Node.js & APIs · 16 min · 140 XP

Logs you can debug from

Write logs as structured, one-line events with a request id, and redact secrets before they're ever written.

A log line is a message to someone debugging production at the worst possible moment, possibly you. console.log("here", user) doesn't help them. What helps: one event per line, as JSON, with the same fields every time: a timestamp, a level, a short fixed message, and the details as named fields. Log tools can then filter (level=error), group (message="payment failed") and count, instead of someone grepping prose.

One event, one line, fields rather than sentences
{"time":"2026-10-09T09:14:02.118Z","level":"error","message":"payment failed","requestId":"r-8f2c","userId":"u_381","provider":"stripe","status":402,"durationMs":812}

Give every request an id and put it on every line that request writes, and in the 500 response the user sees. Then a support ticket that says "error r-8f2c" leads straight to the full story. Keep the message fixed ("payment failed") and put the variable parts in fields. A message like "payment of 500 failed for u_381" is unique on every line, so you can never count how often it happens.

Use levels honestly. error: something failed and someone may need to act. warn: unexpected, but handled. info: normal events worth keeping, such as a request finished or a job ran. debug: detail you switch on while investigating. An app that logs every request at error has trained everyone to ignore errors.

Logs are copied everywhere: to log services, to laptops, into support tickets. Anything written there should be assumed public inside your company and kept for months. Never log passwords, tokens, session cookies, API keys or full card numbers. Redact by field name in the logger, so one careless log("login", { body }) can't leak the password inside it.

Loading your workspace…