PII Redaction API Specification & Integration Reference
Public API Page

POST PII Redaction API

/api/v1/ai/pii-redaction

Automatically detect and securely scrub Personally Identifiable Information (PII) from text to maintain GDPR, HIPAA, and general data compliance.

Base Billing 1 Credit
Target Latency < 150ms (p50)
Client Timeout 5.0s (recommended)
SLA Guarantee 99.9% Uptime
JSON Contract Deterministic v1

Architecture Role & AI Definition

PII Redaction API provides low-latency, deterministic REST execution for production engineering workflows. It processes structured payloads with strict schema validation, returns uniform JSON envelopes, and is secured via SHA-256 API key authentication with atomic credit pre-authorization locks.

Production Reliability Guidelines

1. Strict Timeout Windows

Configure a hard client timeout of 5 to 8 seconds. If network latency spikes, cancel connection to avoid holding open sockets in worker pools.

2. Exponential Backoff with Jitter

Upon receiving 429 Rate Limit or transient 5xx, pause with exponential backoff:
wait = min(max_backoff, base * 2^attempt + jitter).

3. Atomic Pre-Auth Locks

RSFlowHub acquires an atomic lock verifying base credits before model invocation. If validation fails, zero credits are deducted.

Request Body Parameters

Field Type Required Description
text string Required The raw text to be sanitized (Max: 10,000 characters).
redact_types array of strings Optional Specific types to redact. Allowed: `names`, `emails`, `phone_numbers`, `credit_cards`, `ssn`, `addresses`, `passwords`, `ip_addresses`. If empty, redacts all high-risk PII.
redaction_style string Optional How to mask the data. `placeholder` (e.g., [EMAIL]), `asterisk` (e.g., j***@gmail.com), or `scramble`. Default is `placeholder`.
return_entities boolean Optional Optional. If true, returns an analytics array summarizing the types of PII detected and redacted.
model string Optional Optional AI model to use.

Example Request (Selective Redaction)

In this example, we ask the API to specifically target and asterisk-out credit cards and emails, while safely ignoring names or other data.

JSON Request
{
  "text": "Hey, it's Jane Smith. Please update my billing. My new card is 4111-2222-3333-4444 and my receipt email is jane.smith99@example.com. Thanks!",
  "redact_types": ["credit_cards", "emails"],
  "redaction_style": "asterisk",
  "return_entities": true
}
curl-trigger.sh cURL
curl -X POST https://rsflowhub.com/api/v1/ai/pii-redaction \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "text": "Hey, it'\''s Jane Smith. Please update my billing. My new card is 4111-2222-3333-4444 and my receipt email is jane.smith99@example.com. Thanks!",
    "redact_types": ["credit_cards", "emails"],
    "redaction_style": "asterisk",
    "return_entities": true
  }'

Example Response

The API safely sanitizes the requested fields. Notice how "Jane Smith" was intentionally ignored because `names` was not included in the `redact_types` array. The `entities_redacted` array securely provides analytics without exposing the raw strings.

response.json JSON Response
200 OK 118ms
{
  "success": true,
  "data": {
    "result": {
      "redacted_text": "Hey, it's Jane Smith. Please update my billing. My new card is ****-****-****-4444 and my receipt email is j***@example.com. Thanks!",
      "entities_redacted": [
        {
          "type": "CREDIT_CARD",
          "count": 1
        },
        {
          "type": "EMAIL",
          "count": 1
        }
      ]
    }
  },
  "meta": {
    "credits_used": 2,
    "credits_remaining": 986
  }
}

API Request Example

Use the cURL snippet below to test the endpoint.

curl-trigger.sh cURL
curl -X POST 'https://rsflowhub.com/api/v1/ai/pii-redaction' \
  -H 'Authorization: Bearer YOUR_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{
    "text": "My number is 555-1234",
    "redaction_style": "placeholder"
}'

Common Failure Modes & Troubleshooting Matrix

HTTP Code Error Code Root Cause Recommended Remediation
400 bad_request Malformed JSON syntax or missing required top-level parameters. Validate JSON payload with Content-Type: application/json and ensure all required fields are present.
401 unauthorized Missing, revoked, or incorrectly formatted x-api-key header. Verify API key exists in Dashboard → API Keys and pass in x-api-key or Authorization: Bearer.
402 insufficient_credits Account credit balance is lower than the base required credits (1 credits). Top up credits in billing settings or enable auto-recharge to prevent pipeline interruption.
422 validation_error Input failed parameter constraints (e.g., character length exceeded or invalid array types). Review parameters table above and adjust payload length, types, or structure accordingly.
429 rate_limit_exceeded Concurrency limit (60 requests/minute default) reached for this endpoint key. Back off and retry using the timestamp in Retry-After response header, or batch requests.

Technical Q&A (FAQ)

We recommend setting a client timeout of 5 to 8 seconds. While average latency is under 150ms, large input payloads or complex reasoning models may require additional processing time.

RSFlowHub uses an atomic pre-flight check. Before processing, the gateway validates that your wallet has at least 1 base credits. If the request fails validation (422) or is malformed (400), no credits are charged.

When a 429 is received, your application should respect the 'Retry-After' header and use an exponential backoff retry policy with randomized jitter to prevent thundering herd problems.

Every successful response returns { "success": true, "data": { ... }, "meta": { "credits_used": int, "credits_remaining": int } }.

Ready to build?

Create your free account and make your first API call in minutes.