Skip to content

fix(server): stop sending x-vercel-ip - #212

Closed
feugy wants to merge 1 commit into
canaryfrom
damienfeugas/server-drop-x-vercel-ip
Closed

feugy wants to merge 1 commit into
canaryfrom
damienfeugas/server-drop-x-vercel-ip

Conversation

@feugy

@feugy feugy commented Oct 1, 2026

Copy link
Copy Markdown
Member

🖖 What's in there?

@vercel/analytics/server stops sending x-vercel-ip on the beacon it emits from the customer's function. Ingestion no longer reads it (vercel/api#95447), so the header is dead weight.

Server-side events are attributed to the IP that reaches ingestion. Before and after this change, that is the function's egress, not the visitor's browser: the header copied the function's incoming x-forwarded-for, which on Vercel carries the request's edge hop rather than the visitor. Tinybird confirms it over 7 days: 18 of the 23 owners with ≥10K server-side events have a single country (their function region), and vercel.com's own server-side events show as 76% DE / 17% US.

Before Now
Headers sent user-agent, x-vercel-ip, x-va-server, cookie user-agent, x-va-server, cookie
Country shown for server-side events function region, via a forgeable header function region, via the connection

🤺 How to test?

pnpm --filter @vercel/analytics test — server tests updated to assert the header is gone. No change to the event body or to any public API.

🔬 Notes to reviewers

  • x-vercel-ip was never documented (vercel.com/docs or this repo). It was a private contract with api-analytics-ingestion, which was accepting any client-supplied IP on every beacon, including pageviews and vitals from the browser.
  • Reading x-real-ip instead would give the visitor IP for direct traffic, but it would still be a client-supplied value that ingestion must take on faith, and the edge for anyone behind Cloudflare. Not worth keeping a forgeable channel for it.
  • Worth a line in the docs for track() from @vercel/analytics/server: server-side events are attributed to the region of the function that sent them.

🔗 Related PRs

  • vercel/api#95447 — ingestion stops reading x-vercel-ip and other client-supplied IP headers
  • vercel/proxy#25782 — proxy forwards the verified visitor IP for browser beacons behind a reverse proxy

@vercel

vercel Bot commented Oct 1, 2026

Copy link
Copy Markdown

Your Vercel team Analytics Test Projects is not permitted to deploy from this git repository. Contact an administrator to add github organization vercel as a Protected Git Scope in Analytics Test Projects on Vercel. Once added, commit again to see your changes.

Learn more: https://vercel.com/docs/security/protected-git-scopes

@feugy

feugy commented Oct 5, 2026

Copy link
Copy Markdown
Member Author

agent slop, we don't need this

@feugy feugy closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant