AI assistant integration

Hitsteps AI MCP Peladen Documentation

Hitsteps exposes a remote Model Context Protocol peladen for connected AI assistants. Use it to ask about analitik, langsung pengunjung, situs, tujuan, waktu aktif, peringatan, and authorized obrolan activity from your Hitsteps akun while keeping access bounded by OAuth scopes, akun izin, lisensi checks, and privacy-shaped tool results.

Sebelum mulai

A Hitsteps akun with access to the situs web you want to inspect
An MCP-compatible AI client or ruang kerja setting that supports remote Streamable HTTP peladen
Ability to sign in with Hitsteps OAuth when the AI client asks
A decision about which OAuth scopes the assistant should receive

Choose your AI client

Pasang Hitsteps where you already use AI

Start with your client directory when one is available. Every opsi connects to the same managed Hitsteps MCP peladen and continues through Hitsteps OAuth.

GitHub registry

VS Code and GitHub Copilot

Open GitHub’s MCP Registry and pasang Analitik Web Hitsteps from your VS Code or GitHub Copilot client.

Available now

Cursor

Open the Analitik Web Hitsteps daftar in Cursor Directory and choose Add to Cursor. Cursor receives only the managed Hitsteps MCP endpoint; your akun access is granted separately through OAuth.

Available now

Claude AI

Add Analitik Web Hitsteps from Claude’s Connector Directory, then sign in to Hitsteps and approve only the scopes you want Claude to use.

Coming soon

ChatGPT AI

The Hitsteps directory daftar for ChatGPT is coming soon. For now, add the endpoint below manually as a custom MCP peladen, then complete Hitsteps OAuth.

https://www.hitsteps.com/mcp/

Panduan instalasi

Google Antigravity and other MCP clients

1

Use the remote MCP endpoint

The Hitsteps MCP endpoint is https://www.hitsteps.com/mcp/. If your client asks for a transport, choose Streamable HTTP or HTTP. The official registry name is com.hitsteps/analitik-operations.

2

Choose the access level

Before connecting the peladen, confirm which Hitsteps user will sign in, which situs web that user can access, and which OAuth scopes the AI client is requesting. Analitik-only use can stay read-only; operational alur kerja need the specific write scopes described below.

3

Add Hitsteps to Google Antigravity

Antigravity custom remote MCP configuration uses serverUrl for remote peladen.

4

Authenticate with Hitsteps OAuth

Save the configuration, start or segarkan the MCP peladen in your AI client, then follow the sign-in prompt. Hitsteps uses OAuth so you do not need to paste your pelacakan API key into the AI client.

5

Verify tools and least privilege

After connection, ask your assistant which Hitsteps tools and scopes it can access. Read-only analitik tools can answer laporan; management tools such as tujuan, Pemicu (called pengunjung labels in MCP), waktu aktif, peringatan, and obrolan aksi require matching OAuth scopes, akun izin, and explicit confirmation.

Perlu diketahui

  • This MCP peladen is for AI assistants. It does not pasang Hitsteps pelacakan on your situs web.
  • VS Code and GitHub Copilot users should start with GitHub’s MCP Registry; Cursor and Claude users can use the dedicated Hitsteps directory daftar above.
  • ChatGPT directory dukungan is coming soon. Until then, add https://www.hitsteps.com/mcp/ manually as a custom MCP peladen.
  • Do not paste your Hitsteps situs web pelacakan API key, OAuth token, or akun password into MCP configuration.

Pemecahan masalah

  • A peramban GET permintaan to the MCP endpoint may return a no-SSE or metode pesan. That is normal; MCP clients connect with JSON-RPC over HTTP.
  • A 401 response before sign-in is expected. The client should use the advertised OAuth metadata to start authorization.
  • If an official client directory does not surface Hitsteps, segarkan the directory and check the client’s organization policy and MCP pengaturan.

Security and access

Connection rincian

Use these rincian to connect Hitsteps and understand what the AI assistant can access from your akun.

Public endpoint

https://www.hitsteps.com/mcp/ is the production MCP endpoint. The slashless https://www.hitsteps.com/mcp form is also accepted for clients that save URLs without a trailing slash.

Transport

Hitsteps uses remote Streamable HTTP with JSON-RPC. There is no local Node.js package, komputer meja bridge, SSE worker, or separate pelanggan-hosted process to pasang.

