Meta tags:
description= Let an AI assistant explore and manage your Rybbit analytics through the hosted Model Context Protocol server;
author= Rybbit Team;
keywords= web analytics,privacy analytics,open source analytics,Google Analytics alternative,website tracking,self-hosted analytics;
Headings (most frequently used words):
connect, client, tools, and, data, with, claude, code, mcp, guides, available, permissions, roles, destructive, security, boundary, troubleshooting, create, an, api, key, add, the, endpoint, or, oauth, start, context, codex, desktop, cursor, vs, opencode, analytics, read, sites, goals, funnels, people, organization, teams, raw, sql, on, this, page,
Text of the page (most frequently used words):
the (85), and (46), with (34), key (33), api (29), mcp (24), rybbit (22), site (19), #client (17), your (15), analytics (14), read (14), oauth (14), claude (14), for (14), access (14), admin (14), tool (13), data (12), user (12), scopes (12), role (11), organization (10), only (10), tools (9), create (9), this (9), code (9), goals (8), endpoint (8), server (8), call (8), not (8), does (8), clients (8), destructive (7), sites (7), guides (7), connect (7), add (7), grant (7), that (7), resource (7), can (7), one (7), keys (7), permissions (6), teams (6), its (6), use (6), owner (6), same (6), settings (6), desktop (6), funnels (5), list_sites (5), request (5), replace (5), action (5), self (5), hosted (5), you (5), scoped (5), time (5), traffic (5), traits (5), returns (5), any (5), permanently (5), member (5), every (5), write (5), codex (5), authorization (5), troubleshooting (4), roles (4), context (4), page (4), tracking (4), rate (4), scope (4), 403 (4), table (4), each (4), model (4), event (4), rest (4), session (4), per (4), before (4), message (4), are (4), through (4), standard (4), custom (4), assistant (4), list (4), sessions (4), delete (4), team (4), members (4), person (4), funnel (4), goal (4), configuration (4), opencode (4), like (4), https (4), raw (3), sql (3), available (3), start (3), error (3), over (3), known (3), requests (3), credential (3), without (3), names (3), required (3), then (3), login (3), send (3), bearer (3), http (3), run_query (3), still (3), well (3), erasure (3), path (3), events (3), delete_user (3), delete_site (3), full (3), agent (3), from (3), all (3), plus (3), pages (3), users (3), other (3), supports (3), headers (3), cursor (3), which (3), support (3), url (3), protocol (3), documentation (3), security (2), boundary (2), people (2), node (2), javascript (2), stateless (2), post (2), retry (2), based (2), response (2), created (2), needs (2), field (2), includes (2), insufficient (2), org (2), run (2), token (2), authenticate (2), configure (2), tracked (2), paths (2), referrers (2), never (2), surface (2), level (2), has (2), visitor (2), addresses (2), integration (2), own (2), checks (2), requirements (2), limits (2), marked (2), ask (2), them (2), gdpr (2), delete_team (2), delete_funnel (2), delete_goal (2), metadata (2), oidc (2), step (2), those (2), out (2), add_member (2), save_funnel (2), update_user_traits (2), identify_user (2), inputs (2), dashboard (2), clickhouse (2), against (2), recent (2), first (2), devices (2), vitals (2), saved (2), saving (2), definitions (2), autocapture (2), conversion (2), name (2), new (2), counts (2), streamable (2), works (2), remote (2), config (2), file (2), header (2), environment (2), setup (2), into (2), guide (2), limited (2), approve (2), flow (2), skip (2), entirely (2), below (2), rybbit_api_key (2), app (2), installation (2), cloud (2), copy (2), open (2), account (2), managing (2), hosting (2), feature (2), 693 (2), github (2), side, applications, again, membership, may, have, changed, expected, accepts, messages, 405, method, allowed, get, could, verify, valid, 503, service, unavailable, exceeded, plan, limit, 429, too, many, was, lacks, requires, check, results, tables, npm, push, loop, exist, did, invalid, expired, revoked, capable, automatically, via, challenge, www, 401, unauthorized, independently, authenticated, contain, provider, leaves, restricted, row, execution, caps, text, originating, titles, stripped, control, bidi, override, characters, should, treat, these, values, untrusted, instructions, whatever, including, records, where, enabled, trust, separate, revocable, verified, processed, runs, corresponding, route, destroy, annotation, behaved, confirmation, invoking, also, remove, recorded, replays, completing, asynchronously, destructivehint, advertises, discovery, carrying, treated, backward, compatibility, give, mostly, view, see, reporting, filtered, alternatively, connecting, hides, nothing, but, refuses, requiring, require, hold, layer, enforces, underprivileged, gets, explanatory, need, least, work, mirrors, permission, accept, optional, iana, filters, omitting, queries, past_minutes, time_zone, end_date, start_date, scoped_events, schema, rules, get_query_schema, newest, get_events, detail, timeline, get_session, attribution, get_sessions, rename, update_team, create_team, list_teams, restrict, specific, update_member_site_access, existing, list_members, wholesale, link, anonymous, device, merge, profile, linked, locations, get_user, inventory, aggregates, sortable, searchable, get_users, save, update, passing, funnel_id, compute, hoc, analyze_funnel, get_funnels, definition, update_goal, create_goal, stats, get_goals, change, domain, features, exclusions, tags, update_site_config, create_site, get_site, organizations, most, common, navigation, get_journeys, retention, cohort, get_retention, core, web, percentiles, lcp, cls, inp, fcp, ttfb, get_web_vitals, errors, grouped, occurrence, get_errors, get_event_names, visitors, active, right, now, get_live_stats, broken, down, dimension, countries, utm, get_breakdown, overview, kpis, bucketed, get_overview_timeseries, pageviews, bounce, duration, get_overview, generic, env, copilot, mode, kept, json, connector, mobile, command, secrets, coding, agents, pull, development, workflow, checking, whether, just, fixed, occurs, production, looking, matter, refactor, chat, turn, conversational, interface, follow, numeric, return, email, organization_id, site_id, summarize, last, month, docs, signups, prompt, something, grants, advertised, unrestricted, requesting, controls, asks, consent, currently, deny, whole, scopes_supported, discovers, registers, itself, opens, browser, window, log, resulting, acts, exactly, would, protected, secret, variable, when, instead, query, string, accepted, walkthroughs, mcpservers, different, formats, typical, shape, example, com, host, configured, base_url, everything, hand, narrower, object, implies, elevate, apply, deleting, revokes, connection, immediately, shows, once, section, personal, steps, describe, credentials, connects, sends, verifies, processing, authorized, gives, exploring, behavior, profiles, uses, markdown, let, explore, manage, import, inviting, billing, migration, quick, embeds, bot, detection, filter, hiding, sdks, proxy, tagging, identify, track, script, usage, comparison, introduction, reference, search,
