{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "posthog",
    "name": "PostHog",
    "vendor": "PostHog Inc.",
    "vendorUrl": "https://posthog.com",
    "kind": "http-api",
    "category": "product-analytics",
    "summary": "PostHog is an open-source product analytics platform with session replay, feature flags, experiments, error tracking and a data warehouse. Agents reach PostHog Cloud through a REST API with a public OpenAPI spec and an official hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/posthog",
    "markdownUrl": "https://www.anchorterminal.com/tools/posthog.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/posthog.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/posthog.json",
    "repo": "https://github.com/PostHog/posthog",
    "license": "MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://us.posthog.com",
    "packages": [
      {
        "registry": "npm",
        "name": "posthog-node"
      },
      {
        "registry": "npm",
        "name": "posthog-js"
      },
      {
        "registry": "pypi",
        "name": "posthog"
      },
      {
        "registry": "npm",
        "name": "@posthog/cli"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. Private endpoints take a Bearer personal API key (`phx_`) that a signed-in user creates with chosen scopes and project or organisation access, or an OAuth access token. OAuth at oauth.posthog.com supports PKCE, dynamic client registration and client ID metadata documents, with no app review needed to go live. The MCP server uses OAuth by default or a personal API key made with the MCP Server preset. Project secret API keys are in beta. Capture and flag evaluation take the public project token.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with no card, covering 1 million analytics events and 1 million flag requests a month. The paid plan has no base fee and no seat charge, and bills per unit above the free allowance (analytics events from $0.00005). API and MCP calls are not billed, but personal API key queries draw on an hourly read budget that is larger on a paid plan (https://posthog.com/pricing, checked 2026-10-07).",
    "priceSummary": "$0.0001 / tx",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI spec or the pricing page (checked 2026-10-07).",
      "endpoints": []
    },
    "toolCount": 1096,
    "popularity": {
      "githubStars": 40176,
      "npmWeekly": 15243417,
      "pypiWeekly": null,
      "asOf": "2026-10-07"
    },
    "docsUrl": "https://posthog.com/docs/api",
    "llmsTxt": "https://posthog.com/llms.txt",
    "openapi": "https://app.posthog.com/api/schema/",
    "registryName": "io.github.PostHog/mcp",
    "capabilities": [
      "analytics.query",
      "analytics.events",
      "analytics.funnels",
      "analytics.experiments",
      "analytics.flags",
      "observability.errors",
      "observability.logs"
    ],
    "tags": [
      "official",
      "hosted",
      "open-source",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "free-tier",
      "no-card",
      "eu-region",
      "status-page",
      "soc2",
      "typescript",
      "python"
    ],
    "lastRelease": "2026-10-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.4,
      "grade": "B",
      "agentReady": false,
      "rank": 171,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 78,
        "maintenance": 89,
        "payments": 40,
        "reliability": 74,
        "schema": 81,
        "security": 84,
        "transparency": 83
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 74,
          "points": 14.8,
          "reason": "Graded on PostHog Cloud with the hosted lines. Status page on incident.io at posthogstatus.com with per-region components, among them MCP Server and REST API Query endpoints (20). 31 incidents between 9 July and 6 October 2026. Four were analytics query timeouts or failures (15 July for 67 minutes, 31 August open for 27 hours 35 minutes with load shed after 4 hours, 10 September for 9 minutes, 30 September for 2 hours 6 minutes), plus US API errors for 65 minutes on 19 August and MCP sign-in from ChatGPT failing for 20 hours on 10 August. None was marked a full outage of the API, so 10 of 30. Rate limits published with numbers per endpoint class (15). The query read budget answers 429 with `Retry-After` and budget headers, but there is no backoff guidance for the general limits and no idempotency keys for writes were found (9). 99.95 per cent uptime SLA in the terms for the Enterprise package (10). The REST API is generally available and the MCP docs carry no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 81,
          "points": 13.16,
