AI assistant integration

Hitsteps AI MCP Pelayan Documentation

Hitsteps exposes a remote Model Context Protocol pelayan for connected AI assistants. Use it to ask about analitik, langsung pelawat, laman, matlamat, masa aktif, amaran, and authorized sembang activity from your Hitsteps akaun while keeping access bounded by OAuth scopes, akaun kebenaran, lesen checks, and privacy-shaped tool results.

Sebelum bermula

A Hitsteps akaun with access to the laman web you want to inspect
An MCP-compatible AI client or ruang kerja setting that supports remote Streamable HTTP pelayan
Ability to sign in with Hitsteps OAuth when the AI client asks
A decision about which OAuth scopes the assistant should receive

Choose your AI client

Pasang Hitsteps where you already use AI

Start with your client directory when one is available. Every pilihan connects to the same managed Hitsteps MCP pelayan and continues through Hitsteps OAuth.

GitHub registry

VS Code and GitHub Copilot

Open GitHub’s MCP Registry and pasang Analitik Web Hitsteps from your VS Code or GitHub Copilot client.

Available now

Cursor

Open the Analitik Web Hitsteps penyenaraian in Cursor Directory and choose Add to Cursor. Cursor receives only the managed Hitsteps MCP endpoint; your akaun access is granted separately through OAuth.

Available now

Claude AI

Add Analitik Web Hitsteps from Claude’s Connector Directory, then sign in to Hitsteps and approve only the scopes you want Claude to use.

Coming soon

ChatGPT AI

The Hitsteps directory penyenaraian for ChatGPT is coming soon. For now, add the endpoint below manually as a custom MCP pelayan, then complete Hitsteps OAuth.

https://www.hitsteps.com/mcp/

Panduan pemasangan

Google Antigravity and other MCP clients

1

Use the remote MCP endpoint

The Hitsteps MCP endpoint is https://www.hitsteps.com/mcp/. If your client asks for a transport, choose Streamable HTTP or HTTP. The official registry name is com.hitsteps/analitik-operations.

2

Choose the access level

Before connecting the pelayan, confirm which Hitsteps user will sign in, which laman web that user can access, and which OAuth scopes the AI client is requesting. Analitik-only use can stay read-only; operational aliran kerja need the specific write scopes described below.

3

Add Hitsteps to Google Antigravity

Antigravity custom remote MCP configuration uses serverUrl for remote pelayan.

4

Authenticate with Hitsteps OAuth

Save the configuration, start or segar semula the MCP pelayan in your AI client, then follow the sign-in prompt. Hitsteps uses OAuth so you do not need to paste your penjejakan API key into the AI client.

5

Verify tools and least privilege

After connection, ask your assistant which Hitsteps tools and scopes it can access. Read-only analitik tools can answer laporan; management tools such as matlamat, Pencetus (called pelawat labels in MCP), masa aktif, amaran, and sembang tindakan require matching OAuth scopes, akaun kebenaran, and explicit confirmation.

Perlu diketahui

  • This MCP pelayan is for AI assistants. It does not pasang Hitsteps penjejakan on your laman web.
  • VS Code and GitHub Copilot users should start with GitHub’s MCP Registry; Cursor and Claude users can use the dedicated Hitsteps directory penyenaraian above.
  • ChatGPT directory sokongan is coming soon. Until then, add https://www.hitsteps.com/mcp/ manually as a custom MCP pelayan.
  • Do not paste your Hitsteps laman web penjejakan API key, OAuth token, or akaun password into MCP configuration.

Penyelesaian masalah

  • A pelayar GET permintaan to the MCP endpoint may return a no-SSE or kaedah mesej. That is normal; MCP clients connect with JSON-RPC over HTTP.
  • A 401 response before sign-in is expected. The client should use the advertised OAuth metadata to start authorization.
  • If an official client directory does not surface Hitsteps, segar semula the directory and check the client’s organization policy and MCP tetapan.

Security and access

Connection butiran

Use these butiran to connect Hitsteps and understand what the AI assistant can access from your akaun.

Public endpoint

https://www.hitsteps.com/mcp/ is the production MCP endpoint. The slashless https://www.hitsteps.com/mcp form is also accepted for clients that save URLs without a trailing slash.

