Attribution, tags & content logging

Know which end user, feature or tenant spent what; keep prompts and outputs when you need to debug — masked, for a bounded time, only if you switch it on.

Tags and end users

curl
-H "x-tf-tags: env=prod,feature=search,tenant=acme"   # up to five key=value pairs
-d '{"model":"…","user":"customer-42","messages":[…]}'   # OpenAI user field

Both land in the request log. Usage groups by user or by any tag key (console: By user / By tag; API: groupBy=user or groupBy=tag:env) and exports the same way as CSV.

Client request IDs and traces

http
X-Client-Request-Id: order-123-attempt-1
traceparent: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01

X-Client-Request-Id accepts up to 128 printable ASCII characters and is echoed in the response. A valid traceparent is recorded separately. These values correlate logs; they never replace the platform request ID, grant access, or deduplicate charges. Do not include secrets or personal data.

In Logs → Time and advanced filters, search by exact client request ID or trace ID. Searches remain scoped to your project. CSV and NDJSON exports include both IDs and the original traceparent. Async inference keeps the original submission’s correlation across queue execution and idempotent retries. Invalid values are ignored; malformed HTTP headers may be rejected by the HTTP parser.

Content logging

Off by default — the log stores metadata only. Projects › Content log turns it on for 1 to 30 days with PII masking (e-mails, phone numbers, card numbers, secrets). The request detail then shows the prompt and output, and the export includes them with content=true. Zero-data-retention organizations cannot enable it.

Log export

curl
# Set once in your shell: PROJECT (the project id from the console) and
# TF_ACCESS_TOKEN (a console access token with logs:read, shown once when created).
curl "/api/projects/$PROJECT/requests/export?since=2026-09-01T00:00:00Z&until=2026-09-08T00:00:00Z&content=true" \
  -H "Authorization: Bearer $TF_ACCESS_TOKEN"   # NDJSON, one request per line, newest first, up to 50 000

The export uses a console access token, not an inference API key. Access tokens