Logs and webhooks
Connected logs give diagnoses the stack traces behind a ticket and feed the proactive mode. Error events are kept for 30 days.
Sentry
- In Sentry, create an internal integration (Settings, Developer Settings, New Internal Integration). It works on self-hosted Sentry too.
- Give it read access only: Issue and Event, Project, Organization.
- Set the webhook URL shown in the connector settings of Loopback, and tick the
issuewebhooks. - Turn on Alert Action, then create an alert whose action notifies the integration, for new issues, escalations and regressions.
- In Loopback, paste the base URL, the organization slug, the auth token and the client secret. The auth token is required: alerts fire once per issue, so Loopback also reads each issue’s events to count the users affected in 24 hours.
Each webhook is verified with the HMAC signature of its raw body and the client secret; deliveries outside the projects and environments you chose are acknowledged and ignored.
Datadog
- An API key and an application key of a service account with
logs_read_data. - The site of your account, for example
datadoghq.eu. - Optional filters: services, environments and a query.
- Loopback polls the logs search API for errors, within the rate limits of your account.
AWS CloudWatch
Create an IAM role that Loopback assumes with an external id it generates for your workspace:
{ "Version": "2012-10-17", "Statement": [{ "Effect": "Allow", "Principal": { "AWS": "<the account shown in the connector settings>" }, "Action": "sts:AssumeRole", "Condition": { "StringEquals": { "sts:ExternalId": "<the external id shown in the connector settings>" } } }]}Give the role read access to the log groups:
{ "Version": "2012-10-17", "Statement": [{ "Effect": "Allow", "Action": [ "logs:DescribeLogGroups", "logs:FilterLogEvents", "logs:StartQuery", "logs:GetQueryResults", "logs:StopQuery" ], "Resource": "*" }]}- Loopback checks that the role can be assumed with the external id and cannot be assumed without it; otherwise it refuses to store the role.
- Choose the region and up to 20 log groups, with an optional filter pattern.
- Access keys of a read-only user also work, encrypted at rest, but a role is recommended.
Generic endpoint
Without Sentry, Datadog or CloudWatch, send errors from your backend or your log shipper. Create an endpoint connector to get a token; it starts with lbe_ and is shown once.
curl -X POST https://api.loopback.so/v1/ingest/events \ -H "Authorization: Bearer lbe_..." \ -H "Content-Type: application/json" \ -d '{ "events": [{ "event_id": "6f9619ff8b86d011b42d00c04fc964ff", "timestamp": "2026-10-01T10:00:00Z", "release": "2.4.0", "environment": "production", "exception": { "type": "TypeError", "value": "Cannot read properties of undefined (reading id)", "stacktrace": "TypeError: ...\n at createPayment (/srv/app/dist/checkout.js:40:12)" }, "request": { "url": "https://app.example.com/checkout", "method": "POST" }, "user": { "id": "u_123" } }] }'- One event, an object with an
eventsarray, or a bare array: up to 100 events and 1 MiB per request, optionally compressed with gzip. - Retries are deduplicated when the event carries an
event_id. timestampis ISO 8601 with an offset, or epoch seconds; timestamps that are implausible fall back to the time received.user.idis hashed on arrival with the workspace salt;user.id_hashcan carry a hash you computed.202with the accepted count;401for a wrong token;422with the fields in error;429withRetry-After.
What happens to an event
- Secrets and personal data are masked before storage.
- Events are grouped by fingerprint: the normalized message, the first frames of your code after source maps, and the release.
- Minified frames are mapped back to files and lines with the source maps uploaded for that release.
- Events are deleted after 30 days.