# PostHog > PostHog is an open-source product analytics platform with session replay, feature flags, experiments, error tracking and a data warehouse. Agents reach PostHog Cloud through a REST API with a public OpenAPI spec and an official hosted MCP server. - Canonical: https://www.anchorterminal.com/tools/posthog - Markdown: https://www.anchorterminal.com/tools/posthog.md (~8,350 tokens) - Slim: https://www.anchorterminal.com/tools/posthog.min.md (~2,130 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/posthog.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 68.4/100 · rank #171 of 629 · #4 in Product analytics & experimentation · not agent-ready · confidence medium** ## Assessment PostHog suits agents that need to query product data and manage flags or experiments. Its hosted MCP server has OAuth scopes, a read-only mode and a one-tool CLI mode over 1,096 tools. The status page shows 31 incidents in 90 days, four on analytics queries, and three security incidents were disclosed in the last year. ## Facts | Field | Value | | --- | --- | | Vendor | PostHog Inc. (https://posthog.com) | | Kind | HTTP API | | Category | Product analytics & experimentation (https://www.anchorterminal.com/categories/product-analytics) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://us.posthog.com` | | Auth | OAuth or key · Self-serve. Private endpoints take a Bearer personal API key (`phx_`) that a signed-in user creates with chosen scopes and project or organisation access, or an OAuth access token. OAuth at oauth.posthog.com supports PKCE, dynamic client registration and client ID metadata documents, with no app review needed to go live. The MCP server uses OAuth by default or a personal API key made with the MCP Server preset. Project secret API keys are in beta. Capture and flag evaluation take the public project token. | | Pricing | Freemium ($0.0001 / tx) · Free plan with no card, covering 1 million analytics events and 1 million flag requests a month. The paid plan has no base fee and no seat charge, and bills per unit above the free allowance (analytics events from $0.00005). API and MCP calls are not billed, but personal API key queries draw on an hourly read budget that is larger on a paid plan (https://posthog.com/pricing, checked 2026-10-07). | | x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI spec or the pricing page (checked 2026-10-07). | | Licence | MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms | | Tools exposed | 1096 | | Packages | npm: `posthog-node`; npm: `posthog-js`; pypi: `posthog`; npm: `@posthog/cli` | | MCP registry name | `io.github.PostHog/mcp` | | Source | https://github.com/PostHog/posthog | | Docs | https://posthog.com/docs/api | | llms.txt | https://posthog.com/llms.txt | | Last release | 2026-10-05 | | GitHub stars | 40,176 (as of 2026-10-07) | | npm downloads / week | 15,243,417 | | Surface graded | PostHog Cloud. The REST API at us.posthog.com and eu.posthog.com, and the official hosted MCP server at mcp.posthog.com. The open-source hobby deploy is unsupported and was not graded | | API | OpenAPI 3.1 at https://app.posthog.com/api/schema/, readable without a login. 1,742 paths and 2,347 operations on 7 October 2026. Public capture and flag endpoints on us.i.posthog.com and eu.i.posthog.com take the project token | | MCP server | https://mcp.posthog.com/mcp over streamable HTTP. 1,096 tools in 74 categories. CLI mode (one `exec` tool) or tools mode, chosen per client or with `?mode=`. Filters `features=` and `tools=`, `readonly=true`, and project pinning by header or query parameter | | Credentials | OAuth 2 with PKCE, dynamic client registration and client ID metadata documents at oauth.posthog.com, 226 scopes. Personal API keys (`phx_`) with scopes, up to 10 a user. Project secret API keys (`phs_`) in beta | | Rate limits | Per team. Analytics endpoints 240 a minute and 1,200 an hour, `/query` 2,400 an hour and 240 a minute, flag local evaluation 600 a minute, other endpoints 480 a minute and 4,800 an hour. Capture and `/flags` have no request limit | | Query limits | 10 seconds of execution, 3 concurrent queries a project, 100 rows by default and 50,000 at most, and an hourly read budget in bytes for personal API keys that answers 429 with `Retry-After` | | Errors | JSON with `type`, `code`, `detail` and `attr`. The spec documents 400 on 224 operations, 404 on 191, 403 on 96 and 429 on 55 | | Free tier | No card. Each month 1 million analytics events, 5,000 recordings, 1 million flag requests, 100,000 exceptions, 1,500 survey responses and 1 million warehouse rows. 1 project and 1 year of data retention | | Paid | Pay as you go with no base fee and no seat charge. 6 projects and 7 years of retention. Platform packages Boost $250, Scale $750 and Enterprise $2,000 a month | | SDKs | posthog-node 5.55.0 (30 September 2026), posthog-js 1.438.2, Python posthog 7.64.1 (6 October 2026), and @posthog/cli 0.18.9 with `posthog-cli api` for the API and MCP tool list | | Audit | Activity logs with an API and export. Admins see every personal API key that reaches the organisation, with scopes and last use. Querying activity logs with PostHog AI needs the Scale or Enterprise package | | Certifications | SOC 2 Type 2 with the 2026 report published, HIPAA BAA on the Boost package, annual penetration test (May 2026), Bugcrowd vulnerability disclosure programme that pays in merchandise | | Status | https://www.posthogstatus.com on incident.io, with US and EU components that include MCP Server, REST API Query endpoints and All other REST API endpoints | | Data | AWS us-east-1 (Virginia) or eu-central-1 (Germany), chosen at signup. Sub-processor list updated 12 June 2026 with 14 days' notice of changes under the DPA | | Open source | MIT outside the `ee` directory. The MCP server source is in services/mcp of PostHog/posthog | | Capabilities | analytics.query, analytics.events, analytics.funnels, analytics.experiments, analytics.flags, observability.errors, observability.logs | | Tags | official, hosted, open-source, mcp, oauth, openapi, llms-txt, free-tier, no-card, eu-region, status-page, soc2, typescript, python | | JSON | https://www.anchorterminal.com/api/v1/tools/posthog.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 74 | 14.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 81 | 13.2 | | Agent ergonomics | 13% | 16.2 | 78 | 12.7 | | Security & auth | 14% | 17.5 | 84 | 14.7 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 89 | 7.8 | | Transparency & trust (editorial 71, provenance 94) | 7% | 8.8 | 83 | 7.3 | | Negative events | up to −15 | up to −15 | -3: 2025-11-24. Malicious versions of posthog-node, posthog-js and six other npm packages were published with a stolen token after an attacker took CI secrets through a pull request workflow. PostHog removed them in about five hours and published a post-mortem on 26 November 2025, so the deduction is reduced (https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem). -2: 2026-05-29, disclosed 2026-06-02 as PSA-2026-00001 (critical). Researchers used an unsandboxed, outdated Chromium to reach a US Cloud pod and read internal production credentials. PostHog says no customer data was accessed and the credentials were rotated. Fixed and documented (https://posthog.com/handbook/company/security-advisories). -2: 2026-07-11 to 2026-08-04, disclosed 2026-08-21 as PSA-2026-00002 (high). Customer-run nginx proxies set up as PostHog's guide showed sent traffic to released AWS addresses, and a researcher read traffic from six EU customers. The report sat in triage for five weeks. Fixed and documented (https://posthog.com/handbook/company/security-advisories). | -7 | | **Total** | | | | **68.4 → B** | ### Why each score - Reliability 74: Graded on PostHog Cloud with the hosted lines. Status page on incident.io at posthogstatus.com with per-region components, among them MCP Server and REST API Query endpoints (20). 31 incidents between 9 July and 6 October 2026. Four were analytics query timeouts or failures (15 July for 67 minutes, 31 August open for 27 hours 35 minutes with load shed after 4 hours, 10 September for 9 minutes, 30 September for 2 hours 6 minutes), plus US API errors for 65 minutes on 19 August and MCP sign-in from ChatGPT failing for 20 hours on 10 August. None was marked a full outage of the API, so 10 of 30. Rate limits published with numbers per endpoint class (15). The query read budget answers 429 with `Retry-After` and budget headers, but there is no backoff guidance for the general limits and no idempotency keys for writes were found (9). 99.95 per cent uptime SLA in the terms for the Enterprise package (10). The REST API is generally available and the MCP docs carry no beta label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 81: OpenAPI 3.1 served without a login, 1,742 paths and 2,347 operations, and typed JSON Schema inputs on the MCP tools (25). llms.txt, and every docs page has a Markdown copy at the same address with .md (10). 1,487 of 2,347 operations (63 per cent) have a description. MCP tool descriptions average 708 characters and say when to use a tool and what to call first (16). 1,243 enums across 4,792 schemas and a required scope on most operations (13). 706 examples in the spec. It documents 400 on 224 operations and 429 on 55, and the docs show the error shape with examples (9). Dated public changelog with RSS, but the spec version is fixed at 1.0.0 and the API has no versions (8). - Agent ergonomics 78: 1,096 MCP tools is far past 30 (5). Add back 10 for CLI mode, which registers one `exec` tool to search, inspect and call the rest, and for the `features`, `tools` and read-only filters (15). Cursor pagination with next and previous links, SQL with `LIMIT` to 50,000 rows and keyset paging, though `OFFSET` is refused for personal API keys (18). Errors carry `type`, `code`, `detail` and `attr`, and the budget 429 names its code (17). Every MCP tool has readOnlyHint, destructiveHint and idempotentHint (592 read-only, 135 destructive), and 18 admin actions are split into prepare and execute steps. No idempotency keys on REST writes (15). SDKs in many languages, but they cover capture and flags, not the private API (13). - Security & auth 84: OAuth 2 with PKCE, 226 scopes, a revocation endpoint and dynamic registration, or personal API keys with scopes, project limits and rolling. A key can still be created with full access, and keys found in public GitHub repositories are rolled automatically (28). Read-only mode, filters by product area or tool, project pinning, and a typed confirmation for 18 admin actions (18). The MCP docs warn about prompt injection and tell users to review tool calls, and the CLI escapes informational responses. No further mitigation is documented for event and replay data that end users wrote (9). Activity logs with an API, MCP calls recorded with the caller's IP, and an admin view of every key with last use. Longer retention needs a platform package (12). security.txt valid to 30 August 2027, Bugcrowd disclosure programme paid in merchandise, public SOC 2 Type 2 report, annual penetration test and a public advisories page (17). - Payments & pricing 40: No x402, MPP or L402 (0). Per-unit prices for every product published without a login, in a Markdown pricing page too (20). Free plan with no card (20). A person signs up in a browser and creates a key or approves OAuth (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 89: The changelog's newest entry is 5 October 2026 and the repository's newest commit is 7 October 2026 (30). 292 dated changelog entries since 9 July 2026 (20). Public changelog, community questions and in-app support. The repository shows 5,626 open issues and pull requests, and we did not read how quickly they are answered (15 of 25). `io.github.PostHog/mcp` is in the official MCP registry, and the SDKs are current, with posthog-node 5.55.0 on 30 September 2026 and 50 versions in 90 days (15). 142 CI workflow files, four of them for the MCP server (9 of 10, with the npm publishing compromise of November 2025 counted under deductions). - Transparency & trust 83: MIT outside the `ee` directory, which has its own licence and is part of what PostHog Cloud runs (25 of 30). Privacy policy, a self-serve DPA and the terms agree. The terms let PostHog use de-identified customer content to train its own models unless the customer opts out, and bar third parties from training on it. The privacy policy gives no retention periods, while the pricing page gives 1 year on the free plan and 7 on paid (22). No deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice. 16 MCP tools carry a pointer to their replacement (4). Sub-processor list updated 12 June 2026 with locations, 14 days' notice of changes, and data in Virginia or Germany (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/posthog.md (JSON https://www.anchorterminal.com/fixes/posthog.json) ### What we couldn't check - unchecked: PyPI weekly downloads for posthog, pypistats.org answered 429 - unchecked: how quickly issues on PostHog/posthog are answered, we read the repository by clone and the GitHub API count only - unchecked: the live `tools/list` response of the MCP server, which needs a token. Tool counts and annotations come from services/mcp/schema in the repository and the docs tools reference - unchecked: activity log retention by platform package, posthog.com/platform-packages did not return content to our reader - unchecked: the `ee` directory's licence text - The status page lists 'Phishing emails sent via PostHog invite system' on 24 April 2026. We did not read its detail and made no deduction for it - No idempotency key or