What Scout Trails collects
This page lists what each agent sends to Scout Trails, what each agent setting adds, what Scout Trails changes or removes on arrival, and where the data shows up in the dashboard. Everything an actor sends is stored under the actor’s organization and is visible to every member of that organization.
What ingest does to every event
When a batch of telemetry arrives, Scout Trails:
- Checks the key. A batch with a missing, malformed, unknown, rotated or revoked key, or the key of a deactivated actor, is rejected and nothing in it is stored.
- Stamps the organization and actor. Every event is labelled with the organization and actor the key belongs to. Any values the agent sends for these are overwritten.
- Drops connection noise. Events that record an agent’s internal connection activity, rather than its work, are discarded. See the per-agent sections below.
- Removes the agent vendor’s account identity. Claude Code and Codex attach the identity of the Anthropic or OpenAI account they are signed in to. Scout Trails deletes these attributes before storing anything:
user.email,user.id,user.account_id,user.account_uuidandorganization.id. Your telemetry is attributed by your ingest key, never by your vendor account. - Redacts secrets in tool arguments, tool output and error messages. See Secret redaction.
- Counts the events against the organization’s monthly allowance. See Usage limit.
Claude Code
Sent with the standard configuration
With the configuration in Claude Code, Claude Code sends these events:
| Event | What it carries | Where it appears |
|---|---|---|
| Tool result, one per tool that ran | Tool name, success or failure, duration, result size in bytes, MCP server scope, session ID, prompt ID, Claude Code version, operating system, CPU architecture, terminal type | A row in Tool calls and in the session’s Tool-call timeline, with status ok or error |
| Tool decision, one per permission decision | Tool name, whether it was accepted or rejected, and who decided | A rejected call appears as a tool call with status denied and no duration. Accepted decisions don’t add a row. |
| Model request, one per call to the model | Model, input, output, cache-read and cache-creation tokens, estimated cost in USD, duration | Cost on Sessions and on the session page, and the session’s Cost and Spend by model cards |
| Model error | Model and error type | Counted under Model calls in the session’s Cost card, at zero cost |
| User prompt | Prompt length. The prompt text is replaced with <REDACTED> by Claude Code unless you set OTEL_LOG_USER_PROMPTS=1. | Not shown |
Claude Code sends other lifecycle events as well. Scout Trails stores them and counts them toward the allowance, but the dashboard doesn’t display them. It discards one event type entirely: the MCP server connection event, which Claude Code emits repeatedly for every configured MCP server.
What OTEL_LOG_TOOL_DETAILS=1 adds
Without this setting, Claude Code sends tool calls without their arguments, and every MCP call has the tool name mcp_tool. With it, Claude Code adds:
- The tool’s input, serialized as JSON: the shell command for Bash, the file path for Read, Edit and Write, the pattern for Grep, the URL for WebFetch, and so on. Claude Code shortens any single value longer than 512 characters and caps the whole input at about 4 KB, so long inputs, such as the text of a large Write, arrive truncated.
- Bash details: the command, its description and timeout, and, after a successful
git commit, the commit ID and branch. - Names: the MCP server and tool, skill, and subagent type.
In the dashboard this fills the Arguments card on each tool call, the Error row for failed calls, the real tool name of MCP calls, and the Risk flags and External domains that Scout Trails detects from arguments.
Claude Code never puts a tool’s output on these events. The Result card of a Claude Code tool call reads No result recorded. whatever settings you use.
Settings that send more
| Setting | What Claude Code sends | Displayed |
|---|---|---|
OTEL_LOG_USER_PROMPTS=1 | The full text of every prompt you type | No |
OTEL_LOG_RAW_API_BODIES=1 | The complete request and response of every model call: system prompt, conversation history, and the contents of every file and command output in the conversation | No |
OTEL_TRACES_EXPORTER=otlp with CLAUDE_CODE_ENHANCED_TELEMETRY_BETA=1 | Trace spans for each interaction, model request and tool | No |
OTEL_LOG_TOOL_CONTENT=1, with traces | Tool output as span events: file contents read, diffs written, command output | No |
Scout Trails stores what these settings send, but no dashboard page, API endpoint or MCP tool reads it, and secret redaction doesn’t cover prompt text, model request bodies or trace spans. Leave them off unless you have a specific reason to keep the data.
Codex CLI
Sent with the standard configuration
With the configuration in Codex CLI, Codex sends these events:
| Event | What it carries | Where it appears |
|---|---|---|
| Tool result, one per tool that ran | Tool name, call ID, the full arguments as JSON, the tool’s output, success or failure, duration, MCP server and its origin, conversation ID, model | A row in Tool calls and in the session’s Tool-call timeline. The Arguments, Result and Model fields are filled. |
| Tool decision | The approval decision and who made it | Stored; not shown. Calls you decline in Codex don’t appear as denied. |
| Conversation start, model request, user prompt and others | Model and session settings, request status and timing, prompt length | Stored; not shown |
Codex sends a tool’s arguments and output on every tool result. It has no setting that leaves them out, so turn the exporter off for any work whose commands and output must not leave the machine.
Codex’s conversation ID is the session ID in the dashboard. Codex doesn’t report model cost on its events, so the Cost column reads — for Codex sessions.
log_user_prompt = true adds the text of each prompt. The dashboard doesn’t display it, and secret redaction doesn’t cover it.
Scout Trails discards Codex’s WebSocket request, WebSocket connect, server-sent-event and startup-phase events, which record connection bookkeeping rather than work.
Secret redaction
Before storing an event, Scout Trails scans tool arguments, tool output and error messages for common secret formats and replaces each match with a marker such as [REDACTED:github_token]. It covers private key blocks, cloud provider access keys, GitHub, Stripe and Slack tokens, API keys, JSON Web Tokens, passwords in connection strings and URLs, and values assigned to names such as password, secret or token.
Redaction is pattern-based. It catches common formats but can’t recognize every secret, so treat it as a safety net rather than a guarantee.
Usage limit
Each organization has a monthly allowance of ingested events, counted over the organization’s billing period. Every log event that passes ingest counts, including event types the dashboard doesn’t display. Discarded events and trace spans don’t count.
When a batch would take the organization past its allowance, ingest rejects it with the gRPC status RESOURCE_EXHAUSTED and the message monthly event limit reached (tenant <tenant>); contact administrator to raise. Nothing more is stored until the next billing period starts or the allowance is raised. The tenant value in the message is the token shown under Telemetry tenant on the Organization tab of Manage.