PostHog
by PostHog Inc. HTTP API in Product analytics & experimentation
Hosted
PostHog Inc. · posthog.com since 2020 · status page · who's behind it
PostHog is an open-source product analytics platform with session replay, feature flags, experiments, error tracking and a data warehouse. Agents reach PostHog Cloud through a REST API with a public OpenAPI spec and an official hosted MCP server.
Good for An agent that answers product questions in SQL or with funnel, retention and trends queries, and that manages feature flags, experiments and error tracking in the same project.
Is this your product? Claim this listing or verify it
Assessment. PostHog suits agents that need to query product data and manage flags or experiments. Its hosted MCP server has OAuth scopes, a read-only mode and a one-tool CLI mode over 1,096 tools. The status page shows 31 incidents in 90 days, four on analytics queries, and three security incidents were disclosed in the last year.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://us.posthog.com- Auth
- OAuth or key
- Pricing
- Freemium · $0.0001 / tx
- x402
- No
- Licence
- MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms
- Tools exposed
- 1096
- Packages
npmposthog-nodenpmposthog-jspypiposthognpm@posthog/cli- MCP registry
io.github.PostHog/mcp- llms.txt
- published
- Last release
- GitHub stars
- 40k
- npm / week
- 15.2M
- Surface graded
- PostHog Cloud. The REST API at us.posthog.com and eu.posthog.com, and the official hosted MCP server at mcp.posthog.com. The open-source hobby deploy is unsupported and was not graded
- API
- OpenAPI 3.1 at https://app.posthog.com/api/schema/, readable without a login. 1,742 paths and 2,347 operations on 7 October 2026. Public capture and flag endpoints on us.i.posthog.com and eu.i.posthog.com take the project token
- MCP server
- https://mcp.posthog.com/mcp over streamable HTTP. 1,096 tools in 74 categories. CLI mode (one
exectool) or tools mode, chosen per client or with?mode=. Filtersfeatures=andtools=,readonly=true, and project pinning by header or query parameter - Credentials
- OAuth 2 with PKCE, dynamic client registration and client ID metadata documents at oauth.posthog.com, 226 scopes. Personal API keys (
phx_) with scopes, up to 10 a user. Project secret API keys (phs_) in beta - Rate limits
- Per team. Analytics endpoints 240 a minute and 1,200 an hour,
/query2,400 an hour and 240 a minute, flag local evaluation 600 a minute, other endpoints 480 a minute and 4,800 an hour. Capture and/flagshave no request limit - Query limits
- 10 seconds of execution, 3 concurrent queries a project, 100 rows by default and 50,000 at most, and an hourly read budget in bytes for personal API keys that answers 429 with
Retry-After - Errors
- JSON with
type,code,detailandattr. The spec documents 400 on 224 operations, 404 on 191, 403 on 96 and 429 on 55 - Free tier
- No card. Each month 1 million analytics events, 5,000 recordings, 1 million flag requests, 100,000 exceptions, 1,500 survey responses and 1 million warehouse rows. 1 project and 1 year of data retention
- Paid
- Pay as you go with no base fee and no seat charge. 6 projects and 7 years of retention. Platform packages Boost $250, Scale $750 and Enterprise $2,000 a month
- SDKs
- posthog-node 5.55.0 (30 September 2026), posthog-js 1.438.2, Python posthog 7.64.1 (6 October 2026), and @posthog/cli 0.18.9 with
posthog-cli apifor the API and MCP tool list - Audit
- Activity logs with an API and export. Admins see every personal API key that reaches the organisation, with scopes and last use. Querying activity logs with PostHog AI needs the Scale or Enterprise package
- Certifications
- SOC 2 Type 2 with the 2026 report published, HIPAA BAA on the Boost package, annual penetration test (May 2026), Bugcrowd vulnerability disclosure programme that pays in merchandise
- Status
- https://www.posthogstatus.com on incident.io, with US and EU components that include MCP Server, REST API Query endpoints and All other REST API endpoints
- Data
- AWS us-east-1 (Virginia) or eu-central-1 (Germany), chosen at signup. Sub-processor list updated 12 June 2026 with 14 days' notice of changes under the DPA
- Open source
- MIT outside the
eedirectory. The MCP server source is in services/mcp of PostHog/posthog
Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.1 spec with 2,347 operations and a scope on most of them, plus llms.txt and a Markdown copy of every docs page
- Hosted MCP server with OAuth, a read-only switch, filters by product area or tool name and pinning to one project
- CLI mode registers one
exectool that searches, inspects and calls the 1,096 tools on demand - Free plan without a card, with 1 million analytics events and 1 million flag requests a month, and public per-unit prices above that
- MIT source outside the
eedirectory, a public SOC 2 Type 2 report and a public security advisories page
Weaknesses
- 31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures
- Three security incidents in twelve months, among them malicious npm SDK versions on 24 November 2025
- API queries stop at 10 seconds of execution, three at a time per project, with an hourly read budget on personal API keys
- No API versioning or deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice
- Customer content can be used to train PostHog's own models unless the customer opts out in settings
Before you call it notes for agents
- Add
?readonly=trueor thex-posthog-read-onlyheader to the MCP URL unless the task needs writes - Pin the session with
x-posthog-project-id, which also removes theswitch-projectandswitch-organizationtools - In CLI mode run
info <tool>once beforecall, and send oneexeccommand per request - On a 429 with code
api_queries_budget_exceeded, wait forRetry-Afterand readX-PostHog-Query-Budget-Remaining-Bytes - Page SQL results by keyset on
timestamp.OFFSETreturns 400 for personal API keys, and results cap at 50,000 rows
Who's behind it provenance 94/100
- Legal entity namedPostHog Inc. (formerly Hiberly Inc.)20/20
- Domain ageposthog.com, registered 2020-01-23 (6 years)11/15
- Endpoint on the vendor's domainus.posthog.com15/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 1 clause that costs points8/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagewww.posthogstatus.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2026-06-29, states 7 of 7, 2 to know
TL;DR Dated 2026-06-29. States all 7 things a reader expects. To know before relying on it, model training with an opt-out and limits on benchmarking.
Says it may use customer content to train or improve models, and gives an opt-out
Customer Content may be used for Product and Model Development unless (a) otherwise agreed to between Customer and PostHog or (b) Customer has opted out through the applicable service settings within the Licensed Materials and/or product or services interface;
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Restricts benchmarking or competitive usecosts points
Publish benchmarking results about PostHog without our permission.
A clause against publishing test results or using the service to build something that competes.
Gives the date it was last updated Last updated 2026-06-29
Last Updated: June 29, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
This Agreement shall be governed by and construed in accordance with the laws of the State of California, United States, without regard to its conflict of law principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at $1,000
…WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE OR STRICT LIABILITY), OR OTHERWISE, WILL NOT EXCEED, IN THE AGGREGATE, THE GREATER OF (i) ONE THOUSAND DOLLARS ($1,000), OR (ii) THE TOTAL FEES PAID TO POSTHOG HEREUNDER IN THE ONE YEAR PERIOD ENDING ON THE DATE THAT A CLAIM OR DEMAND IS FIRST ASSERTED.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
7.1 This Agreement shall continue until terminated in accordance with this Section 7.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 30 days of notice before a change
If we’re going to increase prices, we need to give you 30 days notice, giving you the chance to cancel with us.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
4.2 Customer shall not remove, alter or obscure any of PostHog’s (or its licensors’) copyright notices, proprietary legends, trademark or service mark attributions, patent markings or other indicia of PostHog’s (or its licensors’) ownership or contribution from the Licensed Materials.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment Names 99.95% availability
…and services operating and available for use, in each calendar month with an uptime percentage of 99.95% as displayed on https://posthogstatus.com only to those customers who have purchased the Enterprise package or where it has been agreed as a special term in an Order Form.
Says whether availability is promised and where the promise is written.
PostHog may raise fees or add new charges at the end of the initial or any renewal term on 30 days' notice by email or in the product.
