{"article":{"slug":"introducing-cloudflare-traces-follow-requests-through-our-entire-platform","title":"Introducing Cloudflare Traces: follow requests through our entire platform","subtitle":null,"summary":"Cloudflare Traces enters open beta: automatic request-level tracing across security rules, transformations, cache, routing, Workers, and origin handling, with Trace Rules sampling, W3C context propagation, dashboard inspection, and OTLP export under unified observability pricing.","content_type":"announcement","language":"en","canonical_url":"https://blog.cloudflare.com/cloudflare-tracing/","author":{"name":"Dan Lapid, Daniel Walsh, Mar Witek, Nevi Shah","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Cloudflare","url":"https://blog.cloudflare.com/","listing_slug":null,"listing":null},"topics":[{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"},{"name":"Developer Tools","slug":"developer-tools","url":"https://listedarticles.com/topics/developer-tools"},{"name":"Observability","slug":"observability","url":"https://listedarticles.com/topics/observability"},{"name":"Cloudflare","slug":"cloudflare","url":"https://listedarticles.com/topics/cloudflare"},{"name":"OpenTelemetry","slug":"opentelemetry","url":"https://listedarticles.com/topics/opentelemetry"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1393,"reading_minutes":6,"published_at":"2026-10-02T00:00:00.000Z","added_at":"2026-10-03T03:13:25.348Z","updated_at":"2026-10-03T03:13:25.348Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/introducing-cloudflare-traces-follow-requests-through-our-entire-platform","markdown_url":"https://listedarticles.com/articles/introducing-cloudflare-traces-follow-requests-through-our-entire-platform.md","example":false,"citation":"Dan Lapid, Daniel Walsh, Mar Witek, Nevi Shah, Cloudflare. \"Introducing Cloudflare Traces: follow requests through our entire platform.\" 2 Oct 2026. https://blog.cloudflare.com/cloudflare-tracing/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.cloudflare.com/cloudflare-tracing/"},"body_markdown":"# Introducing Cloudflare Traces: follow requests through our entire platform\n\nMar Witek, Dan Lapid, Nevi Shah, and Daniel Walsh\n\nToday, we’re introducing __Cloudflare Traces__ in open beta, extending __automatic tracing beyond Workers__ to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in __OpenTelemetry__ and in making Cloudflare the most observable part of your stack.\n\nYou can now:\n\n- **__Automatically trace requests across Cloudflare__:** Capture supported platform operations in one request-level timeline, no additional set up required.\n- **Control which requests are traced** : Set a baseline sampling rate, then use__Trace Rules__ to override it for matching traffic.\n- **End-to-end trace context propagation:** Accept and forward__W3C traceparent headers__\n- **__Investigate traces in Cloudflare__:** View request timelines and span details directly in the Cloudflare dashboard.\n- **__Export traces with OpenTelemetry__:** Send your spans to any destination with a compatible Open Telemetry Protocol (OTLP)__endpoint__ .\n\nYou can __enable tracing in the Cloudflare dashboard__ on any domain or let your agent set up for you:\n\n## Giving you the visibility we use to debug Cloudflare\n\nWhen our own teams investigate, we use our own internal traces, which often include thousands of spans for a single trace, generated by dozens of services and features. This lets us dig deep into every detail of a given request. We don’t think that visibility should stop at our internal systems. __Workers Tracing__ was our first step toward exposing what happens on our platform. Last year, we launched automatic instrumentation for Worker invocations, including __outbound fetches and calls to KV, R2, D1, Durable Objects, and other Workers__. It shows the work performed inside the Workers runtime without requiring tracing code for every operation.\n\nThe goal of Cloudflare Traces is to bring the same level of visibility to **everyone** using Cloudflare, whether you’re building on Cloudflare or just have Cloudflare in front of an origin. You get to see how your traffic moved through our platform, and connect the dots between how you’ve configured Cloudflare, and how this influences request processing time, routing decisions, and more. \n\n## Follow one request end to end\n\nA request’s path through Cloudflare can be complicated! It might pass through security rules, transformations, routing, caching, or proxied to another service entirely. Cloudflare Traces __records each supported step as a span__, including its timing, outcome, and relevant attributes. Instead of reconstructing the request from separate logs and configuration, you can see the request’s path through our system in one place.