event de-duplication rule was found in the capture docs we read - The newest advisory PSA-2026-00002 concerns customer-run proxies. We deducted because PostHog's own guide showed the unsafe configuration and its triage took five weeks ### Sources - API overview, auth and rate limits: (seen 2026-10-07) - query endpoint limits and read budget: (seen 2026-10-07) - OpenAPI spec: (seen 2026-10-07) - MCP overview: (seen 2026-10-07) - MCP FAQ, modes, read-only and filters: (seen 2026-10-07) - MCP tools reference: (seen 2026-10-07) - MCP server source and tool definitions: (seen 2026-10-07) - OAuth docs: (seen 2026-10-07) - OAuth server metadata: (seen 2026-10-07) - personal API keys: (seen 2026-10-07) - pricing: (seen 2026-10-07) - status page and incident history: (seen 2026-10-07) - security advisories: (seen 2026-10-07) - npm compromise post-mortem: (seen 2026-10-07) - security handbook: (seen 2026-10-07) - SOC 2 page: (seen 2026-10-07) - terms, SLA and model development clause: (seen 2026-10-07) - privacy policy: (seen 2026-10-07) - DPA: (seen 2026-10-07) - sub-processors: (seen 2026-10-07) - changelog: (seen 2026-10-07) - activity logs: (seen 2026-10-07) - security.txt: (seen 2026-10-07) - official MCP registry: (seen 2026-10-07) - posthog-node on npm: (seen 2026-10-07) - llms.txt: (seen 2026-10-07) ## Who's behind it (provenance 94/100, checked 2026-10-07) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | PostHog Inc. (formerly Hiberly Inc.) | 20/20 | | Domain age | posthog.com, registered 2020-01-23 (6 years) | 11/15 | | Endpoint on the vendor's domain | us.posthog.com | 15/15 | | Terms of service | read, states 7 of the 7 things a reader expects, and has 1 clause that costs points | 8/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | www.posthogstatus.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The privacy policy names PostHog Inc., formerly known as Hiberly Inc., and its subsidiaries. The security handbook names Hiberly Ltd. as the UK entity. posthog.com/.well-known/security.txt expires 2027-08-30 and points to the security handbook. The copy on us.posthog.com expired 2024-03-14. status.posthog.com redirects to www.posthogstatus.com. RDAP for posthog.com gives a registration date of 2020-01-23. The API, OAuth server and MCP server answer on posthog.com subdomains. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://posthog.com/terms), read 2026-10-08, dated 2026-06-29, states 7 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "Customer Content may be used for Product and Model Development unless (a) otherwise agreed to between Customer and PostHog or (b) Customer has opted out through the applicable service settings within the Licensed Materials and/or product or services interface;" - To know. Restricts benchmarking or competitive use (costs points). "Publish benchmarking results about PostHog without our permission." - Gives the date it was last updated. Last updated 2026-06-29. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Capped at $1,000. - Says how changes to the terms are announced. Gives 30 days of notice before a change. - Refers to a service level or uptime commitment. Names 99.95% availability. - Also in the text (2026-10-08). PostHog may raise fees or add new charges at the end of the initial or any renewal term on 30 days' notice by email or in the product. "PostHog may increase Fees or introduce new charges at the end of the Initial Credit Term (as defined below) or any then-current renewal term upon thirty (30) days’ prior notice to Customer, which may be sent via email or through the services interface or otherwise at PostHog's discretion." - Also in the text (2026-10-08). Prepaid credits are not refundable and expire 12 months after purchase unless agreed otherwise in writing. "Unless otherwise agreed in writing, Prepaid Credits are non-refundable and expire twelve (12) months from the date of purchase." - Also in the text (2026-10-08). The customer is responsible for all activity under its accounts, whether or not the customer authorised it. "Customer is responsible for maintaining the security of Customer’s accounts, passwords (including but not limited to administrative and User passwords) and files, and for all uses and activities occurring under Customer accounts, whether or not authorized by Customer." **Privacy policy** (https://posthog.com/privacy), read 2026-10-08, dated 2026-06-29, states 8 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "Where Customer Content is used for Product and Model Development, PostHog will aggregate or de-identify such data so that it cannot reasonably be used to identify Customer, its Users, or any individual (the "Derived Data")." - To know. Says it sells personal data or shares it for advertising. "We may also share some of your account information that you provide to us (including email addresses) with third-party advertising platforms to create or target marketing and advertising audiences on our behalf." - Gives the date it was last updated. Last updated 2026-06-29. - Says how long data is kept. Names a period of 24 months. - Gives a privacy contact. privacy@posthog.com. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). PostHog may use the names and logos of companies using its products for promotion and marketing unless agreed otherwise in writing. "PostHog may use the name and logo of companies using our products or services for promotional and marketing purposes, unless otherwise agreed to in writing." - Also in the text (2026-10-08). An opt-out from model development applies only from then on, and PostHog need not retrain or delete models or derived data built from earlier content. "PostHog has no obligation to modify, retrain, or delete any models or Derived Data that utilized Customer Content prior to the effective date of any opt-out, except to the extent required by applicable law." - Also in the text (2026-10-08). PostHog reserves the right to publish a support or feedback request to answer it or help other customers, without the sender's personal information. "If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish your request in order to help us clarify or respond to your request or to help us support other customers." ## Live (updated 2026-10-08 18:23 UTC) - Right now: up, HTTP 200, 370 ms, checked 2026-10-08 18:20 UTC (get on `https://us.posthog.com`) - Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 367 ms · p95 484 ms - Vendor status page: unknown, no machine-readable status found - github `PostHog/posthog` posthog-cli/v0.18.10, released 2026-10-08 - npm `@posthog/cli` 0.18.10 - npm `posthog-js` 1.438.2 - npm `posthog-node` 5.55.0 - pypi `posthog` 7.66.0, released 2026-10-08 - security.txt: valid, expires 2027-08-30T00:00:00.000Z - Watching changelog - Watching pricing - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/posthog.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Product analytics event | $0.0001 | per transaction | 1 to 2 million a month, first 1 million free, lower above | | Feature flag request | $0.0001 | per transaction | 1 to 2 million a month, first 1 million free, lower above | | Session recording | $0.005 | per transaction | 5,001 to 15,000 a month, first 5,000 free | | Data warehouse row | $0. | per record | 1 to 10 million a month, first 1 million free | | Boost package | $250 | per month (plan) | | | Scale package | $750 | per month (plan) | | | Enterprise package | $2000 | per month (plan) | | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Public OpenAPI 3.1 spec with 2,347 operations and a scope on most of them, plus llms.txt and a Markdown copy of every docs page - Hosted MCP server with OAuth, a read-only switch, filters by product area or tool name and pinning to one project - CLI mode registers one `exec` tool that searches, inspects and calls the 1,096 tools on demand - Free plan without a card, with 1 million analytics events and 1 million flag requests a month, and public per-unit prices above that - MIT source outside the `ee` directory, a public SOC 2 Type 2 report and a public security advisories page ## Weaknesses - 31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures - Three security incidents in twelve months, among them malicious npm SDK versions on 24 November 2025 - API queries stop at 10 seconds of execution, three at a time per project, with an hourly read budget on personal API keys - No API versioning or deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice - Customer content can be used to train PostHog's own models unless the customer opts out in settings ## Before you call it (notes for agents) 1. Add `?readonly=true` or the `x-posthog-read-only` header to the MCP URL unless the task needs writes 2. Pin the session with `x-posthog-project-id`, which also removes the `switch-project` and `switch-organization` tools 3. In CLI mode run `info ` once before `call`, and send one `exec` command per request 4. On a 429 with code `api_queries_budget_exceeded`, wait for `Retry-After` and read `X-PostHog-Query-Budget-Remaining-Bytes` 5. Page SQL results by keyset on `timestamp`. `OFFSET` returns 