> ## Documentation Index
> Fetch the complete documentation index at: https://docs.datris.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Suggest field protection from field names and types

> Asks the configured CodeGen model which source fields should carry `protect` (hmac, mask with an optional preserve, redact, drop, or none), with a one-line reason per field. Only field names and types are sent to the model; no row value leaves the server. Stateless: nothing is saved. Every suggestion passes the pipeline validator, so confirm the ones you want and save them as `protect` on the source fields. Pass either `pipeline` (its stored source schema is used) or `fields`. At most 150 fields per call (more returns 400 before the model is called); with `pipeline`, keyFields columns are only suggested hmac or none and non-string destination fields only drop or none. Needs the same capability as reading a pipeline.



## OpenAPI

````yaml /openapi.yaml post /api/v1/pipeline/protect/suggest
openapi: 3.0.3
info:
  title: Datris API
  description: >
    REST API for the Datris AI Data Platform. Ingest, validate, transform,
    store, and retrieve data.


    For AI agent integration, use the [MCP
    Server](https://docs.datris.ai/mcp-server) instead.
  version: 1.28.0
  contact:
    name: Datris
    url: https://datris.ai
  license:
    name: Apache 2.0
servers:
  - url: http://localhost:8080
    description: Local development
security:
  - ApiKeyAuth: []
paths:
  /api/v1/pipeline/protect/suggest:
    post:
      tags:
        - Pipelines
      summary: Suggest field protection from field names and types
      description: >-
        Asks the configured CodeGen model which source fields should carry
        `protect` (hmac, mask with an optional preserve, redact, drop, or none),
        with a one-line reason per field. Only field names and types are sent to
        the model; no row value leaves the server. Stateless: nothing is saved.
        Every suggestion passes the pipeline validator, so confirm the ones you
        want and save them as `protect` on the source fields. Pass either
        `pipeline` (its stored source schema is used) or `fields`. At most 150
        fields per call (more returns 400 before the model is called); with
        `pipeline`, keyFields columns are only suggested hmac or none and
        non-string destination fields only drop or none. Needs the same
        capability as reading a pipeline.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              oneOf:
                - type: object
                  required:
                    - pipeline
                  properties:
                    pipeline:
                      type: string
                      description: Existing pipeline name
                - type: object
                  required:
                    - fields
                  properties:
                    fields:
                      type: array
                      items:
                        type: object
                        required:
                          - name
                          - type
                        properties:
                          name:
                            type: string
                          type:
                            type: string
                          protect:
                            $ref: '#/components/schemas/FieldProtectionPolicy'
      responses:
        '200':
          description: One entry per input field, in input order
          content:
            application/json:
              schema:
                type: object
                properties:
                  model:
                    type: string
                    description: The model that produced the suggestions
                  fields:
                    type: array
                    items:
                      type: object
                      properties:
                        name:
                          type: string
                        type:
                          type: string
                        current:
                          nullable: true
                          description: The field's existing `protect`, or null
                          allOf:
                            - $ref: '#/components/schemas/FieldProtectionPolicy'
                        suggested:
                          type: object
                          nullable: true
                          description: Null when no protection is suggested
                          properties:
                            method:
                              type: string
                              enum:
                                - hmac
                                - mask
                                - redact
                                - drop
                            preserve:
                              type: string
                              nullable: true
                              enum:
                                - last4
                                - domain
                                - year
                                - null
                        reason:
                          type: string
                          nullable: true
        '400':
          description: >-
            Neither pipeline nor fields given, pipeline not found, AI not
            configured, or an unusable model answer
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
        '500':
          description: Error
components:
  schemas:
    FieldProtectionPolicy:
      type: object
      description: >-
        Per-field protection applied after the preprocessor and before data
        quality, transformation, Live Read and every destination. `hmac`,
        `mask`, `redact` and `encrypt` require a `string` field on the source
        and on the destination schema; `drop` takes any type but cannot remove a
        `keyFields` column, and a `keyFields` column may only use `hmac`.
        Reserved methods (`fpe`, `tokenize`) are rejected as not yet supported.
        Empty values stay empty.
      required:
        - method
      properties:
        method:
          type: string
          enum:
            - hmac
            - mask
            - redact
            - drop
            - encrypt
          description: >-
            `hmac`: keyed HMAC-SHA256 pseudonym (lowercase hex) under the
            per-environment key; equal inputs give equal outputs. `mask`:
            replace characters with `*` (see `preserve`). `redact`: the value
            becomes `[REDACTED]`. `drop`: remove the column (or top-level JSON
            key) entirely. `encrypt`: AES-256-GCM ciphertext
            `enc:v<n>:<base64url>` bound to the pipeline and field, longer than
            the input; reversible only through `POST /api/v1/protect/reveal`
            with the `protect:reveal` capability.
        preserve:
          type: string
          enum:
            - last4
            - domain
            - year
          description: >-
            Only with `method: mask`. `last4` keeps the last four characters,
            `domain` keeps `@` and the part after it, `year` keeps a leading
            4-digit year.
        params:
          type: object
          description: Reserved for method-specific options.
          additionalProperties:
            type: string
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: Optional API key for authentication (enabled via application.yaml)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.