\n\nYou can answer questions like:\n\n### Why was the request blocked or challenged, and which security rule took action?\n\nSee when __custom or managed rules__ evaluated the request, how long evaluation took, and the resulting action. Identify the rule responsible for a block or challenge through its span events.\n\n### Was the URL rewritten by a Transform Rule before it reached the application?\n\nYou can open the `http_request_transform` span to see each change, the request component it affected, and the rule responsible. You can also see where the transformation occurred relative to routing and origin handling.\n\n### Which Page Rules, Snippets, or Workers handled or changed the request?\n\nThe `workers_routing` span shows whether a route matched, which routing type was used, and the matching route pattern.\n\n### Was the response served from cache, and where was time spent between Cloudflare, the origin connection, and the application?\n\nYou can expand nested cache, upstream, and origin spans to see where the request spent its time. Here, you can see there was a cache miss that went to origin and spent 527ms of the 539ms getting a response.\n\n## Configure your tracing\n\nThere is no special instrumentation, config, or plugins required. Once tracing is enabled for a domain, Cloudflare generates these spans automatically. This lets you extend the trace through third-party services and back again by adhering to __open standards__. From there, you can control which requests are traced using a baseline sampling rate and __Trace Rules__.\n\n### Set a baseline sampling rate\n\nYou can enable tracing on any domain and __set a baseline sampling rate__ to balance visibility, data volume, and cost. You might trace 1% of requests during normal operation, giving you a continuous view of request behavior without collecting a trace for every request.\n\n### Configure Trace Rules\n\n__Trace Rules__ let you keep a low baseline sampling rate while capturing complete traces for a specific investigation. If one customer reports a problem, you can trace 100% of traffic for their hostname, source IP, or identifying request header while leaving everyone else at 1%. Or during an investigation, you could trace 100% of requests carrying a temporary debug header, while leaving all other traffic at the baseline. This lets you reproduce an issue without increasing tracing across the entire domain.\n\nTrace Rules use the same __Cloudflare Rules language__, so you can target paths, methods, headers, IP addresses, geographies, or combinations of those properties.\n\n### Accept and propagate trace context\n\nOne of the most common requests we hear is for true distributed tracing: a single trace that follows a request into Cloudflare, through our platform, and onward through the rest of your stack.\n\nCloudflare Traces can accept a __W3C traceparent header__ from an incoming request, allowing Cloudflare spans to join a trace that began before the request reached our platform. An __incoming propagation policy__ controls whether Cloudflare accepts that context.\n\nCloudflare can also __forward a new traceparent header to your origin__. Any other instrumented services can extract that context and continue the trace through APIs, databases, and services running on Cloudflare or elsewhere. To view everything as one connected trace, you can send both Cloudflare and application spans to the same OpenTelemetry-compatible backend.\n\n## Export traces to your observability platform\n\nYou can export Cloudflare spans over __OTLP__ to a compatible observability platform, where they appear alongside telemetry from the rest of your stack. __Configure an account-level destination__, then choose which domains send traces to it. This is part of our commitment to __OpenTelemetry__: Cloudflare represents request activity as OpenTelemetry spans and delivers them using OTLP, keeping the data portable across observability tools.\n\n## Let your agent investigate Cloudflare Traces\n\nWhen you ask a coding agent to debug a production issue, it might inspect your code and run tests, but it may not be able to see what happened to the request in production. With the __Cloudflare Observability MCP server__, your agent can leverage our __SQL API__ to query your traces (and all of your __observability data__!), giving it access to your investigation production telemetry.\n\nLet your agent find the right requests, comparing failed traces with successful ones, and identifying where their spans diverge. Since the agent can also inspect your repository, it can connect those findings to the relevant code, narrow down what needs to change, and help put up a fix for you to review.