          "reason": "OpenAPI 3.1 served without a login, 1,742 paths and 2,347 operations, and typed JSON Schema inputs on the MCP tools (25). llms.txt, and every docs page has a Markdown copy at the same address with .md (10). 1,487 of 2,347 operations (63 per cent) have a description. MCP tool descriptions average 708 characters and say when to use a tool and what to call first (16). 1,243 enums across 4,792 schemas and a required scope on most operations (13). 706 examples in the spec. It documents 400 on 224 operations and 429 on 55, and the docs show the error shape with examples (9). Dated public changelog with RSS, but the spec version is fixed at 1.0.0 and the API has no versions (8)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "1,096 MCP tools is far past 30 (5). Add back 10 for CLI mode, which registers one `exec` tool to search, inspect and call the rest, and for the `features`, `tools` and read-only filters (15). Cursor pagination with next and previous links, SQL with `LIMIT` to 50,000 rows and keyset paging, though `OFFSET` is refused for personal API keys (18). Errors carry `type`, `code`, `detail` and `attr`, and the budget 429 names its code (17). Every MCP tool has readOnlyHint, destructiveHint and idempotentHint (592 read-only, 135 destructive), and 18 admin actions are split into prepare and execute steps. No idempotency keys on REST writes (15). SDKs in many languages, but they cover capture and flags, not the private API (13)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 84,
          "points": 14.7,
          "reason": "OAuth 2 with PKCE, 226 scopes, a revocation endpoint and dynamic registration, or personal API keys with scopes, project limits and rolling. A key can still be created with full access, and keys found in public GitHub repositories are rolled automatically (28). Read-only mode, filters by product area or tool, project pinning, and a typed confirmation for 18 admin actions (18). The MCP docs warn about prompt injection and tell users to review tool calls, and the CLI escapes informational responses. No further mitigation is documented for event and replay data that end users wrote (9). Activity logs with an API, MCP calls recorded with the caller's IP, and an admin view of every key with last use. Longer retention needs a platform package (12). security.txt valid to 30 August 2027, Bugcrowd disclosure programme paid in merchandise, public SOC 2 Type 2 report, annual penetration test and a public advisories page (17)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Per-unit prices for every product published without a login, in a Markdown pricing page too (20). Free plan with no card (20). A person signs up in a browser and creates a key or approves OAuth (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 89,
          "points": 7.79,
          "reason": "The changelog's newest entry is 5 October 2026 and the repository's newest commit is 7 October 2026 (30). 292 dated changelog entries since 9 July 2026 (20). Public changelog, community questions and in-app support. The repository shows 5,626 open issues and pull requests, and we did not read how quickly they are answered (15 of 25). `io.github.PostHog/mcp` is in the official MCP registry, and the SDKs are current, with posthog-node 5.55.0 on 30 September 2026 and 50 versions in 90 days (15). 142 CI workflow files, four of them for the MCP server (9 of 10, with the npm publishing compromise of November 2025 counted under deductions)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "note": "editorial 71, provenance 94",
          "reason": "MIT outside the `ee` directory, which has its own licence and is part of what PostHog Cloud runs (25 of 30). Privacy policy, a self-serve DPA and the terms agree. The terms let PostHog use de-identified customer content to train its own models unless the customer opts out, and bar third parties from training on it. The privacy policy gives no retention periods, while the pricing page gives 1 year on the free plan and 7 on paid (22). No deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice. 16 MCP tools carry a pointer to their replacement (4). Sub-processor list updated 12 June 2026 with locations, 14 days' notice of changes, and data in Virginia or Germany (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-07",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "1,096 MCP tools is far past 30 (5). Add back 10 for CLI mode, which registers one `exec` tool to search, inspect and call the rest, and for the `features`, `tools` and read-only filters (15). Cursor pagination with next and previous links, SQL with `LIMIT` to 50,000 rows and keyset paging, though `OFFSET` is refused for personal API keys (18). Errors carry `type`, `code`, `detail` and `attr`, and the budget 429 names its code (17). Every MCP tool has readOnlyHint, destructiveHint and idempotentHint (592 read-only, 135 destructive), and 18 admin actions are split into prepare and execute steps. No idempotency keys on REST writes (15). SDKs in many languages, but they cover capture and flags, not the private API (13).",
