{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/growthbook.json",
        "name": "GrowthBook",
        "score": 70.1,
        "shared": [
          "analytics.experiments",
          "analytics.flags",
          "analytics.query",
          "analytics.events"
        ],
        "slug": "growthbook"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/posthog.json",
        "name": "PostHog",
        "score": 68.4,
        "shared": [
          "analytics.query",
          "analytics.events",
          "analytics.experiments",
          "analytics.flags"
        ],
        "slug": "posthog"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/amplitude.json",
        "name": "Amplitude",
        "score": 66.2,
        "shared": [
          "analytics.query",
          "analytics.experiments",
          "analytics.flags",
          "analytics.events"
        ],
        "slug": "amplitude"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/mixpanel.json",
        "name": "Mixpanel",
        "score": 62,
        "shared": [
          "analytics.query",
          "analytics.events",
          "analytics.experiments",
          "analytics.flags"
        ],
        "slug": "mixpanel"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/optimizely.json",
        "name": "Optimizely Experimentation",
        "score": 62.6,
        "shared": [
          "analytics.experiments",
          "analytics.flags",
          "analytics.query"
        ],
        "slug": "optimizely"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/launchdarkly.json",
        "name": "LaunchDarkly",
        "score": 69.2,
        "shared": [
          "analytics.flags",
          "analytics.experiments"
        ],
        "slug": "launchdarkly"
      }
    ],
    "tool": {
      "slug": "statsig",
      "name": "Statsig",
      "vendor": "Amplitude, Inc.",
      "vendorUrl": "https://www.statsig.com",
      "kind": "http-api",
      "category": "product-analytics",
      "summary": "Statsig is a hosted platform for feature flags, experiments and product analytics, run by Amplitude, Inc. since May 2026. Agents reach it through the Console API, which has a public OpenAPI spec, and an official hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/statsig",
      "markdownUrl": "https://www.anchorterminal.com/tools/statsig.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/statsig.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/statsig.json",
      "repo": "https://github.com/statsig-io/statsig-server-core",
      "license": "Proprietary hosted service under Statsig's self-service or enterprise terms. The SDKs and the agent skills repository on GitHub are ISC",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.statsig.com/v3/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@statsig/statsig-node-core"
        },
        {
          "registry": "npm",
          "name": "@statsig/js-client"
        },
        {
          "registry": "pypi",
          "name": "statsig-python-core"
        },
        {
          "registry": "npm",
          "name": "@statsig/siggy"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Console API takes a Console API key in the `STATSIG-API-KEY` header, created in project settings as read-only or read and write. The MCP server uses OAuth with PKCE and dynamic client registration, which issues a personal Console API key carrying the user's role, or takes a Console key in the `statsig-api-key` header. OAuth needs the organisation owner to allow personal keys for the role. Flag evaluation and event logging take a client or server SDK key.",
      "pricing": "freemium",
      "pricingNotes": "Free Developer plan with no card, covering 2 million events and 50,000 session replays a month. Pro is $150 a month with 5 million events, then $0.05 per 1,000 events. Enterprise is by contract. Flag and config checks are unlimited on every plan, and API and MCP calls are not billed. An agent can start on the free plan without a contract (https://www.statsig.com/pricing, checked 2026-10-08).",
      "priceSummary": "$150 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs corpus, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 18,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 4157066,
        "pypiWeekly": 893619,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.statsig.com/console-api/introduction",
      "llmsTxt": "https://docs.statsig.com/llms.txt",
      "openapi": "https://api.statsig.com/openapi/20240601.json",
      "registryName": "com.statsig/statsig-mcp-server",
      "capabilities": [
        "analytics.experiments",
        "analytics.flags",
        "analytics.query",
        "analytics.events"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "soc2",
        "eu-region"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 72.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 94,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 81,
          "payments": 40,
          "reliability": 79,
          "schema": 82,
          "security": 74,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 79,
            "points": 15.8,
            "reason": "Graded on the hosted service with the hosted lines. Statuspage at status.statsig.com with 14 components, among them Console API, Config Delivery API and Log Event API (20). Three incidents between 10 July and 8 October 2026, all delays to Warehouse Native exports and results, marked minor or none (20 of 30). A major incident on 8 July 2026, when launched gates returned false through the V2 Config Delivery API for about 4 hours 44 minutes, falls two days outside the window. The docs give about 1,800 mutation attempts per 15 minutes per project, while the OpenAPI description gives about 100 per 10 seconds and 900 per 15 minutes, and no number was found for reads (12 of 15). The docs ask for exponential backoff with jitter on 429. No `Retry-After` header and no idempotency keys were found (10 of 15). The enterprise terms give 99.95 per cent monthly availability with credits, for customers with premium support, measured on the Console user interface (7 of 10). The Console API is versioned and the MCP V3 docs carry no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 82,
            "points": 13.33,
            "reason": "Public OpenAPI 3.0 spec for Console API version 20240601 with 209 paths and 325 operations, and typed MCP tools per the tool reference (25). llms.txt, llms-full.txt, a Markdown copy of each page and a public docs MCP server (10). Every operation has a summary but only 29 of 325 have a description. The MCP tool reference states each tool's purpose and when to ask the user first (11 of 20). 1,164 enums across 188 schemas, with required fields marked (12 of 15). Examples on most responses. The spec documents 401 on 156 operations, 404 on 126 and 400 on 106, and no 429 (11 of 15). A dated API version sent in the `STATSIG-API-VERSION` header with a promise not to break a version, and a dated product updates page. No changelog for the API alone was found (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 71,
            "points": 11.54,
            "reason": "The MCP V3 server shows 18 default tools, which is 15 on the checklist. Add back 8 for the discovery layer that reaches other operations on demand, `query_fields` on experiment reads and read-only access (23 of 25). `limit` and `page` on 49 list operations with pagination metadata, a cursor on the Logs Explorer query, and filters by tag, status, creator and date (17 of 20). Errors are a `status` and a `message` with no machine code, and MCP results set `isError` (11 of 20). No idempotency keys were found. Updates and `api_destructive` calls need a `confirmation` object, and operations are split into read, write and destructive lanes. We could not read the live tool annotations (10 of 20). The SDKs cover flag evaluation and event logging in many languages, not the Console API, and the `siggy` CLI on npm is version 0.0.4 from September 2024 (10 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 74,
            "points": 12.95,