\n\n## Pricing\n\nCloudflare Traces will be a part of the __unified Cloudflare Observability pricing model__. Instead of charging by the number of spans/events, pricing is based on how much observability data you ingest and how long you retain it. New pricing will take effect across Cloudflare Tracing (and Workers Tracing!) starting December 1, 2026.\n\n| Plan | Included Usage | Retention | Additional Usage | \n|---|---|---|---|\n| Free | 0.5 GB of ingestion per day | 7 Days | Not available | \n| Paid and Enterprise | 50 GB of ingestion 10 GB-month of storage per billing cycle | Up to 1 year  (coming soon) | $0.25 per GB ingested $0.10 per GB-month stored | \n\n## What's next\n\nFollowing the open beta, we plan to launch:\n\n- **Broader automatic instrumentation:** Add more spans across both the HTTP request path (e.g.__DDoS rules__ ,__Access__ ) and the Workers execution path (e.g. Workflows, Queues, Pipelines).\n- **Authenticated context propagation:** Let trusted callers continue an existing trace without accepting context from every incoming request.\n- **Ad hoc tracing:** Capture a specific request on demand without changing the baseline sampling rate.\n- **OpenTelemetry API support in Workers:**__Continue building out our OpenTelemetry APIs__ to enable adding attributes to existing spans or getting trace context.\n- **Longer retention:** Keep trace data available for up to 365 days for longer-running investigations.\n\n## Get started\n\nFollow the __Cloudflare Traces documentation__ to trace your first request and tune sampling with Trace Rules. Cloudflare Traces is available in open beta from the dashboard, through the API, or with Terraform, with support for exporting to an OTLP destination.","body_html":"<h1 id=\"introducing-cloudflare-traces-follow-requests-through-our-entire\">Introducing Cloudflare Traces: follow requests through our entire platform</h1>\n<p>Mar Witek, Dan Lapid, Nevi Shah, and Daniel Walsh</p>\n<p>Today, we’re introducing <strong>Cloudflare Traces</strong> in open beta, extending <strong>automatic tracing beyond Workers</strong> to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in <strong>OpenTelemetry</strong> and in making Cloudflare the most observable part of your stack.</p>\n<p>You can now:</p>\n<ul><li><strong><strong>Automatically trace requests across Cloudflare</strong>:</strong> Capture supported platform operations in one request-level timeline, no additional set up required.</li><li><strong>Control which requests are traced</strong> : Set a baseline sampling rate, then use__Trace Rules__ to override it for matching traffic.</li><li><strong>End-to-end trace context propagation:</strong> Accept and forward__W3C traceparent headers__</li><li><strong><strong>Investigate traces in Cloudflare</strong>:</strong> View request timelines and span details directly in the Cloudflare dashboard.</li><li><strong><strong>Export traces with OpenTelemetry</strong>:</strong> Send your spans to any destination with a compatible Open Telemetry Protocol (OTLP)<strong>endpoint</strong> .</li></ul>\n<p>You can <strong>enable tracing in the Cloudflare dashboard</strong> on any domain or let your agent set up for you:</p>\n<h2 id=\"giving-you-the-visibility-we-use-to-debug-cloudflare\">Giving you the visibility we use to debug Cloudflare</h2>\n<p>When our own teams investigate, we use our own internal traces, which often include thousands of spans for a single trace, generated by dozens of services and features. This lets us dig deep into every detail of a given request. We don’t think that visibility should stop at our internal systems. <strong>Workers Tracing</strong> was our first step toward exposing what happens on our platform. Last year, we launched automatic instrumentation for Worker invocations, including <strong>outbound fetches and calls to KV, R2, D1, Durable Objects, and other Workers</strong>. It shows the work performed inside the Workers runtime without requiring tracing code for every operation.</p>\n<p>The goal of Cloudflare Traces is to bring the same level of visibility to <strong>everyone</strong> using Cloudflare, whether you’re building on Cloudflare or just have Cloudflare in front of an origin. You get to see how your traffic moved through our platform, and connect the dots between how you’ve configured Cloudflare, and how this influences request processing time, routing decisions, and more. </p>\n<h2 id=\"follow-one-request-end-to-end\">Follow one request end to end</h2>\n<p>A request’s path through Cloudflare can be complicated! It might pass through security rules, transformations, routing, caching, or proxied to another service entirely. Cloudflare Traces <strong>records each supported step as a span</strong>, including its timing, outcome, and relevant attributes. Instead of reconstructing the request from separate logs and configuration, you can see the request’s path through our system in one place.