          "maintenance": "The changelog's newest entry is 5 October 2026 and the repository's newest commit is 7 October 2026 (30). 292 dated changelog entries since 9 July 2026 (20). Public changelog, community questions and in-app support. The repository shows 5,626 open issues and pull requests, and we did not read how quickly they are answered (15 of 25). `io.github.PostHog/mcp` is in the official MCP registry, and the SDKs are current, with posthog-node 5.55.0 on 30 September 2026 and 50 versions in 90 days (15). 142 CI workflow files, four of them for the MCP server (9 of 10, with the npm publishing compromise of November 2025 counted under deductions).",
          "payments": "No x402, MPP or L402 (0). Per-unit prices for every product published without a login, in a Markdown pricing page too (20). Free plan with no card (20). A person signs up in a browser and creates a key or approves OAuth (0).",
          "reliability": "Graded on PostHog Cloud with the hosted lines. Status page on incident.io at posthogstatus.com with per-region components, among them MCP Server and REST API Query endpoints (20). 31 incidents between 9 July and 6 October 2026. Four were analytics query timeouts or failures (15 July for 67 minutes, 31 August open for 27 hours 35 minutes with load shed after 4 hours, 10 September for 9 minutes, 30 September for 2 hours 6 minutes), plus US API errors for 65 minutes on 19 August and MCP sign-in from ChatGPT failing for 20 hours on 10 August. None was marked a full outage of the API, so 10 of 30. Rate limits published with numbers per endpoint class (15). The query read budget answers 429 with `Retry-After` and budget headers, but there is no backoff guidance for the general limits and no idempotency keys for writes were found (9). 99.95 per cent uptime SLA in the terms for the Enterprise package (10). The REST API is generally available and the MCP docs carry no beta label (10).",
          "schema": "OpenAPI 3.1 served without a login, 1,742 paths and 2,347 operations, and typed JSON Schema inputs on the MCP tools (25). llms.txt, and every docs page has a Markdown copy at the same address with .md (10). 1,487 of 2,347 operations (63 per cent) have a description. MCP tool descriptions average 708 characters and say when to use a tool and what to call first (16). 1,243 enums across 4,792 schemas and a required scope on most operations (13). 706 examples in the spec. It documents 400 on 224 operations and 429 on 55, and the docs show the error shape with examples (9). Dated public changelog with RSS, but the spec version is fixed at 1.0.0 and the API has no versions (8).",
          "security": "OAuth 2 with PKCE, 226 scopes, a revocation endpoint and dynamic registration, or personal API keys with scopes, project limits and rolling. A key can still be created with full access, and keys found in public GitHub repositories are rolled automatically (28). Read-only mode, filters by product area or tool, project pinning, and a typed confirmation for 18 admin actions (18). The MCP docs warn about prompt injection and tell users to review tool calls, and the CLI escapes informational responses. No further mitigation is documented for event and replay data that end users wrote (9). Activity logs with an API, MCP calls recorded with the caller's IP, and an admin view of every key with last use. Longer retention needs a platform package (12). security.txt valid to 30 August 2027, Bugcrowd disclosure programme paid in merchandise, public SOC 2 Type 2 report, annual penetration test and a public advisories page (17).",
          "transparency": "MIT outside the `ee` directory, which has its own licence and is part of what PostHog Cloud runs (25 of 30). Privacy policy, a self-serve DPA and the terms agree. The terms let PostHog use de-identified customer content to train its own models unless the customer opts out, and bar third parties from training on it. The privacy policy gives no retention periods, while the pricing page gives 1 year on the free plan and 7 on paid (22). No deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice. 16 MCP tools carry a pointer to their replacement (4). Sub-processor list updated 12 June 2026 with locations, 14 days' notice of changes, and data in Virginia or Germany (20)."
