Appearance
Request logging
xgress3 records traffic at three separate layers. They serve different purposes and retain different data.
| Layer | Where it lives | Who uses it |
|---|---|---|
| Request Lookup | xgress3 platform (console) | Operators troubleshooting ingress |
| Agent log files | Agent host ({data-dir}/logs/) | Agent administrators |
| Platform operational telemetry | xgress3 operations (not in the console) | xgress3 support and reliability |
Request Lookup (tenant ingress)
Request Lookup stores records about HTTP requests that reach your service hostnames:
text
https://{account_id}--{service_id}.{region}.xg3.io/{path}This includes:
- Successful relays to your backend
- Gateway-side outcomes such as authentication failure, agent unavailable, and similar errors when request logging is enabled for that service
Request Lookup does not include regional platform endpoints such as OAuth token minting, agent enrollment, or JWKS. Those flows are outside Request Lookup.
Every response from a service hostname includes X-Xg3-Request-Id. Use that value in the console Request Lookup menu to find the matching record.
Records are retained for 7 days, then expire automatically.
Request logging is off by default
On the service detail page, Request logging is a Yes/No setting (toggle when you edit the service). New services start with it off.
- Off — xgress3 does not store a Request Lookup record for that service. The Request Lookup page shows a warning that request logging is disabled.
- On — xgress3 stores metadata for each request (see below).
Turning request logging off clears the detailed capture options for that service.
Always stored when request logging is on (metadata)
| Field | Notes |
|---|---|
X-Xg3-Request-Id | Same value as the response header |
| HTTP method, path, query string | Query is stored as part of request metadata |
| Backend base URL | Configured service backend (not the public hostname) |
| Response HTTP status | From your backend when relayed, or gateway outcome when denied |
| Timing | Start and completion timestamps |
| Relay outcome | Whether the request was relayed, denied, rate-limited, etc. |
| Account, service, agent identifiers | When known |
| Auth mode and credential/key id | JWT or service key mode, plus an opaque credential/key id — not the secret or token value |
Never stored in Request Lookup
- Client request headers (including
X-Xg3-AuthorizationandX-Xg3-Service-Key) - Client request body, unless you enable Capture request body (detailed capture, relayed requests only)
Authentication headers are used only for the live authorization decision and are not persisted in Request Lookup records.
Detailed capture (plan-gated)
Professional and Enterprise plans include Detailed request logging. Starter, free trial, and accounts without an active plan do not. When the plan does not include it, the three detailed toggles are unavailable in the console (shown as —).
When request logging is on and your plan includes detailed capture, you can enable any combination of:
- Capture request body — store the client request body when the request is relayed to your backend (not on deny or error outcomes)
- Capture backend response — store the backend response body when relay succeeds
- Full header logging — store backend response headers (independent of response-body capture; request headers are never stored)
When enabled:
- Request and response bodies up to 1 MB each may be stored; larger bodies are truncated or flagged as too large
- Sensitive response headers (
Authorization,Cookie,Set-Cookie,Proxy-Authorization,X-Xg3-Authorization,X-Xg3-Service-Key) are stored as[REDACTED]
Disable detailed capture when you are not actively troubleshooting. Captured bodies may contain sensitive application content.
Console access
- Request Lookup — search by
X-Xg3-Request-Idand view metadata (method, path, query, status, timing, outcomes) - Captured request body and captured response body — visible only to roles your account admin grants for those purposes; metadata lookup and body viewing are separate capabilities
Agent logs
The xg3 Agent writes rolling log files on the agent host under {data-dir}/logs/. These logs are not uploaded to Request Lookup.
See Install and run — Log files for location, rotation, and RUST_LOG verbosity.
Platform operational telemetry
xgress3 retains operational logs, traces, and metrics to run the service and assist with support. This telemetry is separate from Request Lookup:
- Operational HTTP traces do not include URL query strings or HTTP header values
- Request Lookup metadata may still include query strings on the request path
Avoid placing secrets or personal data in URL query parameters when possible.
Privacy guidance
- Query strings in Request Lookup may contain PII or opaque identifiers — treat records like application logs for data classification
- Optional body capture may contain sensitive payloads — enable only for short troubleshooting windows
- Share
X-Xg3-Request-Idwith teammates or support rather than pasting full URLs with query parameters when avoidable
Related
- Troubleshooting — using Request Lookup for failed requests
- Event Viewer — account configuration and system activity (separate from HTTP request records)
- Agents and services — logging toggles on services
- Billing — which plans include detailed request logging
- Ingress authentication — auth headers and Request Lookup