</p>\n<p>You can answer questions like:</p>\n<h3 id=\"why-was-the-request-blocked-or-challenged-and-which-security-rul\">Why was the request blocked or challenged, and which security rule took action?</h3>\n<p>See when <strong>custom or managed rules</strong> evaluated the request, how long evaluation took, and the resulting action. Identify the rule responsible for a block or challenge through its span events.</p>\n<h3 id=\"was-the-url-rewritten-by-a-transform-rule-before-it-reached-the-\">Was the URL rewritten by a Transform Rule before it reached the application?</h3>\n<p>You can open the <code>http_request_transform</code> span to see each change, the request component it affected, and the rule responsible. You can also see where the transformation occurred relative to routing and origin handling.</p>\n<h3 id=\"which-page-rules-snippets-or-workers-handled-or-changed-the-requ\">Which Page Rules, Snippets, or Workers handled or changed the request?</h3>\n<p>The <code>workers_routing</code> span shows whether a route matched, which routing type was used, and the matching route pattern.</p>\n<h3 id=\"was-the-response-served-from-cache-and-where-was-time-spent-betw\">Was the response served from cache, and where was time spent between Cloudflare, the origin connection, and the application?</h3>\n<p>You can expand nested cache, upstream, and origin spans to see where the request spent its time. Here, you can see there was a cache miss that went to origin and spent 527ms of the 539ms getting a response.</p>\n<h2 id=\"configure-your-tracing\">Configure your tracing</h2>\n<p>There is no special instrumentation, config, or plugins required. Once tracing is enabled for a domain, Cloudflare generates these spans automatically. This lets you extend the trace through third-party services and back again by adhering to <strong>open standards</strong>. From there, you can control which requests are traced using a baseline sampling rate and <strong>Trace Rules</strong>.</p>\n<h3 id=\"set-a-baseline-sampling-rate\">Set a baseline sampling rate</h3>\n<p>You can enable tracing on any domain and <strong>set a baseline sampling rate</strong> to balance visibility, data volume, and cost. You might trace 1% of requests during normal operation, giving you a continuous view of request behavior without collecting a trace for every request.</p>\n<h3 id=\"configure-trace-rules\">Configure Trace Rules</h3>\n<p><strong>Trace Rules</strong> let you keep a low baseline sampling rate while capturing complete traces for a specific investigation. If one customer reports a problem, you can trace 100% of traffic for their hostname, source IP, or identifying request header while leaving everyone else at 1%. Or during an investigation, you could trace 100% of requests carrying a temporary debug header, while leaving all other traffic at the baseline. This lets you reproduce an issue without increasing tracing across the entire domain.</p>\n<p>Trace Rules use the same <strong>Cloudflare Rules language</strong>, so you can target paths, methods, headers, IP addresses, geographies, or combinations of those properties.</p>\n<h3 id=\"accept-and-propagate-trace-context\">Accept and propagate trace context</h3>\n<p>One of the most common requests we hear is for true distributed tracing: a single trace that follows a request into Cloudflare, through our platform, and onward through the rest of your stack.</p>\n<p>Cloudflare Traces can accept a <strong>W3C traceparent header</strong> from an incoming request, allowing Cloudflare spans to join a trace that began before the request reached our platform. An <strong>incoming propagation policy</strong> controls whether Cloudflare accepts that context.</p>\n<p>Cloudflare can also <strong>forward a new traceparent header to your origin</strong>. Any other instrumented services can extract that context and continue the trace through APIs, databases, and services running on Cloudflare or elsewhere. To view everything as one connected trace, you can send both Cloudflare and application spans to the same OpenTelemetry-compatible backend.</p>\n<h2 id=\"export-traces-to-your-observability-platform\">Export traces to your observability platform</h2>\n<p>You can export Cloudflare spans over <strong>OTLP</strong> to a compatible observability platform, where they appear alongside telemetry from the rest of your stack. <strong>Configure an account-level destination</strong>, then choose which domains send traces to it. This is part of our commitment to <strong>OpenTelemetry</strong>: Cloudflare represents request activity as OpenTelemetry spans and delivers them using OTLP, keeping the data portable across observability tools.