---
title: "Data Collection"
description: "See what data the Sentry Laravel SDK collects when you use the data_collection option, and how to control it."
url: https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection/
---

# Data Collection for Laravel

Sentry takes data privacy very seriously and has default settings in place that prioritize data safety, especially when it comes to personally identifiable information (PII) data. When you add the Sentry SDK to your application, you allow it to collect data and send it to Sentry during the runtime of your application.

The category types and amount of data collected vary, depending on the integrations you've enabled in the Sentry SDK. This page lists data categories that the Sentry Laravel SDK collects when you use the `data_collection` option.

Options to control data collection

You can control the categories listed here with the `data_collection` option, which lets you opt in or out of each data category individually. The option is available in version 4.29.0 and later.

Configure it with the `data_collection` key in `config/sentry.php`. The default value, `null`, keeps the legacy options. An empty array applies the defaults of every category:

```php
'data_collection' => [],
```

The [`send_default_pii` option](https://docs.sentry.io/platforms/php/guides/laravel/configuration/options.md#send_default_pii) remains fully supported until the next major version. Without `data_collection`, the SDK collects conservatively, and the defaults described on [Data Collected](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collected.md) apply.

As soon as you pass a `data_collection` array, the categories you don't set explicitly fall back to the defaults described on this page, which are more permissive. For example, cookies, the logged-in user, request and response bodies, SQL query bindings, and AI prompts and responses are then collected unless you opt out. Values whose keys match the built-in sensitive denylist are always scrubbed.

If you set both, `send_default_pii` is ignored. The same applies to the `context_lines` option, which `data_collection` replaces with `frame_context_lines`, and to the `breadcrumbs.sql_bindings` and `tracing.sql_bindings` options, which `data_collection` replaces with `database_query_data`. Run `php artisan about` to check whether `data_collection` is set.

Regardless of these options, you can always scrub any data before it's sent to Sentry. See [Scrubbing Sensitive Data](https://docs.sentry.io/platforms/php/guides/laravel/data-management/sensitive-data.md) for details.

## [HTTP Headers](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#http-headers)

By default, the SDK collects the headers of the requests your application handles and of the responses it sends, as well as the request and response headers of the Laravel HTTP client. Values of sensitive headers are scrubbed. Use `http_headers` to control this. A single behavior applies to both request and response headers:

```php
'data_collection' => [
    // Collect nothing:
    'http_headers' => ['mode' => 'off'],
    // Or only send real values for the listed headers:
    // 'http_headers' => ['mode' => 'allowList', 'terms' => ['content-type']],
    // Or configure request and response headers separately:
    // 'http_headers' => [
    //     'request' => ['mode' => 'denyList', 'terms' => ['-ip']],
    //     'response' => ['mode' => 'off'],
    // ],
],
```

Values whose keys match Sentry's built-in sensitive denylist (such as `auth`, `token`, or `password`) are always scrubbed, while the keys are kept. The `Cookie` and `Set-Cookie` headers are never included in the collected headers. Use the [`cookies`](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#cookies) category to control them instead. See [Key-Value Collection Behavior](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#key-value-collection-behavior) below for details on `mode` and `terms`.

## [Cookies](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#cookies)

By default, the SDK collects cookies, with sensitive values scrubbed. Opt out with `['mode' => 'off']`, or restrict which values are sent using `allowList` or `denyList` mode:

```php
'data_collection' => [
    'cookies' => ['mode' => 'off'],
    // Or only send the real value of the `locale` cookie:
    // 'cookies' => ['mode' => 'allowList', 'terms' => ['locale']],
],
```

## [Information About Logged-in User](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#information-about-logged-in-user)

By default, when a user is authenticated, including with Laravel Sanctum, the SDK sends the user's ID and its `email` (or `mail`) and `username` attributes. This only applies to users that are Eloquent models.

The `user_info` category controls this, as well as the user's IP address (see the next section). User data you set with [`setUser()`](https://docs.sentry.io/platforms/php/guides/laravel/enriching-events/identify-user.md) is always sent to Sentry, regardless of `data_collection`.

## [Users' IP Address](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#users-ip-address)

By default, the SDK sends the user's IP address, as resolved by Laravel with your trusted proxies configuration. Disable it, together with the logged-in user information, by setting `user_info` to `false`:

```php
'data_collection' => [
    'user_info' => false,
],
```

Even when this is disabled, IP addresses can still reach Sentry through collected HTTP headers, cookies, or query parameters (for example, the `X-Forwarded-For` header). Add these terms to the deny lists for those categories so their values are filtered:

```php
'data_collection' => [
    'user_info' => false,
    'http_headers' => [
        'mode' => 'denyList',
        'terms' => ['forwarded', '-ip', 'remote-', 'via', '-user'],
    ],
    'cookies' => [
        'mode' => 'denyList',
        'terms' => ['forwarded', '-ip', 'remote-', 'via', '-user'],
    ],
    'url_query_params' => [
        'mode' => 'denyList',
        'terms' => ['forwarded', '-ip', 'remote-', 'via', '-user'],
    ],
],
```

## [Request URL](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#request-url)

The full URL of the requests your application handles and of the requests made with the Laravel HTTP client is sent to Sentry. Depending on your application, this could contain PII data. Credentials in the URL (for example, `https://user:password@example.com`) are replaced with `[Filtered]`, and query parameters are filtered as described in [Request Query String](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#request-query-string).

