When you omit
endpoint, the SDK posts directly to https://ingest.usenotra.com and does not retry through the dashboard. To use the dashboard ingestion route, set endpoint: "https://app.usenotra.com" and redeploy your site. Self-hosted installations must set endpoint to their own ingestion origin.
The tracker captures only GET requests that look like pages, and it skips anything under /_next/, /_nuxt/, /_vercel/, /_astro/, /_app/immutable/ and /static/, plus any path ending in a common static extension, although it always captures llms.txt and llms-full.txt. An exclude entry can be a string prefix, a RegExp or a (request, url) => boolean function.
The envelope contains the timestamp, method, URL, client IP, edge location headers when present, referer, user agent, accept and accept-language headers and a request id. The SDK does not read or send the request body, cookies or any other headers, and the POST uses keepalive and a 2 second timeout.
Rotating the token
Open API Keys and press Rotate on the tracking token card. Rotation covers the whole organization, so every project gets a new token. Rotation invalidates every tracking token previously issued for the organization and returns a fresh one. Because Notra immediately rejects events from deployments that still send the old token, updateNOTRA_GEO_TOKEN everywhere before you rotate.