Text of the page (random words):
mcp rybbit search k github rybbit io rybbit 12 5k 693 documentation api reference documentation guides setup and feature documentation github rybbit io rybbit 12 5k 693 introduction comparison self hosted vs cloud usage tracking script troubleshooting track events autocapture identify users tagging integration guides proxy guide sdks mcp claude code codex claude desktop cursor vs code opencode hiding your own traffic filter traffic bot detection goals funnels embeds feature guides self hosting quick start managing your installation troubleshooting self hosting guides migration to v1 0 settings account settings organization settings teams billing inviting users site settings data import other definitions mcp mcp let an ai assistant explore and manage your rybbit analytics through the hosted model context protocol server copy markdown open rybbit includes a hosted model context protocol mcp endpoint it gives an ai assistant read and write access to your analytics exploring traffic and behavior data and managing sites goals funnels organization members teams and user profiles through the same api the dashboard uses with the same access checks roles and rate limits your mcp client connects to rybbit over https and sends your api key with each protocol request rybbit verifies the key before processing any message and every tool call is authorized against the key user s role and site access connect a client if your client supports the mcp authorization flow claude code codex claude desktop and opencode all do you can connect with oauth and skip api keys entirely the steps below describe the api key path which works in every client and supports scoped credentials 1 create an api key open settings account in rybbit create a key in the personal api keys section copy it immediately rybbit only shows a new key once a key created without permissions can do everything its user can do to hand an agent a narrower credential create the key with scoped permissions post api user api keys with a permissions object e g analytics read goals read write the mcp tool list and every api call are then limited to those resource action scopes write implies read on the same resource and scopes never elevate org admin owner requirements still apply deleting the key revokes the connection 2 add the endpoint use this streamable http url for rybbit cloud https app rybbit io api mcp for a self hosted installation replace the host with your configured base_url https analytics example com api mcp configure your client to send this header on every request authorization bearer rybbit_api_key mcp clients use different configuration formats a typical remote server configuration has this shape mcpservers rybbit url https app rybbit io api mcp headers authorization bearer rybbit_api_key use your client s secret or environment variable support when available instead of saving the key in a file query string api keys are not accepted by the mcp endpoint per client walkthroughs claude code codex claude desktop cursor vs code opencode are in client guides below or connect with oauth clients that support the mcp authorization flow can skip api keys entirely add the endpoint url with no headers and the client discovers rybbit s authorization server through the standard well known metadata well known oauth protected resource registers itself and opens a browser window for you to log in and approve access the resulting access token acts with your user s role exactly like an api key would oauth grants support the same resource action scopes as api keys advertised in scopes_supported a grant that requests only the standard oidc scopes is unrestricted a grant that requests custom scopes like analytics read is limited to them the requesting client controls which scopes it asks for consent is currently approve or deny as a whole 3 start with context ask the assistant to call list_sites or prompt it with something like list my rybbit sites summarize last month s traffic for the docs site and create a goal for signups list_sites returns the numeric site_id and organization_id required by the other tools plus the key s role in each organization it does not return api keys or member email addresses client guides coding agents can use the endpoint to pull analytics into your development workflow checking whether an error you just fixed still occurs in production or looking up which pages matter before a refactor and chat clients like claude desktop turn it into a conversational analytics interface follow the guide for your client claude claude code one command with oauth or an api key plus a no secrets team setup codex codex mcp add then oauth login or a key from the environment claude claude desktop add a custom connector on claude ai desktop and mobile cursor mcp json with an api key header vs code copilot agent mode with the key kept out of the config file opencode remote server config with oauth login or env based headers any other mcp client that supports streamable http works with the generic configuration from step 2 available tools analytics read tool returns get_overview sessions pageviews users pages per session bounce rate and session duration get_overview_timeseries the overview kpis bucketed over time get_breakdown sessions broken down by one dimension pages referrers countries devices utm get_live_stats visitors active on the site right now get_event_names custom event names tracked on the site with counts get_errors javascript errors grouped by name message with occurrence counts get_web_vitals core web vitals percentiles lcp cls inp fcp ttfb get_retention user retention cohort table get_journeys most common page to page navigation paths sites tool does list_sites list organizations and sites the key can access call this first get_site one site s full configuration create_site add a new site to an organization admin update_site_config change site settings name domain tracking features exclusions tags admin delete_site permanently delete a site and its data admin destructive goals funnels tool does get_goals conversion goals with conversion stats create_goal create a path event or autocapture goal update_goal replace a goal s definition delete_goal permanently delete a goal destructive get_funnels saved funnel definitions analyze_funnel compute an ad hoc funnel without saving it save_funnel save a funnel or update one by passing funnel_id delete_funnel permanently delete a saved funnel destructive people tool does get_users person inventory with per user aggregates and traits sortable searchable get_user one person s profile traits linked devices vitals locations identify_user link an anonymous device to your user id and merge traits update_user_traits replace a person s traits wholesale delete_user gdpr erasure of one person s analytics data admin destructive organization teams tool does list_members organization members with roles site access and teams add_member add an existing rybbit user to the organization admin update_member_site_access restrict a member to specific sites admin list_teams teams with members and site access create_team create a team admin update_team rename a team or replace its members sites admin delete_team permanently delete a team admin destructive raw data sql tool does get_sessions recent visitor sessions with full attribution get_session one session s detail plus its event timeline get_events raw recent events newest first get_query_schema the clickhouse schema and rules for run_query run_query read only clickhouse sql against the site scoped scoped_events table analytics tools accept optional time inputs start_date end_date with an iana time_zone or past_minutes and the same filters as the dashboard omitting time inputs queries all time permissions and roles the mcp surface mirrors the rest api s permission model read tools work for any member with access to the site write tools need at least member level site access goals funnels identify_user update_user_traits save_funnel tools marked admin require the api key s user to hold the admin or owner role in the organization add_member can grant the owner role only from an owner s key the rest layer enforces all of this an underprivileged key gets a 403 with an explanatory message to give an assistant a read only or read mostly view create a scoped api key see step 1 grant only the resource action scopes it needs e g analytics read sessions read for a reporting agent the mcp tool list is filtered to those scopes and any out of scope call returns 403 error insufficient scope required goals write alternatively connecting with a member role user s key hides nothing but refuses every call requiring the admin owner role oauth clients request scopes through the standard grant rybbit advertises the same resource action scopes in its discovery metadata a grant carrying no custom scopes or only the standard oidc scopes is treated as full access for backward compatibility destructive tools delete_goal delete_funnel delete_site delete_team and delete_user permanently destroy data and are marked with the mcp destructivehint annotation so well behaved clients ask for confirmation before invoking them delete_site and delete_user the gdpr erasure path also remove recorded events and replays with erasure completing asynchronously data and security boundary the api key is verified before any mcp message is processed and each tool call re runs the corresponding rest route s own access checks role requirements and rate limits the surface returns whatever the rest api returns for your role including session level records and where a site has ip tracking enabled visitor ip addresses connect only ai clients you trust with that data and use a separate revocable api key per integration text originating in tracked traffic page titles paths referrers event names traits is stripped of control and bidi override characters ai clients should still treat these values as untrusted data never as instructions run_query is restricted to a read only site scoped table with row and execution time caps the server does not contain an ai model or send analytics to an ai provider data only leaves rybbit in response to the mcp client you configure the endpoint is stateless each http request is independently authenticated troubleshooting 401 unauthorized the client did not send a bearer credential or the key token is invalid expired or revoked oauth capable clients re authenticate automatically via the www authenticate challenge oauth login loop or table does not exist self hosted run npm run db push in server to create the oauth tables then retry 403 in tool results the key s user lacks access to that site or organization or the tool requires an org admin owner role check the role field in list_sites 403 insufficient scope the credential was created without the resource action scope this tool needs the required field names it use a key or oauth grant that includes it 429 too many requests the api key exceeded its plan s rate limit 503 service unavailable rybbit could not verify the key retry the request do not replace a known valid key based on this response 405 method not allowed on get this is expected the stateless endpoint accepts mcp messages over post site access error call list_sites again membership or site permissions may have changed javascript node js server side analytics tracking for node js applications claude code connect claude code to rybbit s mcp server with oauth or an api key on this page connect a client 1 create an api key 2 add the endpoint or connect with oauth 3 start with context client guides available tools analytics read sites goals funnels people organization teams raw data sql permissions and roles destructive tools data and security boundary troubleshooting
|