            "reason": "OAuth for the MCP server with PKCE, dynamic client registration and a device code grant, issuing personal Console API keys that carry the user's role. Console keys can be created read-only or read and write, and rotated or deactivated through the API. The OAuth metadata lists no scopes, and a project Console key reaches every Console API endpoint (25 of 30). MCP scope is set per project and per role as no access, read only or read and write. Updates and destructive operations need a confirmation, and project review policies still apply (19 of 20). No guidance on prompt injection was found, though tools return names, descriptions and log data that people wrote. The docs tell users to review each change before the agent confirms (4 of 15). Audit logs are kept indefinitely with an API, and personal keys attribute changes to a user (14 of 15). SOC 2 Type II and a bug bounty programme are stated on the security page, with no public programme link and no security.txt (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). Prices are public without a login. Pro is $150 a month with 5 million events, then $0.05 per 1,000 events (20). The Developer plan is free with no card and 2 million events a month (20). A person signs up in a browser, then creates a key or approves OAuth (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 81,
            "points": 7.09,
            "reason": "The newest product update is dated 12 September 2026 and the server SDKs released 0.23.1 on 28 September 2026 (30). Ten or more dated product updates since 10 July 2026 (20). Closed service with a public updates page and a Slack community. We did not read how quickly questions are answered (10 of 15). `com.statsig/statsig-mcp-server` is in the official MCP registry under the vendor's domain, though the entry dates from 19 September 2025 and lists the V1 URL (13 of 15). The server SDK repository has 25 CI workflow files and 124 commits since 10 July 2026, while the `siggy` CLI has not been published since September 2024 (8 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "note": "editorial 64, provenance 85",
            "reason": "Closed hosted service under a published self-service agreement and enterprise terms. The SDKs are open source under ISC (17 of 30). The terms, DPA and AI governance page mostly agree. The DPA names Amplitude, Inc. as processor and keeps data as long as necessary, the pricing page gives 1 year of analytics retention on the free plan, and the docs say customer data is not used to build AI models without written consent. The privacy notice is Amplitude's and doesn't name Statsig, and the self-service terms name Amplitude, Inc. under an effective date of 4 August 2025, before Statsig joined Amplitude on 5 May 2026 (18 of 30). Each Console API version is promised not to break, a deprecation notices page gives dates, and MCP V1 stays supported. No notice period is stated (12 of 20). Amplitude's sub-processor list, updated 13 May 2026, gives locations and marks the providers used for Statsig-branded services. EU hosting is an Enterprise option (17 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP V3 server shows 18 default tools, which is 15 on the checklist. Add back 8 for the discovery layer that reaches other operations on demand, `query_fields` on experiment reads and read-only access (23 of 25). `limit` and `page` on 49 list operations with pagination metadata, a cursor on the Logs Explorer query, and filters by tag, status, creator and date (17 of 20). Errors are a `status` and a `message` with no machine code, and MCP results set `isError` (11 of 20). No idempotency keys were found. Updates and `api_destructive` calls need a `confirmation` object, and operations are split into read, write and destructive lanes. We could not read the live tool annotations (10 of 20). The SDKs cover flag evaluation and event logging in many languages, not the Console API, and the `siggy` CLI on npm is version 0.0.4 from September 2024 (10 of 15).",
            "maintenance": "The newest product update is dated 12 September 2026 and the server SDKs released 0.23.1 on 28 September 2026 (30). Ten or more dated product updates since 10 July 2026 (20). Closed service with a public updates page and a Slack community. We did not read how quickly questions are answered (10 of 15). `com.statsig/statsig-mcp-server` is in the official MCP registry under the vendor's domain, though the entry dates from 19 September 2025 and lists the V1 URL (13 of 15). The server SDK repository has 25 CI workflow files and 124 commits since 10 July 2026, while the `siggy` CLI has not been published since September 2024 (8 of 10).",
            "payments": "No x402, MPP or L402 (0). Prices are public without a login. Pro is $150 a month with 5 million events, then $0.05 per 1,000 events (20). The Developer plan is free with no card and 2 million events a month (20). A person signs up in a browser, then creates a key or approves OAuth (0).",
            "reliability": "Graded on the hosted service with the hosted lines. Statuspage at status.statsig.com with 14 components, among them Console API, Config Delivery API and Log Event API (20). Three incidents between 10 July and 8 October 2026, all delays to Warehouse Native exports and results, marked minor or none (20 of 30). A major incident on 8 July 2026, when launched gates returned false through the V2 Config Delivery API for about 4 hours 44 minutes, falls two days outside the window. The docs give about 1,800 mutation attempts per 15 minutes per project, while the OpenAPI description gives about 100 per 10 seconds and 900 per 15 minutes, and no number was found for reads (12 of 15). The docs ask for exponential backoff with jitter on 429. No `Retry-After` header and no idempotency keys were found (10 of 15). The enterprise terms give 99.95 per cent monthly availability with credits, for customers with premium support, measured on the Console user interface (7 of 10). The Console API is versioned and the MCP V3 docs carry no beta label (10).",
            "schema": "Public OpenAPI 3.0 spec for Console API version 20240601 with 209 paths and 325 operations, and typed MCP tools per the tool reference (25). llms.txt, llms-full.txt, a Markdown copy of each page and a public docs MCP server (10). Every operation has a summary but only 29 of 325 have a description. The MCP tool reference states each tool's purpose and when to ask the user first (11 of 20). 1,164 enums across 188 schemas, with required fields marked (12 of 15). Examples on most responses. The spec documents 401 on 156 operations, 404 on 126 and 400 on 106, and no 429 (11 of 15). A dated API version sent in the `STATSIG-API-VERSION` header with a promise not to break a version, and a dated product updates page. No changelog for the API alone was found (13 of 15).",
            "security": "OAuth for the MCP server with PKCE, dynamic client registration and a device code grant, issuing personal Console API keys that carry the user's role. Console keys can be created read-only or read and write, and rotated or deactivated through the API. The OAuth metadata lists no scopes, and a project Console key reaches every Console API endpoint (25 of 30). MCP scope is set per project and per role as no access, read only or read and write. Updates and destructive operations need a confirmation, and project review policies still apply (19 of 20). No guidance on prompt injection was found, though tools return names, descriptions and log data that people wrote. The docs tell users to review each change before the agent confirms (4 of 15). Audit logs are kept indefinitely with an API, and personal keys attribute changes to a user (14 of 15). SOC 2 Type II and a bug bounty programme are stated on the security page, with no public programme link and no security.txt (12 of 20).",
            "transparency": "Closed hosted service under a published self-service agreement and enterprise terms. The SDKs are open source under ISC (17 of 30). The terms, DPA and AI governance page mostly agree. The DPA names Amplitude, Inc. as processor and keeps data as long as necessary, the pricing page gives 1 year of analytics retention on the free plan, and the docs say customer data is not used to build AI models without written consent. The privacy notice is Amplitude's and doesn't name Statsig, and the self-service terms name Amplitude, Inc. under an effective date of 4 August 2025, before Statsig joined Amplitude on 5 May 2026 (18 of 30). Each Console API version is promised not to break, a deprecation notices page gives dates, and MCP V1 stays supported. No notice period is stated (12 of 20). Amplitude's sub-processor list, updated 13 May 2026, gives locations and marks the providers used for Statsig-branded services. EU hosting is an Enterprise option (17 of 20)."