Transport

Hitsteps uses remote Streamable HTTP with JSON-RPC. There is no local Node.js package, komputer meja bridge, SSE worker, or separate pelanggan-hosted process to pasang.

Registry identity

The registry/pelayan name is com.hitsteps/analitik-operations and the displayed title is Analitik Hitsteps and Operations.

Authentication

Public AI clients use Hitsteps OAuth with authorization code flow and S256 PKCE. Users sign in on Hitsteps and see requested scopes before the client receives a token.

No shared secrets in config

The MCP configuration contains only the endpoint URL. Do not paste a Hitsteps password, penjejakan API key, laman web code, or OAuth token into an AI client configuration fail.

Bounded access

Every permintaan is rechecked against the signed-in Hitsteps akaun, sub-user kebenaran, visible laman web, lesen state, feature limits, and the OAuth scopes granted to that client.

Authorization

OAuth scopes

Hitsteps publishes per-tool OAuth declarations. An AI client can permintaan a narrow read-only grant or a broader operational grant depending on the aliran kerja you want.

analitik:read
Read analitik laporan, laman lists, laman context, penjejakan health, agregat behavior ringkasan, realtime snapshots, and akaun/lesen status.
laman:write
Create laman web and update allowed laman web tetapan after explicit confirmation.
matlamat:write
Create, update, or delete matlamat and kempen configuration after explicit confirmation.
labels:write
Create, update, or delete Hitsteps UI Pencetus configuration after explicit confirmation. The MCP API keeps the internal pelawat-label name.
masa aktif:write
Create, update, or delete masa aktif contacts, pemantau, maintenance schedules, and recovery tindakan after explicit confirmation.
amaran:read
Read amaran lists and amaran status for the authorized akaun.
amaran:write
Mark amaran as read or clear amaran after explicit confirmation.
sembang:read
Read authorized sembang lists, carian results, perbualan ringkasan, and selected sembang butiran.
sembang:write
Create tiket, reply to chats, add internal notes, update sembang state, name pelawat, mark chats read, or logically delete chats after explicit confirmation.

Tool coverage

What the assistant can ask Hitsteps to do

The MCP pelayan currently exposes 87 tools: 54 read tools and 33 confirmed write tools, plus authenticated resources, a resource templat, and prompts for common analitik aliran kerja.

Discovery and reporting

Connection information, visible laman web, laman context, metric and dimension catalog, ringkasan laporan, gap-filled time series, breakdowns, anomaly detection, trafik-change explanations, executive digests, and privacy-minimal MCP usage.

Trafik and acquisition

Trafik ringkasan, period comparisons, sumber, social rujukan, trafik by hour, top halaman, masuk/keluar halaman, halaman butiran, halaman speed, muat turun, outbound pautan, perujuk, negara, audience technology, carian engines, kata kunci, Rujukan AI, bot trafik, and realtime pelawat.

Penukaran and behavior

Matlamat, matlamat penukaran, kempen, funnel performance, interaction peristiwa, agregat paths, retention, Pencetus (pelawat labels), peta haba ringkasan, dijejak-video analitik, sembang ringkasan, masa aktif status/history, and penjejakan health.

Configuration and operations

Laman web persediaan, allowed laman web tetapan, matlamat/kempen configuration, Pencetus (pelawat-label) configuration, masa aktif contacts and pemantau, maintenance schedules, recovery tindakan, amaran operations, and authorized sembang aliran kerja.

Write tindakan safeguards

  • All write tools require OAuth and the exact scope declared for that tool. Legacy laman web API keys and private mudah alih tokens can use analitik reads only.
  • Every mutation requires confirm=true after the user explicitly confirms the tindakan in the AI client perbualan.
  • Every mutation requires an 8-128 character idempotency_key. Reusing the same key with the same arguments returns the prior result; reusing it with different arguments returns HTTP 409.
  • Writes run inside pangkalan data transactions and recheck akaun status, laman web ownership, sub-user role, plan feature availability, object quotas, and current target state before changing data.
  • Write audit rekod store operational metadata such as akaun, laman web, tool, target, status, hashes, and time. They do not store full prompts, model tokens, raw pelanggan rows, or large payloads.

