// interfaces

Telemetry

[ view markdown ]

Export security events to Datadog, Grafana Cloud, or your OpenTelemetry Collector.

Open Telemetry in the sidebar (/app/telemetry) to send security events to Datadog, Grafana Cloud, or an OpenTelemetry Collector. Destinations are configured by organization owners and are separate from webhook targets.

Configure a destination

  1. Select Add destination.
  2. Enter a name and the full public HTTPS OTLP logs endpoint, including the path such as /v1/logs. Superagent uses this exact URL without appending a path.
  3. Choose HTTP / Protobuf or HTTP / JSON. Datadog's direct OTLP logs intake requires HTTP / Protobuf.
  4. Add authentication headers. For Datadog, use dd-api-key with your Datadog API key and the logs endpoint for your Datadog site. Other providers may use Authorization with a bearer or basic token.
  5. Choose event subscriptions and source groups, then save the destination.
  6. Select Send test event and check your destination for the synthetic event.

Manage destinations

Export is opt in. Disable a destination to pause delivery, or delete it to stop exporting to that destination. Header values are encrypted at rest and are never shown after saving. Editing a destination preserves its saved credentials unless you enter replacement headers or select Remove saved headers. Changes take effect when you select Save destination. Saving an empty replacement removes the headers.

Events and delivery

Telemetry exports the same event catalog and uses the same source matching rules as webhooks.

Each event becomes an OTLP log record, not a metric or trace. The resource identifies service.name as superagent and includes the organization ID. The log body contains the webhook event envelope. Event IDs allow receivers to deduplicate retries. Webhook signing headers are not added to OTLP requests.

The export shares the event outbox, source matching, and asynchronous retry behavior used by webhooks. It does not export internal application logs, model generations, metrics, execution traces, or PR scan lifecycle events. Existing webhook targets are unchanged.

Send test event verifies connectivity and ingestion directly. To verify the queued event path, trigger a subscribed action, such as starting a report, and look for its event in your destination.

Connect Datadog

Use HTTP / Protobuf and the OTLP logs endpoint for your Datadog site. Add dd-api-key as an authentication header with a Datadog API key, not an application key. After sending a test event, open Datadog Logs → Live Tail and search for service:superagent.

See Datadog's OTLP logs setup for the appropriate regional endpoint and API key configuration. Direct Datadog ingestion does not require your own collector or tunnel.

Data access

Event bodies can contain security findings, remediation patches, source code excerpts, and report details. Only configure a destination authorized to receive your organization's security data. Private or local collector URLs are not supported; use a public HTTPS receiver. Do not put credentials in URLs.