          },
          "sources": [
            {
              "what": "Console API overview, auth, rate limits and versioning",
              "url": "https://docs.statsig.com/console-api/introduction",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI spec for Console API version 20240601",
              "url": "https://api.statsig.com/openapi/20240601.json",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP overview",
              "url": "https://docs.statsig.com/integrations/mcp/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP V3 tool reference",
              "url": "https://docs.statsig.com/integrations/mcp/tool-reference",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP manual setup, OAuth and API key",
              "url": "https://docs.statsig.com/integrations/mcp/manual-setup",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP with Claude Code",
              "url": "https://docs.statsig.com/integrations/mcp/claude-code",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP V1 to V3 migration",
              "url": "https://docs.statsig.com/integrations/mcp/migrate-to-v3",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP automation examples",
              "url": "https://docs.statsig.com/integrations/mcp/automation-examples",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth server metadata",
              "url": "https://api.statsig.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "API key types and personal keys",
              "url": "https://docs.statsig.com/access-management/api-keys",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://docs.statsig.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "full docs corpus, 841 pages, generated 8 October 2026",
              "url": "https://docs.statsig.com/llms-full.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing and plan comparison",
              "url": "https://www.statsig.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "self-service subscription agreement",
              "url": "https://www.statsig.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "enterprise subscription terms and SLA",
              "url": "https://www.statsig.com/enterprise-terms",
              "seen": "2026-10-08"
            },
            {
              "what": "data processing addendum",
              "url": "https://statsig.com/legal/online-dpa",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy notice, where statsig.com/privacy redirects",
              "url": "https://amplitude.com/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processor list, where statsig.com/legal/subprocessors redirects",
              "url": "https://amplitude.com/subprocessor-list",
              "seen": "2026-10-08"
            },
            {
              "what": "security statement",
              "url": "https://www.statsig.com/trust/security",
              "seen": "2026-10-08"
            },
            {
              "what": "AI governance, security and privacy",
              "url": "https://docs.statsig.com/compliance/ai_governance_security_privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "status page incidents",
              "url": "https://status.statsig.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "status page components",
              "url": "https://status.statsig.com/api/v2/components.json",
              "seen": "2026-10-08"
            },
            {
              "what": "product updates",
              "url": "https://www.statsig.com/updates",
              "seen": "2026-10-08"
            },
            {
              "what": "Statsig and Amplitude post of 17 June 2026",
              "url": "https://www.statsig.com/blog/statsig-amplitude-phase-1",
              "seen": "2026-10-08"
            },
            {
              "what": "deprecation notices",
              "url": "https://docs.statsig.com/server/deprecation-notices",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=statsig",
              "seen": "2026-10-08"
            },
            {
              "what": "server SDK repository",
              "url": "https://github.com/statsig-io/statsig-server-core",
              "seen": "2026-10-08"
            },
            {
              "what": "agent skills repository",
              "url": "https://github.com/statsig-io/agent-skills",
              "seen": "2026-10-08"
            },
            {
              "what": "@statsig/statsig-node-core on npm",
              "url": "https://registry.npmjs.org/@statsig/statsig-node-core",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt, 404",
              "url": "https://www.statsig.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for statsig.com",
              "url": "https://rdap.verisign.com/com/v1/domain/statsig.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "The lead named Statsig, Inc. as vendor. The self-service terms, the enterprise terms and the DPA name Amplitude, Inc., and a Statsig blog post says Statsig joined Amplitude on 5 May 2026 with the original team now at OpenAI",
            "Amplitude has its own listing. Statsig is listed apart because it has its own domain, API, MCP server, terms, pricing and status page",
            "provenance.privacy points at amplitude.com/privacy, where statsig.com/privacy redirects. It is the contracting entity's notice and the only one published, but it doesn't name Statsig",
            "The self-service terms name Amplitude, Inc. under an effective date of 4 August 2025, which is before the May 2026 change of owner. We could not tell when the text changed",
            "unchecked: the live `tools/list` response of the MCP server and its tool annotations, which need a key. Tool counts and inputs come from the docs tool reference",
            "unchecked: whether the Console API and MCP server are open to the free Developer plan. The docs state no plan limit, and the pricing page lists API controls under Pro without saying what they are",
            "unchecked: GitHub stars and issue response times. The GitHub API answered with a rate limit",
            "unchecked: the bug bounty programme's scope and where to report. The security page names a programme without a link, and no security.txt exists",
            "The docs and the OpenAPI description give different rate limits for the Console API (about 1,800 mutations per 15 minutes against about 900 requests per 15 minutes)",
            "The 8 July 2026 incident, in which launched gates returned false through the V2 Config Delivery API for about 4 hours 44 minutes, is outside the 90-day window and is not one of the deduction types, so no deduction was made",
            "Capabilities put experiments and flags first because the Console API and MCP tools centre on them. Analytics reads are limited to metric values, dashboard widget results and the Logs Explorer query"
          ]
        },
        "negative": 0,
        "verdict": "Statsig suits agents that manage feature gates and experiments and read their results. Its MCP server has 18 default tools, OAuth, read-only access by project and role, and a confirmation on updates. Errors carry only a status and a message, no idempotency keys were found, and the privacy notice is Amplitude's and doesn't name Statsig.",
        "bestFor": "An agent that creates, updates and cleans up feature gates, dynamic configs and experiments, and reads experiment results and audit history.",
        "strengths": [
          "Hosted MCP server with 18 default tools and a discovery layer that replaced 93 tools on the V1 server",
          "MCP access set per project and per role as no access, read only or read and write, with a confirmation on updates",
          "Public OpenAPI 3.0 spec with 325 operations, plus llms.txt and a Markdown copy of every docs page",
          "Free Developer plan with no card and 2 million events a month, and a public overage price of $0.05 per 1,000 events on Pro",
          "Audit logs kept indefinitely and readable through the API and the `log_read` MCP tool"
        ],
        "weaknesses": [
          "Console API errors carry only `status` and `message`, and the spec documents no 429 response",
          "No idempotency keys were found, and most MCP update tools replace the whole resource",
          "The project Console API key reads and writes everything in a project unless created read-only",
          "The privacy notice is Amplitude's, last updated 31 August 2026, and doesn't name Statsig",
          "The 99.95 per cent SLA needs Enterprise premium support and covers the Console user interface"
        ],
        "agentNotes": [
          "Connect to https://api.statsig.com/v3/mcp. The official MCP registry entry still lists the V1 URL, which has 93 tools",
          "Call `get_context` first to learn the project, your permissions and the review settings",
          "Read the resource before `gate_update`, `experiment_update` or `dynamic_config_update`. They replace the whole resource, so resend every field you want kept",
          "Use `discover_tools` for partial edits, and fetch a fresh `operationHandle` when one expires",
          "On a 429 slow down and back off with jitter. Rejected attempts count towards the quota of about 1,800 mutations per 15 minutes"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 72.3
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 81,
          "payments": 40,
          "reliability": 79,
          "schema": 82,
          "security": 74,
          "transparency": 64
        },
        "provenanceScore": 85
      },
      "connect": {
        "claudeCode": "claude mcp add --transport http statsig https://api.statsig.com/v3/mcp",
        "config": {
          "mcpServers": {
            "statsig": {
              "url": "https://api.statsig.com/v3/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/analytics.experiments",
        "tool": "https://letme.dev/statsig"
      },
      "notable": [
        "The MCP V3 server at https://api.statsig.com/v3/mcp shows 18 default tools and a discovery layer, replacing the 93 tools of V1, which stays supported (https://docs.statsig.com/integrations/mcp/migrate-to-v3)",
        "MCP access is set per project and per role as no access, read only or read and write, since a product update of 12 September 2026 (https://www.statsig.com/updates)",
        "Update tools and `api_destructive` operations need a `confirmation` object with a reason, and project review policies still apply (https://docs.statsig.com/integrations/mcp/tool-reference)",
        "The Console API limits mutations to about 1,800 attempts per 15 minutes per project, with burst protection, and rejected attempts count towards the quota (https://docs.statsig.com/console-api/introduction)",
        "The self-service terms, enterprise terms and DPA name Amplitude, Inc., and Statsig's blog says it joined Amplitude on 5 May 2026 (https://www.statsig.com/blog/statsig-amplitude-phase-1)",
        "The enterprise terms give 99.95 per cent monthly availability of the Console for customers with premium support, with credits of 5 or 10 per cent (https://www.statsig.com/enterprise-terms)",
        "A public docs MCP server with three read-only tools needs no key (https://docs.statsig.com/integrations/mcp/docs-mcp-server)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "The hosted service. The official MCP V3 server at https://api.statsig.com/v3/mcp and the Console API at https://statsigapi.net/console/v1. The flag evaluation and event logging APIs behind the SDKs were not graded"
        },
        {
          "label": "Console API",
          "value": "OpenAPI 3.0 for version 20240601, 209 paths and 325 operations on 8 October 2026. Experiments 85, gates 40, metrics 32, autotunes 24, dynamic configs 24, plus segments, layers, holdouts, dashboards, keys, users and audit logs"
        },
        {
          "label": "MCP server",
          "value": "Streamable HTTP. 18 default tools. `get_context`, `search`, `fetch`, five grouped read tools, three create tools, three update tools, `discover_tools`, and `api_read`, `api_write` and `api_destructive` to run discovered operations. 9 more typed tools with expanded exposure"
        },
        {
          "label": "Credentials",
          "value": "Console API keys, read-only or read and write, with rotate and deactivate endpoints. Personal Console API keys carry the user's role. OAuth for MCP with PKCE (S256), dynamic client registration and authorisation code or device code grants"
        },
        {
          "label": "Rate limits",
          "value": "About 1,800 mutation attempts per 15 minutes per project across all Console API keys, with burst protection and a separate quota for segments. The OpenAPI description gives about 100 per 10 seconds and 900 per 15 minutes"
        },
        {
          "label": "Errors",
          "value": "JSON with `status` and `message`. The spec documents 401 on 156 operations, 404 on 126, 400 on 106 and 403 on 23, and no 429. The docs ask for exponential backoff with jitter on 429"
        },
        {
          "label": "Pagination",
          "value": "`limit` and `page` on 49 list operations with `itemsPerPage`, `totalItems` and `nextPage`. The Logs Explorer query takes `limit` up to 1,000 and an `after` cursor"
        },
        {
          "label": "Free tier",
          "value": "Developer plan, no card. 2 million events and 50,000 session replays a month, unlimited flag and config checks, unlimited seats, 1 year of analytics retention"
        },
        {
          "label": "Paid",
          "value": "Pro $150 a month with 5 million events, then $0.05 per 1,000 events, 100,000 session replays and change reviews. Enterprise by contract with Warehouse Native, SSO, role-based access, EU hosting and the SLA"
        },
        {
          "label": "SDKs",
          "value": "Server core SDKs 0.23.1 (28 September 2026) for Node, Python, Java, Go, Rust, PHP, .NET, Elixir and C++, and @statsig/js-client 3.33.5 (27 August 2026), all ISC. They cover evaluation and logging, not the Console API"
        },
        {
          "label": "Audit",
          "value": "Audit logs for every entity in a project, kept indefinitely, with filters by entity, tag, action and user. Readable at /console/v1/audit_logs and through the `log_read` MCP tool"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II per the security page, which also names a bug bounty programme. HIPAA eligibility on Enterprise with a BAA. No security.txt"
        },
        {
          "label": "Status",
          "value": "https://status.statsig.com on Statuspage, 14 components, among them Console, Console API, Config Delivery API and Log Event API"
        },
        {
          "label": "Data",
          "value": "Amplitude's sub-processor list of 13 May 2026 names Google for US hosting of Statsig-branded services, plus MongoDB and Microsoft Azure. EU hosting is an Enterprise option. Warehouse Native runs analysis in the customer's warehouse"
        },
        {
          "label": "Ownership",
          "value": "The terms and DPA name Amplitude, Inc. Statsig's blog says it joined Amplitude on 5 May 2026 and that the original team is now at OpenAI"
        }
      ],
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 150,
          "note": "5 million events and 100,000 session replays included"
        },
        {
          "item": "Metered event",
          "unit": "tx",
          "usd": 0.00005,
          "note": "Pro plan, above 5 million a month"
        }
      ],
      "provenance": {
        "legalEntity": "Amplitude, Inc.",
        "domain": "statsig.com",
        "domainRegistered": "1998-12-29",
        "endpointOnVendorDomain": true,
        "terms": "https://www.statsig.com/terms",
        "privacy": "https://amplitude.com/privacy",
        "statusPage": "https://status.statsig.com",
        "changelog": "https://www.statsig.com/updates",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The self-service subscription agreement at statsig.com/terms, effective 4 August 2025, names Amplitude, Inc. as the party called Statsig. The enterprise terms (effective 18 February 2026) and the DPA do the same.",
          "statsig.com/privacy redirects to amplitude.com/privacy, a notice last updated 31 August 2026 that covers Amplitude, Inc. and its affiliates and doesn't name Statsig. It says it does not apply to end-user data that customers send to the product.",
          "statsig.com/legal/subprocessors redirects to amplitude.com/subprocessor-list, last updated 13 May 2026, which marks the providers used for Statsig-branded services.",
          "The MCP server answers at api.statsig.com. The Console API answers at statsigapi.net, a second domain the vendor's docs name.",
          "www.statsig.com/.well-known/security.txt returns 404.",
          "RDAP for statsig.com gives a registration date of 1998-12-29."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Amplitude, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "statsig.com, registered 1998-12-29 (27 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.statsig.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.statsig.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.statsig.com/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-08-04",
            "words": 3434,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective August 4, 2025",
                "says": "Last updated 2025-08-04"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This SSA will be governed by the laws of the State of Washington, U.S.A.",
                "says": "The law of the State of Washington"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "STATSIG’S TOTAL LIABILITY, WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, WILL NOT EXCEED, IN THE AGGREGATE, $1,000.",
                "says": "Capped at $1,000"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Statsig may suspend, change, or discontinue any part of the Services at any time at its sole discretion."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "NO SEPARATE NOTICE WILL BE REQUIRED, AND CUSTOMER’S CONTINUED USE OF THE SERVICES AFTER THE UPDATED VERSION OF THE SSA IS POSTED WILL CONSTITUTE CUSTOMER’S ACCEPTANCE OF SUCH UPDATED TERMS.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "IF CUSTOMER DOES NOT AGREE TO ALL OF THE TERMS OF THIS SSA, CUSTOMER SHALL NOT SIGN UP FOR AN ACCOUNT OR ACCESS THE SERVICES."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use or access the Services to develop a product or service that is competitive with the Services or use or access the Services to engage in competitive analysis or benchmarking",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "NO SEPARATE NOTICE WILL BE REQUIRED, AND CUSTOMER’S CONTINUED USE OF THE SERVICES AFTER THE UPDATED VERSION OF THE SSA IS POSTED WILL CONSTITUTE CUSTOMER’S ACCEPTANCE OF SUCH UPDATED TERMS.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Statsig may suspend, change, or discontinue any part of the Services at any time at its sole discretion."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "If the parties are unable to resolve the dispute, then either party may initiate binding arbitration in King County, Washington as the sole means of resolving the dispute."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Using the Services gives Statsig the right to use the customer's name and logo in marketing, and the customer agrees to take part in a case study that may be published.",
                "quote": "By using the Services, Customer gives Statsig the right to use Customer’s name and logo in any Statsig marketing materials and agrees to participate in a case study that may be published on Statsig’s website and/or in any marketing materials."
              },
              {
                "date": "2026-10-08",
                "text": "Statsig's total liability under the self service terms is capped at 1,000 US dollars in aggregate.",
                "quote": "STATSIG’S TOTAL LIABILITY, WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, WILL NOT EXCEED, IN THE AGGREGATE, $1,000."
