Amplitude
by Amplitude, Inc. HTTP API in Product analytics & experimentation
Hosted
Amplitude, Inc. · amplitude.com since 1996 · status page · who's behind it
Amplitude is a hosted product analytics platform that records user events and answers questions about funnels, retention, cohorts, experiments and feature flags. Agents reach it through an official remote MCP server, REST APIs and the amp command line.
Good for A team already on Amplitude that wants an agent to query charts, funnels, retention and experiment results, edit dashboards and manage the tracking plan under its own permissions.
Is this your product? Claim this listing or verify it
Assessment. The remote MCP server covers queries, funnels, retention, experiments and flags under OAuth with PKCE, read and write scopes and per-project role actions, and the Free plan needs no card. No MCP rate limits or SLA were found, and status.amplitude.com records a critical outage of the UI, MCP and REST APIs on 13 July 2026.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://mcp.amplitude.com/mcp- Auth
- OAuth or key
- Pricing
- Freemium · Freemium
- x402
- No
- Licence
- Proprietary service under Amplitude's terms of service. The SDKs, the `amp` CLI and the MCP marketplace plugins on GitHub and npm are MIT
- Tools exposed
- 45
- Packages
npm@amplitude/developer-clinpm@amplitude/analytics-nodepypiamplitude-analytics- MCP registry
com.amplitude/mcp-server- llms.txt
- published
- Last release
- npm / week
- 1.3M
- PyPI / week
- 1.8M
- MCP server
- Remote, streaming HTTP, OAuth 2.0 only. https://mcp.amplitude.com/mcp (US) and https://mcp.eu.amplitude.com/mcp (EU). 45 documented tools, with about 25 for ChatGPT
- MCP tool groups
- Discovery and context (3), charts (4), dashboards (1), notebooks, comments and sharing (3), cohorts (1), users (1), experiments and flags (9), taxonomy (6), session replay (3), guides and surveys (2), opportunities (5), feedback (1), agent analytics (2), data warehouse (4)
- Progressive discovery
?discovery=progressiveon either URL returnsget_amplitude_context,list_tool_categories,get_category_toolsanddescribe_toolfirst, and every tool stays callable- REST APIs
- HTTP V2 ingestion at api2.amplitude.com, Dashboard REST and Export at amplitude.com/api, Behavioural Cohorts, Taxonomy, Experiment Management at experiment.amplitude.com, Audit Logs and SCIM, each with EU hosts
- Developer API
- https://developer-api.amplitude.com, OpenAPI 3.1.1, version 0.1.0, 32 paths for projects, taxonomy, saved charts, heatmaps, flags and destinations. Experiment paths are commented out as under construction
- Credentials
- MCP by OAuth with PKCE and dynamic client registration. Developer API by device flow or personal access token with eight scopes. Older APIs by project API key and secret key, or an Experiment management key
- Access controls
- Org-level MCP switch, role actions Use MCP (read) and Use MCP (write) per project, on by default. Read is in every role and write in Member, Manager and Admin
- Rate limits
- Dashboard REST 5 concurrent and 108,000 cost an hour per project. User activity and search 10 concurrent and 360 an hour. Experiment Management 100 a second and 100,000 a day. HTTP V2 30 events a second per user or device. None found for MCP
- Errors and retries
- Developer API answers RFC 9457 problem+json with
error_code,retryableandretry_after_seconds, and takesIdempotency-Keyanddry_runon some operations. HTTP V2 deduplicates oninsert_idfor 7 days - Audit
- Organisation audit log with 90 days of entries and an Audit Logs API. Its event list covers logins, roles, exports and deletions and doesn't name MCP tool calls
- Certifications
- SOC 2 Type II, ISO 27001, ISO 27017 and ISO 27018 on trust.amplitude.com, HIPAA support, a private bug bounty with a Bugcrowd contact in security.txt
- Status
- status.amplitude.com on Statuspage, 29 components including MCP, Management API and Data Reception
- Sub-processors
- List updated 13 May 2026 with data centre locations in the US and EU. Hosting on AWS, with AWS Bedrock, Google Vertex AI and OpenAI for its AI products
Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Remote MCP server with 45 documented tools for queries, funnels, retention, cohorts, experiments, flags and the tracking plan, on US and EU hosts
- OAuth with PKCE, dynamic client registration, a revocation endpoint and
mcp:readandmcp:writescopes, plus two role actions enforced per project on every call - Progressive discovery (
?discovery=progressive) starts with a small tool list and loads schemas on demand - Deletes need a second call with
