diff --git a/litellm/proxy/guardrails/guardrail_initializers.py b/litellm/proxy/guardrails/guardrail_initializers.py index efc09bb1669..56bbd8ff103 100644 --- a/litellm/proxy/guardrails/guardrail_initializers.py +++ b/litellm/proxy/guardrails/guardrail_initializers.py @@ -156,8 +156,8 @@ def initialize_presidio(litellm_params: LitellmParams, guardrail: Guardrail) -> presidio_anonymizer_api_base=litellm_params.presidio_anonymizer_api_base, presidio_language=litellm_params.presidio_language, presidio_entities_deny_list=litellm_params.presidio_entities_deny_list, - presidio_stable_tokens=getattr(litellm_params, "presidio_stable_tokens", None), - presidio_token_salt=getattr(litellm_params, "presidio_token_salt", None), + presidio_stable_tokens=litellm_params.presidio_stable_tokens, + presidio_token_salt=litellm_params.presidio_token_salt, apply_to_output=False, timeout=litellm_params.timeout, _callback_role="scan", diff --git a/litellm/types/guardrails.py b/litellm/types/guardrails.py index 46026c12d24..d2ec10b0ab5 100644 --- a/litellm/types/guardrails.py +++ b/litellm/types/guardrails.py @@ -494,6 +494,20 @@ class PresidioConfigModel(PresidioPresidioConfigModelUserInterface): default=None, description="Path to a JSON file containing ad-hoc recognizers for Presidio", ) + presidio_stable_tokens: bool | None = Field( + default=None, + description=( + "Derive PII placeholders from the value instead of its order in the request, " + "so the same value maps to the same token across turns. Requires presidio_token_salt." + ), + ) + presidio_token_salt: str | None = Field( + default=None, + description=( + "os.environ/ reference holding the HMAC key behind stable tokens. " + "A literal is refused: guardrail params are logged in full at debug level." + ), + ) presidio_analyze_chunk_size_bytes: int | None = Field( default=None, description=(