Custom Parameters & Context Override
These are two different mechanisms — pick based on where the data needs to end up.
- Custom Parameters attach metadata to a challenge that comes back out in the verification result, for your server to use.
- Context Override feeds extra context into the AI evaluator for AI Security Rules — it never appears in verification data.
Custom Parameters
Add params.-prefixed query parameters to the challenge request:
GET /v1/challenge?params.abc=123¶ms.def=456Each parameter is signed into the challenge (part of the salt, verifiable via the challenge's signature) and comes back in the verificationData object on submission:
{
"id": "...",
"classification": "...",
"score": 0,
"params.abc": "123",
"params.def": "456"
}Limits: up to 10 parameters per request, 20 characters per name, 100 characters per value.
Context Override
Some features — currently AI Security Rules — need extra context to evaluate a request correctly. You can supply it two ways:
- Statically, via a Security Group rule.
- Dynamically, as an encrypted URL query parameter — this overrides any statically configured value.
Unlike Custom Parameters, context passed this way is only visible to the AI evaluator and never appears in verificationData.
Encrypting context
Encrypt your JSON payload with AES-GCM using a shared key — set on your Sentinel instance as CONTEXT_DATA_KEY — and encode it as base64(iv) + "." + base64(encrypted). Use that same key's value as key on the client/server code doing the encryption. In Ruby:
require 'openssl'
require 'base64'
require 'json'
def encrypt_context(data, key)
cipher = OpenSSL::Cipher.new('aes-256-gcm')
cipher.encrypt
cipher.key = key
iv = cipher.random_iv
encrypted = cipher.update(data) + cipher.final
tag = cipher.auth_tag
"#{Base64.strict_encode64(iv)}.#{Base64.strict_encode64(encrypted + tag)}"
end
data = { "hello" => "world" }.to_json
puts encrypt_context(data, key)Pass the result as a query parameter on verification:
/v1/verify?context={ENCRYPTED_CONTEXT_DATA}Related
- AI Security Rules — Built-in Context Fields, and how context is used in a prompt.
- Security Groups — the
Schemareference these both build on. - ENV Variables —
CONTEXT_DATA_KEYreference.