Google Gemini¶
There is no native Gemini provider yet. provider.type: google is not
registered (the gateway refuses to start with unknown provider: google), and Gemini's native
generateContent / streamGenerateContent paths are not routed — a transparent
proxy forwards them verbatim, so any PII in them reaches Google in the
clear. A native route is planned for v0.2.0.
Until then, use Gemini's OpenAI-compatible endpoint
(https://generativelanguage.googleapis.com/v1beta/openai/). It speaks the
openai wire schema, so chat messages, streaming deltas, and tool-call
arguments are pseudonymized and restored exactly as described in
openai.md.
Gateway mode¶
The simplest setup: Privyx serves /v1/chat/completions and posts it to the
Gemini endpoint.
proxy:
mode: gateway
routes:
/v1/chat/completions: openai
provider:
type: generic
base_url: https://generativelanguage.googleapis.com/v1beta/openai/chat/completions
export PRIVYX_API_KEY=<your Gemini API key>
privyx proxy -c privyx.yaml
The gateway does not relay the client's key; Privyx sends its own, from
PRIVYX_API_KEY (or provider.api_key). provider.type: generic matters here:
with openai, an exported PRIVYX_OPENAI_API_KEY would take precedence and
your OpenAI key would be sent to Google. The wire schema comes from routes,
not from the provider type. Narrowing routes to the one chat path keeps
Anthropic and Responses requests from being posted to Gemini.
from openai import OpenAI
client = OpenAI(base_url="http://localhost:8000/v1", api_key="unused")
response = client.chat.completions.create(
model="gemini-2.5-flash",
messages=[{"role": "user", "content": "My email is alice@example.com"}],
)
Transparent mode¶
Use this when the client should keep its own key, or needs other Gemini paths
(such as /v1beta/openai/models) to reach the upstream. The Gemini chat path is
not in the default routes, so add it — without the route it is forwarded
verbatim:
proxy:
routes:
/v1beta/openai/chat/completions: openai
proxy.routes replaces the default map rather than merging into it; list the
default paths too if the same config also fronts OpenAI or Anthropic (see
Adding a route).
privyx proxy --transparent -c privyx.yaml --upstream https://generativelanguage.googleapis.com
client = OpenAI(
base_url="http://localhost:8000/v1beta/openai/",
api_key="<your Gemini API key>", # relayed upstream as a bearer token
)
Not covered¶
Forwarded verbatim in transparent mode — keep PII out of them, or set
proxy.passthrough_unknown: false to answer them (and every other unrouted
path, including /v1beta/openai/models) with a 403 instead:
/v1beta/openai/embeddings- native
/v1beta/models/{model}:generateContentand:streamGenerateContent