              },
              {
                "date": "2026-10-08",
                "text": "The agreement renews automatically for one-month terms, and Statsig may raise fees for a renewal term on 30 days' written notice.",
                "quote": "Statsig may increase the Fees for any renewal term by providing Customer with at least 30 days’ prior written notice."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://amplitude.com/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-08-31",
            "words": 7895,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: August 31, 2026",
                "says": "Last updated 2026-08-31"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "Personal Data We Collect And How We Use The Personal Data"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Persistent cookies are stored by a web browser and remain valid until a set expiration date."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "You may choose to participate in an Amplitude program that allows you to pay fees with a credit or debit card, in which case you may provide your credit card or other payment details information directly to our third party payment processor."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not sell your Personal Data or use or disclose sensitive personal information for purposes other than those permitted by the CCPA.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If you do not want to receive communications from us, you can unsubscribe from marketing communications or email us with your preferences at privacy@amplitude.com or ccpa@amplitude.com."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "Customers can opt out of the use of this software during their use of the Product by contacting us at privacy@amplitude.com.",
                "says": "privacy@amplitude.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "These safeguards may include using the European Commission-approved standard contractual clauses to protect the transfer of your Personal Data to Amplitude’s corporate affiliates or service providers, if required by applicable law.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We may share Personal Data with third party ad partners, such as through cookies or by providing lists of email addresses for potential customers so we can reach them across the web with relevant ads."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The notice does not apply to Customer End User Data that customers submit to the product.",
                "quote": "For clarity, this Privacy Notice does not apply to Customer End User Data (as defined below) submitted by our customers to the Product."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/statsig.json",
      "live": {
        "slug": "statsig",
        "probe": {
          "target": "https://api.statsig.com/v3/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:53:03.084375449Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 38,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 42,
          "p95ms24h": 78,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.statsig.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:51:03.938200412Z"
        },
        "pages": [
          {
            "url": "https://www.statsig.com/updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:46.247718302Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3bba7a8e7236"
          },
          {
            "url": "https://www.statsig.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:41.954344318Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d0e8593f7c0e"
          },
          {
            "url": "https://www.statsig.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:44.722171717Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "dc465dc5a41d"
          }
        ],
        "updatedAt": "2026-10-08T19:53:03.084375449Z"
      }
    },
    "verify": {
      "accepts": "a page on statsig.com or one of its subdomains, or the README of github.com/statsig-io/statsig-server-core",
      "badgeUrl": "https://www.anchorterminal.com/badges/statsig.svg",
      "body": {
        "slug": "statsig",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/statsig",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/statsig\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/statsig.svg\" alt=\"Statsig on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Statsig on Anchor Terminal](https://www.anchorterminal.com/badges/statsig.svg)](https://www.anchorterminal.com/tools/statsig)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/statsig\"\u003eStatsig on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/statsig",
    "json": "https://www.anchorterminal.com/tools/statsig.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/statsig.md",
    "slim": "https://www.anchorterminal.com/tools/statsig.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 72.3/100 · rank #94 of 722 · #1 in Product analytics \u0026 experimentation · agent-ready · confidence medium**\n\n\n## Assessment\n\nStatsig suits agents that manage feature gates and experiments and read their results. Its MCP server has 18 default tools, OAuth, read-only access by project and role, and a confirmation on updates. Errors carry only a status and a message, no idempotency keys were found, and the privacy notice is Amplitude's and doesn't name Statsig.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Amplitude, Inc. (https://www.statsig.com) |\n| Kind | HTTP API |\n| Category | Product analytics \u0026 experimentation (https://www.anchorterminal.com/categories/product-analytics) |\n| Transport | HTTP, Streamable HTTP |\n| Endpoint | `https://api.statsig.com/v3/mcp` |\n| Auth | OAuth or key · Self-serve. The Console API takes a Console API key in the `STATSIG-API-KEY` header, created in project settings as read-only or read and write. The MCP server uses OAuth with PKCE and dynamic client registration, which issues a personal Console API key carrying the user's role, or takes a Console key in the `statsig-api-key` header. OAuth needs the organisation owner to allow personal keys for the role. Flag evaluation and event logging take a client or server SDK key. |\n| Pricing | Freemium ($150 / mo) · Free Developer plan with no card, covering 2 million events and 50,000 session replays a month. Pro is $150 a month with 5 million events, then $0.05 per 1,000 events. Enterprise is by contract. Flag and config checks are unlimited on every plan, and API and MCP calls are not billed. An agent can start on the free plan without a contract (https://www.statsig.com/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs corpus, the OpenAPI spec or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary hosted service under Statsig's self-service or enterprise terms. The SDKs and the agent skills repository on GitHub are ISC |\n| Tools exposed | 18 |\n| Packages | npm: `@statsig/statsig-node-core`; npm: `@statsig/js-client`; pypi: `statsig-python-core`; npm: `@statsig/siggy` |\n| MCP registry name | `com.statsig/statsig-mcp-server` |\n| Source | https://github.com/statsig-io/statsig-server-core |\n| Docs | https://docs.statsig.com/console-api/introduction |\n| llms.txt | https://docs.statsig.com/llms.txt |\n| Last release | 2026-09-28 |\n| npm downloads / week | 4,157,066 |\n| PyPI downloads / week | 893,619 |\n| Surface graded | The hosted service. The official MCP V3 server at https://api.statsig.com/v3/mcp and the Console API at https://statsigapi.net/console/v1. The flag evaluation and event logging APIs behind the SDKs were not graded |\n| Console API | OpenAPI 3.0 for version 20240601, 209 paths and 325 operations on 8 October 2026. Experiments 85, gates 40, metrics 32, autotunes 24, dynamic configs 24, plus segments, layers, holdouts, dashboards, keys, users and audit logs |\n| MCP server | Streamable HTTP. 18 default tools. `get_context`, `search`, `fetch`, five grouped read tools, three create tools, three update tools, `discover_tools`, and `api_read`, `api_write` and `api_destructive` to run discovered operations. 