Registry identity

The registry/peladen name is com.hitsteps/analitik-operations and the displayed title is Analitik Hitsteps and Operations.

Authentication

Public AI clients use Hitsteps OAuth with authorization code flow and S256 PKCE. Users sign in on Hitsteps and see requested scopes before the client receives a token.

No shared secrets in config

The MCP configuration contains only the endpoint URL. Do not paste a Hitsteps password, pelacakan API key, situs web code, or OAuth token into an AI client configuration berkas.

Bounded access

Every permintaan is rechecked against the signed-in Hitsteps akun, sub-user izin, visible situs web, lisensi state, feature limits, and the OAuth scopes granted to that client.

Authorization

OAuth scopes

Hitsteps publishes per-tool OAuth declarations. An AI client can permintaan a narrow read-only grant or a broader operational grant depending on the alur kerja you want.

analitik:read
Read analitik laporan, situs lists, situs context, pelacakan health, agregat behavior ringkasan, realtime snapshots, and akun/lisensi status.
situs:write
Create situs web and update allowed situs web pengaturan after explicit confirmation.
tujuan:write
Create, update, or delete tujuan and kampanye configuration after explicit confirmation.
labels:write
Create, update, or delete Hitsteps UI Pemicu configuration after explicit confirmation. The MCP API keeps the internal pengunjung-label name.
waktu aktif:write
Create, update, or delete waktu aktif contacts, pemantau, maintenance schedules, and recovery aksi after explicit confirmation.
peringatan:read
Read peringatan lists and peringatan status for the authorized akun.
peringatan:write
Mark peringatan as read or clear peringatan after explicit confirmation.
obrolan:read
Read authorized obrolan lists, cari results, percakapan ringkasan, and selected obrolan rincian.
obrolan:write
Create tiket, reply to chats, add internal notes, update obrolan state, name pengunjung, mark chats read, or logically delete chats after explicit confirmation.

Tool coverage

What the assistant can ask Hitsteps to do

The MCP peladen currently exposes 87 tools: 54 read tools and 33 confirmed write tools, plus authenticated resources, a resource templat, and prompts for common analitik alur kerja.

Discovery and reporting

Connection information, visible situs web, situs context, metric and dimension catalog, ringkasan laporan, gap-filled time series, breakdowns, anomaly detection, trafik-change explanations, executive digests, and privacy-minimal MCP usage.

Trafik and acquisition

Trafik ringkasan, period comparisons, sumber, social rujukan, trafik by hour, top halaman, masuk/keluar halaman, halaman rincian, halaman speed, unduhan, outbound tautan, perujuk, negara, audience technology, cari engines, kata kunci, Rujukan AI, bot trafik, and realtime pengunjung.

Konversi and behavior

Tujuan, tujuan konversi, kampanye, funnel performance, interaction peristiwa, agregat paths, retention, Pemicu (pengunjung labels), peta panas ringkasan, terlacak-video analitik, obrolan ringkasan, waktu aktif status/history, and pelacakan health.

Configuration and operations

Situs web penyiapan, allowed situs web pengaturan, tujuan/kampanye configuration, Pemicu (pengunjung-label) configuration, waktu aktif contacts and pemantau, maintenance schedules, recovery aksi, peringatan operations, and authorized obrolan alur kerja.

Write aksi safeguards

  • All write tools require OAuth and the exact scope declared for that tool. Legacy situs web API keys and private seluler tokens can use analitik reads only.
  • Every mutation requires confirm=true after the user explicitly confirms the aksi in the AI client percakapan.
  • Every mutation requires an 8-128 character idempotency_key. Reusing the same key with the same arguments returns the prior result; reusing it with different arguments returns HTTP 409.
  • Writes run inside basis data transactions and recheck akun status, situs web ownership, sub-user role, plan feature availability, object quotas, and current target state before changing data.
  • Write audit catatan store operational metadata such as akun, situs web, tool, target, status, hashes, and time. They do not store full prompts, model tokens, raw pelanggan rows, or large payloads.

