Skip to content

Telemetry (on by default) ​

jshookmcp ships built-in OpenTelemetry instrumentation: it exports tool-call and search behaviour over the standard OTLP/HTTP protocol. On by default — with zero configuration, data goes to the project maintainer's ingress (minimal content, see the table below; identified only by an anonymous install.id).

To ship to your own backend (a self-hosted opentelemetry-collector, SigNoz, Grafana Cloud) or turn it off entirely, use these environment variables.

Configuration ​

Set these in .env (or the MCP server process environment):

bash
# Ship to your own backend:
OTEL_EXPORTER_OTLP_ENDPOINT=<endpoint-url>
OTEL_EXPORTER_OTLP_HEADERS="authorization=Bearer <token>"
# Turn it off entirely (zero network, zero overhead):
JSHOOK_OBSERVABILITY_EXPORTER=none

What is collected (minimal by design) ​

SignalContentNever includes
tool.execute spantool name, domain, duration, success/failuretool arguments and response contents are never collected
search.query spanquery text (see policy below), top-K, result count, latency, BM25 confidence score, vector participationsearch result contents
search_feedback_used metricrank bucket of the invoked tool (top1/3/5/10) + tool name—
tool.execute span argumentsargument KEY NAMES only by default (shape — keys are already public in the tool schemas; values are never collected). Setting JSHOOK_OTLP_TOOL_ARGS=truncated/full opts into values, with credential-ish keys (authorization/cookie/token/secret…) masked as *** and a total size capfull argument values are not collected by default
Resource identityservice.name=jshookmcp, per-process service.instance.id, anonymous random install UUID install.idno hostname, no username, no IP, no machine fingerprint — install.id is a random UUID generated locally on first run

Query text policy (JSHOOK_OTLP_QUERY_TEXT) ​

Search queries can contain your own sensitive material (target URLs, tokens, sample content). The default truncated sends only the first 64 characters plus an overflow marker:

bash
JSHOOK_OTLP_QUERY_TEXT=off         # never send query text (numeric stats still flow)
JSHOOK_OTLP_QUERY_TEXT=truncated   # default: first 64 chars + …(+N)
JSHOOK_OTLP_QUERY_TEXT=full        # full text (use only against a private endpoint)

Turning it off ​

Remove the variables above and the exporter reverts to the default no-op (no network activity). The anonymous install.id lives in ~/.jshookmcp/state/install-id — delete that file to reset the identity.

Proxied networks: the exporter automatically honors HTTPS_PROXY/ALL_PROXY environment variables (NO_PROXY entries and localhost endpoints always connect directly) — no extra configuration needed.

Other backends ​

JSHOOK_OBSERVABILITY_EXPORTER=memory keeps spans/metrics in process memory (diagnostics); none is the default no-op.

Released under AGPL-3.0-only