Monitoring changedcowork/monitoring
Nearest release: v2.1.229, published 4 hours after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 12 Aug 2026 15:16 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+83added
Lines−83removed
From line
16
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits2to this page, all time
The whole hunk
from line 16, old and new numbered
/
from line 16
1616
17172. Configure the following fields:
1818
19 | Field | Description | Example |
20 | ----------------- | ----------------------------------------- | ----------------------------------- |
21 | **OTLP endpoint** | Your OpenTelemetry collector URL | `http://collector.example.com:4318` |
22 | **OTLP protocol** | Transport protocol | `http/json` or `http/protobuf` |
23 | **OTLP headers** | Authentication headers for your collector | `Authorization=Bearer your-token` |
19 | Field | Description | Example |
20 | - | - | - |
21 | **OTLP endpoint** | Your OpenTelemetry collector URL | `http://collector.example.com:4318` |
22 | **OTLP protocol** | Transport protocol | `http/json` or `http/protobuf` |
23 | **OTLP headers** | Authentication headers for your collector | `Authorization=Bearer your-token` |
2424
25253. Save your settings
2626
from line 38
3838
3939When a user submits a prompt, Cowork may make multiple API calls and run several tools. The `prompt.id` attribute links all events back to the single prompt that triggered them.
4040
41| Attribute | Description |
42| ----------- | ------------------------------------------------------------------------------------ |
41| Attribute | Description |
42| - | - |
4343| `prompt.id` | UUID v4 identifier linking all events produced while processing a single user prompt |
4444
4545To trace all activity triggered by a single prompt, filter your events by a specific `prompt.id` value.
from line 50
5050
5151All events include these attributes:
5252
53| Attribute | Description |
54| ---------------------- | -------------------------------------------------------------------------------------------- |
55| `session.id` | Unique session identifier |
56| `organization.id` | Organization UUID |
57| `user.account_uuid` | User's account UUID |
58| `user.account_id` | Account ID in tagged format matching Anthropic admin APIs (for example, `user_01BWBeN28...`) |
59| `user.id` | Anonymous device/installation identifier |
60| `user.email` | User email |
61| `workspace.host_paths` | Host workspace directories selected in the desktop app (string array) |
62| `terminal.type` | Terminal type (`non-interactive` for Cowork) |
53| Attribute | Description |
54| - | - |
55| `session.id` | Unique session identifier |
56| `organization.id` | Organization UUID |
57| `user.account_uuid` | User's account UUID |
58| `user.account_id` | Account ID in tagged format matching Anthropic admin APIs (for example, `user_01BWBeN28...`) |
59| `user.id` | Anonymous device/installation identifier |
60| `user.email` | User email |
61| `workspace.host_paths` | Host workspace directories selected in the desktop app (string array) |
62| `terminal.type` | Terminal type (`non-interactive` for Cowork) |
6363
6464<Note>
6565 The account attributes — `organization.id`, `user.account_uuid`, `user.account_id`, and `user.email` — are populated from the user's Anthropic account, so they appear on first-party deployments only. On [third-party deployments](/docs/third-party/claude-desktop/overview) there is no Anthropic account and these attributes are absent; instead, the export carries the signed-in user's identity as the `enduser.id` resource attribute, described under [User attribution](/docs/third-party/claude-desktop/telemetry#user-attribution). The `process.owner` resource attribute (the operating-system login name) is standard OpenTelemetry process metadata and is present on all deployments.