9 more typed tools with expanded exposure |\n| Credentials | Console API keys, read-only or read and write, with rotate and deactivate endpoints. Personal Console API keys carry the user's role. OAuth for MCP with PKCE (S256), dynamic client registration and authorisation code or device code grants |\n| Rate limits | About 1,800 mutation attempts per 15 minutes per project across all Console API keys, with burst protection and a separate quota for segments. The OpenAPI description gives about 100 per 10 seconds and 900 per 15 minutes |\n| Errors | JSON with `status` and `message`. The spec documents 401 on 156 operations, 404 on 126, 400 on 106 and 403 on 23, and no 429. The docs ask for exponential backoff with jitter on 429 |\n| Pagination | `limit` and `page` on 49 list operations with `itemsPerPage`, `totalItems` and `nextPage`. The Logs Explorer query takes `limit` up to 1,000 and an `after` cursor |\n| Free tier | Developer plan, no card. 2 million events and 50,000 session replays a month, unlimited flag and config checks, unlimited seats, 1 year of analytics retention |\n| Paid | Pro $150 a month with 5 million events, then $0.05 per 1,000 events, 100,000 session replays and change reviews. Enterprise by contract with Warehouse Native, SSO, role-based access, EU hosting and the SLA |\n| SDKs | Server core SDKs 0.23.1 (28 September 2026) for Node, Python, Java, Go, Rust, PHP, .NET, Elixir and C++, and @statsig/js-client 3.33.5 (27 August 2026), all ISC. They cover evaluation and logging, not the Console API |\n| Audit | Audit logs for every entity in a project, kept indefinitely, with filters by entity, tag, action and user. Readable at /console/v1/audit_logs and through the `log_read` MCP tool |\n| Certifications | SOC 2 Type II per the security page, which also names a bug bounty programme. HIPAA eligibility on Enterprise with a BAA. No security.txt |\n| Status | https://status.statsig.com on Statuspage, 14 components, among them Console, Console API, Config Delivery API and Log Event API |\n| Data | Amplitude's sub-processor list of 13 May 2026 names Google for US hosting of Statsig-branded services, plus MongoDB and Microsoft Azure. EU hosting is an Enterprise option. Warehouse Native runs analysis in the customer's warehouse |\n| Ownership | The terms and DPA name Amplitude, Inc. Statsig's blog says it joined Amplitude on 5 May 2026 and that the original team is now at OpenAI |\n| Capabilities | analytics.experiments, analytics.flags, analytics.query, analytics.events |\n| Tags | official, hosted, mcp, oauth, openapi, llms-txt, free-tier, no-card, status-page, soc2, eu-region |\n| JSON | https://www.anchorterminal.com/api/v1/tools/statsig.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 79 | 15.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 82 | 13.3 |\n| Agent ergonomics | 13% | 16.2 | 71 | 11.5 |\n| Security \u0026 auth | 14% | 17.5 | 74 | 12.9 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 81 | 7.1 |\n| Transparency \u0026 trust (editorial 64, provenance 85) | 7% | 8.8 | 75 | 6.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **72.3 → BB** |\n\n### Why each score\n\n- Reliability 79: Graded on the hosted service with the hosted lines. Statuspage at status.statsig.com with 14 components, among them Console API, Config Delivery API and Log Event API (20). Three incidents between 10 July and 8 October 2026, all delays to Warehouse Native exports and results, marked minor or none (20 of 30). A major incident on 8 July 2026, when launched gates returned false through the V2 Config Delivery API for about 4 hours 44 minutes, falls two days outside the window. The docs give about 1,800 mutation attempts per 15 minutes per project, while the OpenAPI description gives about 100 per 10 seconds and 900 per 15 minutes, and no number was found for reads (12 of 15). The docs ask for exponential backoff with jitter on 429. No `Retry-After` header and no idempotency keys were found (10 of 15). The enterprise terms give 99.95 per cent monthly availability with credits, for customers with premium support, measured on the Console user interface (7 of 10). The Console API is versioned and the MCP V3 docs carry no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 82: Public OpenAPI 3.0 spec for Console API version 20240601 with 209 paths and 325 operations, and typed MCP tools per the tool reference (25). llms.txt, llms-full.txt, a Markdown copy of each page and a public docs MCP server (10). Every operation has a summary but only 29 of 325 have a description. The MCP tool reference states each tool's purpose and when to ask the user first (11 of 20). 1,164 enums across 188 schemas, with required fields marked (12 of 15). Examples on most responses. The spec documents 401 on 156 operations, 404 on 126 and 400 on 106, and no 429 (11 of 15). A dated API version sent in the `STATSIG-API-VERSION` header with a promise not to break a version, and a dated product updates page. No changelog for the API alone was found (13 of 15).\n- Agent ergonomics 71: The MCP V3 server shows 18 default tools, which is 15 on the checklist. Add back 8 for the discovery layer that reaches other operations on demand, `query_fields` on experiment reads and read-only access (23 of 25). `limit` and `page` on 49 list operations with pagination metadata, a cursor on the Logs Explorer query, and filters by tag, status, creator and date (17 of 20). Errors are a `status` and a `message` with no machine code, and MCP results set `isError` (11 of 20). No idempotency keys were found. Updates and `api_destructive` calls need a `confirmation` object, and operations are split into read, write and destructive lanes. We could not read the live tool annotations (10 of 20). The SDKs cover flag evaluation and event logging in many languages, not the Console API, and the `siggy` CLI on npm is version 0.0.4 from September 2024 (10 of 15).\n- Security \u0026 auth 74: OAuth for the MCP server with PKCE, dynamic client registration and a device code grant, issuing personal Console API keys that carry the user's role. Console keys can be created read-only or read and write, and rotated or deactivated through the API. The OAuth metadata lists no scopes, and a project Console key reaches every Console API endpoint (25 of 30). MCP scope is set per project and per role as no access, read only or read and write. Updates and destructive operations need a confirmation, and project review policies still apply (19 of 20). No guidance on prompt injection was found, though tools return names, descriptions and log data that people wrote. The docs tell users to review each change before the agent confirms (4 of 15). Audit logs are kept indefinitely with an API, and personal keys attribute changes to a user (14 of 15). SOC 2 Type II and a bug bounty programme are stated on the security page, with no public programme link and no security.txt (12 of 20).\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). Prices are public without a login. Pro is $150 a month with 5 million events, then $0.05 per 1,000 events (20). The Developer plan is free with no card and 2 million events a month (20). A person signs up in a browser, then creates a key or approves OAuth (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 81: The newest product update is dated 12 September 2026 and the server SDKs released 0.23.1 on 28 September 2026 (30). Ten or more dated product updates since 10 July 2026 (20). Closed service with a public updates page and a Slack community. We did not read how quickly questions are answered (10 of 15). `com.statsig/statsig-mcp-server` is in the official MCP registry under the vendor's domain, though the entry dates from 19 September 2025 and lists the V1 URL (13 of 15). The server SDK repository has 25 CI workflow files and 124 commits since 10 July 2026, while the `siggy` CLI has not been published since September 2024 (8 of 10).\n- Transparency \u0026 trust 75: Closed hosted service under a published self-service agreement and enterprise terms. The SDKs are open source under ISC (17 of 30). The terms, DPA and AI governance page mostly agree. The DPA names Amplitude, Inc. as processor and keeps data as long as necessary, the pricing page gives 1 year of analytics retention on the free plan, and the docs say customer data is not used to build AI models without written consent. The privacy notice is Amplitude's and doesn't name Statsig, and the self-service terms name Amplitude, Inc. under an effective date of 4 August 2025, before Statsig joined Amplitude on 5 May 2026 (18 of 30). Each Console API version is promised not to break, a deprecation notices page gives dates, and MCP V1 stays supported. No notice period is stated (12 of 20). Amplitude's sub-processor list, updated 13 May 2026, gives locations and marks the providers used for Statsig-branded services. EU hosting is an Enterprise option (17 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/statsig.md (JSON https://www.anchorterminal.com/fixes/statsig.json)\n\n### What we couldn't check\n\n- The lead named Statsig, Inc. as vendor. The self-service terms, the enterprise terms and the DPA name Amplitude, Inc., and a Statsig blog post says Statsig joined Amplitude on 5 May 2026 with the original team now at OpenAI\n- Amplitude has its own listing. Statsig is listed apart