## [Request Query String](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#request-query-string)

By default, the SDK sends the query string of incoming and outgoing HTTP requests. Depending on your application, this could contain PII data. Values whose keys match the built-in sensitive denylist (such as `auth`, `token`, `password`, and `secret`) are replaced with `[Filtered]`.

Use `url_query_params` to control this. Set it to `['mode' => 'off']` to disable collection entirely, or use `allowList` or `denyList` mode to filter which values are sent:

```php
'data_collection' => [
    'url_query_params' => ['mode' => 'off'],
],
```

Sentry also has some additional [server-side data scrubbing](https://docs.sentry.io/security-legal-pii/scrubbing/server-side-scrubbing.md) in place to remove sensitive data from the query string.

## [Request and Response Bodies](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#request-and-response-bodies)

By default, the SDK collects HTTP request and response bodies. Whether a body is sent depends on its type and size:

* **The type of the body:**

  * JSON and form bodies are sent, with values whose keys match the built-in sensitive denylist scrubbed
  * Bodies in other formats, or bodies that can't be parsed, are replaced with `[Filtered]`
  * Streamed responses and file downloads aren't sent to Sentry
  * Uploaded files are never sent to Sentry

* **The size of the body:** There's a [`max_request_body_size` option](https://docs.sentry.io/platforms/php/guides/laravel/configuration/options.md#max_request_body_size) that's set to `medium` by default. Bodies that exceed the size limit aren't sent to Sentry.

To disable body collection, set `http_bodies` to an empty array, or provide only the body types you want:

```php
'data_collection' => [
    // Collect only incoming request bodies:
    'http_bodies' => ['incomingRequest'],
],
```

The valid body types are:

* `incomingRequest`: The body of the request your application handles.
* `outgoingResponse`: The body of the response your application sends.
* `outgoingRequest`: The body of a request sent with the Laravel HTTP client.
* `incomingResponse`: The body of a response received with the Laravel HTTP client.

## [Database Query Parameters](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#database-query-parameters)

By default, the SDK attaches the bindings of SQL queries to `db.sql.query` breadcrumbs and, when [tracing](https://docs.sentry.io/platforms/php/guides/laravel/tracing.md) is enabled, to `db.sql.query` spans. The same setting controls the command parameters on `db.redis` spans, if you enabled `tracing.redis_commands`. Disable this by setting `database_query_data` to `false`:

```php
'data_collection' => [
    'database_query_data' => false,
],
```

Query bindings are usually positional rather than named, so the built-in sensitive denylist can't recognize them and their values are sent as is. If your queries contain sensitive values, such as passwords or tokens, set `database_query_data` to `false`.

The `breadcrumbs.sql_bindings` and `tracing.sql_bindings` options are ignored when you use `data_collection`.

## [Queue Jobs](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#queue-jobs)

When [tracing](https://docs.sentry.io/platforms/php/guides/laravel/tracing.md) is enabled, the SDK attaches the data of queued jobs to `queue.publish` and `queue.process` spans, with values whose keys match the built-in sensitive denylist scrubbed. This only applies to jobs pushed with an array of data, such as `Queue::push(ProcessPodcast::class, ['podcast_id' => 1])`. The data of job classes, such as `ProcessPodcast::dispatch($podcast)`, isn't collected.

Disable this by setting `queues` to `false`:

```php
'data_collection' => [
    'queues' => false,
],
```

## [Laravel AI](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#laravel-ai)

When [Agent Tracing](https://docs.sentry.io/platforms/php/guides/laravel/agent-tracing.md) is active, Sentry collects metadata about agent activity. This can include agent names, provider names, model names, token usage, streaming state, finish reasons, conversation IDs, and tool names.

By default, the SDK also collects the inputs and outputs of LLMs and tools:

* **Inputs:** Prompts, system instructions, attachments, tool definitions, tool call arguments, embedding inputs, and the questions of classifications.
* **Outputs:** Assistant responses, tool call results, and the answers of classifications.

The SDK truncates large message payloads and replaces binary or base64 content with a placeholder before sending it to Sentry. Use `gen_ai` to opt out of inputs, outputs, or both:

```php
'data_collection' => [
    'gen_ai' => [
        'inputs' => false,
        'outputs' => false,
    ],
],
```

## [Source Context](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#source-context)

When an unhandled exception is sent to Sentry, a snapshot of the source code surrounding the line where the error originates is sent with it.

Use `frame_context_lines` to control how many lines above and below each stack frame are captured. It defaults to `5`. Set it to `0` to only send the line where the error occurred:

```php
'data_collection' => [
    'frame_context_lines' => 0,
],
```

## [Local Variables In Stack Trace](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#local-variables-in-stack-trace)

When unhandled errors and exceptions are sent to Sentry, the names and values of local variables that were set when the errors occurred are sent at the same time.