        },
        "sources": [
          {
            "what": "API overview, auth and rate limits",
            "url": "https://posthog.com/docs/api",
            "seen": "2026-10-07"
          },
          {
            "what": "query endpoint limits and read budget",
            "url": "https://posthog.com/docs/api/queries",
            "seen": "2026-10-07"
          },
          {
            "what": "OpenAPI spec",
            "url": "https://app.posthog.com/api/schema/",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP overview",
            "url": "https://posthog.com/docs/model-context-protocol",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP FAQ, modes, read-only and filters",
            "url": "https://posthog.com/docs/model-context-protocol/faq",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP tools reference",
            "url": "https://posthog.com/docs/model-context-protocol/tools",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP server source and tool definitions",
            "url": "https://github.com/PostHog/posthog/tree/master/services/mcp",
            "seen": "2026-10-07"
          },
          {
            "what": "OAuth docs",
            "url": "https://posthog.com/docs/api/oauth",
            "seen": "2026-10-07"
          },
          {
            "what": "OAuth server metadata",
            "url": "https://oauth.posthog.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-07"
          },
          {
            "what": "personal API keys",
            "url": "https://posthog.com/docs/api/personal-api-keys",
            "seen": "2026-10-07"
          },
          {
            "what": "pricing",
            "url": "https://posthog.com/pricing",
            "seen": "2026-10-07"
          },
          {
            "what": "status page and incident history",
            "url": "https://www.posthogstatus.com/",
            "seen": "2026-10-07"
          },
          {
            "what": "security advisories",
            "url": "https://posthog.com/handbook/company/security-advisories",
            "seen": "2026-10-07"
          },
          {
            "what": "npm compromise post-mortem",
            "url": "https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem",
            "seen": "2026-10-07"
          },
          {
            "what": "security handbook",
            "url": "https://posthog.com/handbook/company/security",
            "seen": "2026-10-07"
          },
          {
            "what": "SOC 2 page",
            "url": "https://posthog.com/docs/privacy/soc2",
            "seen": "2026-10-07"
          },
          {
            "what": "terms, SLA and model development clause",
            "url": "https://posthog.com/terms",
            "seen": "2026-10-07"
          },
          {
            "what": "privacy policy",
            "url": "https://posthog.com/privacy",
            "seen": "2026-10-07"
          },
          {
            "what": "DPA",
            "url": "https://posthog.com/dpa",
            "seen": "2026-10-07"
          },
          {
            "what": "sub-processors",
            "url": "https://posthog.com/subprocessors",
            "seen": "2026-10-07"
          },
          {
            "what": "changelog",
            "url": "https://posthog.com/changelog",
            "seen": "2026-10-07"
          },
          {
            "what": "activity logs",
            "url": "https://posthog.com/docs/settings/activity-logs",
            "seen": "2026-10-07"
          },
          {
            "what": "security.txt",
            "url": "https://posthog.com/.well-known/security.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "official MCP registry",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=posthog",
            "seen": "2026-10-07"
          },
          {
            "what": "posthog-node on npm",
            "url": "https://registry.npmjs.org/posthog-node/latest",
            "seen": "2026-10-07"
          },
          {
            "what": "llms.txt",
            "url": "https://posthog.com/llms.txt",
            "seen": "2026-10-07"
          }
        ],
        "openQuestions": [
          "unchecked: PyPI weekly downloads for posthog, pypistats.org answered 429",
          "unchecked: how quickly issues on PostHog/posthog are answered, we read the repository by clone and the GitHub API count only",
          "unchecked: the live `tools/list` response of the MCP server, which needs a token. Tool counts and annotations come from services/mcp/schema in the repository and the docs tools reference",
          "unchecked: activity log retention by platform package, posthog.com/platform-packages did not return content to our reader",
          "unchecked: the `ee` directory's licence text",
          "The status page lists 'Phishing emails sent via PostHog invite system' on 24 April 2026. We did not read its detail and made no deduction for it",
          "No idempotency key or event de-duplication rule was found in the capture docs we read",
          "The newest advisory PSA-2026-00002 concerns customer-run proxies. We deducted because PostHog's own guide showed the unsafe configuration and its triage took five weeks"
        ]
      },
      "negative": -7,
      "negativeNotes": [
        "-3: 2025-11-24. Malicious versions of posthog-node, posthog-js and six other npm packages were published with a stolen token after an attacker took CI secrets through a pull request workflow. PostHog removed them in about five hours and published a post-mortem on 26 November 2025, so the deduction is reduced (https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem).",
        "-2: 2026-05-29, disclosed 2026-06-02 as PSA-2026-00001 (critical). Researchers used an unsandboxed, outdated Chromium to reach a US Cloud pod and read internal production credentials. PostHog says no customer data was accessed and the credentials were rotated. Fixed and documented (https://posthog.com/handbook/company/security-advisories).",
        "-2: 2026-07-11 to 2026-08-04, disclosed 2026-08-21 as PSA-2026-00002 (high). Customer-run nginx proxies set up as PostHog's guide showed sent traffic to released AWS addresses, and a researcher read traffic from six EU customers. The report sat in triage for five weeks. Fixed and documented (https://posthog.com/handbook/company/security-advisories)."
      ],
      "verdict": "PostHog suits agents that need to query product data and manage flags or experiments. Its hosted MCP server has OAuth scopes, a read-only mode and a one-tool CLI mode over 1,096 tools. The status page shows 31 incidents in 90 days, four on analytics queries, and three security incidents were disclosed in the last year.",
      "bestFor": "An agent that answers product questions in SQL or with funnel, retention and trends queries, and that manages feature flags, experiments and error tracking in the same project.",
      "strengths": [
        "Public OpenAPI 3.1 spec with 2,347 operations and a scope on most of them, plus llms.txt and a Markdown copy of every docs page",
        "Hosted MCP server with OAuth, a read-only switch, filters by product area or tool name and pinning to one project",
        "CLI mode registers one `exec` tool that searches, inspects and calls the 1,096 tools on demand",
        "Free plan without a card, with 1 million analytics events and 1 million flag requests a month, and public per-unit prices above that",
        "MIT source outside the `ee` directory, a public SOC 2 Type 2 report and a public security advisories page"
      ],
      "weaknesses": [
        "31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures",
        "Three security incidents in twelve months, among them malicious npm SDK versions on 24 November 2025",
        "API queries stop at 10 seconds of execution, three at a time per project, with an hourly read budget on personal API keys",
        "No API versioning or deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice",
        "Customer content can be used to train PostHog's own models unless the customer opts out in settings"
      ],
      "agentNotes": [
        "Add `?readonly=true` or the `x-posthog-read-only` header to the MCP URL unless the task needs writes",
        "Pin the session with `x-posthog-project-id`, which also removes the `switch-project` and `switch-organization` tools",
        "In CLI mode run `info \u003ctool\u003e` once before `call`, and send one `exec` command per request",
        "On a 429 with code `api_queries_budget_exceeded`, wait for `Retry-After` and read `X-PostHog-Query-Budget-Remaining-Bytes`",
        "Page SQL results by keyset on `timestamp`. `OFFSET` returns 400 for personal API keys, and results cap at 50,000 rows"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.4
        }
      ],
      "editorialScores": {
        "ergonomics": 78,
        "maintenance": 89,
        "payments": 40,
        "reliability": 74,
        "schema": 81,
        "security": 84,
        "transparency": 71
      },
      "provenanceScore": 94
    },
    "connect": {
      "install": "npx @posthog/wizard mcp add",
      "http": "curl \\\n  -H 'Content-Type: application/json' \\\n  -H \"Authorization: Bearer $POSTHOG_PERSONAL_API_KEY\" \\\n  https://us.posthog.com/api/projects/:project_id/query/ \\\n  -d '{\"query\": {\"kind\": \"HogQLQuery\", \"query\": \"select event, count() from events group by event limit 100\"}}'",
      "claudeCode": "claude mcp add --transport http posthog https://mcp.posthog.com/mcp -s user",
      "config": {
        "mcpServers": {
          "posthog": {
            "url": "https://mcp.posthog.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/analytics.query",
      "tool": "https://letme.dev/posthog"
    },
    "notable": [
      "The MCP server is hosted at https://mcp.posthog.com/mcp, routes to the US or EU region of the signed-in account and is free to call, though tools that run LLMs may bill as PostHog AI spend (https://posthog.com/docs/model-context-protocol)",
      "The tools reference lists 1,096 MCP tools in 74 categories, and CLI mode replaces them with a single `exec` tool that most clients get by default (https://posthog.com/docs/model-context-protocol/faq)",
      "Private API limits are per team, 240 a minute and 1,200 an hour on analytics endpoints, 2,400 an hour on `/query`, 480 a minute on other endpoints, and PostHog says it sells no higher limits (https://posthog.com/docs/api)",
      "API queries run for at most 10 seconds, three at a time per project, return 100 rows by default and 50,000 at most, and PostHog says `/query` is not a supported export path (https://posthog.com/docs/api/queries)",
      "The advisories page lists PSA-2026-00002 of 21 August 2026 (traffic from six EU customers' own reverse proxies readable by a researcher) and PSA-2026-00001 of 2 June 2026 (internal production credentials exposed on US Cloud, no customer data accessed) (https://posthog.com/handbook/company/security-advisories)",
      "The terms give a 99.95 per cent monthly uptime SLA with credits only to customers on the Enterprise package or with an order form (https://posthog.com/terms)",
      "The repository is MIT except the `ee` directory, and PostHog says the self-hosted hobby deploy scales to about 100,000 events a month with no support (https://github.com/PostHog/posthog)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "PostHog Cloud. The REST API at us.posthog.com and eu.posthog.com, and the official hosted MCP server at mcp.posthog.com. The open-source hobby deploy is unsupported and was not graded"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.1 at https://app.posthog.com/api/schema/, readable without a login. 1,742 paths and 2,347 operations on 7 October 2026. Public capture and flag endpoints on us.i.posthog.com and eu.i.posthog.com take the project token"
