com"]}'

# Disable redaction (pass-through mode)
curl -X POST http://localhost:8090/token-proxy/config/status \
  -H "Content-Type: application/json" \
  -d '{"redaction_enabled": false}'

Whitelist categories: ner_skiplist, domain_allowlist, known_persons, known_orgs, known_hostnames

Audit & Inspection API

Inspect what the proxy is doing in real-time:

# List active sessions
curl http://localhost:8090/token-proxy/sessions

# View pseudonym mappings for a session
curl http://localhost:8090/token-proxy/sessions/{session_id}/mappings

# View redaction activity log
curl http://localhost:8090/token-proxy/sessions/{session_id}/log

# Search mappings
curl http://localhost:8090/token-proxy/sessions/{session_id}/search?q=admin

# View captured payloads (what the LLM actually saw)
curl http://localhost:8090/token-proxy/sessions/{session_id}/payloads

# Token usage for a session (input/output tokens across all requests)
curl http://localhost:8090/token-proxy/sessions/{session_id}/usage

# Global statistics (includes total_tokens across all sessions)
curl http://localhost:8090/token-proxy/stats

Token Usage Tracking

Download Tool