`stack_frame_variables` controls this and defaults to `true`. Values of variables whose names match the built-in sensitive denylist are scrubbed. Set it to `false` to stop sending variables, or use a key-value behavior to filter which variables are sent by name:

```php
'data_collection' => [
    'stack_frame_variables' => false,
    // Or filter additional variables by name:
    // 'stack_frame_variables' => ['mode' => 'denyList', 'terms' => ['email']],
],
```

Setting `zend.exception_ignore_args=1` in your `php.ini` prevents PHP from providing variables to the SDK, regardless of `stack_frame_variables`. On some distributions, this setting is already set to `1` by default.

## [`data_collection` Reference](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#data_collection-reference)

### [Keys](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#keys)

| Key                     | Type                                                       | Default                                                                          | Description                                                                                                                                                                                        |
| ----------------------- | ---------------------------------------------------------- | -------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `user_info`             | `bool`                                                     | `true`                                                                           | Populate user fields, such as the ID, email address, and IP address, from instrumentation.                                                                                                         |
| `cookies`               | key-value behavior                                         | `['mode' => 'denyList']`                                                         | Collect cookies.                                                                                                                                                                                   |
| `http_headers`          | key-value behavior, or `['request' => …, 'response' => …]` | `['mode' => 'denyList']`                                                         | Collect HTTP headers. A single behavior applies to both request and response headers.                                                                                                              |
| `http_bodies`           | `string[]`                                                 | `['incomingRequest', 'outgoingRequest', 'incomingResponse', 'outgoingResponse']` | Body types to collect. Set to `[]` to disable.                                                                                                                                                     |
| `url_query_params`      | key-value behavior                                         | `['mode' => 'denyList']`                                                         | Collect URL query parameters.                                                                                                                                                                      |
| `database_query_data`   | `bool`                                                     | `true`                                                                           | Collect SQL query bindings and Redis command parameters.                                                                                                                                           |
| `queues`                | `bool`                                                     | `true`                                                                           | Collect the data of queued jobs.                                                                                                                                                                   |
| `gen_ai`                | `['inputs' => bool, 'outputs' => bool]`                    | `['inputs' => true, 'outputs' => true]`                                          | Collect the inputs and outputs of LLMs and tools.                                                                                                                                                  |
| `stack_frame_variables` | `bool` or key-value behavior                               | `true`                                                                           | Include variable values captured within stack frames. Accepts a boolean (`true` collects all variables, `false` collects none) or a key-value behavior to filter which variables are sent by name. |
| `frame_context_lines`   | `int`                                                      | `5`                                                                              | Source code lines captured above and below each stack frame.                                                                                                                                       |

Invalid values are ignored and the default is used instead. The SDK logs a debug message through the configured [`logger`](https://docs.sentry.io/platforms/php/guides/laravel/configuration/options.md#logger) when this happens.

### [Key-Value Collection Behavior](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#key-value-collection-behavior)

The `cookies`, `http_headers`, `url_query_params`, and `stack_frame_variables` categories take an array with a `mode` and an optional list of `terms`:

```php
['mode' => 'denyList', 'terms' => ['forwarded', '-ip', 'remote-', 'via', '-user']]
```

| `mode`        | Behavior                                                                                                              |
| ------------- | --------------------------------------------------------------------------------------------------------------------- |
| `'denyList'`  | Collect everything, replacing the value of any key matching `terms` (in addition to the built-in sensitive denylist). |
| `'allowList'` | Only keys matching `terms` send their real value. Every other key is kept, but its value is replaced.                 |
| `'off'`       | Collect nothing in this category.                                                                                     |

If you omit `mode`, it defaults to `'denyList'`. `terms` match partially and case-insensitively, so `'-ip'` matches `X-Real-IP`. Filtered values are replaced with `[Filtered]`; the key itself is always preserved. The built-in sensitive denylist (`auth`, `token`, `secret`, `password`, `key`, `session`, and similar) always applies, even in `'allowList'` mode.

### [Preserving `send_default_pii` Behavior](https://docs.sentry.io/platforms/php/guides/laravel/data-management/data-collection.md#preserving-send_default_pii-behavior)

To keep roughly the conservative collection you get with `send_default_pii` set to `false` while using `data_collection`, opt out of each category explicitly:

```php
'data_collection' => [
    'user_info' => false,
    'cookies' => ['mode' => 'off'],
    'http_headers' => [
        'request' => [
            'mode' => 'denyList',
            'terms' => ['forwarded', '-ip', 'remote-', 'via', '-user'],
        ],
        'response' => ['mode' => 'off'],
    ],
    'url_query_params' => [
        'mode' => 'denyList',
        'terms' => ['forwarded', '-ip', 'remote-', 'via', '-user'],
    ],
    'http_bodies' => ['incomingRequest'],
    'database_query_data' => false,
    'queues' => false,
    'gen_ai' => [
        'inputs' => false,
        'outputs' => false,
    ],
],
```

If you previously set `send_default_pii` to `true`, set `data_collection` to an empty array to use the defaults described on this page.
