Sentry Vercel AI integration records inputs and outputs by default

Sentry's Vercel AI integration records inputs and outputs by default when genAI collection is on. Check what Sume tool calls and results put in spans.

5 min readSume
All posts

If your app calls Sume through the Vercel AI SDK and you use Sentry, the telemetry may include more than you expect. The Sentry Vercel AI integration page says recordInputs and recordOutputs default to true when dataCollection.genAI is enabled, and that it is enabled by default, read 2026-10-03. It also says not to combine the integration with the AI SDK v7 registerTelemetry API.

What ends up in a span

For a Sume workflow, the inputs and outputs are the model messages and tool calls. A create call carries a prompt, an idempotency_key and options such as max_spend_usd. A result carries job state and asset URLs. The Sume jobs guide describes status and result envelopes; whatever is in them can be recorded.

Sentry recording defaults and what to decide, read 2026-10-03.
SettingDefaultDecision for Sume tools
recordInputstrue with genAI collection onPrompts and brand copy are recorded unless you turn it off
recordOutputstrue with genAI collection onResult URLs and job envelopes are recorded
dataCollection.genAIEnabledTurn off, or scope it, if prompts are sensitive
registerTelemetry (AI SDK v7)Do not combinePick one telemetry path

What not to rely on

The Sentry page does not say how long spans are retained or who can read them in your project; check your Sentry settings. Do not assume that a credential is safe because it is in a header: a client that logs request options could capture one. Keep keys in the transport configuration and out of prompts and tool arguments.

Turning it down

If you leave recording on, treat the trace store as a copy of your prompts and treat access to it accordingly.

  • Set recordInputs and recordOutputs to false for flows that handle unreleased creative or customer data.
  • Keep job ids and status in your own logs, which is enough to debug a stuck job through jobs_result.
  • Remember that an idempotency key is not a secret, but it identifies a paid action.
  • Review the integration after every AI SDK major upgrade, since the page warns about v7 telemetry.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume