Skip to main content
The gateway logs the method, host, path, status, and latency of every request that reaches your . A logging policy also saves headers, query data, or bodies for the requests it matches. Use it to debug a route. It never rejects a request or changes what your app receives. To add one, open the app, go to Policies, click Add Policy, and pick Logging.

Settings

Each setting turns on one kind of data. In the dashboard all five start on, so check the switches before you save. In the API they all default to false, so a policy with none set saves nothing extra.
boolean
default:"false"
Save request headers, plus the user agent and client IP.
boolean
default:"false"
Save response headers.
boolean
default:"false"
Save the request body, up to 1 MiB.
boolean
default:"false"
Save the response body, up to 1 MiB.
boolean
default:"false"
Save the query string and parameters. It’s separate from headers because URLs often carry secrets like ?api_key=....
Example: capture everything on one debugging route

What gets saved

  • Several matching policies combine. A request matched by a requestHeaders policy and a requestBody policy gets both saved. A policy with no match expressions applies to every request.
  • Bodies are cut off at 1 MiB in each direction in the log. The request and response themselves are never cut. Streaming requests are covered too.
  • Rejected requests aren’t logged, whatever the logging policy says.

What’s always redacted

These are replaced with [REDACTED] before anything is saved:
  • The Authorization header.
  • Every header and query parameter listed as a key location in any API key authentication policy, even turned-off ones. When a query parameter is redacted, the saved query string can be in a different order or encoding than the original.
  • Body fields marked x-unkey-redact: true in your OpenAPI spec, when an OpenAPI validation policy is on.

Where to see the data

Saved data shows up in the project’s Requests view in the dashboard and in the gateway_requests_v1 analytics table. The header, query, and body columns are empty for requests no logging policy matched.

Next steps

OpenAPI validation policy

Mark body fields for redaction with x-unkey-redact.

Gateway policies

Match expressions that pick which requests to capture.
Last modified on September 29, 2026