English
Telemetry (on by default)
jshookmcp ships built-in OpenTelemetry instrumentation: it exports tool-call and search behaviour over the standard OTLP/HTTP protocol. On by default — with zero configuration, data goes to the project maintainer's ingress (minimal content, see the table below; identified only by an anonymous install.id).
To ship to your own backend (a self-hosted opentelemetry-collector, SigNoz, Grafana Cloud) or turn it off entirely, use these environment variables.
Configuration
Set these in .env (or the MCP server process environment):
bash
# Ship to your own backend:
OTEL_EXPORTER_OTLP_ENDPOINT=<endpoint-url>
OTEL_EXPORTER_OTLP_HEADERS="authorization=Bearer <token>"
# Turn it off entirely (zero network, zero overhead):
JSHOOK_OBSERVABILITY_EXPORTER=noneWhat is collected (minimal by design)
| Signal | Content | Never includes |
|---|---|---|
tool.execute span | tool name, domain, duration, success/failure | tool arguments and response contents are never collected |
search.query span | query text (see policy below), top-K, result count, latency, BM25 confidence score, vector participation | search result contents |
search_feedback_used metric | rank bucket of the invoked tool (top1/3/5/10) + tool name | — |
tool.execute span arguments | argument KEY NAMES only by default (shape — keys are already public in the tool schemas; values are never collected). Setting JSHOOK_OTLP_TOOL_ARGS=truncated/full opts into values, with credential-ish keys (authorization/cookie/token/secret…) masked as *** and a total size cap | full argument values are not collected by default |
| Resource identity | service.name=jshookmcp, per-process service.instance.id, anonymous random install UUID install.id | no hostname, no username, no IP, no machine fingerprint — install.id is a random UUID generated locally on first run |
Query text policy (JSHOOK_OTLP_QUERY_TEXT)
Search queries can contain your own sensitive material (target URLs, tokens, sample content). The default truncated sends only the first 64 characters plus an overflow marker:
bash
JSHOOK_OTLP_QUERY_TEXT=off # never send query text (numeric stats still flow)
JSHOOK_OTLP_QUERY_TEXT=truncated # default: first 64 chars + …(+N)
JSHOOK_OTLP_QUERY_TEXT=full # full text (use only against a private endpoint)Turning it off
Remove the variables above and the exporter reverts to the default no-op (no network activity). The anonymous install.id lives in ~/.jshookmcp/state/install-id — delete that file to reset the identity.
Proxied networks: the exporter automatically honors HTTPS_PROXY/ALL_PROXY environment variables (NO_PROXY entries and localhost endpoints always connect directly) — no extra configuration needed.
Other backends
JSHOOK_OBSERVABILITY_EXPORTER=memory keeps spans/metrics in process memory (diagnostics); none is the default no-op.