      },
      {
        "label": "MCP server",
        "value": "https://mcp.posthog.com/mcp over streamable HTTP. 1,096 tools in 74 categories. CLI mode (one `exec` tool) or tools mode, chosen per client or with `?mode=`. Filters `features=` and `tools=`, `readonly=true`, and project pinning by header or query parameter"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2 with PKCE, dynamic client registration and client ID metadata documents at oauth.posthog.com, 226 scopes. Personal API keys (`phx_`) with scopes, up to 10 a user. Project secret API keys (`phs_`) in beta"
      },
      {
        "label": "Rate limits",
        "value": "Per team. Analytics endpoints 240 a minute and 1,200 an hour, `/query` 2,400 an hour and 240 a minute, flag local evaluation 600 a minute, other endpoints 480 a minute and 4,800 an hour. Capture and `/flags` have no request limit"
      },
      {
        "label": "Query limits",
        "value": "10 seconds of execution, 3 concurrent queries a project, 100 rows by default and 50,000 at most, and an hourly read budget in bytes for personal API keys that answers 429 with `Retry-After`"
      },
      {
        "label": "Errors",
        "value": "JSON with `type`, `code`, `detail` and `attr`. The spec documents 400 on 224 operations, 404 on 191, 403 on 96 and 429 on 55"
      },
      {
        "label": "Free tier",
        "value": "No card. Each month 1 million analytics events, 5,000 recordings, 1 million flag requests, 100,000 exceptions, 1,500 survey responses and 1 million warehouse rows. 1 project and 1 year of data retention"
      },
      {
        "label": "Paid",
        "value": "Pay as you go with no base fee and no seat charge. 6 projects and 7 years of retention. Platform packages Boost $250, Scale $750 and Enterprise $2,000 a month"
      },
      {
        "label": "SDKs",
        "value": "posthog-node 5.55.0 (30 September 2026), posthog-js 1.438.2, Python posthog 7.64.1 (6 October 2026), and @posthog/cli 0.18.9 with `posthog-cli api` for the API and MCP tool list"
      },
      {
        "label": "Audit",
        "value": "Activity logs with an API and export. Admins see every personal API key that reaches the organisation, with scopes and last use. Querying activity logs with PostHog AI needs the Scale or Enterprise package"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2 with the 2026 report published, HIPAA BAA on the Boost package, annual penetration test (May 2026), Bugcrowd vulnerability disclosure programme that pays in merchandise"
      },
      {
        "label": "Status",
        "value": "https://www.posthogstatus.com on incident.io, with US and EU components that include MCP Server, REST API Query endpoints and All other REST API endpoints"
      },
      {
        "label": "Data",
        "value": "AWS us-east-1 (Virginia) or eu-central-1 (Germany), chosen at signup. Sub-processor list updated 12 June 2026 with 14 days' notice of changes under the DPA"
      },
      {
        "label": "Open source",
        "value": "MIT outside the `ee` directory. The MCP server source is in services/mcp of PostHog/posthog"
      }
    ],
    "unitPrices": [
      {
        "item": "Product analytics event",
        "unit": "tx",
        "usd": 0.00005,
        "note": "1 to 2 million a month, first 1 million free, lower above"
      },
      {
        "item": "Feature flag request",
        "unit": "tx",
        "usd": 0.0001,
        "note": "1 to 2 million a month, first 1 million free, lower above"
      },
      {
        "item": "Session recording",
        "unit": "tx",
        "usd": 0.005,
        "note": "5,001 to 15,000 a month, first 5,000 free"
      },
      {
        "item": "Data warehouse row",
        "unit": "record",
        "usd": 0.000015,
        "note": "1 to 10 million a month, first 1 million free"
      },
      {
        "item": "Boost package",
        "unit": "month",
        "usd": 250
      },
      {
        "item": "Scale package",
        "unit": "month",
        "usd": 750
      },
      {
        "item": "Enterprise package",
        "unit": "month",
        "usd": 2000
      }
    ],
    "provenance": {
      "legalEntity": "PostHog Inc. (formerly Hiberly Inc.)",
      "domain": "posthog.com",
      "domainRegistered": "2020-01-23",
      "endpointOnVendorDomain": true,
      "terms": "https://posthog.com/terms",
      "privacy": "https://posthog.com/privacy",
      "statusPage": "https://www.posthogstatus.com",
      "changelog": "https://posthog.com/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-07",
      "notes": [
        "The privacy policy names PostHog Inc., formerly known as Hiberly Inc., and its subsidiaries. The security handbook names Hiberly Ltd. as the UK entity.",
        "posthog.com/.well-known/security.txt expires 2027-08-30 and points to the security handbook. The copy on us.posthog.com expired 2024-03-14.",
        "status.posthog.com redirects to www.posthogstatus.com.",
        "RDAP for posthog.com gives a registration date of 2020-01-23.",
        "The API, OAuth server and MCP server answer on posthog.com subdomains."