PostHog may increase Fees or introduce new charges at the end of the Initial Credit Term (as defined below) or any then-current renewal term upon thirty (30) days’ prior notice to Customer, which may be sent via email or through the services interface or otherwise at PostHog's discretion.
Noted by a second reader on 2026-10-08.
Prepaid credits are not refundable and expire 12 months after purchase unless agreed otherwise in writing.
Unless otherwise agreed in writing, Prepaid Credits are non-refundable and expire twelve (12) months from the date of purchase.
Noted by a second reader on 2026-10-08.
The customer is responsible for all activity under its accounts, whether or not the customer authorised it.
Customer is responsible for maintaining the security of Customer’s accounts, passwords (including but not limited to administrative and User passwords) and files, and for all uses and activities occurring under Customer accounts, whether or not authorized by Customer.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 16,114 words
Privacy policy dated 2026-06-29, states 8 of 8, 2 to know
TL;DR Dated 2026-06-29. States all 8 things a reader expects. To know before relying on it, model training with an opt-out and selling or sharing data for advertising.
Says it may use customer content to train or improve models, and gives an opt-out
Where Customer Content is used for Product and Model Development, PostHog will aggregate or de-identify such data so that it cannot reasonably be used to identify Customer, its Users, or any individual (the "Derived Data").
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Says it sells personal data or shares it for advertising
We may also share some of your account information that you provide to us (including email addresses) with third-party advertising platforms to create or target marketing and advertising audiences on our behalf.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-06-29
Last Updated: June 29, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
💻 We collect data like your IP address, device info, and pages/content you view to improve your experience.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 24 months
Your data may be processed outside your country, and we keep it for 24 months unless you ask us to delete it.
Says when data sent to the service is deleted.
Says who else receives the data
🌐 We share your information with trusted service providers to run our site and product.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
…of Customer Personal Information from Customer to PostHog pursuant to the Agreement constitute a sale of information to PostHog, and that nothing in the Agreement shall be construed as providing for the sale of Customer Personal Information to PostHog.
A plain statement either way.
Says what rights people have over their data
…under your country's or state's laws, including (in the European Economic Area ("EEA"), and UK), a right to object to some processing that we carry out or, where we rely on consent, how to withdraw that consent.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@posthog.com
As part of our commitment to the DPF Principles, if you are a resident of the European Union, UK, or Switzerland and you have a privacy or data use concern, please contact PostHog directly at privacy@posthog.com and PostHog will use its best efforts to address your concern within 45 days of receipt of your complaint.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
We're part of the EU-US Data Privacy Framework, ensuring your data is safe.
The countries data goes to and the safeguard used.
PostHog may use the names and logos of companies using its products for promotion and marketing unless agreed otherwise in writing.
PostHog may use the name and logo of companies using our products or services for promotional and marketing purposes, unless otherwise agreed to in writing.
Noted by a second reader on 2026-10-08.
An opt-out from model development applies only from then on, and PostHog need not retrain or delete models or derived data built from earlier content.
PostHog has no obligation to modify, retrain, or delete any models or Derived Data that utilized Customer Content prior to the effective date of any opt-out, except to the extent required by applicable law.
Noted by a second reader on 2026-10-08.
PostHog reserves the right to publish a support or feedback request to answer it or help other customers, without the sender's personal information.
If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish your request in order to help us clarify or respond to your request or to help us support other customers.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 15,436 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The privacy policy names PostHog Inc., formerly known as Hiberly Inc., and its subsidiaries. The security handbook names Hiberly Ltd. as the UK entity.
posthog.com/.well-known/security.txt expires 2027-08-30 and points to the security handbook. The copy on us.posthog.com expired 2024-03-14.
status.posthog.com redirects to www.posthogstatus.com.
RDAP for posthog.com gives a registration date of 2020-01-23.
The API, OAuth server and MCP server answer on posthog.com subdomains.
Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://us.posthog.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page unknown, no machine-readable status found · 1 hour ago
- github
PostHog/posthogposthog-cli/v0.18.10, released 2026-10-08 - npm
@posthog/cli0.18.10 - npm
posthog-js1.438.2 - npm
posthog-node5.55.0 - pypi
posthog7.66.0, released 2026-10-08 - GitHub stars 40k
- npm downloads a week 15.2M
- PyPI downloads a week 10.6M
- security.txt valid, expires 2027-08-30T00:00:00.000Z · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/posthog.json
Notable
- The MCP server is hosted at https://mcp.posthog.com/mcp, routes to the US or EU region of the signed-in account and is free to call, though tools that run LLMs may bill as PostHog AI spend source
- The tools reference lists 1,096 MCP tools in 74 categories, and CLI mode replaces them with a single
exectool that most clients get by default source - Private API limits are per team, 240 a minute and 1,200 an hour on analytics endpoints, 2,400 an hour on
/query, 480 a minute on other endpoints, and PostHog says it sells no higher limits source - API queries run for at most 10 seconds, three at a time per project, return 100 rows by default and 50,000 at most, and PostHog says
/queryis not a supported export path source - The advisories page lists PSA-2026-00002 of 21 August 2026 (traffic from six EU customers' own reverse proxies readable by a researcher) and PSA-2026-00001 of 2 June 2026 (internal production credentials exposed on US Cloud, no customer data accessed) source
- The terms give a 99.95 per cent monthly uptime SLA with credits only to customers on the Enterprise package or with an order form source
- The repository is MIT except the
eedirectory, and PostHog says the self-hosted hobby deploy scales to about 100,000 events a month with no support source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 14.8 | |
Graded on PostHog Cloud with the hosted lines. Status page on incident.io at posthogstatus.com with per-region components, among them MCP Server and REST API Query endpoints (20). 31 incidents between 9 July and 6 October 2026. Four were analytics query timeouts or failures (15 July for 67 minutes, 31 August open for 27 hours 35 minutes with load shed after 4 hours, 10 September for 9 minutes, 30 September for 2 hours 6 minutes), plus US API errors for 65 minutes on 19 August and MCP sign-in from ChatGPT failing for 20 hours on 10 August. None was marked a full outage of the API, so 10 of 30. Rate limits published with numbers per endpoint class (15). The query read budget answers 429 with Retry-After and budget headers, but there is no backoff guidance for the general limits and no idempotency keys for writes were found (9). 99.95 per cent uptime SLA in the terms for the Enterprise package (10). The REST API is generally available and the MCP docs carry no beta label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.2 | |
| OpenAPI 3.1 served without a login, 1,742 paths and 2,347 operations, and typed JSON Schema inputs on the MCP tools (25). llms.txt, and every docs page has a Markdown copy at the same address with .md (10). 1,487 of 2,347 operations (63 per cent) have a description. MCP tool descriptions average 708 characters and say when to use a tool and what to call first (16). 1,243 enums across 4,792 schemas and a required scope on most operations (13). 706 examples in the spec. It documents 400 on 224 operations and 429 on 55, and the docs show the error shape with examples (9). Dated public changelog with RSS, but the spec version is fixed at 1.0.0 and the API has no versions (8). | |||
| Agent ergonomics | 13%16.2 | 12.7 | |
1,096 MCP tools is far past 30 (5). Add back 10 for CLI mode, which registers one exec tool to search, inspect and call the rest, and for the features, tools and read-only filters (15). Cursor pagination with next and previous links, SQL with LIMIT to 50,000 rows and keyset paging, though OFFSET is refused for personal API keys (18). Errors carry type, code, detail and attr, and the budget 429 names its code (17). Every MCP tool has readOnlyHint, destructiveHint and idempotentHint (592 read-only, 135 destructive), and 18 admin actions are split into prepare and execute steps. No idempotency keys on REST writes (15). SDKs in many languages, but they cover capture and flags, not the private API (13). | |||
| Security & auth | 14%17.5 | 14.7 | |
