Stores the project-level OTLP trace-export settings. The auth secret is referenced only (headers_secret_ref); the raw value is never accepted or stored. Bumps the generation counter and marks the config pending for downstream delivery. The project scope is carried by the route id path parameter and the org is derived from that project.
Body
Required
Typed JSON config
-
ContentMode selects span content redaction. Empty means metadata_only.
Values are
metadata_onlyorfull. -
EgressMode selects where spans are delivered. Empty means platform_only.
Values are
platform_only,platform_and_customer_mirror, orcustomer_only. -
Enabled is a pointer so the handler can distinguish an omitted field (nil, rejected) from an explicit false (a valid "disable export" request).
-
Endpoint is the customer's OTLP/HTTP endpoint. Required when enabled. Must be https and must not point at an internal/loopback address (see Validate).
Maximum length is
2048. -
Headers holds NON-SECRET export headers a preset requires (e.g. a workspace id). Secret values must never be placed here — use HeadersSecretRef.
-
HeadersSecretRef is a pointer to the single stored auth secret (typically an API key). It is a reference — never the secret value. Must be scoped to the caller's project (see Validate).
Maximum length is
512. -
InsecureSkipVerify disables TLS verification of the customer endpoint. A pointer so nil (verify, the default) is distinct from an explicit opt-out; the UI surfaces enabling this as a deliberate reduction in security.
-
Protocol is the outbound OTLP protocol. v1 supports http/protobuf only.
Value is
http/protobuf. -
ResourceAttributes are extra OTLP resource attributes stamped onto every span sent to the customer endpoint (e.g. a destination-required project/model identifier). Which keys a given destination requires comes from its preset (see pkg/traceexportconfig/presets); values are always customer-supplied, since they typically name a project on the destination's own side that this platform has no way to look up.
-
SamplingPolicy selects the head sampler applied before export.
-
SecretHeaderName is the header name the referenced secret's value is sent as (e.g. "api_key"), taken from the preset's secret_header_keys or entered by the user for a custom destination. The platform composes the outbound ": " header line, so the stored secret is always the bare value (never a pre-formatted header line). Required when HeadersSecretRef is set (see Validate).
Maximum length is
128.
Responses
-
Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence.
-
OK
-
Invalid config
-
Missing or invalid credentials
-
Caller lacks project-owner permission
-
Config exceeds 16 KB
curl \
--request PUT 'https://agentengine.mongodb.com/api/v1/projects/{id}/trace-export/config' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{
"content_mode": "metadata_only",
"egress_mode": "platform_only",
"enabled": true,
"endpoint": "string",
"headers": {
"additionalProperty1": "string",
"additionalProperty2": "string"
},
"headers_secret_ref": "string",
"insecure_skip_verify": true,
"protocol": "http/protobuf",
"resource_attributes": {
"additionalProperty1": "string",
"additionalProperty2": "string"
},
"sampling_policy": {
"ratio": 42.0,
"type": "always_on"
},
"secret_header_name": "string"
}'
{
"content_mode": "metadata_only",
"egress_mode": "platform_only",
"enabled": true,
"endpoint": "string",
"headers": {
"additionalProperty1": "string",
"additionalProperty2": "string"
},
"headers_secret_ref": "string",
"insecure_skip_verify": true,
"protocol": "http/protobuf",
"resource_attributes": {
"additionalProperty1": "string",
"additionalProperty2": "string"
},
"sampling_policy": {
"ratio": 42.0,
"type": "always_on"
},
"secret_header_name": "string"
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation supports text/event-stream, which the Accept header excludes. Remove unsupported media-type parameters or accept this type with a positive q value.",
"error": 406,
"errorCode": "UNACCEPTABLE_MEDIA_TYPE",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "The requested API version is not supported. Supported versions: 2026-09-20-preview.",
"error": 406,
"errorCode": "UNSUPPORTED_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"generation": 42,
"updated_at": "string"
}
{
"generation": 42,
"updated_at": "string"
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}