      ],
      "score": 94,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "PostHog Inc. (formerly Hiberly Inc.)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "posthog.com, registered 2020-01-23 (6 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "us.posthog.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "www.posthogstatus.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://posthog.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-29",
          "words": 16114,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: June 29, 2026",
              "says": "Last updated 2026-06-29"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement shall be governed by and construed in accordance with the laws of the State of California, United States, without regard to its conflict of law principles.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE OR STRICT LIABILITY), OR OTHERWISE, WILL NOT EXCEED, IN THE AGGREGATE, THE GREATER OF (i) ONE THOUSAND DOLLARS ($1,000), OR (ii) THE TOTAL FEES PAID TO POSTHOG HEREUNDER IN THE ONE YEAR PERIOD ENDING ON THE DATE THAT A CLAIM OR DEMAND IS FIRST ASSERTED.",
              "says": "Capped at $1,000"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "7.1 This Agreement shall continue until terminated in accordance with this Section 7."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "If we’re going to increase prices, we need to give you 30 days notice, giving you the chance to cancel with us.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "4.2 Customer shall not remove, alter or obscure any of PostHog’s (or its licensors’) copyright notices, proprietary legends, trademark or service mark attributions, patent markings or other indicia of PostHog’s (or its licensors’) ownership or contribution from the Licensed Materials."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "…and services operating and available for use, in each calendar month with an uptime percentage of 99.95% as displayed on https://posthogstatus.com only to those customers who have purchased the Enterprise package or where it has been agreed as a special term in an Order Form.",
              "says": "Names 99.95% availability"
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "Customer Content may be used for Product and Model Development unless (a) otherwise agreed to between Customer and PostHog or (b) Customer has opted out through the applicable service settings within the Licensed Materials and/or product or services interface;"
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Publish benchmarking results about PostHog without our permission.",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "PostHog may raise fees or add new charges at the end of the initial or any renewal term on 30 days' notice by email or in the product.",
              "quote": "PostHog may increase Fees or introduce new charges at the end of the Initial Credit Term (as defined below) or any then-current renewal term upon thirty (30) days’ prior notice to Customer, which may be sent via email or through the services interface or otherwise at PostHog's discretion."
            },
            {
              "date": "2026-10-08",
              "text": "Prepaid credits are not refundable and expire 12 months after purchase unless agreed otherwise in writing.",
              "quote": "Unless otherwise agreed in writing, Prepaid Credits are non-refundable and expire twelve (12) months from the date of purchase."