confirmedset to true, and cohort syncs preview the export before sending - Free plan with 2 million events a month and no card, and the pricing page says MCP works on every plan
Weaknesses
- No rate limit for the MCP server or the Developer API was found in the reviewed documentation
- status.amplitude.com lists one critical and six major incidents between 9 July and 23 September 2026, with the UI, MCP and REST APIs down on 13 July
- No SLA found, and the terms of 21 July 2026 disclaim uninterrupted service
- MCP is on by default for every user, and the Member, Manager and Admin roles include write access until an admin changes them
- Session replays, feedback comments and user properties reach the model with no prompt-injection guidance for hosts
Before you call it notes for agents
- Connect to https://mcp.amplitude.com/mcp, or https://mcp.eu.amplitude.com/mcp for EU projects. The client must support streaming HTTP and OAuth, since API keys aren't accepted
- Append
?discovery=progressiveto load tool schemas on demand, then callget_amplitude_contextfirst to pick the project and read its AI context - Ask an admin for a role with only Use MCP (read) on the projects you need. Tools stay listed and fail at call time when the role lacks the action
- Send events through the HTTP V2 API with an
insert_idon each one. On 429, pause that user or device for 30 seconds before retrying - Budget Dashboard REST queries by cost (days times conditions times chart cost), within 108,000 an hour and 5 concurrent requests per project
Who's behind it provenance 93/100
- Legal entity namedAmplitude, Inc.20/20
- Domain ageamplitude.com, registered 1996-05-09 (30 years)15/15
- Endpoint on the vendor's domainmcp.amplitude.com15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 3 clauses that cost points3.1/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.amplitude.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2026-07-21, states 6 of 7, 5 to know
TL;DR Dated 2026-07-21. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, model training with no opt-out found, limits on benchmarking, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
Amplitude may use techniques such as machine learning in order to improve the Services, and Customer instructs Amplitude to process its Customer Data for such purpose
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Restricts benchmarking or competitive usecosts points
(h) use or access the Amplitude Services to either develop or commercialize a product or service that is competitive with or a substitute for the Amplitude Services or to engage in competitive analysis or benchmarking
A clause against publishing test results or using the service to build something that competes.
Says the terms or the service can change without noticecosts points
NO SEPARATE NOTICE WILL BE REQUIRED, AND YOUR CONTINUED USE OF THE AMPLITUDE SERVICES AFTER THE UPDATED VERSION OF THE TERMS IS POSTED WILL CONSTITUTE YOUR ACCEPTANCE OF SUCH UPDATED TERMS.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
Amplitude may terminate or suspend Customer’s access to the Amplitude Services, without prior notice or liability, at any time and for any reason.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
IMPORTANT NOTICE: THESE TERMS OF SERVICE CONTAIN A BINDING ARBITRATION PROVISION AND WAIVER OF CLASS ACTION RIGHTS AS DETAILED IN THE SECTION 10 ARBITRATION AND WAIVER OF CLASS ACTION SECTION BELOW.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-07-21
Effective Date: July 21, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
These Terms shall be governed by the laws of the State of California without regard to its conflict of laws provisions.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at $1,000
AMPLITUDE’S MAXIMUM AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS AND DAMAGES ARISING OUT OF OR RELATED TO THESE TERMS, WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE OR OTHERWISE, SHALL NOT EXCEED $1,000.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Amplitude may terminate or suspend Customer’s access to the Amplitude Services, without prior notice or liability, at any time and for any reason.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Changes are posted, with no other notice named
THE MOST CURRENT VERSION OF THESE TERMS WILL BE POSTED TO OUR WEBSITE AND ANY UPDATED VERSION OF THESE TERMS WILL SUPERSEDE ALL PREVIOUS VERSIONS.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Notwithstanding any other provision of these Terms, Customer shall not enter into settlement of any Claim without the prior written consent of Amplitude.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Amplitude's total liability under these terms is capped at 1,000 US dollars.
AMPLITUDE’S MAXIMUM AGGREGATE LIABILITY FOR ANY AND ALL CLAIMS AND DAMAGES ARISING OUT OF OR RELATED TO THESE TERMS, WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE OR OTHERWISE, SHALL NOT EXCEED $1,000.
Noted by a second reader on 2026-10-08.
Using the service gives Amplitude the right to use the customer's company name and logo in marketing, and the customer agrees to take part in a case study.
By using the Amplitude Services, Customer gives Amplitude the right to use Customer’s company name and logo in any Amplitude marketing materials, and agrees to participate in a case study that may be published on Amplitude’s website and/or in any marketing materials.
Noted by a second reader on 2026-10-08.
After termination Amplitude has no obligation to store Customer Data and may permanently delete it at its sole discretion, subject to the data processing addendum.
Subject to the TOS DPA, following termination Amplitude shall have no obligation to Customer with respect to the storage of Customer Data and may, in its sole discretion, permanently delete Customer Data.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 6,085 words
Privacy policy dated 2026-08-31, states 8 of 8, 1 to know
TL;DR Dated 2026-08-31. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
We may share Personal Data with third party ad partners, such as through cookies or by providing lists of email addresses for potential customers so we can reach them across the web with relevant ads.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-08-31
Last Updated: August 31, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
Personal Data We Collect And How We Use The Personal Data
The basic statement a privacy policy exists to make.
Says how long data is kept
Persistent cookies are stored by a web browser and remain valid until a set expiration date.
Says when data sent to the service is deleted.
Says who else receives the data
You may choose to participate in an Amplitude program that allows you to pay fees with a credit or debit card, in which case you may provide your credit card or other payment details information directly to our third party payment processor.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell your Personal Data or use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
A plain statement either way.
Says what rights people have over their data
If you do not want to receive communications from us, you can unsubscribe from marketing communications or email us with your preferences at privacy@amplitude.com or ccpa@amplitude.com.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@amplitude.com
Customers can opt out of the use of this software during their use of the Product by contacting us at privacy@amplitude.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
These safeguards may include using the European Commission-approved standard contractual clauses to protect the transfer of your Personal Data to Amplitude’s corporate affiliates or service providers, if required by applicable law.
The countries data goes to and the safeguard used.
The notice does not apply to Customer End User Data that customers submit to the product.
For clarity, this Privacy Notice does not apply to Customer End User Data (as defined below) submitted by our customers to the Product.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 7,895 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (effective 21 July 2026) and the privacy notice (updated 31 August 2026) name Amplitude, Inc., 201 3rd Street, Suite 200, San Francisco, CA 94103.
The MCP server answers at mcp.amplitude.com and mcp.eu.amplitude.com, the Developer API at developer-api.amplitude.com and ingestion at api2.amplitude.com, all amplitude.com subdomains.
amplitude.com/.well-known/security.txt gives a Bugcrowd tracker and security@amplitude.com as contacts and expires 2028-12-31.
RDAP for amplitude.com gives a registration date of 1996-05-09.
The data processing addendum for the terms of service is dated 4 June 2024 and points to the sub-processor list at amplitude.com/subprocessor-list, updated 13 May 2026.
Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:50 UTC
Probed every five minutes at https://mcp.amplitude.com/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page all systems normal, All Systems Operational · under a minute ago
- npm
@amplitude/analytics-node1.5.77 - npm
@amplitude/developer-cli0.4.0 - pypi
amplitude-analytics1.2.3, released 2026-03-31 - GitHub stars 42
- npm downloads a week 342
- PyPI downloads a week 1.8M
- security.txt valid, expires 2028-12-31T23:59:00Z · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/amplitude.json
Notable
- The MCP page lists 45 tools in 14 groups, among them
query_amplitude_datafor segmentation, funnels and retention,query_experiment,get_flags,use_amplitude_cohortsand three session replay tools, plus three progressive discovery tools source - OAuth metadata at mcp.amplitude.com lists PKCE S256, dynamic client registration, a revocation endpoint and the scopes
mcp:read,mcp:writeandoffline_accesssource - The Developer API at developer-api.amplitude.com is described by an OpenAPI 3.1.1 document, version 0.1.0, with 32 paths. The root file is public, its referenced path files returned 404 to us and /v1/openapi.json asks for a token source
- The Dashboard REST API limits each project to 5 concurrent requests and 108,000 cost an hour, where cost is days times conditions times a per-chart figure source
- status.amplitude.com has an MCP component and recorded a critical incident on 13 July 2026, with the UI, MCP and REST APIs affected from 14:04 PT and the incident resolved at 16:07 PT source
- The official MCP registry lists com.amplitude/mcp-server 1.0.0 with the US and EU remotes, published 16 October 2025 source
- The
ampCLI, @amplitude/developer-cli on npm, went from 0.1.0 on 26 June 2026 to 0.4.0 on 2 October 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 12.0 | |
Read with the hosted lines and scored on what an agent calls, the remote MCP server first and the REST APIs beside it. status.amplitude.com on Statuspage has 29 components, MCP among them, with incident history (20). Between 9 July and 7 October 2026 it lists one critical and six major incidents. The critical one, on 13 July, affected the UI, MCP and REST APIs in the US from 14:04 PT and was resolved at 16:07 PT. The majors were on shared embeds, EU web latency, a metrics page, AI chat and two export delays on 22 and 23 September, so one outage reached the agent surface and the rest did not (5 of 30, between one major and several). Rate limits with numbers for the Dashboard REST API (5 concurrent, 108,000 cost an hour), Experiment Management (100 a second, 100,000 a day) and HTTP V2 (30 events a second per user or device), and none found for MCP or the Developer API (12 of 15). HTTP V2 says to pause 30 seconds on 429 and deduplicates on insert_id, and the Developer API returns retryable and retry_after_seconds and accepts Idempotency-Key on some operations. No guidance for MCP (13 of 15). No SLA found, and the terms disclaim uninterrupted service (0). The MCP server carries no beta label and is 1.0.0 in the official registry. The Developer API's spec is version 0.1.0 (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 11.7 | |
| The Developer API has an OpenAPI 3.1.1 document whose root file is public, but its referenced path files returned 404 and the bundled /v1/openapi.json needs a token. The older REST APIs have no spec, and we couldn't read the MCP tool schemas without an Amplitude sign-in (15 of 25). llms.txt, five product feeds, llms-full.txt and Markdown for every docs page (10). The MCP page says what the server is for and what it isn't, and gives each of 45 tools a one-line description (15 of 20). REST parameter tables are typed with required fields, and the Developer API documents scopes, limits and formats. MCP input schemas unread (9 of 15). Request and response examples throughout the REST docs and error tables per API (13 of 15). Dated release notes at amplitude.com/releases and versioned API paths, but the registry entry has stayed at 1.0.0 since October 2025 while tools were consolidated on 17 August 2026 (10 of 15). | |||
| Agent ergonomics | 13%16.2 | 11.7 | |
45 tools is over the 30 line (5), with 10 added back for progressive discovery, which starts with four tools and loads schemas on demand, and a subset of about 25 for ChatGPT (15 of 25). Cursor and limit pagination on the Developer API (default 50, maximum 200), the Experiment Management API and the data warehouse tools, and filters on search and replay tools. The MCP page warns that hosts may truncate large charts (17 of 20). RFC 9457 errors with error_code, retryable and field errors on the Developer API and detailed 400 and 429 bodies on HTTP V2. MCP error shapes unread (15 of 20). Idempotency-Key and dry_run on some Developer API operations, insert_id on events, two-step deletes and optimistic concurrency on dashboards and notebooks. We couldn't see whether tools carry readOnlyHint or destructiveHint (13 of 20). Official SDKs in many languages cover ingestion and experiment evaluation, not queries, and the amp CLI prints compact JSON when piped (12 of 15). | |||
| Security & auth | 14%17.5 | 12.9 | |
The MCP server takes OAuth 2.0 with PKCE S256, dynamic client registration, a revocation endpoint and mcp:read and mcp:write scopes, and the Developer API takes scoped tokens. The older REST APIs still use a project API key and secret key, which aren't scoped (28 of 30). Two role actions, Use MCP (read) and Use MCP (write), are enforced per project on each call, an admin can switch MCP off for the organisation, deletes need a second confirmed call and cohort syncs preview first. MCP is on by default and three standard roles include write (17 of 20). Session replays, feedback comments and user properties are untrusted content, and we found only a disclaimer about model outputs, no injection guidance for hosts (2 of 15). An organisation audit log with 90 days of entries and an API, whose event list doesn't name MCP tool calls (9 of 15). security.txt valid to 31 December 2028, SOC 2 Type II, ISO 27001, 27017 and 27018 on the trust portal and a bug bounty that is private (18 of 20). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| Read with the hosted rubric. No x402, MPP or L402 (0). Plans are public but Plus shows a price only through an estimator that asks for a card, and Growth and Enterprise go through sales (10). The Free plan has 2 million events a month with no card, and MCP works on it (20). A person signs up and approves OAuth in a browser, or creates keys in settings (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.3 | |
| @amplitude/developer-cli 0.4.0 on 2 October 2026, and the release notes add MCP taxonomy delete and restore on 12 September (30). At least 15 dated release notes since 17 August and four CLI releases since 5 August (20). Closed service with public release notes, a feedback form for MCP and 19 commits to the amplitude/mcp-marketplace repository since 9 July. We didn't test support (11 of 15). com.amplitude/mcp-server is in the official MCP registry under the vendor's domain (15). The marketplace plugin bumps versions automatically (1.6.0 on 8 September), while the CLI needs Node.js 26 and the registry entry is a year old (7 of 10). | |||
| Transparency & trusteditorial 63, provenance 93 | 7%8.8 | 6.8 | |
| Closed service with terms effective 21 July 2026. The SDKs, CLI and marketplace plugins are MIT (15). The DPA of 4 June 2024 promises destruction within 90 days of termination and use only to run the service, while the terms let Amplitude apply machine learning to customer data to improve the services and delete data at its discretion after termination. The AI docs say data isn't used for model training (20 of 30). A written SDK lifecycle with at least 12 months of maintenance for a superseded major version. No deprecation policy for the REST APIs or MCP tools found (10 of 20). Sub-processor list updated 13 May 2026 with US and EU data centre locations and 10 business days' notice of additions under the DPA (18 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 66.2 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 16 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Amplitude, or have the agent fetch /fixes/amplitude.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Amplitude From Anchor Terminal's listing at https://www.anchorterminal.com/tools/amplitude, the October 2026 research run, assessed 7 October 2026. Grade B, 66.2 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Amplitude: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: Read with the hosted rubric. No x402, MPP or L402 (0). Plans are public but Plus shows a price only through an estimator that asks for a card, and Growth and Enterprise go through sales (10). The Free plan has 2 million events a month with no card, and MCP works on it (20). A person signs up and approves OAuth in a browser, or creates keys in settings (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Reliability, 60 out of 100, up to 8 more on the total Why it scored 60: Read with the hosted