AI 助手集成

Hitsteps AI MCP 服务器文档

Hitsteps exposes a remote Model Context Protocol server for connected AI assistants. Use it to ask about analytics, live visitors, sites, goals, uptime, alerts, Mentions, and authorized chat activity from your Hitsteps account while keeping access bounded by OAuth scopes, account permissions, license checks, and privacy-shaped tool results.

开始之前

可访问您要查看的网站的 Hitsteps 账户
支持远程 Streamable HTTP 服务器的 MCP 兼容 AI 客户端或工作区设置
当 AI 客户端询问时,能够使用 Hitsteps OAuth 登录
关于助理应接收哪些 OAuth 范围的决定

选择您的人工智能客户端

在已经使用AI的地方安装Hitsteps

客户端目录可用时,请从那里开始。每种方式都会连接到同一托管 Hitsteps MCP 服务器,随后进入 Hitsteps OAuth 授权流程。

GitHub注册表

VS Code 和 GitHub Copilot

打开 GitHub 的 MCP 注册表并从 VS Code 或 GitHub Copilot 客户端安装 Hitsteps Web Analytics。

现已上市

Cursor

打开 Hitsteps Web Analytics 目录中的 Hitsteps Web Analytics 列表,然后选择添加到 Cursor。 Cursor仅接收被管理的Hitsteps MCP端点;您的帐户访问权限是通过 OAuth 单独授予的。

现已上市

Claude AI

从 Claude 的连接器目录添加 Hitsteps Web Analytics,然后登录到 Hitsteps 并仅批准您希望 Claude 使用的范围。

即将推出

ChatGPT AI

Hitsteps 的 ChatGPT 目录条目即将推出。目前请手动将下方端点添加为自定义 MCP 服务器,然后完成 Hitsteps OAuth 授权。

https://www.hitsteps.com/mcp/

安装指南

Google Antigravity 和其他 MCP 客户端

1

使用远程 MCP 端点

Hitsteps MCP 端点为 https://www.hitsteps.com/mcp/。如果客户端要求选择传输方式,请选择 Streamable HTTP 或 HTTP。官方注册名称为 com.hitsteps/analytics-operations。

2

选择访问级别

在连接服务器之前,请确认哪个Hitsteps用户将登录、该用户可以访问哪些网站以及AI客户端请求的OAuth范围。仅分析用途可以保持只读;操作工作流需要下面描述的特定写入范围。

3

将 Hitsteps 添加到 Google Antigravity

Antigravity 的自定义远程 MCP 配置使用 serverUrl 指定远程服务器。

4

使用 Hitsteps OAuth 进行身份验证

保存配置,在 AI 客户端中启动或刷新 MCP 服务器,然后按照提示登录。Hitsteps 使用 OAuth,因此无需将跟踪 API 密钥粘贴到 AI 客户端。

5

验证工具和最低权限

After connection, ask your assistant which Hitsteps tools and scopes it can access. Read-only analytics tools can answer reports; management tools such as goals, Segments, uptime, alerts, Mentions, and chat actions require matching OAuth scopes, account permissions, and explicit confirmation.

值得了解

  • 此 MCP 服务器供 AI 助手使用。它不会在您的网站上安装 Hitsteps 跟踪代码。
  • VS Code和GitHub Copilot用户应从GitHub的MCP注册表开始; Cursor 和 Claude 用户可以使用上面的专用 Hitsteps 目录列表。
  • ChatGPT 目录支持即将推出。在此之前,手动添加 https://www.hitsteps.com/mcp/ 作为自定义 MCP 服务器。
  • 请勿将您的 Hitsteps 网站跟踪 API 密钥、OAuth 令牌或帐户密码粘贴到 MCP 配置中。

故障排查

  • 浏览器对 MCP 端点发起 GET 请求时,可能返回无 SSE 或方法相关消息。这是正常现象;MCP 客户端通过 HTTP 使用 JSON-RPC 进行连接。
  • 登录前收到 401 响应是正常的。客户端应使用公布的 OAuth 元数据开始授权。
  • 如果官方客户端目录未显示 Hitsteps,请刷新目录并检查客户端的组织策略和 MCP 设置。

控制面板中的 Hitsteps AI

按您的方式使用 AI:在 Hitsteps 内或在您自己的助手中

您可以直接在控制面板中使用 Hitsteps AI,也可以将免费的 Hitsteps MCP Plugin 连接到您自己的兼容 AI 助手,进行对话式网站分析。

安全和访问

连接详情

使用这些详细信息连接 Hitsteps 并了解 AI 助手可以从您的帐户访问哪些内容。

公共端点

https://www.hitsteps.com/mcp/ is the production MCP endpoint. The slashless https://www.hitsteps.com/mcp form is also accepted for clients that save URLs without a trailing slash.

