Telemetry
Alibi collects nothing by default and never contacts a telemetry service. Telemetry is a hook for your code: you install a sink, the library hands it events, and you decide where they go.
Enable it
Section titled “Enable it”Provide a TelemetrySink and register it on the builder:
use crate::auth_schema::AppAuthSchema;use async_trait::async_trait;use alibi::sqlx::SqlxStore;use alibi::telemetry::{TelemetryConfig, TelemetryEvent, TelemetrySink};use alibi::{AuthConfig, AuthResult, BetterAuth};
struct EventLog;
#[async_trait]impl TelemetrySink for EventLog { async fn track(&self, event: TelemetryEvent) -> AuthResult<()> { eprintln!("auth event {}: {}", event.event_type, event.payload); Ok(()) }}
async fn build_auth( config: AuthConfig, store: SqlxStore<AppAuthSchema>,) -> AuthResult<BetterAuth<AppAuthSchema>> { BetterAuth::<AppAuthSchema>::new(config) .store(store) .telemetry(TelemetryConfig::new(EventLog)) .build() .await}TelemetryConfig::new(sink) enables delivery; .enabled(false) turns it off again. Without a configured sink nothing is emitted.
Events
Section titled “Events”Initialization publishes one event:
{"type":"init","payload":{"libraryVersion":"0.1.1","runtime":"rust","platform":"linux","architecture":"x86_64","plugins":["email-password","session-management","oauth"]}}It contains the library version, platform and the installed plugin names — no hostnames, URLs, secrets or user data. Publish your own application events through the same sink:
use crate::auth_schema::AppAuthSchema;use alibi::BetterAuth;use alibi::telemetry::TelemetryEvent;use serde_json::json;
async fn record(auth: &BetterAuth<AppAuthSchema>) { auth.publish_telemetry(TelemetryEvent::new("checkout_started", json!({ "plan": "pro" }))).await;}Delivery semantics
Section titled “Delivery semantics”- The sink owns transport and retention: batch it, forward it to your analytics system, or drop it.
- A sink error produces a log warning (without the payload or the error text, which may hold credentials) and never fails authentication.
- Application payloads come from your trusted code, never from HTTP requests.