because it has its own domain, API, MCP server, terms, pricing and status page\n- provenance.privacy points at amplitude.com/privacy, where statsig.com/privacy redirects. It is the contracting entity's notice and the only one published, but it doesn't name Statsig\n- The self-service terms name Amplitude, Inc. under an effective date of 4 August 2025, which is before the May 2026 change of owner. We could not tell when the text changed\n- unchecked: the live `tools/list` response of the MCP server and its tool annotations, which need a key. Tool counts and inputs come from the docs tool reference\n- unchecked: whether the Console API and MCP server are open to the free Developer plan. The docs state no plan limit, and the pricing page lists API controls under Pro without saying what they are\n- unchecked: GitHub stars and issue response times. The GitHub API answered with a rate limit\n- unchecked: the bug bounty programme's scope and where to report. The security page names a programme without a link, and no security.txt exists\n- The docs and the OpenAPI description give different rate limits for the Console API (about 1,800 mutations per 15 minutes against about 900 requests per 15 minutes)\n- The 8 July 2026 incident, in which launched gates returned false through the V2 Config Delivery API for about 4 hours 44 minutes, is outside the 90-day window and is not one of the deduction types, so no deduction was made\n- Capabilities put experiments and flags first because the Console API and MCP tools centre on them. Analytics reads are limited to metric values, dashboard widget results and the Logs Explorer query\n\n### Sources\n\n- Console API overview, auth, rate limits and versioning: \u003chttps://docs.statsig.com/console-api/introduction\u003e (seen 2026-10-08)\n- OpenAPI spec for Console API version 20240601: \u003chttps://api.statsig.com/openapi/20240601.json\u003e (seen 2026-10-08)\n- MCP overview: \u003chttps://docs.statsig.com/integrations/mcp/overview\u003e (seen 2026-10-08)\n- MCP V3 tool reference: \u003chttps://docs.statsig.com/integrations/mcp/tool-reference\u003e (seen 2026-10-08)\n- MCP manual setup, OAuth and API key: \u003chttps://docs.statsig.com/integrations/mcp/manual-setup\u003e (seen 2026-10-08)\n- MCP with Claude Code: \u003chttps://docs.statsig.com/integrations/mcp/claude-code\u003e (seen 2026-10-08)\n- MCP V1 to V3 migration: \u003chttps://docs.statsig.com/integrations/mcp/migrate-to-v3\u003e (seen 2026-10-08)\n- MCP automation examples: \u003chttps://docs.statsig.com/integrations/mcp/automation-examples\u003e (seen 2026-10-08)\n- OAuth server metadata: \u003chttps://api.statsig.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- API key types and personal keys: \u003chttps://docs.statsig.com/access-management/api-keys\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://docs.statsig.com/llms.txt\u003e (seen 2026-10-08)\n- full docs corpus, 841 pages, generated 8 October 2026: \u003chttps://docs.statsig.com/llms-full.txt\u003e (seen 2026-10-08)\n- pricing and plan comparison: \u003chttps://www.statsig.com/pricing\u003e (seen 2026-10-08)\n- self-service subscription agreement: \u003chttps://www.statsig.com/terms\u003e (seen 2026-10-08)\n- enterprise subscription terms and SLA: \u003chttps://www.statsig.com/enterprise-terms\u003e (seen 2026-10-08)\n- data processing addendum: \u003chttps://statsig.com/legal/online-dpa\u003e (seen 2026-10-08)\n- privacy notice, where statsig.com/privacy redirects: \u003chttps://amplitude.com/privacy\u003e (seen 2026-10-08)\n- sub-processor list, where statsig.com/legal/subprocessors redirects: \u003chttps://amplitude.com/subprocessor-list\u003e (seen 2026-10-08)\n- security statement: \u003chttps://www.statsig.com/trust/security\u003e (seen 2026-10-08)\n- AI governance, security and privacy: \u003chttps://docs.statsig.com/compliance/ai_governance_security_privacy\u003e (seen 2026-10-08)\n- status page incidents: \u003chttps://status.statsig.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- status page components: \u003chttps://status.statsig.com/api/v2/components.json\u003e (seen 2026-10-08)\n- product updates: \u003chttps://www.statsig.com/updates\u003e (seen 2026-10-08)\n- Statsig and Amplitude post of 17 June 2026: \u003chttps://www.statsig.com/blog/statsig-amplitude-phase-1\u003e (seen 2026-10-08)\n- deprecation notices: \u003chttps://docs.statsig.com/server/deprecation-notices\u003e (seen 2026-10-08)\n- official MCP registry: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=statsig\u003e (seen 2026-10-08)\n- server SDK repository: \u003chttps://github.com/statsig-io/statsig-server-core\u003e (seen 2026-10-08)\n- agent skills repository: \u003chttps://github.com/statsig-io/agent-skills\u003e (seen 2026-10-08)\n- @statsig/statsig-node-core on npm: \u003chttps://registry.npmjs.org/@statsig/statsig-node-core\u003e (seen 2026-10-08)\n- security.txt, 404: \u003chttps://www.statsig.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- RDAP for statsig.com: \u003chttps://rdap.verisign.com/com/v1/domain/statsig.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 85/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Amplitude, Inc. | 20/20 |\n| Domain age | statsig.com, registered 1998-12-29 (27 years) | 15/15 |\n| Endpoint on the vendor's domain | api.statsig.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.statsig.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe self-service subscription agreement at statsig.com/terms, effective 4 August 2025, names Amplitude, Inc. as the party called Statsig. The enterprise terms (effective 18 February 2026) and the DPA do the same.\n\nstatsig.com/privacy redirects to amplitude.com/privacy, a notice last updated 31 August 2026 that covers Amplitude, Inc. and its affiliates and doesn't name Statsig. It says it does not apply to end-user data that customers send to the product.\n\nstatsig.com/legal/subprocessors redirects to amplitude.com/subprocessor-list, last updated 13 May 2026, which marks the providers used for Statsig-branded services.\n\nThe MCP server answers at api.statsig.com. The Console API answers at statsigapi.net, a second domain the vendor's docs name.\n\nwww.statsig.com/.well-known/security.txt returns 404.\n\nRDAP for statsig.com gives a registration date of 1998-12-29.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.statsig.com/terms), read 2026-10-08, dated 2025-08-04, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"use or access the Services to develop a product or service that is competitive with the Services or use or access the Services to engage in competitive analysis or benchmarking\"\n- To know. Says the terms or the service can change without notice (costs points). \"NO SEPARATE NOTICE WILL BE REQUIRED, AND CUSTOMER’S CONTINUED USE OF THE SERVICES AFTER THE UPDATED VERSION OF THE SSA IS POSTED WILL CONSTITUTE CUSTOMER’S ACCEPTANCE OF SUCH UPDATED TERMS.\"\n- To know. Says access can be ended without notice or for any reason. \"Statsig may suspend, change, or discontinue any part of the Services at any time at its sole discretion.\"\n- To know. Requires arbitration or waives class actions. \"If the parties are unable to resolve the dispute, then either party may initiate binding arbitration in King County, Washington as the sole means of resolving the dispute.\"\n- Gives the date it was last updated. Last updated 2025-08-04.\n- Names the governing law or courts. The law of the State of Washington.\n- States a limit on its liability. Capped at $1,000.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Using the Services gives Statsig the right to use the customer's name and logo in marketing, and the customer agrees to take part in a case study that may be published. \"By using the Services, Customer gives Statsig the right to use Customer’s name and logo in any Statsig marketing materials and agrees to participate in a case study that may be published on Statsig’s website and/or in any marketing materials.\"\n- Also in the text (2026-10-08). Statsig's total liability under the self service terms is capped at 1,000 US dollars in aggregate. \"STATSIG’S TOTAL LIABILITY, WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, WILL NOT EXCEED, IN THE AGGREGATE, $1,000.\"\n- Also in the text (2026-10-08). The agreement renews automatically for one-month terms, and Statsig may raise fees for a renewal term on 30 days' written notice. \"Statsig may increase the Fees for any renewal term by providing Customer with at least 30 days’ prior written notice.\"\n\n**Privacy policy** (https://amplitude.com/privacy), read 2026-10-08, dated 2026-08-31, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"We may share Personal Data with third party ad partners, such as through cookies or by providing lists of email addresses for potential customers so we can reach them across the web with relevant ads.