from line 75
7575
7676All [standard attributes](#standard-attributes), plus:
7777
78| Attribute | Description |
79| ----------------- | --------------------------------------------------------------------- |
80| `event.timestamp` | ISO 8601 timestamp |
81| `event.sequence` | Monotonically increasing counter for ordering events within a session |
82| `prompt_length` | Length of the prompt |
83| `prompt` | Prompt content |
78| Attribute | Description |
79| - | - |
80| `event.timestamp` | ISO 8601 timestamp |
81| `event.sequence` | Monotonically increasing counter for ordering events within a session |
82| `prompt_length` | Length of the prompt |
83| `prompt` | Prompt content |
8484
8585### Model response event
8686
from line 92
9292
9393All [standard attributes](#standard-attributes), plus:
9494
95| Attribute | Description |
96| ----------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
97| `event.timestamp` | ISO 8601 timestamp |
98| `event.sequence` | Monotonically increasing counter for ordering events within a session |
99| `model` | Model that produced the response |
100| `request_id` | API request identifier |
101| `response_length` | Length of the response |
102| `response` | Model response text. Includes text output only; thinking content is excluded. Truncated to 60 KB. When model response capture is disabled, the value is the literal string `<REDACTED>`. |
95| Attribute | Description |
96| - | - |
97| `event.timestamp` | ISO 8601 timestamp |
98| `event.sequence` | Monotonically increasing counter for ordering events within a session |
99| `model` | Model that produced the response |
100| `request_id` | API request identifier |
101| `response_length` | Length of the response |
102| `response` | Model response text. Includes text output only; thinking content is excluded. Truncated to 60 KB. When model response capture is disabled, the value is the literal string `<REDACTED>`. |
103103
104104Model responses are captured when [`otlpContentCapture`](/docs/third-party/claude-desktop/telemetry#content-capture) includes `assistantResponses`, and also whenever user prompts are captured.
105105
from line 113
113113
114114All [standard attributes](#standard-attributes), plus:
115115
116| Attribute | Description |
117| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
118| `event.timestamp` | ISO 8601 timestamp |
119| `event.sequence` | Monotonically increasing counter for ordering events within a session |
120| `tool_name` | Name of the tool |
121| `success` | `"true"` or `"false"` |
122| `duration_ms` | Execution time in milliseconds |
123| `error` | Error message (if failed) |
124| `decision_type` | Either `"accept"` or `"reject"` |
125| `decision_source` | How the decision was made — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
126| `tool_result_size_bytes` | Size of the tool result in bytes |
127| `mcp_server_scope` | MCP server scope identifier (for MCP tools) |
128| `tool_parameters` | JSON string containing tool-specific parameters, including `mcp_server_name` and `mcp_tool_name` for MCP tools |
129| `tool_input` | JSON-serialized tool arguments. Individual strings over 512 characters are truncated; entire string limited to \~4K characters. Applies to all tools including MCP tools. |
116| Attribute | Description |
117| - | - |
118| `event.timestamp` | ISO 8601 timestamp |
119| `event.sequence` | Monotonically increasing counter for ordering events within a session |
120| `tool_name` | Name of the tool |
121| `success` | `"true"` or `"false"` |
122| `duration_ms` | Execution time in milliseconds |
123| `error` | Error message (if failed) |
124| `decision_type` | Either `"accept"` or `"reject"` |
125| `decision_source` | How the decision was made — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
126| `tool_result_size_bytes` | Size of the tool result in bytes |
127| `mcp_server_scope` | MCP server scope identifier (for MCP tools) |
128| `tool_parameters` | JSON string containing tool-specific parameters, including `mcp_server_name` and `mcp_tool_name` for MCP tools |
129| `tool_input` | JSON-serialized tool arguments. Individual strings over 512 characters are truncated; entire string limited to \~4K characters. Applies to all tools including MCP tools. |
130130
131131### API request event
132132
from line 138
138138
139139All [standard attributes](#standard-attributes), plus:
140140
141| Attribute | Description |
142| ----------------------- | --------------------------------------------------------------------- |
143| `event.timestamp` | ISO 8601 timestamp |
144| `event.sequence` | Monotonically increasing counter for ordering events within a session |
145| `model` | Model used (e.g., `claude-sonnet-5`) |
