Passthrough DSN

Passthrough DSN

Passthrough DSN mirrors accepted envelopes to a second DSN, letting you compare Tindra with another monitoring service during a migration.

How it works

When a passthrough DSN is configured on a project, Tindra:

  1. Processes the incoming envelope through normal ingestion, which can queue items for later storage
  2. Starts forwarding after envelope handling reaches its successful response path, without waiting for queued data to be stored

Tindra rewrites the envelope header to use the upstream DSN, while retaining the original telemetry content. PII scrubbing rules apply to storage only. The forwarded event is the original, unscrubbed payload.

Configuring passthrough

Expand the project in Settings > Projects and find Passthrough DSN. Paste the DSN of the service you want to forward events to.

The passthrough DSN can be any Sentry-compatible endpoint: another Sentry instance, a different Tindra instance, or a third-party service.

Private destinations

Passthrough delivery blocks private/internal destinations by default. Set WEBHOOK_ALLOW_PRIVATE_IPS=true on the server only when forwarding to such an endpoint is intentional. This shares the alert-webhook outbound policy; UPTIME_ALLOW_PRIVATE_IPS does not control passthrough. See Configuration.

A hostname must resolve to permitted addresses at connection time. Redirect destinations use the same checks, so forwarding can fail if a public endpoint redirects internally or its DNS answers include a blocked address.

Error handling

Forwarding failures do not produce an SDK error. If the passthrough endpoint is unreachable or returns an error, Tindra logs the failure internally but does not retry and does not affect the response sent back to the SDK.

Do not rely on passthrough for anything critical. It is a best-effort mirror.

Disabling passthrough

Clear the passthrough DSN field in project settings to stop forwarding.

Use cases

Gradual migration: point your SDKs at Tindra and passthrough to your existing Sentry instance. Once you are happy with Tindra, remove the passthrough DSN and stop paying for Sentry.

Comparing delivery: inspect the same traffic in another service while testing your configuration. Passthrough has no retry or guaranteed-delivery mechanism, so use a separate durable pipeline if you need a backup or audit archive.