We are evaluating an OAuth authorization-code integration on Vercel. The identity provider returns code and state in the callback URL query string. We cannot assume it supports response_mode=form_post.
We need to deliver these values to our callback function for validation and code exchange, while preventing their persistence in platform-managed logs.
The Runtime Logs documentation lists Search Params in request details, and the Log Drains reference describes request-path fields containing query parameters:
Is there a supported setting to exclude these parameter values before storage, covering Runtime Logs, edge/proxy/access logs, Firewall logs, traces, and Log Drains? We are not asking about hiding values in the dashboard, filtering only exports, Web Analytics beforeSend, or removing application console.log calls.
If supported, please identify the exact configuration, applicable plans, any exclusions, and how to verify it using dummy values. Please distinguish customer-visible logs from internally retained request metadata.
Vercel Help's AI assistant said this is not supported, but we have not obtained a staff-confirmed answer or a documented reference for that conclusion. Could a Vercel team member confirm the capability and its limits, or point us to authoritative documentation?
We understand that single-use codes and PKCE mitigate risks, but they do not establish that values are excluded from storage. If exclusion is unavailable, an explicit confirmation would help us choose the appropriate architecture.