Keep the ingestion key out of the browser
Send only approved fields to an endpoint you control. Forward them with a server-side credential and a timeout.
Send approved frontend and edge events through your server. Keep API keys there, check consent, and use route templates instead of raw URLs.
Reviewed by the Telemetry product team on . We checked where the code runs, shared event fields, verification steps, and the linked implementation guides. Who reviews this page
3 implementation guides
Every guide includes a server-side snippet, delivery and privacy boundaries, a verification query, related SQL, and links to upstream documentation.
Browse guidesSelection framework
Send only approved fields to an endpoint you control. Forward them with a server-side credential and a timeout.
Use route templates, Web Vitals, controlled error categories, and release fields. Exclude raw URLs, DOM text, form values, cookies, and arbitrary messages.
Navigation, blockers, connectivity, and page termination can lose client events. Do not use best-effort browser collection as an exact billing or audit ledger.
Shared event contract
Adapt these fields to your workflow. Document units, allowed statuses, and identifiers before several services write to the same table. Name the team responsible for the schema.
Verification
Implementation guides
Send Core Web Vitals and approved frontend result fields through a rate-limited server proxy. Keep the Telemetry API key on the server.
Open guideSend SQL-ready events from Next.js route handlers and server actions without exposing an ingestion key to the browser.
Open guideLog edge request status, latency, provider failures, cron runs, and queue workers from Cloudflare Workers.
Open guideCreate a free API key, choose the closest runtime guide, and send one known success and failure before expanding coverage.