\"\n- Gives the date it was last updated. Last updated 2026-08-31.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@amplitude.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). The notice does not apply to Customer End User Data that customers submit to the product. \"For clarity, this Privacy Notice does not apply to Customer End User Data (as defined below) submitted by our customers to the Product.\"\n\n## Live (updated 2026-10-08 19:53 UTC)\n\n- Right now: up, HTTP 401, 38 ms, checked 2026-10-08 19:53 UTC (get on `https://api.statsig.com/v3/mcp`, asks for auth)\n- Uptime 24h 100.0% (27 probes) · 30 days 100.0% (27 probes) · p50 42 ms · p95 78 ms\n- Vendor status page: none, All Systems Operational\n- Watching changelog \u003chttps://www.statsig.com/updates\u003e\n- Watching pricing \u003chttps://www.statsig.com/pricing\u003e\n- Watching terms \u003chttps://www.statsig.com/terms\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/statsig.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Pro plan | $150 | per month (plan) | 5 million events and 100,000 session replays included |\n| Metered event | $0.0001 | per transaction | Pro plan, above 5 million a month |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Hosted MCP server with 18 default tools and a discovery layer that replaced 93 tools on the V1 server\n- MCP access set per project and per role as no access, read only or read and write, with a confirmation on updates\n- Public OpenAPI 3.0 spec with 325 operations, plus llms.txt and a Markdown copy of every docs page\n- Free Developer plan with no card and 2 million events a month, and a public overage price of $0.05 per 1,000 events on Pro\n- Audit logs kept indefinitely and readable through the API and the `log_read` MCP tool\n\n## Weaknesses\n\n- Console API errors carry only `status` and `message`, and the spec documents no 429 response\n- No idempotency keys were found, and most MCP update tools replace the whole resource\n- The project Console API key reads and writes everything in a project unless created read-only\n- The privacy notice is Amplitude's, last updated 31 August 2026, and doesn't name Statsig\n- The 99.95 per cent SLA needs Enterprise premium support and covers the Console user interface\n\n## Before you call it (notes for agents)\n\n1. Connect to https://api.statsig.com/v3/mcp. The official MCP registry entry still lists the V1 URL, which has 93 tools\n2. Call `get_context` first to learn the project, your permissions and the review settings\n3. Read the resource before `gate_update`, `experiment_update` or `dynamic_config_update`. They replace the whole resource, so resend every field you want kept\n4. Use `discover_tools` for partial edits, and fetch a fresh `operationHandle` when one expires\n5. On a 429 slow down and back off with jitter. Rejected attempts count towards the quota of about 1,800 mutations per 15 minutes\n\n## Connect\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http statsig https://api.statsig.com/v3/mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"statsig\": {\n      \"url\": \"https://api.statsig.com/v3/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/statsig (letme picks it for analytics.experiments, the top-graded tool for the job, letme picks it for analytics.flags, the top-graded tool for the job, letme picks it for analytics.query, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| GrowthBook | BB | 70.1 | 142 | analytics.experiments, analytics.flags, analytics.query, analytics.events | no | https://www.anchorterminal.com/tools/growthbook.md |\n| PostHog | B | 68.4 | 181 | analytics.query, analytics.events, analytics.experiments, analytics.flags | no | https://www.anchorterminal.com/tools/posthog.md |\n| Amplitude | B | 66.2 | 243 | analytics.query, analytics.experiments, analytics.flags, analytics.events | no | https://www.anchorterminal.com/tools/amplitude.md |\n| Mixpanel | B | 62 | 351 | analytics.query, analytics.events, analytics.experiments, analytics.flags | no | https://www.anchorterminal.com/tools/mixpanel.md |\n| Optimizely Experimentation | B | 62.6 | 330 | analytics.experiments, analytics.flags, analytics.query | no | https://www.anchorterminal.com/tools/optimizely.md |\n| LaunchDarkly | B | 69.2 | 165 | analytics.flags, analytics.experiments | no | https://www.anchorterminal.com/tools/launchdarkly.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The MCP V3 server at https://api.statsig.com/v3/mcp shows 18 default tools and a discovery layer, replacing the 93 tools of V1, which stays supported (source: \u003chttps://docs.statsig.com/integrations/mcp/migrate-to-v3\u003e)\n- MCP access is set per project and per role as no access, read only or read and write, since a product update of 12 September 2026 (source: \u003chttps://www.statsig.com/updates\u003e)\n- Update tools and `api_destructive` operations need a `confirmation` object with a reason, and project review policies still apply (source: \u003chttps://docs.statsig.com/integrations/mcp/tool-reference\u003e)\n- The Console API limits mutations to about 1,800 attempts per 15 minutes per project, with burst protection, and rejected attempts count towards the quota (source: \u003chttps://docs.statsig.com/console-api/introduction\u003e)\n- The self-service terms, enterprise terms and DPA name Amplitude, Inc., and Statsig's blog says it joined Amplitude on 5 May 2026 (source: \u003chttps://www.statsig.com/blog/statsig-amplitude-phase-1\u003e)\n- The enterprise terms give 99.95 per cent monthly availability of the Console for customers with premium support, with credits of 5 or 10 per cent (source: \u003chttps://www.statsig.com/enterprise-terms\u003e)\n- A public docs MCP server with three read-only tools needs no key (source: \u003chttps://docs.statsig.com/integrations/mcp/docs-mcp-server\u003e)\n\n## Compare\n\n- [Amplitude vs Statsig](https://www.anchorterminal.com/compare/amplitude-vs-statsig.md): B 66.2 vs BB 72.3\n- [Fullstory vs Statsig](https://www.anchorterminal.com/compare/fullstory-vs-statsig.md): B 62.6 vs BB 72.3\n- [Mixpanel vs Statsig](https://www.anchorterminal.com/compare/mixpanel-vs-statsig.md): B 62 vs BB 72.3\n- [Pendo vs Statsig](https://www.anchorterminal.com/compare/pendo-vs-statsig.md): D 48.2 vs BB 72.3\n- [PostHog vs Statsig](https://www.anchorterminal.com/compare/posthog-vs-statsig.md): B 68.4 vs BB 72.3\n- [Heap vs Statsig](https://www.anchorterminal.com/compare/heap-vs-statsig.md): D 53 vs BB 72.3\n- [GrowthBook vs Statsig](https://www.anchorterminal.com/compare/growthbook-vs-statsig.md): BB 70.1 vs BB 72.3\n- [Optimizely Experimentation vs Statsig](https://www.anchorterminal.com/compare/optimizely-vs-statsig.md): B 62.6 vs BB 72.3\n- [LaunchDarkly vs Statsig](https://www.anchorterminal.com/compare/launchdarkly-vs-statsig.md): B 69.2 vs BB 72.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on statsig.com or one of its subdomains, or the README of github.com/statsig-io/statsig-server-core. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"statsig\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/statsig\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/statsig.svg\" alt=\"Statsig on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Statsig on Anchor Terminal](https://www.anchorterminal.com/badges/statsig.svg)](https://www.anchorterminal.com/tools/statsig)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/statsig\"\u003eStatsig on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Statsig is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/statsig-dark.png\n- Light: https://www.anchorterminal.com/assets/share/statsig-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Product analytics \u0026 experimentation",
        "url": "https://www.anchorterminal.com/categories/product-analytics"
      },
      {
        "name": "Statsig",
        "url": ""
      }
    ],
    "description": "Statsig is a hosted platform for feature flags, experiments and product analytics, run by Amplitude, Inc. since May 2026. Agents reach it through the Console API, which has a public OpenAPI spec, and an official hosted MCP server.",
    "facts": [
      "rank #94 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Statsig",
    "image": "https://www.anchorterminal.com/assets/og/tools-statsig.png",
    "path": "/tools/statsig",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Statsig review for AI agents, grade BB (72.3/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/statsig"
  },
  "tokens": {
    "markdown": 8350,
    "slim": 2030
  },
  "version": 1
}