</p>\n<h2 id=\"let-your-agent-investigate-cloudflare-traces\">Let your agent investigate Cloudflare Traces</h2>\n<p>When you ask a coding agent to debug a production issue, it might inspect your code and run tests, but it may not be able to see what happened to the request in production. With the <strong>Cloudflare Observability MCP server</strong>, your agent can leverage our <strong>SQL API</strong> to query your traces (and all of your <strong>observability data</strong>!), giving it access to your investigation production telemetry.</p>\n<p>Let your agent find the right requests, comparing failed traces with successful ones, and identifying where their spans diverge. Since the agent can also inspect your repository, it can connect those findings to the relevant code, narrow down what needs to change, and help put up a fix for you to review.</p>\n<h2 id=\"pricing\">Pricing</h2>\n<p>Cloudflare Traces will be a part of the <strong>unified Cloudflare Observability pricing model</strong>. Instead of charging by the number of spans/events, pricing is based on how much observability data you ingest and how long you retain it. New pricing will take effect across Cloudflare Tracing (and Workers Tracing!) starting December 1, 2026.</p>\n<div class=\"table-wrap\"><table><thead><tr><th>Plan</th><th>Included Usage</th><th>Retention</th><th>Additional Usage</th></tr></thead><tbody><tr><td>Free</td><td>0.5 GB of ingestion per day</td><td>7 Days</td><td>Not available</td></tr><tr><td>Paid and Enterprise</td><td>50 GB of ingestion 10 GB-month of storage per billing cycle</td><td>Up to 1 year  (coming soon)</td><td>$0.25 per GB ingested $0.10 per GB-month stored</td></tr></tbody></table></div>\n<h2 id=\"what-s-next\">What&#39;s next</h2>\n<p>Following the open beta, we plan to launch:</p>\n<ul><li><strong>Broader automatic instrumentation:</strong> Add more spans across both the HTTP request path (e.g.<strong>DDoS rules</strong> ,<strong>Access</strong> ) and the Workers execution path (e.g. Workflows, Queues, Pipelines).</li><li><strong>Authenticated context propagation:</strong> Let trusted callers continue an existing trace without accepting context from every incoming request.</li><li><strong>Ad hoc tracing:</strong> Capture a specific request on demand without changing the baseline sampling rate.</li><li><strong>OpenTelemetry API support in Workers:</strong><strong>Continue building out our OpenTelemetry APIs</strong> to enable adding attributes to existing spans or getting trace context.</li><li><strong>Longer retention:</strong> Keep trace data available for up to 365 days for longer-running investigations.</li></ul>\n<h2 id=\"get-started\">Get started</h2>\n<p>Follow the <strong>Cloudflare Traces documentation</strong> to trace your first request and tune sampling with Trace Rules. Cloudflare Traces is available in open beta from the dashboard, through the API, or with Terraform, with support for exporting to an OTLP destination.</p>","headings":[{"level":1,"text":"Introducing Cloudflare Traces: follow requests through our entire platform","id":"introducing-cloudflare-traces-follow-requests-through-our-entire"},{"level":2,"text":"Giving you the visibility we use to debug Cloudflare","id":"giving-you-the-visibility-we-use-to-debug-cloudflare"},{"level":2,"text":"Follow one request end to end","id":"follow-one-request-end-to-end"},{"level":3,"text":"Why was the request blocked or challenged, and which security rule took action?","id":"why-was-the-request-blocked-or-challenged-and-which-security-rul"},{"level":3,"text":"Was the URL rewritten by a Transform Rule before it reached the application?","id":"was-the-url-rewritten-by-a-transform-rule-before-it-reached-the-"},{"level":3,"text":"Which Page Rules, Snippets, or Workers handled or changed the request?","id":"which-page-rules-snippets-or-workers-handled-or-changed-the-requ"},{"level":3,"text":"Was the response served from cache, and where was time spent between Cloudflare, the origin connection, and the application?","id":"was-the-response-served-from-cache-and-where-was-time-spent-betw"},{"level":2,"text":"Configure your tracing","id":"configure-your-tracing"},{"level":3,"text":"Set a baseline sampling rate","id":"set-a-baseline-sampling-rate"},{"level":3,"text":"Configure Trace Rules","id":"configure-trace-rules"},{"level":3,"text":"Accept and propagate trace context","id":"accept-and-propagate-trace-context"},{"level":2,"text":"Export traces to your observability platform","id":"export-traces-to-your-observability-platform"},{"level":2,"text":"Let your agent investigate Cloudflare Traces","id":"let-your-agent-investigate-cloudflare-traces"},{"level":2,"text":"Pricing","id":"pricing"},{"level":2,"text":"What's next","id":"what-s-next"},{"level":2,"text":"Get started","id":"get-started"}]}}