Skip to main content
HTTP Resources support HTTP/1.1 and HTTP/2. A direct client connects to the gateway on TCP 443; a Resource-bound Forge credential in Proxy-Authorization authenticates the caller and selects the Resource.
With automatic routing, use the destination’s original URL and ordinary authentication behavior instead.

Policy fields and actions

Forge can match the method, path without query parameters, and normalized content type. A connection or request can be allowed, flagged, approved, or blocked. For one complete, uncompressed JSON value no larger than 32 KiB, Forge can:
  • redact selected request fields before destination credentials are added;
  • redact selected response fields; or
  • remove matching response objects.
An enforcing transformation fails closed when targeted data is missing, malformed, compressed, oversized, streaming, or non-JSON. Monitor mode records the intended outcome without changing traffic.

Destination authentication

HTTP Resources support bearer tokens, named credential headers, OAuth 2.0 client credentials, and OAuth 2.0 token exchange. The gateway injects the selected destination credential only after policy allows the request.

Current limits

Query-parameter and arbitrary-header conditions, multipart or form bodies, compressed or binary bodies, streaming JSON, SSE, WebSocket, HTTP/3, and gRPC message policy are not supported. Unsupported targeted transformations fail closed rather than forwarding uninspected data. See Credentials and identity and Resource Policies.