Skip to main content

Review tool usage

The Tool Usage screen in the console summarizes tool calls through the Connector Gateway. It shows data only after you turn on tool call recording, which is off by default.

Record tool calls​

After returning each tool result, the gateway queues a record of the call in Redis or Valkey. A background sender then delivers the queued records to the Enterprise Manager, which stores them for the Tool Usage screen. Turn on the queue and the token the sender authenticates with:

values.yaml
connector-gateway:
enterpriseConfig:
outbox:
enabled: true
meteringTokenProjection:
enabled: true

The sender reuses the gateway's Enterprise Manager connection from enterpriseConfig.directory, and the queue uses the Redis or Valkey instance the gateway already needs. The platform chart adds the gateway's ServiceAccount to the Enterprise Manager's metering allowlist, and the Enterprise Manager validates the token against the clusterOidcIssuer you set in Connect the gateway to the Enterprise Manager.

Queued records survive gateway restarts only if your Redis or Valkey instance does, so use a Redis or Valkey deployment with persistence and replication when you rely on these numbers. The chart refuses to render when outbox.enabled is true and meteringTokenProjection.enabled is false.

What the screen shows​

Choose Last 24h, Last 7d, or Last 30d to set the period for the Tool calls, Active connectors, and Top connector tiles. The Tool calls trend chart always covers the last three months.

Below the chart, By connector compares traffic across connectors, and By tool ranks individual tools with the connector that serves each one. Both tabs show each row's share of total calls in the period.

The screen reports tool calls only. To review model traffic, see the AI Gateway. Users see a summary of their own calls on the Usage tab under Gateways > Connectors. See Manage your connections.

Next steps​

Troubleshooting​

The screen shows "No tool calls in this window"

Check that tool call recording is on, as described in Record tool calls. The gateway records only calls made after you turn it on.

If recording is on, check the gateway's logs for errors delivering records to the Enterprise Manager:

kubectl logs deployment/stacklok-enterprise-connector-gateway -n stacklok-system

An Unauthenticated error means the Enterprise Manager can't validate the gateway's token. Check that enterprise-manager.grpc.callerAuth.clusterOidcIssuer matches the issuer your cluster reports.

A connector that users call doesn't appear

The screen lists only connectors with recorded calls in the selected period. If users can't call the connector at all, see Troubleshooting on the connectors page.