lines and scored on what an agent calls, the remote MCP server first and the REST APIs beside it. status.amplitude.com on Statuspage has 29 components, MCP among them, with incident history (20). Between 9 July and 7 October 2026 it lists one critical and six major incidents. The critical one, on 13 July, affected the UI, MCP and REST APIs in the US from 14:04 PT and was resolved at 16:07 PT. The majors were on shared embeds, EU web latency, a metrics page, AI chat and two export delays on 22 and 23 September, so one outage reached the agent surface and the rest did not (5 of 30, between one major and several). Rate limits with numbers for the Dashboard REST API (5 concurrent, 108,000 cost an hour), Experiment Management (100 a second, 100,000 a day) and HTTP V2 (30 events a second per user or device), and none found for MCP or the Developer API (12 of 15). HTTP V2 says to pause 30 seconds on 429 and deduplicates on `insert_id`, and the Developer API returns `retryable` and `retry_after_seconds` and accepts `Idempotency-Key` on some operations. No guidance for MCP (13 of 15). No SLA found, and the terms disclaim uninterrupted service (0). The MCP server carries no beta label and is 1.0.0 in the official registry. The Developer API's spec is version 0.1.0 (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 3. Schema & documentation, 72 out of 100, up to 4.6 more on the total Why it scored 72: The Developer API has an OpenAPI 3.1.1 document whose root file is public, but its referenced path files returned 404 and the bundled /v1/openapi.json needs a token. The older REST APIs have no spec, and we couldn't read the MCP tool schemas without an Amplitude sign-in (15 of 25). llms.txt, five product feeds, llms-full.txt and Markdown for every docs page (10). The MCP page says what the server is for and what it isn't, and gives each of 45 tools a one-line description (15 of 20). REST parameter tables are typed with required fields, and the Developer API documents scopes, limits and formats. MCP input schemas unread (9 of 15). Request and response examples throughout the REST docs and error tables per API (13 of 15). Dated release notes at amplitude.com/releases and versioned API paths, but the registry entry has stayed at 1.0.0 since October 2025 while tools were consolidated on 17 August 2026 (10 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 4. Agent ergonomics, 72 out of 100, up to 4.6 more on the total Why it scored 72: 45 tools is over the 30 line (5), with 10 added back for progressive discovery, which starts with four tools and loads schemas on demand, and a subset of about 25 for ChatGPT (15 of 25). Cursor and `limit` pagination on the Developer API (default 50, maximum 200), the Experiment Management API and the data warehouse tools, and filters on search and replay tools. The MCP page warns that hosts may truncate large charts (17 of 20). RFC 9457 errors with `error_code`, `retryable` and field errors on the Developer API and detailed 400 and 429 bodies on HTTP V2. MCP error shapes unread (15 of 20). `Idempotency-Key` and `dry_run` on some Developer API operations, `insert_id` on events, two-step deletes and optimistic concurrency on dashboards and notebooks. We couldn't see whether tools carry readOnlyHint or destructiveHint (13 of 20). Official SDKs in many languages cover ingestion and experiment evaluation, not queries, and the `amp` CLI prints compact JSON when piped (12 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Security & auth, 74 out of 100, up to 4.6 more on the total Why it scored 74: The MCP server takes OAuth 2.0 with PKCE S256, dynamic client registration, a revocation endpoint and `mcp:read` and `mcp:write` scopes, and the Developer API takes scoped tokens. The older REST APIs still use a project API key and secret key, which aren't scoped (28 of 30). Two role actions, Use MCP (read) and Use MCP (write), are enforced per project on each call, an admin can switch MCP off for the organisation, deletes need a second confirmed call and cohort syncs preview first. MCP is on by default and three standard roles include write (17 of 20). Session replays, feedback comments and user properties are untrusted content, and we found only a disclaimer about model outputs, no injection guidance for hosts (2 of 15). An organisation audit log with 90 days of entries and an API, whose event list doesn't name MCP tool calls (9 of 15). security.txt valid to 31 December 2028, SOC 2 Type II, ISO 27001, 27017 and 27018 on the trust portal and a bug bounty that is private (18 