Hello,
I'm using the Vercel Hobby plan and I'm investigating a security/observability concern.
Using a completely fake canary value, I verified that Vercel Runtime Logs records the full incoming Request Path and Search Params. The fake value was visible in the collected request details. No real credential was used.
My application uses TanStack Start/Nitro on Vercel and communicates with the Telegram Bot API. Telegram requires the bot token to be included in the API URL path, conceptually:
/bot/...
and for file downloads:
/file/bot/...
I would like to know whether Vercel provides a supported mechanism to prevent these sensitive URL values from being ingested or stored by Runtime Logs or Outgoing Requests before collection — not simply hidden or masked in the dashboard afterward.
Specifically:
Can Request Path be redacted or disabled before ingestion? Can Search Params / query strings be redacted before ingestion? Can specific outbound fetch URLs or hosts be excluded from Runtime Logs / Outgoing Requests before ingestion? Does /otel instrumentationConfig.fetch.ignoreUrls affect only OpenTelemetry spans, or does it also prevent the URLs from being stored in Vercel Runtime Logs / Outgoing Requests? Is there any project/team-level sensitive-data redaction available for these fields on the Hobby plan? If no pre-ingestion protection exists, what architecture does Vercel recommend when an external API requires a credential in the URL path?
My requirement is specifically protection before ingestion/storage. Dashboard-only masking or filtering after collection would not solve the issue.
I would also appreciate clarification on whether headers, request/response bodies, exceptions, or related telemetry can automatically capture sensitive credential-bearing values.
I will only use fake canary values for any additional validation and will not share real credentials.
Thank you.