| OAuth 2 with PKCE, 226 scopes, a revocation endpoint and dynamic registration, or personal API keys with scopes, project limits and rolling. A key can still be created with full access, and keys found in public GitHub repositories are rolled automatically (28). Read-only mode, filters by product area or tool, project pinning, and a typed confirmation for 18 admin actions (18). The MCP docs warn about prompt injection and tell users to review tool calls, and the CLI escapes informational responses. No further mitigation is documented for event and replay data that end users wrote (9). Activity logs with an API, MCP calls recorded with the caller's IP, and an admin view of every key with last use. Longer retention needs a platform package (12). security.txt valid to 30 August 2027, Bugcrowd disclosure programme paid in merchandise, public SOC 2 Type 2 report, annual penetration test and a public advisories page (17). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
| No x402, MPP or L402 (0). Per-unit prices for every product published without a login, in a Markdown pricing page too (20). Free plan with no card (20). A person signs up in a browser and creates a key or approves OAuth (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.8 | |
The changelog's newest entry is 5 October 2026 and the repository's newest commit is 7 October 2026 (30). 292 dated changelog entries since 9 July 2026 (20). Public changelog, community questions and in-app support. The repository shows 5,626 open issues and pull requests, and we did not read how quickly they are answered (15 of 25). io.github.PostHog/mcp is in the official MCP registry, and the SDKs are current, with posthog-node 5.55.0 on 30 September 2026 and 50 versions in 90 days (15). 142 CI workflow files, four of them for the MCP server (9 of 10, with the npm publishing compromise of November 2025 counted under deductions). | |||
| Transparency & trusteditorial 71, provenance 94 | 7%8.8 | 7.3 | |
MIT outside the ee directory, which has its own licence and is part of what PostHog Cloud runs (25 of 30). Privacy policy, a self-serve DPA and the terms agree. The terms let PostHog use de-identified customer content to train its own models unless the customer opts out, and bar third parties from training on it. The privacy policy gives no retention periods, while the pricing page gives 1 year on the free plan and 7 on paid (22). No deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice. 16 MCP tools carry a pointer to their replacement (4). Sub-processor list updated 12 June 2026 with locations, 14 days' notice of changes, and data in Virginia or Germany (20). | |||
| Negative events | ≤15 |
| -7 |
| Total | 68.4 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on PostHog, or have the agent fetch /fixes/posthog.md. A fix counts at the next check, once it's public.
Show it
# Fix list: PostHog From Anchor Terminal's listing at https://www.anchorterminal.com/tools/posthog, the October 2026 research run, assessed 7 October 2026. Grade B, 68.4 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on PostHog: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 40 out of 100, up to 7.5 more on the total Why it scored 40: No x402, MPP or L402 (0). Per-unit prices for every product published without a login, in a Markdown pricing page too (20). Free plan with no card (20). A person signs up in a browser and creates a key or approves OAuth (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Reliability, 74 out of 100, up to 5.2 more on the total Why it scored 74: Graded on PostHog Cloud with the hosted lines. Status page on incident.io at posthogstatus.com with per-region components, among them MCP Server and REST API Query endpoints (20). 31 incidents between 9 July and 6 October 2026. Four were analytics query timeouts or failures (15 July for 67 minutes, 31 August open for 27 hours 35 minutes with load shed after 4 hours, 10 September for 9 minutes, 30 September for 2 hours 6 minutes), plus US API errors for 65 minutes on 19 August and MCP sign-in from ChatGPT failing for 20 hours on 10 August. None was marked a full outage of the API, so 10 of 30. Rate limits published with numbers per endpoint class (15). The query read budget answers 429 with `Retry-After` and budget headers, but there is no backoff guidance for the general limits and no idempotency keys for writes were found (9). 99.95 per cent uptime SLA in the terms for the Enterprise package (10). The REST API is generally available and the MCP docs carry no beta label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 3. Agent ergonomics, 78 out of 100, up to 3.6 more on the total Why it scored 78: 1,096 MCP tools is far past 30 (5). Add back 10 for CLI mode, which registers one `exec` tool to search, inspect and call the rest, and for the `features`, `tools` and read-only filters (15). Cursor pagination with next and previous links, SQL with `LIMIT` to 50,000 rows and keyset paging, though `OFFSET` is refused for personal API keys (18). Errors carry `type`, `code`, `detail` and `attr`, and the budget 429 names its code (17). Every MCP tool has readOnlyHint, destructiveHint and idempotentHint (592 read-only, 135 destructive), and 18 admin actions are split into prepare and execute steps. No idempotency keys on REST writes (15). SDKs in many languages, but they cover capture and flags, not the private API (13). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Schema & documentation, 81 out of 100, up to 3.1 more on the total Why it scored 81: OpenAPI 3.1 served without a login, 1,742 paths and 2,347 operations, and typed JSON Schema inputs on the MCP tools (25). llms.txt, and every docs page has a Markdown copy at the same address with .md (10). 1,487 of 2,347 operations (63 per cent) have a description. MCP tool descriptions average 708 characters and say when to use a tool and what to call first (16). 1,243 enums across 4,792 schemas and a required scope on most operations (13). 706 examples in the spec. It documents 400 on 224 operations and 429 on 55, and the docs show the error shape with examples (9). Dated public changelog with RSS, but the spec version is fixed at 1.0.0 and the API has no versions (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Security & auth, 84 out of 100, up to 2.8 more on the total Why it scored 84: OAuth 2 with PKCE, 226 scopes, a revocation endpoint and dynamic registration, or personal API keys with scopes, project limits and rolling. A key can still be created with full access, and keys found in public GitHub repositories are rolled automatically (28). Read-only mode, filters by product area or tool, project pinning, and a typed confirmation for 18 admin actions (18). The MCP docs warn about prompt injection and tell users to review tool calls, and the CLI escapes informational responses. No further mitigation is documented for event and replay data that end users wrote (9). Activity logs with an API, MCP calls recorded with the caller's IP, and an admin view of every key with last use. Longer retention needs a platform package (12). security.txt valid to 30 August 2027, Bugcrowd disclosure programme paid in merchandise, public SOC 2 Type 2 report, annual penetration test and a public advisories page (17). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 6. Transparency & trust, 83 out of 100, up to 1.5 more on the total Made of editorial 71, provenance 94. Why it scored 83: MIT outside the `ee` directory, which has its own licence and is part of what PostHog Cloud runs (25 of 30). Privacy policy, a self-serve DPA and the terms agree. The terms let PostHog use de-identified customer content to train its own models unless the customer opts out, and bar third parties from training on it. The privacy policy gives no retention periods, while the pricing page gives 1 year on the free plan and 7 on paid (22). No deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice. 16 MCP tools carry a pointer to their replacement (4). Sub-processor list updated 12 June 2026 with locations, 14 days' notice of changes, and data in Virginia or Germany (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: posthog.com, registered 2020-01-23 (6 years) (11 of 15) - Terms of service: read, states 7 of the 7 things a reader expects, and has 1 clause that costs points (8 of 10) ## 7. Maintenance & community, 89 out of 100, up to 1 more on the total Why it scored 89: The changelog's newest entry is 5 October 2026 and the repository's newest commit is 7 October 2026 (30). 292 dated changelog entries since 9 July 2026 (20). Public changelog, community questions and in-app support. The repository shows 5,626 open issues and pull requests, and we did not read how quickly they are answered (15 of 25). `io.github.PostHog/mcp` is in the official MCP registry, and the SDKs are current, with posthog-node 5.55.0 on 30 September 2026 and 50 versions in 90 days (15). 142 CI workflow files, four of them for the MCP server (9 of 10, with the npm publishing compromise of November 2025 counted under deductions). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - -3: 2025-11-24. Malicious versions of posthog-node, posthog-js and six other npm packages were published with a stolen token after an attacker took CI secrets through a pull request workflow. PostHog removed them in about five hours and published a post-mortem on 26 November 2025, so the deduction is reduced (https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem). - -2: 2026-05-29, disclosed 2026-06-02 as PSA-2026-00001 (critical). Researchers used an unsandboxed, outdated Chromium to reach a US Cloud pod and read internal production credentials. PostHog says no customer data was accessed and the credentials were rotated. Fixed and documented (https://posthog.com/handbook/company/security-advisories). - -2: 2026-07-11 to 2026-08-04, disclosed 2026-08-21 as PSA-2026-00002 (high). Customer-run nginx proxies set up as PostHog's guide showed sent traffic to released AWS addresses, and a researcher read traffic from six EU customers. The report sat in triage for five weeks. Fixed and documented (https://posthog.com/handbook/company/security-advisories). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: PyPI weekly downloads for posthog, pypistats.org answered 429 - unchecked: how quickly issues on PostHog/posthog are answered, we read the repository by clone and the GitHub API count only - unchecked: the live `tools/list` response of the MCP server, which needs a token. Tool counts and annotations come from services/mcp/schema in the repository and the docs tools reference - unchecked: activity log retention by platform package, posthog.com/platform-packages did not return content to our reader - unchecked: the `ee` directory's licence text - The status page lists 'Phishing emails sent via PostHog invite system' on 24 April 2026. We did not read its detail and made no deduction for it - No idempotency key or event de-duplication rule was found in the capture docs we read - The newest advisory PSA-2026-00002 concerns customer-run proxies. We deducted because PostHog's own guide showed the unsafe configuration and its triage took five weeks ## Weaknesses - 31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures - Three security incidents in twelve months, among them malicious npm SDK versions on 24 November 2025 - API queries stop at 10 seconds of execution, three at a time per project, with an hourly read budget on personal API keys - No API versioning or deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice - Customer content can be used to train PostHog's own models unless the customer opts out in settings ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Add `?readonly=true` or the `x-posthog-read-only` header to the MCP URL unless the task needs writes - Pin the session with `x-posthog-project-id`, which also removes the `switch-project` and `switch-organization` tools - In CLI mode run `info <tool>` once before `call`, and send one `exec` command per request - On a 429 with code `api_queries_budget_exceeded`, wait for `Retry-After` and read `X-PostHog-Query-Budget-Remaining-Bytes` - Page SQL results by keyset on `timestamp`. `OFFSET` returns 400 for personal API keys, and results cap at 50,000 rows ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: PyPI weekly downloads for posthog, pypistats.org answered 429
- unchecked: how quickly issues on PostHog/posthog are answered, we read the repository by clone and the GitHub API count only
- unchecked: the live
tools/listresponse of the MCP server, which needs a token. Tool counts and annotations come from services/mcp/schema in the repository and the docs tools reference - unchecked: activity log retention by platform package, posthog.com/platform-packages did not return content to our reader
- unchecked: the
eedirectory's licence text - The status page lists 'Phishing emails sent via PostHog invite system' on 24 April 2026. We did not read its detail and made no deduction for it
- No idempotency key or event de-duplication rule was found in the capture docs we read
- The newest advisory PSA-2026-00002 concerns customer-run proxies. We deducted because PostHog's own guide showed the unsafe configuration and its triage took five weeks
Sources 26
- API overview, auth and rate limits posthog.com · seen 2026-10-07
- query endpoint limits and read budget posthog.com · seen 2026-10-07
- OpenAPI spec app.posthog.com · seen 2026-10-07
- MCP overview posthog.com · seen 2026-10-07
- MCP FAQ, modes, read-only and filters posthog.com · seen 2026-10-07
- MCP tools reference posthog.com · seen 2026-10-07
- MCP server source and tool definitions github.com · seen 2026-10-07
- OAuth docs posthog.com · seen 2026-10-07
- OAuth server metadata oauth.posthog.com · seen 2026-10-07
- personal API keys posthog.com · seen 2026-10-07
- pricing posthog.com · seen 2026-10-07
- status page and incident history posthogstatus.com · seen 2026-10-07
- security advisories posthog.com · seen 2026-10-07
- npm compromise post-mortem posthog.com · seen 2026-10-07
