OpenTelemetry spans for MCP tools: tag the Sume request_id

Claude Code v2.1.283 adds MCP tool outputs to OpenTelemetry spans. Put the Sume request_id on the span and keep signed URLs off it.

4 min readSume
All posts

Claude Code v2.1.283 adds MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTEL_LOG_TOOL_CONTENT=1, per its release notes. When a Sume call fails, the one value worth reading off that span is the request_id in the error body, which the Sume docs say is safe to share.

Why this matters

Tool outputs on spans end up in your tracing backend, which usually has wider access than your secrets store. A Sume job result can contain artifact URLs. A request id is built for sharing; a URL or key is not.

What to keep and what to drop

Span hygiene for Sume tool outputs (read 2026-10-03)
ValueOn the span?Why
request_id from error.request_idYesDocs: safe to share with support
job_idYesJoins to status and result
API key or bearer tokenNeverSpends your balance
Signed or raw media URLsNoDocs say not to include them in reports
Private workspace or user idsNoDocs say not to include them

The error envelope

Sume errors have an error object with code, message, request_id and details. The id is also exposed in response headers. A 429 may carry retry-after; a queue_full 429 means the workspace queue is full until an existing job finishes.

Setting the attribute

Wrap your Sume call and set attributes on the active span. This sketch uses the OpenTelemetry API for JavaScript.

import { trace } from "@opentelemetry/api";

export async function sumeCall(path: string, body: unknown) {
  const span = trace.getActiveSpan();
  const res = await fetch(`https://api.sume.com${path}`, {
    method: "POST",
    headers: {
      Authorization: `Bearer ${process.env.SUME_API_KEY}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify(body),
  });
  const json = await res.json();
  const id = json?.error?.request_id ?? json?.request_id;
  if (id) span?.setAttribute("sume.request_id", String(id));
  span?.setAttribute("sume.http_status", res.status);
  return json;
}

A caution

Your agent client records tool outputs on its own spans, outside code you control, once content logging is on. Leave OTEL_LOG_TOOL_CONTENT unset unless you need it, check for content redaction in your collector, and do not rely on the post-hoc attribute alone.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume