{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "amplitude",
    "name": "Amplitude",
    "vendor": "Amplitude, Inc.",
    "vendorUrl": "https://amplitude.com",
    "kind": "http-api",
    "category": "product-analytics",
    "summary": "Amplitude is a hosted product analytics platform that records user events and answers questions about funnels, retention, cohorts, experiments and feature flags. Agents reach it through an official remote MCP server, REST APIs and the `amp` command line.",
    "url": "https://www.anchorterminal.com/tools/amplitude",
    "markdownUrl": "https://www.anchorterminal.com/tools/amplitude.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/amplitude.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/amplitude.json",
    "repo": "https://github.com/amplitude/mcp-marketplace",
    "license": "Proprietary service under Amplitude's terms of service. The SDKs, the `amp` CLI and the MCP marketplace plugins on GitHub and npm are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://mcp.amplitude.com/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@amplitude/developer-cli"
      },
      {
        "registry": "npm",
        "name": "@amplitude/analytics-node"
      },
      {
        "registry": "pypi",
        "name": "amplitude-analytics"
      }
    ],
    "auth": "mixed",
    "authNotes": "Access is self-serve, with no app review or partner approval. The MCP server takes only OAuth 2.0 (authorisation code with PKCE S256, dynamic client registration, scopes `mcp:read`, `mcp:write` and `offline_access`), and a person signs in to Amplitude in a browser. Each call runs with that user's permissions, limited by two role actions, Use MCP (read) and Use MCP (write), per project. The Developer API takes a Bearer token from the OAuth device flow or a personal access token with eight scopes. The older REST APIs use HTTP Basic with a project API key and secret key, the Experiment Management API a management key, and HTTP V2 ingestion the public project API key in the request body.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with 2 million events a month and no card, and the pricing page says MCP and agent access work on every plan. Plus is usage-based from $0 with the first 2 million events free, up to 70 million, and needs a card to see an estimate. Growth and Enterprise are priced by sales. API and MCP calls aren't metered in money. There's no separate sandbox, so an agent starts on a Free organisation (https://amplitude.com/pricing, checked 2026-10-07).",
    "priceSummary": "Freemium",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the Developer API's OpenAPI document or the pricing page (checked 2026-10-07).",
      "endpoints": []
    },
    "toolCount": 45,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 1331780,
      "pypiWeekly": 1779665,
      "asOf": "2026-10-07"
    },
    "docsUrl": "https://amplitude.com/docs/apis",
    "llmsTxt": "https://amplitude.com/docs/llms.txt",
    "openapi": "https://developer-api.amplitude.com/openapi.yaml",
    "registryName": "com.amplitude/mcp-server",
    "capabilities": [
      "analytics.query",
      "analytics.funnels",
      "analytics.experiments",
      "analytics.flags",
      "analytics.events"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "freemium",
      "free-tier",
      "no-card",
      "eu-region",
      "cli",
      "status-page",
      "soc2",
      "python",
      "typescript"
    ],
    "lastRelease": "2026-10-02",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 66.2,
      "grade": "B",
      "agentReady": false,
      "rank": 223,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 72,
        "maintenance": 83,
        "payments": 30,
        "reliability": 60,
        "schema": 72,
        "security": 74,
        "transparency": 78
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 60,
          "points": 12,
          "reason": "Read with the hosted lines and scored on what an agent calls, the remote MCP server first and the REST APIs beside it. status.amplitude.com on Statuspage has 29 components, MCP among them, with incident history (20). Between 9 July and 7 October 2026 it lists one critical and six major incidents. The critical one, on 13 July, affected the UI, MCP and REST APIs in the US from 14:04 PT and was resolved at 16:07 PT. The majors were on shared embeds, EU web latency, a metrics page, AI chat and two export delays on 22 and 23 September, so one outage reached the agent surface and the rest did not (5 of 30, between one major and several). Rate limits with numbers for the Dashboard REST API (5 concurrent, 108,000 cost an hour), Experiment Management (100 a second, 100,000 a day) and HTTP V2 (30 events a second per user or device), and none found for MCP or the Developer API (12 of 15). HTTP V2 says to pause 30 seconds on 429 and deduplicates on `insert_id`, and the Developer API returns `retryable` and `retry_after_seconds` and accepts `Idempotency-Key` on some operations. No guidance for MCP (13 of 15). No SLA found, and the terms disclaim uninterrupted service (0). The MCP server carries no beta label and is 1.0.0 in the official registry. The Developer API's spec is version 0.1.0 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "The Developer API has an OpenAPI 3.1.1 document whose root file is public, but its referenced path files returned 404 and the bundled /v1/openapi.json needs a token. The older REST APIs have no spec, and we couldn't read the MCP tool schemas without an Amplitude sign-in (15 of 25). llms.txt, five product feeds, llms-full.txt and Markdown for every docs page (10). The MCP page says what the server is for and what it isn't, and gives each of 45 tools a one-line description (15 of 20). REST parameter tables are typed with required fields, and the Developer API documents scopes, limits and formats. MCP input schemas unread (9 of 15). Request and response examples throughout the REST docs and error tables per API (13 of 15). Dated release notes at amplitude.com/releases and versioned API paths, but the registry entry has stayed at 1.0.0 since October 2025 while tools were consolidated on 17 August 2026 (10 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "45 tools is over the 30 line (5), with 10 added back for progressive discovery, which starts with four tools and loads schemas on demand, and a subset of about 25 for ChatGPT (15 of 25). Cursor and `limit` pagination on the Developer API (default 50, maximum 200), the Experiment Management API and the data warehouse tools, and filters on search and replay tools. The MCP page warns that hosts may truncate large charts (17 of 20). RFC 9457 errors with `error_code`, `retryable` and field errors on the Developer API and detailed 400 and 429 bodies on HTTP V2. MCP error shapes unread (15 of 20). `Idempotency-Key` and `dry_run` on some Developer API operations, `insert_id` on events, two-step deletes and optimistic concurrency on dashboards and notebooks. We couldn't see whether tools carry readOnlyHint or destructiveHint (13 of 20). Official SDKs in many languages cover ingestion and experiment evaluation, not queries, and the `amp` CLI prints compact JSON when piped (12 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 74,
          "points": 12.95,
          "reason": "The MCP server takes OAuth 2.0 with PKCE S256, dynamic client registration, a revocation endpoint and `mcp:read` and `mcp:write` scopes, and the Developer API takes scoped tokens. The older REST APIs still use a project API key and secret key, which aren't scoped (28 of 30). Two role actions, Use MCP (read) and Use MCP (write), are enforced per project on each call, an admin can switch MCP off for the organisation, deletes need a second confirmed call and cohort syncs preview first. MCP is on by default and three standard roles include write (17 of 20). Session replays, feedback comments and user properties are untrusted content, and we found only a disclaimer about model outputs, no injection guidance for hosts (2 of 15). An organisation audit log with 90 days of entries and an API, whose event list doesn't name MCP tool calls (9 of 15). security.txt valid to 31 December 2028, SOC 2 Type II, ISO 27001, 27017 and 27018 on the trust portal and a bug bounty that is private (18 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Plans are public but Plus shows a price only through an estimator that asks for a card, and Growth and Enterprise go through sales (10). The Free plan has 2 million events a month with no card, and MCP works on it (20). A person signs up and approves OAuth in a browser, or creates keys in settings (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "@amplitude/developer-cli 0.4.0 on 2 October 2026, and the release notes add MCP taxonomy delete and restore on 12 September (30). At least 15 dated release notes since 17 August and four CLI releases since 5 August (20). Closed service with public release notes, a feedback form for MCP and 19 commits to the amplitude/mcp-marketplace repository since 9 July. We didn't test support (11 of 15). com.amplitude/mcp-server is in the official MCP registry under the vendor's domain (15). The marketplace plugin bumps versions automatically (1.6.0 on 8 September), while the CLI needs Node.js 26 and the registry entry is a year old (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "note": "editorial 63, provenance 93",
          "reason": "Closed service with terms effective 21 July 2026. The SDKs, CLI and marketplace plugins are MIT (15). The DPA of 4 June 2024 promises destruction within 90 days of termination and use only to run the service, while the terms let Amplitude apply machine learning to customer data to improve the services and delete data at its discretion after termination. The AI docs say data isn't used for model training (20 of 30). A written SDK lifecycle with at least 12 months of maintenance for a superseded major version. No deprecation policy for the REST APIs or MCP tools found (10 of 20). Sub-processor list updated 13 May 2026 with US and EU data centre locations and 10 business days' notice of additions under the DPA (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-07",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "45 tools is over the 30 line (5), with 10 added back for progressive discovery, which starts with four tools and loads schemas on demand, and a subset of about 25 for ChatGPT (15 of 25). Cursor and `limit` pagination on the Developer API (default 50, maximum 200), the Experiment Management API and the data warehouse tools, and filters on search and replay tools. The MCP page warns that hosts may truncate large charts (17 of 20). RFC 9457 errors with `error_code`, `retryable` and field errors on the Developer API and detailed 400 and 429 bodies on HTTP V2. MCP error shapes unread (15 of 20). `Idempotency-Key` and `dry_run` on some Developer API operations, `insert_id` on events, two-step deletes and optimistic concurrency on dashboards and notebooks. We couldn't see whether tools carry readOnlyHint or destructiveHint (13 of 20). Official SDKs in many languages cover ingestion and experiment evaluation, not queries, and the `amp` CLI prints compact JSON when piped (12 of 15).",
          "maintenance": "@amplitude/developer-cli 0.4.0 on 2 October 2026, and the release notes add MCP taxonomy delete and restore on 12 September (30). At least 15 dated release notes since 17 August and four CLI releases since 5 August (20). Closed service with public release notes, a feedback form for MCP and 19 commits to the amplitude/mcp-marketplace repository since 9 July. We didn't test support (11 of 15). com.amplitude/mcp-server is in the official MCP registry under the vendor's domain (15). The marketplace plugin bumps versions automatically (1.6.0 on 8 September), while the CLI needs Node.js 26 and the registry entry is a year old (7 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Plans are public but Plus shows a price only through an estimator that asks for a card, and Growth and Enterprise go through sales (10). The Free plan has 2 million events a month with no card, and MCP works on it (20). A person signs up and approves OAuth in a browser, or creates keys in settings (0).",
          "reliability": "Read with the hosted lines and scored on what an agent calls, the remote MCP server first and the REST APIs beside it. status.amplitude.com on Statuspage has 29 components, MCP among them, with incident history (20). Between 9 July and 7 October 2026 it lists one critical and six major incidents. The critical one, on 13 July, affected the UI, MCP and REST APIs in the US from 14:04 PT and was resolved at 16:07 PT. The majors were on shared embeds, EU web latency, a metrics page, AI chat and two export delays on 22 and 23 September, so one outage reached the agent surface and the rest did not (5 of 30, between one major and several). Rate limits with numbers for the Dashboard REST API (5 concurrent, 108,000 cost an hour), Experiment Management (100 a second, 100,000 a day) and HTTP V2 (30 events a second per user or device), and none found for MCP or the Developer API (12 of 15). HTTP V2 says to pause 30 seconds on 429 and deduplicates on `insert_id`, and the Developer API returns `retryable` and `retry_after_seconds` and accepts `Idempotency-Key` on some operations. No guidance for MCP (13 of 15). No SLA found, and the terms disclaim uninterrupted service (0). The MCP server carries no beta label and is 1.0.0 in the official registry. The Developer API's spec is version 0.1.0 (10).",
          "schema": "The Developer API has an OpenAPI 3.1.1 document whose root file is public, but its referenced path files returned 404 and the bundled /v1/openapi.json needs a token. The older REST APIs have no spec, and we couldn't read the MCP tool schemas without an Amplitude sign-in (15 of 25). llms.txt, five product feeds, llms-full.txt and Markdown for every docs page (10). The MCP page says what the server is for and what it isn't, and gives each of 45 tools a one-line description (15 of 20). REST parameter tables are typed with required fields, and the Developer API documents scopes, limits and formats. MCP input schemas unread (9 of 15). Request and response examples throughout the REST docs and error tables per API (13 of 15). Dated release notes at amplitude.com/releases and versioned API paths, but the registry entry has stayed at 1.0.0 since October 2025 while tools were consolidated on 17 August 2026 (10 of 15).",
          "security": "The MCP server takes OAuth 2.0 with PKCE S256, dynamic client registration, a revocation endpoint and `mcp:read` and `mcp:write` scopes, and the Developer API takes scoped tokens. The older REST APIs still use a project API key and secret key, which aren't scoped (28 of 30). Two role actions, Use MCP (read) and Use MCP (write), are enforced per project on each call, an admin can switch MCP off for the organisation, deletes need a second confirmed call and cohort syncs preview first. MCP is on by default and three standard roles include write (17 of 20). Session replays, feedback comments and user properties are untrusted content, and we found only a disclaimer about model outputs, no injection guidance for hosts (2 of 15). An organisation audit log with 90 days of entries and an API, whose event list doesn't name MCP tool calls (9 of 15). security.txt valid to 31 December 2028, SOC 2 Type II, ISO 27001, 27017 and 27018 on the trust portal and a bug bounty that is private (18 of 20).",
          "transparency": "Closed service with terms effective 21 July 2026. The SDKs, CLI and marketplace plugins are MIT (15). The DPA of 4 June 2024 promises destruction within 90 days of termination and use only to run the service, while the terms let Amplitude apply machine learning to customer data to improve the services and delete data at its discretion after termination. The AI docs say data isn't used for model training (20 of 30). A written SDK lifecycle with at least 12 months of maintenance for a superseded major version. No deprecation policy for the REST APIs or MCP tools found (10 of 20). Sub-processor list updated 13 May 2026 with US and EU data centre locations and 10 business days' notice of additions under the DPA (18 of 20)."
        },
        "sources": [
          {
            "what": "MCP server guide, tools, regions and role controls",
            "url": "https://amplitude.com/docs/amplitude-ai/amplitude-mcp",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP OAuth authorisation server metadata",
            "url": "https://mcp.amplitude.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-07"
          },
          {
            "what": "Developer API guide (auth, scopes, pagination, errors, idempotency)",
            "url": "https://amplitude.com/docs/apis/developer",
            "seen": "2026-10-07"
          },
          {
            "what": "Developer API OpenAPI root document",
            "url": "https://developer-api.amplitude.com/openapi.yaml",
            "seen": "2026-10-07"
          },
          {
            "what": "Dashboard REST API and its rate limits",
            "url": "https://amplitude.com/docs/apis/analytics/dashboard-rest",
            "seen": "2026-10-07"
          },
          {
            "what": "HTTP V2 API, limits and 429 handling",
            "url": "https://amplitude.com/docs/apis/analytics/http-v2",
            "seen": "2026-10-07"
          },
          {
            "what": "Experiment Management API",
            "url": "https://amplitude.com/docs/apis/experiment/experiment-management-api",
            "seen": "2026-10-07"
          },
          {
            "what": "Keys and tokens",
            "url": "https://amplitude.com/docs/apis/keys-and-tokens",
            "seen": "2026-10-07"
          },
          {
            "what": "llms.txt",
            "url": "https://amplitude.com/docs/llms.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "pricing",
            "url": "https://amplitude.com/pricing",
            "seen": "2026-10-07"
          },
          {
            "what": "status incident history",
            "url": "https://status.amplitude.com/api/v2/incidents.json",
            "seen": "2026-10-07"
          },
          {
            "what": "13 July 2026 critical incident",
            "url": "https://stspg.io/xvxd55g7kwjb",
            "seen": "2026-10-07"
          },
          {
            "what": "release notes",
            "url": "https://amplitude.com/releases",
            "seen": "2026-10-07"
          },
          {
            "what": "official MCP registry entry",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=amplitude",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP marketplace repository",
            "url": "https://github.com/amplitude/mcp-marketplace",
            "seen": "2026-10-07"
          },
          {
            "what": "amp CLI on npm",
            "url": "https://registry.npmjs.org/@amplitude/developer-cli",
            "seen": "2026-10-07"
          },
          {
            "what": "terms of service",
            "url": "https://amplitude.com/terms",
            "seen": "2026-10-07"
          },
          {
            "what": "data processing addendum",
            "url": "https://amplitude.com/terms/dpa",
            "seen": "2026-10-07"
          },
          {
            "what": "privacy notice",
            "url": "https://amplitude.com/privacy",
            "seen": "2026-10-07"
          },
          {
            "what": "sub-processor list",
            "url": "https://www.amplitude.com/subprocessor-list",
            "seen": "2026-10-07"
          },
          {
            "what": "security.txt",
            "url": "https://amplitude.com/.well-known/security.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "security and privacy FAQ",
            "url": "https://amplitude.com/docs/faq/security-and-privacy",
            "seen": "2026-10-07"
          },
          {
            "what": "trust portal",
            "url": "https://trust.amplitude.com/",
            "seen": "2026-10-07"
          },
          {
            "what": "audit log",
            "url": "https://amplitude.com/docs/admin/audit-log",
            "seen": "2026-10-07"
          }
        ],
        "openQuestions": [
          "unchecked: the MCP tools' JSON Schema inputs and their readOnlyHint and destructiveHint annotations, which need an Amplitude sign-in to list",
          "unchecked: the Developer API's per-operation schemas, since the path files referenced by the public OpenAPI root returned 404 and /v1/openapi.json needs a token",
          "unchecked: the Plus plan's price per event, shown only in an estimator",
          "unchecked: whether MCP tool calls appear in the organisation audit log, which the audit log page doesn't say",
          "unchecked: how MCP service accounts are created, named on the MCP page with no setup guide found",
          "No rate limit for the MCP server or the Developer API was found in the reviewed documentation",
          "No SLA was found on amplitude.com (amplitude.com/sla returns 404). An enterprise contract may include one",
          "GitHub star counts weren't collected. npmWeekly is @amplitude/analytics-node and pypiWeekly is amplitude-analytics, both ingestion SDKs"
        ]
      },
      "negative": 0,
      "verdict": "The remote MCP server covers queries, funnels, retention, experiments and flags under OAuth with PKCE, read and write scopes and per-project role actions, and the Free plan needs no card. No MCP rate limits or SLA were found, and status.amplitude.com records a critical outage of the UI, MCP and REST APIs on 13 July 2026.",
      "bestFor": "A team already on Amplitude that wants an agent to query charts, funnels, retention and experiment results, edit dashboards and manage the tracking plan under its own permissions.",
      "strengths": [
        "Remote MCP server with 45 documented tools for queries, funnels, retention, cohorts, experiments, flags and the tracking plan, on US and EU hosts",
        "OAuth with PKCE, dynamic client registration, a revocation endpoint and `mcp:read` and `mcp:write` scopes, plus two role actions enforced per project on every call",
        "Progressive discovery (`?discovery=progressive`) starts with a small tool list and loads schemas on demand",
        "Deletes need a second call with `confirmed` set to true, and cohort syncs preview the export before sending",
        "Free plan with 2 million events a month and no card, and the pricing page says MCP works on every plan"
      ],
      "weaknesses": [
        "No rate limit for the MCP server or the Developer API was found in the reviewed documentation",
        "status.amplitude.com lists one critical and six major incidents between 9 July and 23 September 2026, with the UI, MCP and REST APIs down on 13 July",
        "No SLA found, and the terms of 21 July 2026 disclaim uninterrupted service",
        "MCP is on by default for every user, and the Member, Manager and Admin roles include write access until an admin changes them",
        "Session replays, feedback comments and user properties reach the model with no prompt-injection guidance for hosts"
      ],
      "agentNotes": [
        "Connect to https://mcp.amplitude.com/mcp, or https://mcp.eu.amplitude.com/mcp for EU projects. The client must support streaming HTTP and OAuth, since API keys aren't accepted",
        "Append `?discovery=progressive` to load tool schemas on demand, then call `get_amplitude_context` first to pick the project and read its AI context",
        "Ask an admin for a role with only Use MCP (read) on the projects you need. Tools stay listed and fail at call time when the role lacks the action",
        "Send events through the HTTP V2 API with an `insert_id` on each one. On 429, pause that user or device for 30 seconds before retrying",
        "Budget Dashboard REST queries by cost (days times conditions times chart cost), within 108,000 an hour and 5 concurrent requests per project"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 66.2
        }
      ],
      "editorialScores": {
        "ergonomics": 72,
        "maintenance": 83,
        "payments": 30,
        "reliability": 60,
        "schema": 72,
        "security": 74,
        "transparency": 63
      },
      "provenanceScore": 93
    },
    "connect": {
      "install": "npm install -g @amplitude/developer-cli",
      "http": "curl --location --request GET 'https://amplitude.com/api/3/chart/:chart_id/csv' \\\n-u '{api_key}:{secret_key}'",
      "claudeCode": "claude mcp add -t http -s user Amplitude \"https://mcp.amplitude.com/mcp\"",
      "config": {
        "mcpServers": {
          "amplitude": {
            "type": "http",
            "url": "https://mcp.amplitude.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/analytics.query",
      "tool": "https://letme.dev/amplitude"
    },
    "notable": [
      "The MCP page lists 45 tools in 14 groups, among them `query_amplitude_data` for segmentation, funnels and retention, `query_experiment`, `get_flags`, `use_amplitude_cohorts` and three session replay tools, plus three progressive discovery tools (https://amplitude.com/docs/amplitude-ai/amplitude-mcp)",
      "OAuth metadata at mcp.amplitude.com lists PKCE S256, dynamic client registration, a revocation endpoint and the scopes `mcp:read`, `mcp:write` and `offline_access` (https://mcp.amplitude.com/.well-known/oauth-authorization-server)",
      "The Developer API at developer-api.amplitude.com is described by an OpenAPI 3.1.1 document, version 0.1.0, with 32 paths. The root file is public, its referenced path files returned 404 to us and /v1/openapi.json asks for a token (https://developer-api.amplitude.com/openapi.yaml)",
      "The Dashboard REST API limits each project to 5 concurrent requests and 108,000 cost an hour, where cost is days times conditions times a per-chart figure (https://amplitude.com/docs/apis/analytics/dashboard-rest)",
      "status.amplitude.com has an MCP component and recorded a critical incident on 13 July 2026, with the UI, MCP and REST APIs affected from 14:04 PT and the incident resolved at 16:07 PT (https://stspg.io/xvxd55g7kwjb)",
      "The official MCP registry lists com.amplitude/mcp-server 1.0.0 with the US and EU remotes, published 16 October 2025 (https://registry.modelcontextprotocol.io/v0/servers?search=amplitude)",
      "The `amp` CLI, @amplitude/developer-cli on npm, went from 0.1.0 on 26 June 2026 to 0.4.0 on 2 October 2026 (https://registry.npmjs.org/@amplitude/developer-cli)"
    ],
    "area": "business",
    "details": [
      {
        "label": "MCP server",
        "value": "Remote, streaming HTTP, OAuth 2.0 only. https://mcp.amplitude.com/mcp (US) and https://mcp.eu.amplitude.com/mcp (EU). 45 documented tools, with about 25 for ChatGPT"
      },
      {
        "label": "MCP tool groups",
        "value": "Discovery and context (3), charts (4), dashboards (1), notebooks, comments and sharing (3), cohorts (1), users (1), experiments and flags (9), taxonomy (6), session replay (3), guides and surveys (2), opportunities (5), feedback (1), agent analytics (2), data warehouse (4)"
      },
      {
        "label": "Progressive discovery",
        "value": "`?discovery=progressive` on either URL returns `get_amplitude_context`, `list_tool_categories`, `get_category_tools` and `describe_tool` first, and every tool stays callable"
      },
      {
        "label": "REST APIs",
        "value": "HTTP V2 ingestion at api2.amplitude.com, Dashboard REST and Export at amplitude.com/api, Behavioural Cohorts, Taxonomy, Experiment Management at experiment.amplitude.com, Audit Logs and SCIM, each with EU hosts"
      },
      {
        "label": "Developer API",
        "value": "https://developer-api.amplitude.com, OpenAPI 3.1.1, version 0.1.0, 32 paths for projects, taxonomy, saved charts, heatmaps, flags and destinations. Experiment paths are commented out as under construction"
      },
      {
        "label": "Credentials",
        "value": "MCP by OAuth with PKCE and dynamic client registration. Developer API by device flow or personal access token with eight scopes. Older APIs by project API key and secret key, or an Experiment management key"
      },
      {
        "label": "Access controls",
        "value": "Org-level MCP switch, role actions Use MCP (read) and Use MCP (write) per project, on by default. Read is in every role and write in Member, Manager and Admin"
      },
      {
        "label": "Rate limits",
        "value": "Dashboard REST 5 concurrent and 108,000 cost an hour per project. User activity and search 10 concurrent and 360 an hour. Experiment Management 100 a second and 100,000 a day. HTTP V2 30 events a second per user or device. None found for MCP"
      },
      {
        "label": "Errors and retries",
        "value": "Developer API answers RFC 9457 problem+json with `error_code`, `retryable` and `retry_after_seconds`, and takes `Idempotency-Key` and `dry_run` on some operations. HTTP V2 deduplicates on `insert_id` for 7 days"
      },
      {
        "label": "Audit",
        "value": "Organisation audit log with 90 days of entries and an Audit Logs API. Its event list covers logins, roles, exports and deletions and doesn't name MCP tool calls"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II, ISO 27001, ISO 27017 and ISO 27018 on trust.amplitude.com, HIPAA support, a private bug bounty with a Bugcrowd contact in security.txt"
      },
      {
        "label": "Status",
        "value": "status.amplitude.com on Statuspage, 29 components including MCP, Management API and Data Reception"
      },
      {
        "label": "Sub-processors",
        "value": "List updated 13 May 2026 with data centre locations in the US and EU. Hosting on AWS, with AWS Bedrock, Google Vertex AI and OpenAI for its AI products"
      }
    ],
    "provenance": {
      "legalEntity": "Amplitude, Inc.",
      "domain": "amplitude.com",
      "domainRegistered": "1996-05-09",
      "endpointOnVendorDomain": true,
      "terms": "https://amplitude.com/terms",
      "privacy": "https://amplitude.com/privacy",
      "statusPage": "https://status.amplitude.com",
      "changelog": "https://amplitude.com/releases",
      "securityTxt": "valid",
      "checked": "2026-10-07",
      "notes": [
        "The terms of service (effective 21 July 2026) and the privacy notice (updated 31 August 2026) name Amplitude, Inc., 201 3rd Street, Suite 200, San Francisco, CA 94103.",
        "The MCP server answers at mcp.amplitude.com and mcp.eu.amplitude.com, the Developer API at developer-api.amplitude.com and ingestion at api2.amplitude.com, all amplitude.com subdomains.",
        "amplitude.com/.well-known/security.txt gives a Bugcrowd tracker and security@amplitude.com as contacts and expires 2028-12-31.",
        "RDAP for amplitude.com gives a registration date of 1996-05-09.",
        "The data processing addendum for the terms of service is dated 4 June 2024 and points to the sub-processor list at amplitude.com/subprocessor-list, updated 13 May 2026."
      ],
      "score": 93,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Amplitude, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "amplitude.com, registered 1996-05-09 (30 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.amplitude.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 3.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.amplitude.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://amplitude.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-07-21",
          "words": 6085,
          "points": 3.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective Date: July 21, 2026",
              "says": "Last updated 2026-07-21"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms shall be governed by the laws of the State of California without regard to its conflict of laws provisions.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "AMPLITUDE’S MAXIMUM AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS AND DAMAGES ARISING OUT OF OR RELATED TO THESE TERMS, WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE OR OTHERWISE, SHALL NOT EXCEED $1,000.",
              "says": "Capped at $1,000"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Amplitude may terminate or suspend Customer’s access to the Amplitude Services, without prior notice or liability, at any time and for any reason."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "THE MOST CURRENT VERSION OF THESE TERMS WILL BE POSTED TO OUR WEBSITE AND ANY UPDATED VERSION OF THESE TERMS WILL SUPERSEDE ALL PREVIOUS VERSIONS.",
              "says": "Changes are posted, with no other notice named"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Notwithstanding any other provision of these Terms, Customer shall not enter into settlement of any Claim without the prior written consent of Amplitude."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "Amplitude may use techniques such as machine learning in order to improve the Services, and Customer instructs Amplitude to process its Customer Data for such purpose",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(h) use or access the Amplitude Services to either develop or commercialize a product or service that is competitive with or a substitute for the Amplitude Services or to engage in competitive analysis or benchmarking",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "NO SEPARATE NOTICE WILL BE REQUIRED, AND YOUR CONTINUED USE OF THE AMPLITUDE SERVICES AFTER THE UPDATED VERSION OF THE TERMS IS POSTED WILL CONSTITUTE YOUR ACCEPTANCE OF SUCH UPDATED TERMS.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Amplitude may terminate or suspend Customer’s access to the Amplitude Services, without prior notice or liability, at any time and for any reason."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "IMPORTANT NOTICE: THESE TERMS OF SERVICE CONTAIN A BINDING ARBITRATION PROVISION AND WAIVER OF CLASS ACTION RIGHTS AS DETAILED IN THE SECTION 10 ARBITRATION AND WAIVER OF CLASS ACTION SECTION BELOW."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Amplitude's total liability under these terms is capped at 1,000 US dollars.",
              "quote": "AMPLITUDE’S MAXIMUM AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS AND DAMAGES ARISING OUT OF OR RELATED TO THESE TERMS, WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE OR OTHERWISE, SHALL NOT EXCEED $1,000."
            },
            {
              "date": "2026-10-08",
              "text": "Using the service gives Amplitude the right to use the customer's company name and logo in marketing, and the customer agrees to take part in a case study.",
              "quote": "By using the Amplitude Services, Customer gives Amplitude the right to use Customer’s company name and logo in any Amplitude marketing materials, and agrees to participate in a case study that may be published on Amplitude’s website and/or in any marketing materials."
            },
            {
              "date": "2026-10-08",
              "text": "After termination Amplitude has no obligation to store Customer Data and may permanently delete it at its sole discretion, subject to the data processing addendum.",
              "quote": "Subject to the TOS DPA, following termination Amplitude shall have no obligation to Customer with respect to the storage of Customer Data and may, in its sole discretion, permanently delete Customer Data."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://amplitude.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-31",
          "words": 7895,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: August 31, 2026",
              "says": "Last updated 2026-08-31"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Personal Data We Collect And How We Use The Personal Data"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Persistent cookies are stored by a web browser and remain valid until a set expiration date."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "You may choose to participate in an Amplitude program that allows you to pay fees with a credit or debit card, in which case you may provide your credit card or other payment details information directly to our third party payment processor."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell your Personal Data or use or disclose sensitive personal information for purposes other than those permitted by the CCPA.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "If you do not want to receive communications from us, you can unsubscribe from marketing communications or email us with your preferences at privacy@amplitude.com or ccpa@amplitude.com."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Customers can opt out of the use of this software during their use of the Product by contacting us at privacy@amplitude.com.",
              "says": "privacy@amplitude.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "These safeguards may include using the European Commission-approved standard contractual clauses to protect the transfer of your Personal Data to Amplitude’s corporate affiliates or service providers, if required by applicable law.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We may share Personal Data with third party ad partners, such as through cookies or by providing lists of email addresses for potential customers so we can reach them across the web with relevant ads."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice does not apply to Customer End User Data that customers submit to the product.",
              "quote": "For clarity, this Privacy Notice does not apply to Customer End User Data (as defined below) submitted by our customers to the Product."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/amplitude.json",
    "live": {
      "slug": "amplitude",
      "probe": {
        "target": "https://mcp.amplitude.com/mcp",
        "method": "get",
        "lastAt": "2026-10-08T17:36:29.893944025Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 576,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 610,
        "p95ms24h": 768,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.amplitude.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:37:25.635395146Z"
      },
      "versions": [
        {
          "registry": "npm",
          "name": "@amplitude/analytics-node",
          "version": "1.5.77",
          "seenAt": "2026-10-08T15:58:25.174053517Z"
        },
        {
          "registry": "npm",
          "name": "@amplitude/developer-cli",
          "version": "0.4.0",
          "seenAt": "2026-10-08T15:58:22.636133576Z"
        },
        {
          "registry": "pypi",
          "name": "amplitude-analytics",
          "version": "1.2.3",
          "released": "2026-03-31",
          "seenAt": "2026-10-08T15:58:25.442829492Z"
        }
      ],
      "githubStars": 42,
      "npmWeekly": 342,
      "pypiWeekly": 1809174,
      "securityTxt": {
        "url": "https://amplitude.com/.well-known/security.txt",
        "state": "valid",
        "expires": "2028-12-31T23:59:00Z",
        "checkedAt": "2026-10-08T15:39:04.89032491Z"
      },
      "updatedAt": "2026-10-08T17:37:25.635395146Z"
    }
  }
}
