This page lists every option you can pass to atatusRum.init(). licenseKey and appName are required. Everything else has a default, so start small and add options as you need them.

For log-specific options, see Logs.

Identity and transport

These options label your data and control where it is sent:

Option Default Purpose
licenseKey Required Identifies your account
appName Required Application name shown in the dashboard
env None Environment tag, such as production or staging
version None Application version, used to compare releases
service Falls back to appName Service name
serverUrl None Custom intake host. Leave unset in production
Warning:

appName identifies your application to the intake, and data sent without it is rejected. appName and service are the same identity: setting either one fills both, so an application that only sets service is also valid. Setting neither means nothing you send is stored.

Sampling

Sampling controls how much data you collect. All rates are percentages from 0 to 100:

Option Default Purpose
sessionSampleRate 100 Percentage of sessions collected
sessionReplaySampleRate 0 Percentage of collected sessions that also record replay
traceSampleRate 100 Percentage of requests given trace headers
telemetrySampleRate 20 The agent's own health telemetry
profilingSampleRate 0 Continuous profiling. Loads an extra file
Note:

sessionReplaySampleRate applies to sessions that sessionSampleRate already kept, so the two multiply. Setting the session rate to 50 and the replay rate to 30 records replay for 15% of all sessions, not 30%.

What gets tracked

Views, errors, and web vitals are collected automatically. Turn on the rest as you need them:

Option Default Purpose
trackUserInteractions false Collect clicks and taps as actions
trackResources false Collect timing for requests and assets
trackLongTasks false Collect main-thread long tasks
trackResourceHeaders false true, or a list of headers to attach to resources
trackViewsManually false Stop automatic views so you can call startView()
trackAnonymousUser false Keep an anonymous ID across sessions
actionNameAttribute None Extra attribute to read action names from, checked alongside the built-in data-atatus-action-name
excludedActivityUrls [] URLs that should not count as page activity
allowedGraphQlUrls [] GraphQL endpoints to read operation name and type from

These options control how sessions are stored and when data is allowed to leave the browser:

Option Default Purpose
trackingConsent granted granted or not-granted. Nothing is sent until granted
sessionPersistence cookie cookie or local-storage
trackSessionAcrossSubdomains false Share one session across subdomains
useSecureSessionCookie false Set the session cookie as Secure
usePartitionedCrossSiteSessionCookie false Partitioned cross-site cookie
storeContextsAcrossPages false Keep global and user context in local storage
allowedTrackingOrigins None Restrict which origins may run the agent
allowUntrustedEvents false Accept synthetic events, useful in tests
compressIntakeRequests false Compress payloads in a worker. Needs workerUrl
workerUrl None URL of the compression worker you host
silentMultipleInit false Suppress the warning when init() runs twice
remoteConfiguration None { id, sync, required } for server-driven config
enableExperimentalFeatures [] Turn on unreleased behavior by name

If you need consent before collecting anything, start with not-granted and switch once the user agrees:

atatusRum.init({
  licenseKey: '<license-key>',
  appName: 'Storefront',
  trackingConsent: 'not-granted',
});

// Later, once the user accepts.
atatusRum.setTrackingConsent('granted');

Nothing is sent while consent is not-granted, and nothing is buffered for later.

Tracing

Tracing attaches headers to the requests your application makes, so a click in RUM links to the backend trace it caused. Your backend must be instrumented with Application Monitoring:

atatusRum.init({
  licenseKey: '<license-key>',
  appName: 'Storefront',
  allowedTracingUrls: [
    /^https?:\/\/[^/]+\/api(?:\/.*)?$/,  // regular expression
    'https://api.example.com',           // prefix match
    (url) => url.startsWith('/v1/'),     // predicate
  ],
  traceSampleRate: 100,
  traceContextInjection: 'sampled',      // 'all' or 'sampled'
  propagateTraceBaggage: true,
});
Warning:

Every URL matched by allowedTracingUrls receives trace headers. A pattern broad enough to catch third-party endpoints sends those headers cross-origin, and can cause CORS preflight failures on services that do not expect them. Match only your own API.

Change events before they are sent

beforeSend runs on every event just before it leaves the browser. Use it to redact data or to drop an event entirely by returning false:

atatusRum.init({
  licenseKey: '<license-key>',
  appName: 'Storefront',
  beforeSend: (event) => {
    event.view.url = scrub(event.view.url);
    if (event.type === 'resource' && event.resource) {
      event.resource.url = scrub(event.resource.url);
    }
    return true;
  },
});

This is the right place to strip credentials that appear in URLs, such as password reset tokens, invite links, and API keys.

Next steps