iblai-api-agent-privacy
Configure an agent's Privacy Router via the API: enable PII detection, pick the
redact / mask / block action and the entity types to watch, set the response
returned when PII is caught, and toggle output filtering — all saved through the
single settings/ endpoint. Use when controlling how the agent handles personal
data.
Auth & conventions
- Base URL:
https://api.iblai.app
- Header:
Authorization: Api-Token $IBLAI_API_KEY on every request.
- Path vars:
{org} = $IBLAI_ORG, {username} = $IBLAI_USERNAME,
{mentor} = the agent's unique id (e.g. d17dc729-60fd-4363-81a0-f67d9318b03e).
- Settings writes go through one endpoint —
PUT
…/users/{username}/mentors/{mentor}/settings/ with
multipart/form-data — sending only the changed field(s).
- Not connected yet? Run
/iblai-api-login first to populate IBLAI_ORG,
IBLAI_USERNAME, and IBLAI_API_KEY.
Reads
- GET
https://api.iblai.app/dm/api/ai-mentor/orgs/{org}/users/{username}/mentors/{mentor}/settings/ — load the current privacy fields.
- GET
https://api.iblai.app/dm/api/ai-mentor/orgs/{org}/users/{username}/mentors/{mentor}/public-settings/ — privacy-router state for anonymous (unauthenticated) requests.
Writes
- PUT
…/mentors/{mentor}/settings/ — update privacy fields (multipart/form-data, send only changed keys):{
"enable_privacy_router": "boolean",
"privacy_action": "redact|mask|block",
"privacy_entities": "string[] (PERSON, EMAIL_ADDRESS, US_SSN, …)",
"privacy_response": "string",
"enable_privacy_output_filter": "boolean"
}
Example
Enable the Privacy Router to redact names, emails, and SSNs, with a custom
response and output filtering on (only the changed fields are sent):
curl -X PUT \
"https://api.iblai.app/dm/api/ai-mentor/orgs/$IBLAI_ORG/users/$IBLAI_USERNAME/mentors/$MENTOR/settings/" \
-H "Authorization: Api-Token $IBLAI_API_KEY" \
-F "enable_privacy_router=true" \
-F "privacy_action=redact" \
-F "privacy_entities=PERSON" \
-F "privacy_entities=EMAIL_ADDRESS" \
-F "privacy_entities=US_SSN" \
-F "privacy_response=I can't process personal information. Please remove it and try again." \
-F "enable_privacy_output_filter=true"
Notes
- A field left out of the PUT is left unchanged — never resend the whole object.
privacy_action is one of redact, mask, or block; block stops the turn
and returns privacy_response, while redact/mask rewrite the detected PII.
privacy_entities is a list of detector names (PERSON, EMAIL_ADDRESS,
US_SSN, …) — repeat the -F key per entity in multipart/form-data.
enable_privacy_output_filter applies the same detection to the agent's
output, not just the user's input.
- Use the
public-settings/ read to confirm the state applied to anonymous
(unauthenticated) requests.
1---2name: iblai-api-agent-privacy3description: Configure an ibl.ai agent's Privacy Router via the platform API — enable PII detection, choose redact/mask/block action, select entity types (PERSON, EMAIL_ADDRESS, US_SSN, …), set the privacy response, and toggle output filtering (saved through the agent settings endpoint). Use when controlling how the agent handles personal data.4---56# iblai-api-agent-privacy78Configure an agent's Privacy Router via the API: enable PII detection, pick the9redact / mask / block action and the entity types to watch, set the response10returned when PII is caught, and toggle output filtering — all saved through the11single `settings/` endpoint. Use when controlling how the agent handles personal12data.1314## Auth & conventions1516- **Base URL:** `https://api.iblai.app`17- **Header:** `Authorization: Api-Token $IBLAI_API_KEY` on every request.18- **Path vars:** `{org}` = `$IBLAI_ORG`, `{username}` = `$IBLAI_USERNAME`,19 `{mentor}` = the agent's unique id (e.g. `d17dc729-60fd-4363-81a0-f67d9318b03e`).20- **Settings writes** go through one endpoint —21 **PUT** `…/users/{username}/mentors/{mentor}/settings/` with22 `multipart/form-data` — sending **only the changed field(s)**.23- Not connected yet? Run **`/iblai-api-login`** first to populate `IBLAI_ORG`,24 `IBLAI_USERNAME`, and `IBLAI_API_KEY`.2526## Reads2728- **GET** `https://api.iblai.app/dm/api/ai-mentor/orgs/{org}/users/{username}/mentors/{mentor}/settings/` — load the current privacy fields.29- **GET** `https://api.iblai.app/dm/api/ai-mentor/orgs/{org}/users/{username}/mentors/{mentor}/public-settings/` — privacy-router state for anonymous (unauthenticated) requests.3031## Writes3233- **PUT** `…/mentors/{mentor}/settings/` — update privacy fields (`multipart/form-data`, send only changed keys):34 ```json35 {36 "enable_privacy_router": "boolean",37 "privacy_action": "redact|mask|block",38 "privacy_entities": "string[] (PERSON, EMAIL_ADDRESS, US_SSN, …)",39 "privacy_response": "string",40 "enable_privacy_output_filter": "boolean"41 }42 ```4344## Example4546Enable the Privacy Router to redact names, emails, and SSNs, with a custom47response and output filtering on (only the changed fields are sent):4849```bash50curl -X PUT \51 "https://api.iblai.app/dm/api/ai-mentor/orgs/$IBLAI_ORG/users/$IBLAI_USERNAME/mentors/$MENTOR/settings/" \52 -H "Authorization: Api-Token $IBLAI_API_KEY" \53 -F "enable_privacy_router=true" \54 -F "privacy_action=redact" \55 -F "privacy_entities=PERSON" \56 -F "privacy_entities=EMAIL_ADDRESS" \57 -F "privacy_entities=US_SSN" \58 -F "privacy_response=I can't process personal information. Please remove it and try again." \59 -F "enable_privacy_output_filter=true"60```6162## Notes6364- A field left out of the PUT is left unchanged — never resend the whole object.65- `privacy_action` is one of `redact`, `mask`, or `block`; `block` stops the turn66 and returns `privacy_response`, while `redact`/`mask` rewrite the detected PII.67- `privacy_entities` is a list of detector names (`PERSON`, `EMAIL_ADDRESS`,68 `US_SSN`, …) — repeat the `-F` key per entity in `multipart/form-data`.69- `enable_privacy_output_filter` applies the same detection to the agent's70 output, not just the user's input.71- Use the `public-settings/` read to confirm the state applied to anonymous72 (unauthenticated) requests.