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 6. Transparency & trust, 78 out of 100, up to 1.9 more on the total Made of editorial 63, provenance 93. Why it scored 78: Closed service with terms effective 21 July 2026. The SDKs, CLI and marketplace plugins are MIT (15). The DPA of 4 June 2024 promises destruction within 90 days of termination and use only to run the service, while the terms let Amplitude apply machine learning to customer data to improve the services and delete data at its discretion after termination. The AI docs say data isn't used for model training (20 of 30). A written SDK lifecycle with at least 12 months of maintenance for a superseded major version. No deprecation policy for the REST APIs or MCP tools found (10 of 20). Sub-processor list updated 13 May 2026 with US and EU data centre locations and 10 business days' notice of additions under the DPA (18 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points (3.1 of 10) ## 7. Maintenance & community, 83 out of 100, up to 1.5 more on the total Why it scored 83: @amplitude/developer-cli 0.4.0 on 2 October 2026, and the release notes add MCP taxonomy delete and restore on 12 September (30). At least 15 dated release notes since 17 August and four CLI releases since 5 August (20). Closed service with public release notes, a feedback form for MCP and 19 commits to the amplitude/mcp-marketplace repository since 9 July. We didn't test support (11 of 15). com.amplitude/mcp-server is in the official MCP registry under the vendor's domain (15). The marketplace plugin bumps versions automatically (1.6.0 on 8 September), while the CLI needs Node.js 26 and the registry entry is a year old (7 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the MCP tools' JSON Schema inputs and their readOnlyHint and destructiveHint annotations, which need an Amplitude sign-in to list - unchecked: the Developer API's per-operation schemas, since the path files referenced by the public OpenAPI root returned 404 and /v1/openapi.json needs a token - unchecked: the Plus plan's price per event, shown only in an estimator - unchecked: whether MCP tool calls appear in the organisation audit log, which the audit log page doesn't say - unchecked: how MCP service accounts are created, named on the MCP page with no setup guide found - No rate limit for the MCP server or the Developer API was found in the reviewed documentation - No SLA was found on amplitude.com (amplitude.com/sla returns 404). An enterprise contract may include one - GitHub star counts weren't collected. npmWeekly is @amplitude/analytics-node and pypiWeekly is amplitude-analytics, both ingestion SDKs ## Weaknesses - No rate limit for the MCP server or the Developer API was found in the reviewed documentation - status.amplitude.com lists one critical and six major incidents between 9 July and 23 September 2026, with the UI, MCP and REST APIs down on 13 July - No SLA found, and the terms of 21 July 2026 disclaim uninterrupted service - MCP is on by default for every user, and the Member, Manager and Admin roles include write access until an admin changes them - Session replays, feedback comments and user properties reach the model with no prompt-injection guidance for hosts ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Connect to https://mcp.amplitude.com/mcp, or https://mcp.eu.amplitude.com/mcp for EU projects. The client must support streaming HTTP and OAuth, since API keys aren't accepted - Append `?discovery=progressive` to load tool schemas on demand, then call `get_amplitude_context` first to pick the project and read its AI context - Ask an admin for a role with only Use MCP (read) on the projects you need. Tools stay listed and fail at call time when the role lacks the action - Send events through the HTTP V2 API with an `insert_id` on each one. On 429, pause that user or device for 30 seconds before retrying - Budget Dashboard REST queries by cost (days times conditions times chart cost), within 108,000 an hour and 5 concurrent requests per project ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the MCP tools' JSON Schema inputs and their readOnlyHint and destructiveHint annotations, which need an Amplitude sign-in to list
- unchecked: the Developer API's per-operation schemas, since the path files referenced by the public OpenAPI root returned 404 and /v1/openapi.json needs a token
- unchecked: the Plus plan's price per event, shown only in an estimator
- unchecked: whether MCP tool calls appear in the organisation audit log, which the audit log page doesn't say
