Skip to main content
AppSignal collects a limited set of HTTP request headers by default for supported frameworks. These headers can help track down errors or performance issues caused by a client request. To comply with GDPR, AppSignal keeps this default set small, collecting no user identifiable data. You can limit it further by configuring which headers AppSignal collects.
🔐 Do not send Personal Identifiable Information (PII) to AppSignal. Filter PII (e.g., names, emails) and use an ID, hash, or pseudonymized identifier instead.

For HIPAA-covered entities, more info on signing a Business Associate Agreement (BAA) is available in our Business Add-Ons documentation.

Configure Headers

Request headers are configured in an allowlist. AppSignal collects the headers on the list, and neither the name nor the value of any other header outside of it. Header names are lowercase and dash-separated, the way an HTTP request writes them. Report the X-Custom-Header header by adding x-custom-header to the list. AppSignal for Ruby names them differently when it reports to the agent. This guide will show you how to configure your application’s request header filtering allowlist based on what language your application uses:

Ruby

AppSignal automatically stores the configured request headers in the Ruby integration for Rails apps and other frameworks. It reads them from the Rack environment, which names a header’s key by prefixing it with HTTP_, uppercasing it, and replacing dashes (-) with underscores (_). So X-Custom-Header becomes HTTP_X_CUSTOM_HEADER. CONTENT_LENGTH and CONTENT_TYPE are the two keys Rack does not prefix. The request_headers config option lists those Rack keys. Some of them hold values other than headers, such as REQUEST_METHOD and SERVER_NAME.

Ruby in collector mode

When AppSignal for Ruby reports to a collector, it reports request headers under their HTTP names, and reports the rest of the Rack environment separately. Two config options replace request_headers:
  • keep_request_headers lists request headers, named the way an HTTP request writes them. Report the X-Custom-Header header by adding x-custom-header to the list.
  • keep_request_environment lists the Rack environment keys to report that represent information other than headers, such as REMOTE_ADDR.
Until you set these configuration options, AppSignal derives their values from request_headers, so that the same headers are reported in collector mode as they were in agent mode.

Elixir

AppSignal automatically stores the configured request headers for Phoenix apps and other frameworks in the Elixir integration. It has a built-in list of request headers collected by default which you can customize using the request_headers config option. To configure which request headers to collect for each request, add the following configuration to your config/appsignal.exs file in the environment group where you want it to apply. The request_headers value is a list of strings.

Node.js

In the Node.js integration, AppSignal automatically stores the configured request headers for Express apps and other frameworks. It has a built-in list of request headers to collect by default that you can customize with the requestHeaders config option. To configure which request headers to collect for each request, add the following configuration to your AppSignal client instance creation. The requestHeaders value is an array of strings.

Python

In the Python integration, if an app sets request headers, AppSignal will automatically collect the configured request headers. It has a built-in list of request headers to collect by default that you can customize with the request_headers config option. To configure which request headers to collect for each request, add the following configuration to your AppSignal client instance creation. The request_headers value is a list of strings.

Go

If an app records request headers, AppSignal will automatically filter the configured request headers. It has a built-in list of request headers to collect by default that you can customize with the request_headers config option. See the Go configuration page for more information on how to configure OpenTelemetry for Go apps. To configure which request headers to collect for each request, add the following configuration to your AppSignal client instance creation. The request_headers value is a slice of strings.

Java

In the Java integration, if an app sets request headers, AppSignal will automatically collect the configured request headers. It has a built-in list of request headers to collect by default that you can customize with the request_headers config option. To configure which request headers to collect for each request, add the following configuration. The request_headers value is an array of strings.

PHP

In the PHP integration, if an app sets request headers, AppSignal will automatically collect the configured request headers. It has a built-in list of request headers to collect by default that you can customize with the request_headers config option. To configure which request headers to collect for each request, add the following configuration. The request_headers value is an array of strings.