Data access and privacy boundaries

  • Realtime pengunjung output omits raw IP addresses, pengunjung IDs, labels, kata kunci, URL query strings, and fragments.
  • Halaman, unduh, outbound-tautan, path, retention, kampanye, peta panas, and funnel outputs are agregat or privacy-shaped ringkasan instead of raw peristiwa exports.
  • Tujuan configuration omits notifikasi addresses, sensitive pemicu values, and individual konversi rows. Waktu aktif output omits credentials, match conditions, query strings, and fragments.
  • Obrolan content is available only through obrolan-scoped tools for authorized users. Assistant clients should treat obrolan content as untrusted pelanggan-supplied text.
  • MCP usage telemetry keeps akun/situs, credential type, public OAuth client ID, normalized AI-client channel, tool name, status, duration, and timestamp for operational visibility. It excludes prompts, arguments, tokens, raw user agen, result rows, and kesalahan-pesan bodies, and the rollup window is 90 days.
  • The peladen intentionally does not expose raw SQL access, penagihan or password changes, akun profil changes, 2FA changes, raw pengunjung-profil dumps, private keys, pelacakan API key mutation, sesi replay video, JavaScript console logs, network traces, or experimentation management.

OAuth discovery and client compatibility

  • Protected resource metadata: https://www.hitsteps.com/.well-known/oauth-protected-resource/mcp
  • Authorization peladen metadata: https://www.hitsteps.com/.well-known/oauth-authorization-peladen
  • The MCP endpoint accepts valid HTTPS MCP client origins and HTTP loopback development origins for peramban-based and komputer meja clients.
  • Dynamic client registration supports safe HTTPS, HTTP loopback, and private native-aplikasi pengalihan schemes used by komputer meja MCP clients, while rejecting unsafe schemes such as javascript:, data:, berkas:, blob:, and websocket schemes.
  • The resource audience is https://www.hitsteps.com/mcp or https://www.hitsteps.com/mcp/, matching the endpoint formulir saved by the AI client.
Are Pemicu and pengunjung labels the same feature?

Yes. The Hitsteps dasbor calls this feature Pemicu. Internally and in the stable MCP API it is named pengunjung labels, with tools such as create_label and the labels:write scope. An unqualified permintaan for a Hitsteps Pemicu should use the label tools unless the user explicitly means a konversi-tujuan or kampanye condition.

Is this the pelacakan code for my situs web?

No. The MCP peladen is for connected AI assistants that need to read or operate on Hitsteps data. Situs web pelacakan still uses the Hitsteps JavaScript pelacakan code or a platform-specific Hitsteps pengaya.

Can an AI assistant change my Hitsteps akun after I connect it?

Only if the OAuth grant includes the required write scope and the user explicitly confirms the specific write aksi. Read-only analitik grants cannot create situs web, change pengaturan, edit waktu aktif pemantau, update peringatan, or send obrolan replies.

Can I connect ChatGPT or Claude AI?

Yes. Claude users can pasang Analitik Web Hitsteps from the Claude Connector Directory. The ChatGPT directory daftar is coming soon; until then, add https://www.hitsteps.com/mcp/ manually as a custom MCP peladen in ChatGPT and complete Hitsteps OAuth.

What happens if my Hitsteps uji coba, lisensi, or plan limit blocks access?

The peladen returns a structured license_action_required response with non-sensitive akun status and a Hitsteps URL where the user can check, renew, or tingkatkan. Connection info, situs daftar, and akun status remain available so the assistant can explain the issue.

Does Hitsteps store my AI prompts?

MCP usage telemetry is privacy-minimal. It catatan operational bidang such as public OAuth client ID, normalized AI-client channel, tool name, status, duration, credential type, akun/situs, and timestamp. It does not store prompts, tool arguments, model tokens, raw user agen, raw result rows, or full kesalahan-pesan bodies.

Setelah instalasi

What AI assistants can do with Hitsteps

Ask for trafik ringkasan, sumber breakdowns, top halaman, kampanye, realtime pengunjung, pelacakan health, and executive digests from current Hitsteps data.
Work with Hitsteps-native operations such as situs web penyiapan, tujuan, Pemicu (called pengunjung labels in MCP), waktu aktif contacts and pemantau, per-user peringatan, and authorized obrolan alur kerja.
Keep access bounded by OAuth scopes, akun izin, plan limits, confirmation prompts, and privacy-aware result shapes.