- unchecked: how MCP service accounts are created, named on the MCP page with no setup guide found
- No rate limit for the MCP server or the Developer API was found in the reviewed documentation
- No SLA was found on amplitude.com (amplitude.com/sla returns 404). An enterprise contract may include one
- GitHub star counts weren't collected. npmWeekly is @amplitude/analytics-node and pypiWeekly is amplitude-analytics, both ingestion SDKs
Sources 24
- MCP server guide, tools, regions and role controls amplitude.com · seen 2026-10-07
- MCP OAuth authorisation server metadata mcp.amplitude.com · seen 2026-10-07
- Developer API guide (auth, scopes, pagination, errors, idempotency) amplitude.com · seen 2026-10-07
- Developer API OpenAPI root document developer-api.amplitude.com · seen 2026-10-07
- Dashboard REST API and its rate limits amplitude.com · seen 2026-10-07
- HTTP V2 API, limits and 429 handling amplitude.com · seen 2026-10-07
- Experiment Management API amplitude.com · seen 2026-10-07
- Keys and tokens amplitude.com · seen 2026-10-07
- llms.txt amplitude.com · seen 2026-10-07
- pricing amplitude.com · seen 2026-10-07
- status incident history status.amplitude.com · seen 2026-10-07
- 13 July 2026 critical incident stspg.io · seen 2026-10-07
- release notes amplitude.com · seen 2026-10-07
- official MCP registry entry registry.modelcontextprotocol.io · seen 2026-10-07
- MCP marketplace repository github.com · seen 2026-10-07
- amp CLI on npm registry.npmjs.org · seen 2026-10-07
- terms of service amplitude.com · seen 2026-10-07
- data processing addendum amplitude.com · seen 2026-10-07
- privacy notice amplitude.com · seen 2026-10-07
- sub-processor list amplitude.com · seen 2026-10-07
- security.txt amplitude.com · seen 2026-10-07
- security and privacy FAQ amplitude.com · seen 2026-10-07
- trust portal trust.amplitude.com · seen 2026-10-07
- audit log amplitude.com · seen 2026-10-07
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium Freemium Free plan with 2 million events a month and no card, and the pricing page says MCP and agent access work on every plan. Plus is usage-based from $0 with the first 2 million events free, up to 70 million, and needs a card to see an estimate. Growth and Enterprise are priced by sales. API and MCP calls aren't metered in money. There's no separate sandbox, so an agent starts on a Free organisation (https://amplitude.com/pricing, checked 2026-10-07).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/amplitude.xml, or this listing's score history at history.json.
Connect
Install
npm install -g @amplitude/developer-cli
First request
curl --location --request GET 'https://amplitude.com/api/3/chart/:chart_id/csv' \
-u '{api_key}:{secret_key}'
Claude Code
claude mcp add -t http -s user Amplitude "https://mcp.amplitude.com/mcp"
MCP client configuration
{
"mcpServers": {
"amplitude": {
"type": "http",
"url": "https://mcp.amplitude.com/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/amplitude
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
PostHog BMixpanel BPendo DHeap D
Head to head Amplitude vs Mixpanel · Amplitude vs Pendo · Amplitude vs PostHog · Amplitude vs Heap
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| PostHog PostHog Inc. | B | 68.4 | analytics.query analytics.events analytics.funnels analytics.experiments analytics.flags | no |
| Mixpanel Mixpanel, Inc. | B | 62 | analytics.query analytics.funnels analytics.events analytics.experiments analytics.flags | no |
| Pendo Pendo.io, Inc. | D | 48.2 | analytics.query analytics.funnels analytics.events | no |
| Heap Contentsquare (Content Square, Inc.) | D | 53 | analytics.events | no |
Machine-readable
- JSON
/api/v1/tools/amplitude.json· historyhistory.json· badge/badges/amplitude.svg· changes feed/feeds/tools/amplitude.xml - Markdown
/tools/amplitude.md· slim/tools/amplitude.min.md(or sendAccept: text/markdown) - Fix list
/fixes/amplitude.md·/fixes/amplitude.json - From a terminal
anchor tool amplitude --md(the CLI) · over MCPget_tool {"slug": "amplitude"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/amplitude"><img src="https://www.anchorterminal.com/badges/amplitude.svg" alt="Amplitude on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/amplitude)<a href="https://www.anchorterminal.com/tools/amplitude">Amplitude on Anchor Terminal</a>It counts on a page on amplitude.com or one of its subdomains, or the README of github.com/amplitude/mcp-marketplace.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "amplitude", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
