@bugreels/web-script
v0.0.9
Published
BugReels browser session recording SDK
Readme
@bugreels/web-script
The BugReels v1 browser SDK records a session and sends versioned events to the BugReels ingest API.
import { createBugReels } from "@bugreels/web-script";
const bugreels = createBugReels({ apiKey: "br_live_..." });
await bugreels.start();
bugreels.identify("customer-123");
bugreels.setTags([{ tag: "checkout" }]);
bugreels.setRelease("2026.07.17");
try {
await submitOrder();
} catch (error) {
bugreels.captureException(error, { flow: "checkout", attempt: 2 });
}
await bugreels.stop({ endSession: true });captureException(error, context?) reports an error the application already
handled. The event carries handled: true (automatic error capture reports
handled: false), the same sanitized name/message/stack fields as
automatic capture, and an optional flat context map bounded to 20 entries with
string (redacted, at most 500 characters), finite number, or boolean values.
Calls made before start() resolves or after the session ended are ignored
with a console.debug notice, and calls on excluded pages are dropped.
createBugReels also publishes the most recently created client as
window.bugreels. Browser tooling such as the BugReels QA extension uses this
supported bridge to read the session ID and identify authenticated QA sessions.
By default, the SDK sends token and event requests through the production ingest
proxy at https://bugreels.com/be/be-ingest. Pass an explicit endpoint when
using a self-hosted or local ingest service. Custom endpoints must use HTTPS;
HTTP is accepted only for loopback hosts such as localhost, 127.0.0.1, or
[::1] during local development.
Configuration and public method inputs are validated at runtime. Form inputs are masked, secret-bearing keys are redacted, and HTTP request and response bodies are never captured by default. Page unload flushes pending events but does not end the session.
Individual capture features can be toggled through features; all default to
true:
navigationemits anavigation.pageevent with a fresh page view ID for the initial page load and every history push/replace, back/forward (pop), and hash navigation. URLs (and the initial referrer) are sanitized and redacted; at most 200 navigation events are recorded per session.interactionsrecords document clicks as bounded structural selectors (tag names plus sanitized id/class tokens only — never text content or other attribute values) with ahad_effectflag that reports whether the click caused a DOM mutation, a navigation, or a completed network request within ~800ms. Entries are batched intointeraction.clickevents and capped at 300 per session.webVitalsaggregates LCP, INP (approximated as the worst observed interaction duration), and CLS per page view and emits oneperformance.vitalsevent when the page view ends. It requires thenavigationfeature for page view identity and no-ops in browsers withoutPerformanceObserversupport.
const bugreels = createBugReels({
apiKey: "br_live_...",
features: { webVitals: false },
});WebSocket capture is metadata-only by default: it records connection lifecycle, direction, sanitized URLs, close codes, and payload byte sizes without recording text frame contents or close reasons. Payload previews and close reasons require an explicit privacy opt-in and are redacted and limited to 2,000 characters:
const bugreels = createBugReels({
apiKey: "br_live_...",
privacy: { captureWebSocketPayloadPreviews: true },
});Only enable previews for protocols whose frame contents are safe to record. Positional or otherwise unlabelled secrets may not be identifiable by key-based redaction.
