Safe diagnostic information without sharing secrets
What to include in a report, and what to redact first.
The fastest way to get a ticket resolved is to include the full failing request and response — but a few things should never leave your machine:
Never include
- Your raw API key, password, MFA code, or recovery phrase
- Another user's personal data beyond what's strictly needed to demonstrate the issue
Safe to include
- The exact endpoint and method (e.g.
POST /api/Address/create) - The full response body, including the
messagefield — see understanding the API response envelope - The approximate time the request was made
- Your API key's last few characters only, if you need to reference which key was used — never the full value
Redacting a request before sharing it
Replace the key's value with something obviously fake, like PTERI_API_KEY=***redacted***, before pasting a request into a ticket, a log, or anywhere else. See also protecting an API credential.