Odel
Hitsteps Analytics and Operations

Hitsteps Analytics and Operations

@hitstepsUpdated 2w ago

AI access to Hitsteps analytics, live visitors, uptime, goals, alerts, and chats.

View on GitHub
Server endpointStreamable HTTPOAuthProbed

This is the third-party server itself — Odel doesn't run it. Hitting this URL directly talks straight to the upstream server with no auth or proxying. Connect through Odel to front it with managed auth.

Hitsteps MCP Server

Public metadata and setup notes for the Hitsteps remote Model Context Protocol server.

Hitsteps exposes a hosted MCP server for analytics and website operations:

https://www.hitsteps.com/mcp/

The current registry metadata release is 1.1.6. This repository is intentionally small: it contains public registry metadata and setup notes, not the production Hitsteps PHP service, private OAuth keys, reviewer accounts, customer data, or deployment credentials.

Install

Use the full Hitsteps setup and security guide:

https://www.hitsteps.com/plugin/?type=mcp

Available client paths:

Google Antigravity configuration:

{
  "mcpServers": {
    "Hitsteps": {
      "serverUrl": "https://www.hitsteps.com/mcp/"
    }
  }
}

The same managed endpoint is used by every client. There is no local package, Node.js process, desktop bridge, SSE worker, or separate customer-hosted service to install.

Registry Metadata

The root server.json file is the canonical public metadata for MCP registries and galleries. It declares:

  • registry name: com.hitsteps/analytics-operations
  • display title: Hitsteps Analytics and Operations
  • transport: Streamable HTTP
  • remote endpoint: https://www.hitsteps.com/mcp/
  • icon: https://www.hitsteps.com/favicon.png
  • documentation: https://www.hitsteps.com/plugin/?type=mcp
  • current metadata version: 1.1.6

The com.hitsteps/analytics-operations name is domain-authenticated. Keep this identity unless Hitsteps intentionally publishes a second GitHub-namespaced entry such as io.github.Hitsteps/....

Authentication and Safety

Hitsteps uses OAuth for public MCP access. Users sign in on Hitsteps and approve the requested scopes before the client receives a token. The client configuration contains only the endpoint URL; never paste a Hitsteps password, tracking API key, OAuth token, private key, or reviewer credential into a client configuration or this repository.

The server rechecks the signed-in account, sub-user permissions, visible websites, license state, feature limits, and granted OAuth scopes on every request. Write operations require their specific scope, explicit confirmation, and an idempotency key. Results are privacy-shaped and do not expose raw SQL, private keys, raw visitor-profile dumps, or session-replay video.

Validation

Validate metadata before publishing:

mcp-publisher validate

Publish from this repository only after domain authentication is available to the publisher environment. Private signing keys and domain-authentication material must stay outside this repository.

Security Reports

Please report suspected vulnerabilities through the Hitsteps contact page. Do not open public issues containing OAuth tokens, customer analytics data, account credentials, private keys, reviewer credentials, or raw request logs with sensitive values.