Attribution, tags & content logging
Know which end user, feature or tenant spent what; keep prompts and outputs when you need to debug — masked, for a bounded time, only if you switch it on.
Client request IDs and traces
X-Client-Request-Id: order-123-attempt-1 traceparent: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01
X-Client-Request-Id accepts up to 128 printable ASCII characters and is echoed in the response. A valid traceparent is recorded separately. These values correlate logs; they never replace the platform request ID, grant access, or deduplicate charges. Do not include secrets or personal data.
In Logs → Time and advanced filters, search by exact client request ID or trace ID. Searches remain scoped to your project. CSV and NDJSON exports include both IDs and the original traceparent. Async inference keeps the original submission’s correlation across queue execution and idempotent retries. Invalid values are ignored; malformed HTTP headers may be rejected by the HTTP parser.
Content logging
Off by default — the log stores metadata only. Projects › Content log turns it on for 1 to 30 days with PII masking (e-mails, phone numbers, card numbers, secrets). The request detail then shows the prompt and output, and the export includes them with content=true. Zero-data-retention organizations cannot enable it.
Log export
# Set once in your shell: PROJECT (the project id from the console) and # TF_ACCESS_TOKEN (a console access token with logs:read, shown once when created). curl "/api/projects/$PROJECT/requests/export?since=2026-09-01T00:00:00Z&until=2026-09-08T00:00:00Z&content=true" \ -H "Authorization: Bearer $TF_ACCESS_TOKEN" # NDJSON, one request per line, newest first, up to 50 000
The export uses a console access token, not an inference API key. Access tokens