Spotter watches your site for what went wrong.
When someone reports a problem, or your code notices one, Spotter captures it with the screenshot, the replay, the console and the network requests attached, and keeps the reporter updated until it is fixed. The same script gives you cookieless web analytics.
clicked Pay → POST /api/charge 502 → error toast shown
Reports that arrive ready to fix.
A report reaches your inbox from a person, from your code or from an error, and it carries what you would otherwise have to ask for.
From the people using your site
A widget with a screenshot they can mark up with arrows, boxes, pins and blur, an element picker, and a field for what they expected to happen. On mobile, they can shake to report.
From your code
Call spotter.report() when something fails, or spotter.flag() and assert() when something looks wrong. Flags are grouped and counted, and a rule turns one into a report, such as "20 in an hour" or "any critical".
With everything attached
The console, errors with source-mapped stack traces, network requests as a HAR file, the path through the site, the browser and device, the release, and steps to reproduce, one line at a time.
One issue, however many times it is reported.
Spotter fingerprints each report and groups repeats under the first, so twenty people hitting the same bug make one issue with twenty votes. Reporters can see similar open reports and add their own.
- Trusplex Dispatcher
- Built in and on by default: every report becomes a triaged ticket, and the ticket's status comes back to the report.
- GitHub Issues
- One issue per fingerprint, with two-way status: a merged pull request that says "Fixes #N" resolves the report.
- Routing rules
- "If the category is billing, assign it to Finance and post to #billing." Every rule that matches applies.
- Signed webhooks
- Every new issue and every status change, to any endpoint, with failed deliveries retried.
- Trusplex Operator
- "Investigate in Operator" hands the report to Operator's agent, to look into on your servers.
Like a parcel tracker, for a bug report.
Everyone who reports an issue gets a reference number and a tracking page: Received, In progress, then Resolved or Closed, with the notes your team chooses to share. Nothing technical is ever shown on it.
Updates as it moves
Reporters are told when the report arrives, when someone starts on it, and when it is fixed. The tracking page names the release that fixed it.
Questions, answered in place
Ask the reporter for more detail and they reply from the tracking page or the widget. Their answer lands on the report and on its Dispatcher ticket.
A portal for clients
Invite a client or stakeholder as a guest. They report without an account, and their portal shows their own reports and conversations.
See the problems nobody reported.
Session replay
Replays attach to reports, upload when an error or a flag fires, or are sampled. The player marks clicks, errors, failed requests and rage clicks, and follows along in the console and network panes.
Insights
Reports by page, release, browser and category, a click heatmap, and suggested issues drawn from rage clicks, dead clicks and abandoned forms in your replays.
Web analytics, without cookies
Visitors, pages, sources, campaigns, countries and devices, live. Goals and funnels show where visitors drop off, and which issues were filed on each step.
Web Vitals and releases
LCP, INP and CLS per route at the 75th percentile, issues per 1,000 pageviews, and a flag when a new release makes a route slower.
Share a read-only traffic dashboard with anyone, and export your raw events as CSV whenever you like. Spotter also accepts Plausible-style events, so a site can switch in or out.
Spotter records other people's users, so its defaults are the safe ones.
- No IP addresses
- A visitor is a hash under a random salt that is deleted at the end of each day, so nobody can be followed from one day to the next.
- Masked in the browser
- Replays mask what people type, and never record password fields.
- Encrypted at rest
- Screenshots, recordings, replays and source maps are encrypted before they are stored. Source maps are never served back.
- Your rules
- Honour Global Privacy Control and Do Not Track, keep each kind of data only as long as you choose, and delete everything a reporter filed for a GDPR or CCPA request.
- Locked to your site
- A site's public key only works from the origins you allow, and secret-looking values are scrubbed from URLs as they arrive.
One command on a Next.js site.
Create a site in Trusplex Console, then run the installer. It adds @trusplex/spotter, wraps your Next config, mounts the provider and creates the /api/spotter route. Your builds then declare their release and upload source maps.
Widget settings, sampling and targeting change from the console without a redeploy, and install health warns you about a mistake before it costs you a thin report.
# in your Next.js app npx trusplex spotter init # .env — keys from Spotter → Settings NEXT_PUBLIC_SPOTTER_KEY=pk_live_… SPOTTER_SECRET_KEY=sk_… SPOTTER_INGEST_URL=https://console.trusplex.com/hooks/spotter
Know what went wrong before you have to ask.
Create a site, install Spotter, and the next report arrives with everything attached. Pair it with Trusplex Dispatcher to route each one to its fix.