Settings
Each setting turns on one kind of data. In the dashboard all five start on, so check the switches before you save. In the API they all default tofalse, so a policy with none set saves nothing extra.
boolean
default:"false"
Save request headers, plus the user agent and client IP.
boolean
default:"false"
Save response headers.
boolean
default:"false"
Save the request body, up to 1 MiB.
boolean
default:"false"
Save the response body, up to 1 MiB.
boolean
default:"false"
Save the query string and parameters. It’s separate from headers because URLs often carry secrets like
?api_key=....Example: capture everything on one debugging route
What gets saved
- Several matching policies combine. A request matched by a
requestHeaderspolicy and arequestBodypolicy gets both saved. A policy with no match expressions applies to every request. - Bodies are cut off at 1 MiB in each direction in the log. The request and response themselves are never cut. Streaming requests are covered too.
- Rejected requests aren’t logged, whatever the logging policy says.
What’s always redacted
These are replaced with[REDACTED] before anything is saved:
- The
Authorizationheader. - Every header and query parameter listed as a key location in any API key authentication policy, even turned-off ones. When a query parameter is redacted, the saved query string can be in a different order or encoding than the original.
- Body fields marked
x-unkey-redact: truein your OpenAPI spec, when an OpenAPI validation policy is on.
Where to see the data
Saved data shows up in the project’s Requests view in the dashboard and in thegateway_requests_v1 analytics table. The header, query, and body columns are empty for requests no logging policy matched.
Next steps
OpenAPI validation policy
Mark body fields for redaction with
x-unkey-redact.Gateway policies
Match expressions that pick which requests to capture.