- security handbook posthog.com · seen 2026-10-07
- SOC 2 page posthog.com · seen 2026-10-07
- terms, SLA and model development clause posthog.com · seen 2026-10-07
- privacy policy posthog.com · seen 2026-10-07
- DPA posthog.com · seen 2026-10-07
- sub-processors posthog.com · seen 2026-10-07
- changelog posthog.com · seen 2026-10-07
- activity logs posthog.com · seen 2026-10-07
- security.txt posthog.com · seen 2026-10-07
- official MCP registry registry.modelcontextprotocol.io · seen 2026-10-07
- posthog-node on npm registry.npmjs.org · seen 2026-10-07
- llms.txt posthog.com · seen 2026-10-07
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $0.0001 / tx Free plan with no card, covering 1 million analytics events and 1 million flag requests a month. The paid plan has no base fee and no seat charge, and bills per unit above the free allowance (analytics events from $0.00005). API and MCP calls are not billed, but personal API key queries draw on an hourly read budget that is larger on a paid plan (https://posthog.com/pricing, checked 2026-10-07).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Product analytics event | $0.0001 | per transaction | 1 to 2 million a month, first 1 million free, lower above |
| Feature flag request | $0.0001 | per transaction | 1 to 2 million a month, first 1 million free, lower above |
| Session recording | $0.005 | per transaction | 5,001 to 15,000 a month, first 5,000 free |
| Data warehouse row | $0. | per record | 1 to 10 million a month, first 1 million free |
| Boost package | $250 | per month (plan) | |
| Scale package | $750 | per month (plan) | |
| Enterprise package | $2000 | per month (plan) |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/posthog.xml, or this listing's score history at history.json.
Connect
Install
npx @posthog/wizard mcp add
First request
curl \
-H 'Content-Type: application/json' \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
https://us.posthog.com/api/projects/:project_id/query/ \
-d '{"query": {"kind": "HogQLQuery", "query": "select event, count() from events group by event limit 100"}}'
Claude Code
claude mcp add --transport http posthog https://mcp.posthog.com/mcp -s user
MCP client configuration
{
"mcpServers": {
"posthog": {
"url": "https://mcp.posthog.com/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/posthog
letme picks this listing for analytics.events, because it's the top-graded tool for the job. letme picks this listing for analytics.experiments, because it's the top-graded tool for the job. letme picks this listing for analytics.flags, because it's the top-graded tool for the job. letme picks this listing for analytics.funnels, because it's the top-graded tool for the job. letme picks this listing for analytics.query, because it's the top-graded tool for the job. letme picks this listing for observability.logs, because it's the top-graded tool for the job.
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Amplitude BMixpanel BPendo DSentry MCP BBDatadog MCP Server CHeap D
Head to head Amplitude vs PostHog · Mixpanel vs PostHog · Pendo vs PostHog · Heap vs PostHog
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Amplitude Amplitude, Inc. | B | 66.2 | analytics.query analytics.funnels analytics.experiments analytics.flags analytics.events | no |
| Mixpanel Mixpanel, Inc. | B | 62 | analytics.query analytics.funnels analytics.events analytics.experiments analytics.flags | no |
| Pendo Pendo.io, Inc. | D | 48.2 | analytics.query analytics.funnels analytics.events | no |
| Sentry MCP Sentry | BB | 70.2 | observability.errors | no |
| Datadog MCP Server Datadog | C | 56.6 | observability.logs | no |
| Heap Contentsquare (Content Square, Inc.) | D | 53 | analytics.events | no |
Machine-readable
- JSON
/api/v1/tools/posthog.json· historyhistory.json· badge/badges/posthog.svg· changes feed/feeds/tools/posthog.xml - Markdown
/tools/posthog.md· slim/tools/posthog.min.md(or sendAccept: text/markdown) - Fix list
/fixes/posthog.md·/fixes/posthog.json - From a terminal
anchor tool posthog --md(the CLI) · over MCPget_tool {"slug": "posthog"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/posthog"><img src="https://www.anchorterminal.com/badges/posthog.svg" alt="PostHog on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/posthog)<a href="https://www.anchorterminal.com/tools/posthog">PostHog on Anchor Terminal</a>It counts on a page on posthog.com or one of its subdomains, or the README of github.com/PostHog/posthog.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "posthog", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