传输方式

Hitsteps 将远程 Streamable HTTP 与 JSON-RPC 结合使用。无需安装本地 Node.js 软件包、桌面桥、SSE 工作线程或单独的客户托管进程。

注册身份

注册表/服务器名称为 com.hitsteps/analytics-operations,显示的标题为 Hitsteps Analytics and Operations。

身份验证

Public AI clients use Hitsteps OAuth with authorization code flow and S256 PKCE. Dynamic registration supports new and custom clients, while the consent page asks you to verify the exact callback and scopes and requires an extra acknowledgement for write access.

配置中无需共享密钥

MCP 配置仅包含端点 URL。请勿将 Hitsteps 密码、跟踪 API 密钥、网站代码或 OAuth 令牌粘贴到 AI 客户端配置文件中。

受限访问

每个请求都会根据登录的 Hitsteps 帐户、子用户权限、可见网站、许可证状态、功能限制以及授予该客户端的 OAuth 范围进行重新检查。

授权

OAuth 范围

Hitsteps 为每个工具发布 OAuth 声明。AI 客户端可以根据所需工作流程申请范围较窄的只读授权,或范围更广的操作授权。

analytics:read
阅读分析报告、站点列表、站点上下文、跟踪运行状况、聚合行为摘要、实时快照和帐户/许可证状态。
sites:write
创建网站并在明确确认后更新允许的网站设置。
goals:write
明确确认后创建、更新或删除目标和营销活动配置。
labels:write
Create, update, or delete Segments after explicit confirmation. The MCP API keeps its legacy label identifiers for compatibility.
uptime:write
明确确认后,创建、更新或删除可用性联系人、监控、维护计划和恢复操作。
alerts:read
读取授权帐户的警报列表和警报状态。
alerts:write
明确确认后将警报标记为已读或清除警报。
chat:read
阅读授权的聊天列表、搜索结果、对话摘要和选定的聊天详细信息。
chat:write
创建票证、回复聊天、添加内部注释、更新聊天状态、命名访客、将聊天标记为已读,或在明确确认后逻辑删除聊天。
mentions:read
Read active Mentions queries and combined Web Search/X results.
mentions:write
Add, rename, or remove active Mentions keyword queries after explicit confirmation.

工具覆盖范围

助理可以要求 Hitsteps 做什么

MCP 服务器提供分析读取工具、需要确认的写入工具、需要身份验证的资源、资源模板和提示词。Mentions 读取使用一小时缓存;更改 Mentions 查询需要明确确认。

数据查询与报告

连接信息、可见网站、站点上下文、指标和维度目录、概览报告、补齐缺口的时间序列、数据细分、异常检测、流量变化解释、管理层摘要以及最少化的 MCP 使用遥测。

流量与获客

流量摘要、时段比较、来源、社交引荐流量、分时流量、热门页面、进入/退出页面、页面详情与速度、下载、出站链接、引荐来源、国家/地区、受众技术、搜索引擎、关键词、AI 引荐流量、机器人流量和实时访客。

转化和行为

Goals, goal conversions, campaigns, funnel performance, interaction events, aggregate paths, retention, Segments, heatmap summaries, tracked-video analytics, chat summaries, uptime status/history, and tracking health.

配置与操作

Website setup, allowed website settings, goal/campaign configuration, Segment configuration, uptime contacts and monitors, maintenance schedules, recovery actions, alert operations, Mentions query configuration, and authorized chat workflows.

写入操作保障措施

  • 所有更改工具都需要 OAuth,以及为该工具指定的准确权限范围。旧版网站 API 密钥和私有移动令牌只能读取分析数据。
  • 每项更改操作都要求用户先在 AI 客户端对话中明确确认,然后提供 confirm=true。
  • 每项更改操作都需要 8–128 个字符的 idempotency_key。使用相同参数重复使用同一密钥会返回先前结果;使用不同参数重复使用则返回 HTTP 409。
  • 更改操作在数据库事务内执行;修改数据前会重新检查账户状态、网站所有权、子用户角色、套餐功能是否可用、对象配额及目标的当前状态。
  • 写入审核记录存储操作元数据,例如帐户、网站、工具、目标、状态、哈希值和时间。它们不存储完整的提示、模型令牌、原始客户行或大型有效负载。

