Request header
> traceparent: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01Traceparent Header: W3C Trace Context Format
The traceparent header carries trace id, parent span id and flags across services. Exact format, tracestate limits, OpenTelemetry, and privacy rules.
- Direction
- Request
- Category
- Diagnostics
- JS can set it
- Yes
- CORS-safelisted
- No: may trigger a preflight
On this page
TL;DR:
traceparentis the W3C Trace Context header that identifies a request across services:00-<32-hex trace id>-<16-hex parent span id>-<2-hex flags>. Every hop keeps the trace id, replaces the parent id with its own span id, and passes the header on.
Format
traceparent: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01
version - trace-id (16 bytes) - parent-id (8 bytes) - trace-flags
00 - 4bf92f3577b34da6a3ce929d0e0e4736 - 00f067aa0ba902b7 - 01
version: 2 hex characters, currently00.ffis forbidden.trace-id: 32 lowercase hex characters. All zeros is invalid.parent-id: 16 lowercase hex characters, the id of the caller’s span. All zeros is invalid.trace-flags: 2 hex characters. Only the lowest bit,sampled, is defined.
The header name is case-insensitive on the wire, and the value is lowercase. A receiver that fails to parse it should ignore it and start a new trace.
How a trace moves
Service A starts a trace with trace id 4bf9..., creates span 00f0..., and calls B with traceparent: 00-4bf9...-00f0...-01. B creates its own span, say a1b2..., and calls C with 00-4bf9...-a1b2...-01. Trace id stays constant; parent id changes at every hop; that is how a backend rebuilds the tree.
tracestate
traceparent: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01
tracestate: vendorA=opaque123,vendorB=t61rcWkgMzE
tracestate is a comma-separated list of vendor key=value pairs, at most 32 members, each value up to 256 printable ASCII characters. The spec says vendors should propagate at least 512 characters of the combined header. Pass it through unchanged unless you are the vendor that owns an entry; a vendor updates its own member and moves it to the front.
Sampled flag
01 means the caller may have recorded data for this trace. The spec treats it as advice: a callee may sample differently because of load or bugs in the caller. Head-based sampling decides at the root and everyone honors the flag; tail-based sampling ignores it and decides after the trace completes in a collector.
OpenTelemetry
W3C Trace Context is the default propagator in OpenTelemetry SDKs, so auto-instrumented HTTP clients inject the header and servers extract it. Manual propagation in Node:
import { context, propagation } from '@opentelemetry/api'
const headers = {}
propagation.inject(context.active(), headers)
// headers.traceparent is now set for the active span
await fetch('http://billing.internal/charge', { headers })
Log the trace id in every log line so logs and traces join. If you also set X-Request-ID, keep both: the request id is the short handle for humans, the trace id is the key for your tracing backend.
Security and privacy
- Trace ids must come from a random source that does not use anything user-identifiable (the spec says generation must not rely on such information). Do not derive them from session ids, IPs or account numbers.
- A public endpoint that honors incoming
traceparentlets any caller forcesampled=01and drive up tracing cost, or choose trace ids to collide with others. Many teams restart the trace at the public edge and link to the incoming id as an attribute instead. - Do not put secrets or personal data in
tracestatevalues; they travel to every downstream service, and across vendors. - Browsers do not send
traceparenton their own. If you add it from JavaScript to cross-origin requests, it is not CORS-safelisted and triggers a preflight, so the API must list it inAccess-Control-Allow-Headers.
Debug
curl -si https://api.example.com/health \
-H 'traceparent: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01'
Search your tracing backend for 4bf92f3577b34da6a3ce929d0e0e4736. If it is missing, check that a gateway is not stripping the header and that the service’s propagator is configured for tracecontext.
Related
Frequently asked questions
What is the format of the traceparent header?
Four lowercase hexadecimal fields joined by hyphens: version-trace-id-parent-id-trace-flags. Version is 2 hex characters (currently 00), trace-id is 32 hex characters, parent-id is 16 hex characters, and trace-flags is 2 hex characters. Example: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01.
What makes a traceparent invalid?
An all-zero trace-id or an all-zero parent-id is invalid, version ff is forbidden, and fields must be the exact lengths in lowercase hex. A receiver that cannot parse the header should ignore it and start a new trace rather than reject the request.
What is the difference between traceparent and tracestate?
traceparent is the vendor-neutral identity every participant understands. tracestate is an optional list of vendor-specific key=value entries (up to 32 members) that lets multiple tracing systems add their own data to the same trace without conflicting.
What does the 01 trace-flag mean?
The least significant bit is the sampled flag. 01 means the caller may have recorded trace data for this request. It is a recommendation to the callee, not a command, so services can apply their own sampling.
Does OpenTelemetry use traceparent?
Yes. W3C Trace Context is the default propagator in the OpenTelemetry SDKs, so instrumented HTTP clients inject traceparent and servers extract it automatically. Other propagators such as B3 or Jaeger formats are opt-in.
Can traceparent leak private information?
The spec requires that trace-id generation must not rely on information that could identify a user. The bigger practical risks are forged sampled flags forcing tracing overhead and trace ids from untrusted callers polluting your data, so consider restarting the trace at your public edge.
Sources
Related
X-Request-ID Header: Correlation IDs Across Services
X-Request-ID tags one request so you can find it in every log. nginx $request_id, Heroku behavior, propagation between services, and traceparent.
Server-Timing Header
Learn how the Server-Timing header communicates server-side performance metrics to browsers. Analyze backend timing, database queries, and optimize performance.
Via Header
Learn how the Via header tracks the path of HTTP requests through proxies and gateways. Debug routing issues and understand your network infrastructure.
Accept Header
Learn how the Accept header tells servers which content types (JSON, HTML, XML) your client can handle. Master content negotiation and quality values.