            },
            {
              "date": "2026-10-08",
              "text": "The customer is responsible for all activity under its accounts, whether or not the customer authorised it.",
              "quote": "Customer is responsible for maintaining the security of Customer’s accounts, passwords (including but not limited to administrative and User passwords) and files, and for all uses and activities occurring under Customer accounts, whether or not authorized by Customer."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://posthog.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-29",
          "words": 15436,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: June 29, 2026",
              "says": "Last updated 2026-06-29"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "💻 We collect data like your IP address, device info, and pages/content you view to improve your experience."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Your data may be processed outside your country, and we keep it for 24 months unless you ask us to delete it.",
              "says": "Names a period of 24 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "🌐 We share your information with trusted service providers to run our site and product."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "…of Customer Personal Information from Customer to PostHog pursuant to the Agreement constitute a sale of information to PostHog, and that nothing in the Agreement shall be construed as providing for the sale of Customer Personal Information to PostHog."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "…under your country's or state's laws, including (in the European Economic Area (\"EEA\"), and UK), a right to object to some processing that we carry out or, where we rely on consent, how to withdraw that consent."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "As part of our commitment to the DPF Principles, if you are a resident of the European Union, UK, or Switzerland and you have a privacy or data use concern, please contact PostHog directly at privacy@posthog.com and PostHog will use its best efforts to address your concern within 45 days of receipt of your complaint.",
              "says": "privacy@posthog.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "We're part of the EU-US Data Privacy Framework, ensuring your data is safe.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "Where Customer Content is used for Product and Model Development, PostHog will aggregate or de-identify such data so that it cannot reasonably be used to identify Customer, its Users, or any individual (the \"Derived Data\")."
            },
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We may also share some of your account information that you provide to us (including email addresses) with third-party advertising platforms to create or target marketing and advertising audiences on our behalf."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "PostHog may use the names and logos of companies using its products for promotion and marketing unless agreed otherwise in writing.",
              "quote": "PostHog may use the name and logo of companies using our products or services for promotional and marketing purposes, unless otherwise agreed to in writing."
            },
            {
              "date": "2026-10-08",
              "text": "An opt-out from model development applies only from then on, and PostHog need not retrain or delete models or derived data built from earlier content.",
              "quote": "PostHog has no obligation to modify, retrain, or delete any models or Derived Data that utilized Customer Content prior to the effective date of any opt-out, except to the extent required by applicable law."
            },
            {
              "date": "2026-10-08",
              "text": "PostHog reserves the right to publish a support or feedback request to answer it or help other customers, without the sender's personal information.",
              "quote": "If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish your request in order to help us clarify or respond to your request or to help us support other customers."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/posthog.json",
    "live": {
      "slug": "posthog",
      "probe": {
        "target": "https://us.posthog.com",
        "method": "get",
        "lastAt": "2026-10-08T19:08:56.183162663Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 355,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 364,
        "p95ms24h": 479,
        "samples24h": 42,
        "samples30d": 42,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 42,
            "ok": 42
          }
        ]
      },
      "vendorStatus": {
        "page": "https://www.posthogstatus.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:51:07.411527172Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "PostHog/posthog",
          "version": "posthog-cli/v0.18.10",
          "released": "2026-10-08",
          "seenAt": "2026-10-08T16:26:05.264718319Z"
        },
        {
          "registry": "npm",
          "name": "@posthog/cli",
          "version": "0.18.10",
          "seenAt": "2026-10-08T16:26:03.360315129Z"
        },
        {
          "registry": "npm",
          "name": "posthog-js",
          "version": "1.438.2",
          "seenAt": "2026-10-08T16:26:01.219902492Z"
        },
        {
          "registry": "npm",
          "name": "posthog-node",
          "version": "5.55.0",
          "seenAt": "2026-10-08T16:26:00.932213759Z"
        },
        {
          "registry": "pypi",
          "name": "posthog",
          "version": "7.66.0",
          "released": "2026-10-08",
          "seenAt": "2026-10-08T16:26:03.179505005Z"
        }
      ],
      "githubStars": 40189,
      "npmWeekly": 15243417,
      "pypiWeekly": 10625439,
      "securityTxt": {
        "url": "https://posthog.com/.well-known/security.txt",
        "state": "valid",
        "expires": "2027-08-30T00:00:00.000Z",
        "checkedAt": "2026-10-08T15:38:33.305841715Z"
      },
      "pages": [
        {
          "url": "https://posthog.com/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:13.700564471Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ede31863795a"
        },
        {
          "url": "https://posthog.com/pricing",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:16.013448729Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "2cc031ef02b6"
        },
        {
          "url": "https://posthog.com/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:17.807151985Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "4cbb2a93a904"
        },
        {
          "url": "https://posthog.com/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:23:20.222126648Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "8b42f8ddf893"
        }
      ],
      "updatedAt": "2026-10-08T19:08:56.183162663Z"
    }
  }
}
