theauth-go emits spans via the pluggable Tracer adapter. The span catalog below is the authoritative list as of v2.3.0.
Span names are exported as constants (theauth.SpanOAuthToken, etc.) so dashboards and alert rules can reference them by symbol.
Span catalog
Every instrumented operation opens a span at its entry point and closes it at return. On error the span receives RecordError plus a status="error" attribute and an error_code="<stable code>" attribute matching models.TheAuthError.Code.
Standard span attributes
Cardinality note
client_id, subject, and resource are high-cardinality; they are attached to spans only and never used as metric labels. This is enforced by review at library call sites. Last modified on October 7, 2026