数据访问和隐私边界

  • Realtime visitor output omits raw IP addresses, visitor IDs, Segment matches, keywords, URL query strings, and fragments.
  • 页面、下载、出站链接、路径、留存、营销活动、热图和漏斗结果以汇总或隐私保护后的摘要形式提供,而不是导出原始事件。
  • 目标配置不包含通知地址、敏感触发器值和单条转化记录。可用性输出不包含凭据、匹配条件、查询字符串和 URL 片段(# 后部分)。
  • 获授权的用户只能通过具有聊天权限范围的工具访问聊天内容。AI 客户端应将聊天内容视为由客户提供且不可信的文本。
  • MCP 使用遥测保留帐户/站点、凭证类型、公共 OAuth 客户端 ID、标准化 AI 客户端通道、工具名称、状态、持续时间和时间戳,以实现操作可见性。它不包括提示、参数、令牌、原始用户代理、结果行和错误消息正文,并且汇总窗口为 90 天。
  • 服务器特意不提供原始 SQL 访问、账单或密码修改、账户资料或 2FA 修改、原始访客资料转储、私钥、跟踪 API 密钥修改、会话回放视频、JavaScript 控制台日志、网络跟踪或实验管理。

OAuth 发现和客户端兼容性

  • 受保护资源元数据: https://www.hitsteps.com/.well-known/oauth-protected-resource/mcp
  • 授权服务器元数据: https://www.hitsteps.com/.well-known/oauth-authorization-server
  • MCP 端点接受基于浏览器和桌面客户端的有效 HTTPS MCP 客户端源和 HTTP 环回开发源。
  • 动态客户端注册支持桌面 MCP 客户端使用的安全 HTTPS、HTTP 环回和私有原生应用重定向方案,同时拒绝 javascript:、data:、file:、blob: 和 websocket 等不安全方案。
  • Registration is intentionally open for new and custom clients. The consent page asks users to verify the exact callback and scopes, and requires an extra acknowledgement before write-capable access is granted.
  • 资源的 audience 值为 https://www.hitsteps.com/mcp 或 https://www.hitsteps.com/mcp/,与 AI 客户端保存的端点形式一致。

FAQ

Questions about connecting Hitsteps to AI

Review the access, tracking, and privacy answers before you connect an AI assistant.

Why do MCP tool names still say label?

The Hitsteps dashboard calls the feature Segments, and each saved object is a Segment. Stable MCP tools and scopes retain legacy identifiers such as create_label and labels:write for compatibility. An unqualified request for a Hitsteps Segment should use those tools unless the user explicitly means a conversion-goal or campaign trigger condition.

这是我网站的跟踪代码吗?

不是。MCP 服务器供连接的 AI 助手读取或操作 Hitsteps 数据;网站跟踪仍使用 Hitsteps JavaScript 跟踪代码或对应平台的 Hitsteps 插件。

连接后,AI助手可以更改我的Hitsteps账户吗?

只有在 OAuth 授权包含所需写入范围,且用户明确确认具体写入操作时才可以。只读分析权限不能创建网站、更改设置、编辑可用性监控、更新警报或发送聊天回复。

我可以连接ChatGPT或Claude AI吗?

是的。 Claude 用户可以从 Claude 连接器目录安装 Hitsteps Web Analytics。 ChatGPT 目录列表即将推出;在此之前,请在 ChatGPT 中手动添加 https://www.hitsteps.com/mcp/ 作为自定义 MCP 服务器,并完成 Hitsteps OAuth。

How do I know an MCP client is trusted?

Hitsteps supports new and custom clients through open OAuth registration. Start the connection from the client you chose, then review the Hitsteps consent page: verify that the exact callback destination and requested scopes match what the client shows you. Cancel unexpected requests, and treat write-capable access as an additional decision.

如果我的 Hitsteps 试用版、许可证或计划限制阻止访问,会发生什么情况?

服务器返回结构化的 license_action_required 响应,其中包含非敏感帐户状态和 Hitsteps URL,用户可以在其中检查、续订或升级。连接信息、站点列表和帐户状态仍然可用,以便助理可以解释问题。

Hitsteps 会存储我的 AI 提示吗?

MCP 使用遥测仅收集最少的隐私相关数据。它记录公共 OAuth 客户端 ID、标准化 AI 客户端通道、工具名称、状态、持续时间、凭证类型、帐户或站点和时间戳等操作字段;不存储提示词、工具参数、模型令牌、原始用户代理、原始结果行或完整错误消息正文。

安装后

AI 助手可通过 Hitsteps 完成什么

基于当前 Hitsteps 数据,查询流量概览、来源细分、热门页面、广告活动、实时访客、跟踪状态和管理层摘要。
Work with Hitsteps-native operations such as website setup, goals, Segments, uptime contacts and monitors, per-user alerts, Mentions query management, and authorized chat workflows.
通过 OAuth 范围、账户权限、套餐限制、确认提示和隐私友好的结果结构来限制访问。