146| `cost_usd` | Estimated cost in USD |
147| `duration_ms` | Request duration in milliseconds |
148| `input_tokens` | Number of input tokens |
149| `output_tokens` | Number of output tokens |
150| `cache_read_tokens` | Number of tokens read from cache |
151| `cache_creation_tokens` | Number of tokens used for cache creation |
152| `speed` | `"fast"` or `"normal"` |
141| Attribute | Description |
142| - | - |
143| `event.timestamp` | ISO 8601 timestamp |
144| `event.sequence` | Monotonically increasing counter for ordering events within a session |
145| `model` | Model used (e.g., `claude-sonnet-5`) |
146| `cost_usd` | Estimated cost in USD |
147| `duration_ms` | Request duration in milliseconds |
148| `input_tokens` | Number of input tokens |
149| `output_tokens` | Number of output tokens |
150| `cache_read_tokens` | Number of tokens read from cache |
151| `cache_creation_tokens` | Number of tokens used for cache creation |
152| `speed` | `"fast"` or `"normal"` |
153153
154154### API error event
155155
from line 161
161161
162162All [standard attributes](#standard-attributes), plus:
163163
164| Attribute | Description |
165| ----------------- | --------------------------------------------------------------------- |
166| `event.timestamp` | ISO 8601 timestamp |
167| `event.sequence` | Monotonically increasing counter for ordering events within a session |
168| `model` | Model used |
169| `error` | Error message |
170| `status_code` | HTTP status code as a string, or `"undefined"` for non-HTTP errors |
171| `duration_ms` | Request duration in milliseconds |
172| `attempt` | Attempt number (for retried requests) |
173| `speed` | `"fast"` or `"normal"` |
164| Attribute | Description |
165| - | - |
166| `event.timestamp` | ISO 8601 timestamp |
167| `event.sequence` | Monotonically increasing counter for ordering events within a session |
168| `model` | Model used |
169| `error` | Error message |
170| `status_code` | HTTP status code as a string, or `"undefined"` for non-HTTP errors |
171| `duration_ms` | Request duration in milliseconds |
172| `attempt` | Attempt number (for retried requests) |
173| `speed` | `"fast"` or `"normal"` |
174174
175175### Tool decision event
176176
from line 182
182182
183183All [standard attributes](#standard-attributes), plus:
184184
185| Attribute | Description |
186| ----------------- | ------------------------------------------------------------------------------------------------------------------ |
187| `event.timestamp` | ISO 8601 timestamp |
188| `event.sequence` | Monotonically increasing counter for ordering events within a session |
189| `tool_name` | Name of the tool |
190| `decision` | Either `"accept"` or `"reject"` |
191| `source` | Decision source — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
185| Attribute | Description |
186| - | - |
187| `event.timestamp` | ISO 8601 timestamp |
188| `event.sequence` | Monotonically increasing counter for ordering events within a session |
189| `tool_name` | Name of the tool |
190| `decision` | Either `"accept"` or `"reject"` |
191| `source` | Decision source — `"config"`, `"hook"`, `"user_permanent"`, `"user_temporary"`, `"user_abort"`, or `"user_reject"` |
192192
193193## Event analysis
194194
from line 216
216216
217217All events are exported with the following resource attributes:
218218
219| Attribute | Description |
220| ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
221| `service.name` | `cowork` |
222| `service.version` | Claude app version |
223| `host.arch` | Host architecture (e.g., `arm64`) |
224| `os.type` | Operating system type (e.g., `darwin`) |
225| `os.version` | Operating system version string |
226| `enduser.id` | The signed-in user's identity, on third-party deployments only. Controlled by the [`endUserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) setting; see [User attribution](/docs/third-party/claude-desktop/telemetry#user-attribution). |
227| `process.owner` | Operating-system login name |
219| Attribute | Description |
220| - | - |
221| `service.name` | `cowork` |
222| `service.version` | Claude app version |
223| `host.arch` | Host architecture (e.g., `arm64`) |
224| `os.type` | Operating system type (e.g., `darwin`) |
225| `os.version` | Operating system version string |
226| `enduser.id` | The signed-in user's identity, on third-party deployments only. Controlled by the [`endUserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) setting; see [User attribution](/docs/third-party/claude-desktop/telemetry#user-attribution). |
227| `process.owner` | Operating-system login name |
228228
229229## Security and privacy
230230
No line in this hunk matches that.