What is collected
Every report is a single JSON document with these fields:Feature flags
features is a flat map of booleans derived from your resolved options. It records only whether a capability is on, never any value tied to it:
How projectId is derived
projectId is a one-way, irreversible hash:
payload.secret is used only as a salt and is never transmitted — it is high-entropy and private, so the digest cannot be reversed. This mirrors how Payload derives its own telemetry id.
rawSource is the first available of, reported as projectIdSource:
git— the repository’sremote.origin.urlpackageJSON— your app’spackage.jsonnameserverURL—payload.config.serverURLcwd— the process working directory
What is never sent
No IP address, nopayload.secret, no API keys, no info values, no server URLs or hosts, no paths, no collection or global names, and nothing from the generated document. features carries booleans only.
Opting out
Telemetry is disabled automatically if any of these is true:payload.config.telemetryisfalse(the host’s own Payload opt-out)- the plugin’s
telemetryisfalse - the
OPENAPI_TELEMETRY_DISABLEDorDO_NOT_TRACKenvironment variable is set to a truthy value - a
CIenvironment is detected NODE_ENVistest
enabled: false the plugin sends nothing either.
To opt out explicitly:
payload.config.ts
Sending to your own collector
Pass an object with aurl to point reports at a collector you control:
payload.config.ts
Transport
Reports are fire-and-forget: they run after your ownonInit, never block boot, never throw, and are capped at a 2-second timeout — a telemetry failure can never affect your application. At most one report is sent per project per UTC day (best-effort, via a timestamp in the OS temp directory).