Scout Trails Docs

Connecting agents

Scout Trails collects telemetry from LLM coding agents through the agents’ own built-in OpenTelemetry exporters. You don’t install anything: you give the agent the Scout Trails ingest endpoint and an ingest key, and every tool call it makes shows up in the dashboard under your organization. This section explains how ingest works, how to configure each supported agent, exactly what data is sent and kept, and how to fix a connection that isn’t working.

Supported agents

AgentGuideWhere the configuration lives
Claude CodeClaude Code~/.claude/settings.json env block, shell environment variables, or managed settings
Codex CLICodex CLI[otel] table in ~/.codex/config.toml

How ingest works

Every agent sends to the same endpoint:

https://ingest.scoutmonitoring.io:443

The endpoint accepts:

  • Protocol: OTLP over gRPC, with TLS, on port 443. OTLP over HTTP (http/protobuf or http/json) is not accepted, so always select the agent’s gRPC exporter.
  • Signals: logs (events) and traces. Metrics are not accepted; leave the agent’s metrics exporter pointed somewhere else or turned off.
  • Authentication: an authorization header of the exact form Bearer <ingest-key>. Bearer is case-sensitive and is followed by a single space.
  • Request size: up to 32 MiB per export request.

Each request is checked against the key on arrival. A key works as soon as it is issued, and stops working the moment it is rotated or revoked or its actor is deactivated. The key alone decides which organization and actor the data belongs to: any organization or actor identifiers the agent itself puts in the data are replaced.

Scout Trails builds tool calls from the agent’s log events. A session appears in the dashboard once at least one of its tool calls arrives. See What Scout Trails collects for the per-agent details.

Getting an ingest key

An ingest key belongs to an actor: one machine, CI runner or agent that sends telemetry. Give each machine its own actor, so the Actor column and the Scope filter can tell them apart. See Actors.

  1. Sign in to the dashboard at https://ui.scoutmonitoring.io.
  2. Open the organization menu (your organization’s name in the header) and choose Manage, then open the Actors & ingest keys tab.
  3. Under New actor, enter a Display name for the machine, for example alice-laptop, choose a Kind, and select Create actor. The new actor gets an ingest key straight away and the key appears in a dialog.
  4. Select Copy and paste the key into the agent configuration described on the agent’s page.

The key stays visible in the Ingest key column of the All actors table to every member of the organization, so you can copy it again later. To replace a key, select Rotate key; the old key stops working immediately. See Ingest keys for rotating, revoking and deactivating.

Any member of the organization can create actors and manage their keys.

Checking that data arrives

  1. Start the agent with the configuration in place and have it run a few tools, for example by asking it to list the files in a directory.
  2. Wait about ten seconds. Agents batch their telemetry and send it every few seconds.
  3. Open Tool calls in the dashboard. Set Window to 1h and Scope to Whole organization, then select Apply. The calls appear with the newest first.
  4. Open Sessions. Your session appears with your actor’s display name in the Actor column and the agent’s name (claude-code or codex-cli) in the Agent column.

If nothing appears, see Troubleshooting. For what each page shows, see Sessions and Tool calls.

Network requirements

The agent opens an outbound TLS connection to ingest.scoutmonitoring.io on TCP port 443 and speaks gRPC over HTTP/2. Firewalls and proxies must:

  • allow outbound connections to that hostname on port 443;
  • pass HTTP/2 through end to end. A proxy that downgrades the connection to HTTP/1.1 breaks gRPC;
  • if they inspect TLS, be trusted by the agent. Point Claude Code’s OTEL_EXPORTER_OTLP_CERTIFICATE or Codex’s tls.ca-certificate setting at your proxy’s CA certificate.

In this section

  • Claude Code — configure Claude Code, per user or across a team.
  • Codex CLI — configure Codex CLI.
  • What Scout Trails collects — what each agent sends, what each privacy setting adds, and what Scout Trails redacts and drops.
  • Troubleshooting — nothing showing up, authentication errors, the wrong organization, missing arguments.