JSON Threat Protection

Enterprise only

Allow non-JSON requestsv3.14+

Configure the JSON Threat Protection plugin with allow_non_json_requests set to true. This setting allows non-JSON requests to bypass any configured rules, while still blocking requests that contain invalid JSON.

Set up the plugin

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!