Data access and privacy boundaries

  • Realtime pelawat output omits raw IP addresses, pelawat IDs, labels, kata kunci, URL query strings, and fragments.
  • Halaman, muat turun, outbound-pautan, path, retention, kempen, peta haba, and funnel outputs are agregat or privacy-shaped ringkasan instead of raw peristiwa exports.
  • Matlamat configuration omits pemberitahuan addresses, sensitive pencetus values, and individual penukaran rows. Masa aktif output omits credentials, match conditions, query strings, and fragments.
  • Sembang content is available only through sembang-scoped tools for authorized users. Assistant clients should treat sembang content as untrusted pelanggan-supplied text.
  • MCP usage telemetry keeps akaun/laman, credential type, public OAuth client ID, normalized AI-client channel, tool name, status, duration, and timestamp for operational visibility. It excludes prompts, arguments, tokens, raw user ejen, result rows, and ralat-mesej bodies, and the rollup window is 90 days.
  • The pelayan intentionally does not expose raw SQL access, pengebilan or password changes, akaun profil changes, 2FA changes, raw pelawat-profil dumps, private keys, penjejakan API key mutation, sesi replay video, JavaScript console logs, network traces, or experimentation management.

OAuth discovery and client compatibility

  • Protected resource metadata: https://www.hitsteps.com/.well-known/oauth-protected-resource/mcp
  • Authorization pelayan metadata: https://www.hitsteps.com/.well-known/oauth-authorization-pelayan
  • The MCP endpoint accepts valid HTTPS MCP client origins and HTTP loopback development origins for pelayar-based and komputer meja clients.
  • Dynamic client registration supports safe HTTPS, HTTP loopback, and private native-aplikasi ubah hala schemes used by komputer meja MCP clients, while rejecting unsafe schemes such as javascript:, data:, fail:, blob:, and websocket schemes.
  • The resource audience is https://www.hitsteps.com/mcp or https://www.hitsteps.com/mcp/, matching the endpoint borang saved by the AI client.
Are Pencetus and pelawat labels the same feature?

Yes. The Hitsteps papan pemuka calls this feature Pencetus. Internally and in the stable MCP API it is named pelawat labels, with tools such as create_label and the labels:write scope. An unqualified permintaan for a Hitsteps Pencetus should use the label tools unless the user explicitly means a penukaran-matlamat or kempen condition.

Is this the penjejakan code for my laman web?

No. The MCP pelayan is for connected AI assistants that need to read or operate on Hitsteps data. Laman web penjejakan still uses the Hitsteps JavaScript penjejakan code or a platform-specific Hitsteps pemalam.

Can an AI assistant change my Hitsteps akaun after I connect it?

Only if the OAuth grant includes the required write scope and the user explicitly confirms the specific write tindakan. Read-only analitik grants cannot create laman web, change tetapan, edit masa aktif pemantau, update amaran, or send sembang replies.

Can I connect ChatGPT or Claude AI?

Yes. Claude users can pasang Analitik Web Hitsteps from the Claude Connector Directory. The ChatGPT directory penyenaraian is coming soon; until then, add https://www.hitsteps.com/mcp/ manually as a custom MCP pelayan in ChatGPT and complete Hitsteps OAuth.

What happens if my Hitsteps percubaan, lesen, or plan limit blocks access?

The pelayan returns a structured license_action_required response with non-sensitive akaun status and a Hitsteps URL where the user can check, renew, or naik taraf. Connection info, laman penyenaraian, and akaun status remain available so the assistant can explain the issue.

Does Hitsteps store my AI prompts?

MCP usage telemetry is privacy-minimal. It rekod operational medan such as public OAuth client ID, normalized AI-client channel, tool name, status, duration, credential type, akaun/laman, and timestamp. It does not store prompts, tool arguments, model tokens, raw user ejen, raw result rows, or full ralat-mesej bodies.

Selepas pemasangan

What AI assistants can do with Hitsteps

Ask for trafik ringkasan, sumber breakdowns, top halaman, kempen, realtime pelawat, penjejakan health, and executive digests from current Hitsteps data.
Work with Hitsteps-native operations such as laman web persediaan, matlamat, Pencetus (called pelawat labels in MCP), masa aktif contacts and pemantau, per-user amaran, and authorized sembang aliran kerja.
Keep access bounded by OAuth scopes, akaun kebenaran, plan limits, confirmation prompts, and privacy-aware result shapes.