
This guide covers client-side trace export from Claude Code, which works
on Claude for Teams and Claude for Enterprise. To ingest claude.ai chats and
Cowork sessions, use the Claude Compliance
integration instead. It reads transcripts from Anthropic’s Compliance API and
requires Claude Enterprise. See Which Claude surfaces are
covered.
Prerequisites
- An Openlayer API key and the ID of the inference pipeline that should receive the traces.
- A way to deliver Claude Code managed settings to your developers. Either:
- Server-managed settings, from the claude.ai admin console. Requires Claude for Teams or Claude for Enterprise and the Owner or Primary Owner role.
- Endpoint-managed settings, deployed to each device through MDM, an OS policy, or a
managed-settings.jsonfile.
- Claude Code v2.1.251 or later on developer machines. Earlier versions don’t fully lock the export destination described in What developers can and can’t change.
How Claude Code tracing works
Claude Code tracing is a beta feature and is off by default. Three settings turn it on:
Each prompt a developer sends starts a
claude_code.interaction root span. Model calls and tool
calls are recorded as its children, and each tool call has its own children for time spent
waiting on a permission decision and for execution. When Claude spawns a subagent, the
subagent’s spans nest under the tool call that started it.
1. Write the managed settings
Put the followingenv block in your managed settings, replacing the two placeholders:
OTEL_EXPORTER_OTLP_TRACES_*scopes the endpoint, protocol, and credentials to traces. If your organization already exports Claude Code metrics or logs to another collector, that export keeps working, and your Openlayer API key is never sent to it.- The endpoint is the full traces path, because a traces-specific variable doesn’t have
/v1/tracesappended to it. - The
x-bt-parentheader chooses the inference pipeline that receives the traces. - The three
OTEL_LOG_*values keep content redacted and stop individual developers from turning content capture on in their own settings. Remove them only if you deliberately opt in.
2. Deliver the managed settings
Deliver the block through whichever mechanism you already use to manage Claude Code. By default, Claude Code reads its policy from one managed source, the highest-ranked one present on the machine. If you already deliver a policy, add the block to that source.- Admin console
- MDM or OS policy
- managed-settings.json
Server-managed settings reach every Claude Code user who signs in to your organization,
with nothing to install on their devices.
- In claude.ai, open Admin Settings > Claude Code > Managed settings.
- Add the
envblock to the JSON and save.
CLAUDE_CODE_USE_* provider variable, such as
CLAUDE_CODE_USE_BEDROCK, or a custom ANTHROPIC_BASE_URL. Cowork sessions never fetch
them either. Use endpoint-managed settings for those machines.3. Verify the export
- On a developer’s machine, start Claude Code and run
/status. TheSetting sourcesline should listEnterprise managed settingswith the source you used:(remote)for the admin console,(plist)or(HKLM)for MDM, and(file)or(drop-ins)for a managed settings file. - If you used the admin console, run
claude doctorand check theManaged settings (remote)line. It says whether the settings loaded, the fetch failed, or Claude Code skipped it and why. - Send a prompt in Claude Code. Within a few seconds, a trace appears in your Openlayer inference
pipeline, with the
claude_code.interactionspan at its root.
[3P telemetry] First traces export line,
followed by the reason when it fails, such as FAILED (Unauthorized). Lines prefixed
[Anthropic telemetry] describe Anthropic’s own operational telemetry and don’t indicate a problem
with this setup.
What developers can and can’t change
Managed settings sit at the top of Claude Code’s settings precedence, so no user, project, or command-line setting overrides them. With the block above in place:- The destination is locked. Because managed settings set the traces endpoint and
credentials, Claude Code removes any traces endpoint a developer sets in their shell or user
settings at startup, including
BETA_TRACING_ENDPOINT, and logs a warning in the debug log. - Tracing can’t be turned off. The enable flags and
OTEL_TRACES_EXPORTERare managed, so a developer can’t set the exporter tononeorconsole, or disable telemetry. - Repositories can’t change it. Claude Code ignores OpenTelemetry variables in a repository’s
.claude/settings.jsonand.claude/settings.local.json. - Content stays redacted. A developer can’t set the
OTEL_LOG_*values to1for their own sessions.
Privacy and data handling
With the configuration above, traces carry metadata only: model, token counts, latencies, tool names, success or failure, and the length of each prompt. Claude Code replaces prompt text with<REDACTED> and leaves out tool inputs and tool output.
To send content to Openlayer, set these variables to 1 in managed settings:
Claude Code truncates each content attribute at 60 KB by default. These flags don’t add Claude’s
replies. For those, turn on detailed tracing.
Capture Claude’s replies with detailed tracing
Claude Code’s detailed beta tracing adds the text of Claude’s replies, and the messages and tool results sent in each model request. Openlayer uses them to show the prompt as each trace’s input and Claude’s final reply as its output. Add these variables to theenv block from step 1, replacing the
OTEL_LOG_USER_PROMPTS value there:
BETA_TRACING_ENDPOINTis a base URL. Claude Code appends/v1/tracesto it and sends traces there instead of toOTEL_EXPORTER_OTLP_TRACES_ENDPOINT. It still sends theOTEL_EXPORTER_OTLP_TRACES_HEADERScredentials.OTEL_LOG_USER_PROMPTSgates the prompt and reply text. Without it, detailed traces still arrive, but each trace’s input and output are empty.- Detailed tracing doesn’t use
otelHeadersHelper. Set the credentials inOTEL_EXPORTER_OTLP_TRACES_HEADERS. - Claude Code also sends logs to
/v1/logsunder the same base URL. Openlayer doesn’t ingest logs, so those requests fail and the debug log shows anOTEL diag errorfor each. Traces are unaffected.

claude -p sessions and the Agent SDK don’t need
the allowlist. For every attribute it adds, see Traces
(beta) in Anthropic’s monitoring
guide.
Which Claude surfaces are covered
The OTLP configuration on this page applies wherever Claude Code reads managed settings:
The two integrations differ in plan, direction, and data:
- Claude Code OTLP export (this page) works on Claude for Teams and Claude for Enterprise. Claude Code pushes traces to Openlayer as each developer works.
- Claude Compliance requires Claude for Enterprise. Openlayer pulls transcripts of claude.ai chats, Cowork sessions, and Claude Code sessions from Anthropic’s Compliance API on a schedule.
Rotate the API key with a headers helper
To avoid distributing a long-lived API key, point Claude Code at a script that prints the headers instead. Deploy the script to each machine, then replaceOTEL_EXPORTER_OTLP_TRACES_HEADERS in
your managed settings with the top-level otelHeadersHelper key:
otelHeadersHelper failed in the session and in /status.
The helper doesn’t apply to detailed tracing,
which only sends the credentials in OTEL_EXPORTER_OTLP_TRACES_HEADERS.
Troubleshooting
For every Claude Code telemetry setting, see Anthropic’s monitoring
guide.