400 for personal API keys, and results cap at 50,000 rows ## Connect Install: ```bash npx @posthog/wizard mcp add ``` First request: ```bash curl \ -H 'Content-Type: application/json' \ -H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \ https://us.posthog.com/api/projects/:project_id/query/ \ -d '{"query": {"kind": "HogQLQuery", "query": "select event, count() from events group by event limit 100"}}' ``` Claude Code: ```bash claude mcp add --transport http posthog https://mcp.posthog.com/mcp -s user ``` MCP client configuration: ```json { "mcpServers": { "posthog": { "url": "https://mcp.posthog.com/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/posthog (letme picks it for analytics.funnels, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Amplitude | B | 66.2 | 223 | analytics.query, analytics.funnels, analytics.experiments, analytics.flags, analytics.events | no | https://www.anchorterminal.com/tools/amplitude.md | | Mixpanel | B | 62 | 313 | analytics.query, analytics.funnels, analytics.events, analytics.experiments, analytics.flags | no | https://www.anchorterminal.com/tools/mixpanel.md | | Statsig | BB | 72.3 | 89 | analytics.experiments, analytics.flags, analytics.query, analytics.events | no | https://www.anchorterminal.com/tools/statsig.md | | GrowthBook | BB | 70.1 | 135 | analytics.experiments, analytics.flags, analytics.query, analytics.events | no | https://www.anchorterminal.com/tools/growthbook.md | | LaunchDarkly | B | 69.2 | 155 | analytics.flags, analytics.experiments, observability.logs, observability.errors | no | https://www.anchorterminal.com/tools/launchdarkly.md | | Pendo | D | 48.2 | 541 | analytics.query, analytics.funnels, analytics.events | no | https://www.anchorterminal.com/tools/pendo.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The MCP server is hosted at https://mcp.posthog.com/mcp, routes to the US or EU region of the signed-in account and is free to call, though tools that run LLMs may bill as PostHog AI spend (source: ) - The tools reference lists 1,096 MCP tools in 74 categories, and CLI mode replaces them with a single `exec` tool that most clients get by default (source: ) - Private API limits are per team, 240 a minute and 1,200 an hour on analytics endpoints, 2,400 an hour on `/query`, 480 a minute on other endpoints, and PostHog says it sells no higher limits (source: ) - API queries run for at most 10 seconds, three at a time per project, return 100 rows by default and 50,000 at most, and PostHog says `/query` is not a supported export path (source: ) - The advisories page lists PSA-2026-00002 of 21 August 2026 (traffic from six EU customers' own reverse proxies readable by a researcher) and PSA-2026-00001 of 2 June 2026 (internal production credentials exposed on US Cloud, no customer data accessed) (source: ) - The terms give a 99.95 per cent monthly uptime SLA with credits only to customers on the Enterprise package or with an order form (source: ) - The repository is MIT except the `ee` directory, and PostHog says the self-hosted hobby deploy scales to about 100,000 events a month with no support (source: ) ## Compare - [Amplitude vs PostHog](https://www.anchorterminal.com/compare/amplitude-vs-posthog.md): B 66.2 vs B 68.4 - [Mixpanel vs PostHog](https://www.anchorterminal.com/compare/mixpanel-vs-posthog.md): B 62 vs B 68.4 - [Pendo vs PostHog](https://www.anchorterminal.com/compare/pendo-vs-posthog.md): D 48.2 vs B 68.4 - [PostHog vs Statsig](https://www.anchorterminal.com/compare/posthog-vs-statsig.md): B 68.4 vs BB 72.3 - [Heap vs PostHog](https://www.anchorterminal.com/compare/heap-vs-posthog.md): D 53 vs B 68.4 - [GrowthBook vs PostHog](https://www.anchorterminal.com/compare/growthbook-vs-posthog.md): BB 70.1 vs B 68.4 - [LaunchDarkly vs PostHog](https://www.anchorterminal.com/compare/launchdarkly-vs-posthog.md): B 69.2 vs B 68.4 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on posthog.com or one of its subdomains, or the README of github.com/PostHog/posthog. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "posthog", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html PostHog on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![PostHog on Anchor Terminal](https://www.anchorterminal.com/badges/posthog.svg)](https://www.anchorterminal.com/tools/posthog) ``` Plain link: ```html PostHog on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say PostHog is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/posthog-dark.png - Light: https://www.anchorterminal.com/assets/share/posthog-light.png