# Statsig (slim) > Statsig is a hosted platform for feature flags, experiments and product analytics, run by Amplitude, Inc. since May 2026. Agents reach it through the Console API, which has a public OpenAPI spec, and an official hosted MCP server. - Full: https://www.anchorterminal.com/tools/statsig.md (~8,350 tokens) · this version ~2,030 tokens · JSON https://www.anchorterminal.com/tools/statsig.json · canonical https://www.anchorterminal.com/tools/statsig - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 72.3/100 · rank #94 of 722 · #1 in Product analytics & experimentation · agent-ready · confidence medium** Assessment: Statsig suits agents that manage feature gates and experiments and read their results. Its MCP server has 18 default tools, OAuth, read-only access by project and role, and a confirmation on updates. Errors carry only a status and a message, no idempotency keys were found, and the privacy notice is Amplitude's and doesn't name Statsig. ## Facts - Kind: HTTP API · vendor: Amplitude, Inc. · category: Product analytics & experimentation · legal entity: Amplitude, Inc. · provenance 85/100 - Endpoint: `https://api.statsig.com/v3/mcp` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary hosted service under Statsig's self-service or enterprise terms. The SDKs and the agent skills repository on GitHub are ISC - Probe metrics: not measured yet (probes haven't run) - Surface graded: The hosted service. The official MCP V3 server at https://api.statsig.com/v3/mcp and the Console API at https://statsigapi.net/console/v1. The flag evaluation and event logging APIs behind the SDKs were not graded - Console API: OpenAPI 3.0 for version 20240601, 209 paths and 325 operations on 8 October 2026. Experiments 85, gates 40, metrics 32, autotunes 24, dynamic configs 24, plus segments, layers, holdouts, dashboards, keys, users and audit logs - MCP server: Streamable HTTP. 18 default tools. `get_context`, `search`, `fetch`, five grouped read tools, three create tools, three update tools, `discover_tools`, and `api_read`, `api_write` and `api_destructive` to run discovered operations. 9 more typed tools with expanded exposure - Credentials: Console API keys, read-only or read and write, with rotate and deactivate endpoints. Personal Console API keys carry the user's role. OAuth for MCP with PKCE (S256), dynamic client registration and authorisation code or device code grants - Rate limits: About 1,800 mutation attempts per 15 minutes per project across all Console API keys, with burst protection and a separate quota for segments. The OpenAPI description gives about 100 per 10 seconds and 900 per 15 minutes - Errors: JSON with `status` and `message`. The spec documents 401 on 156 operations, 404 on 126, 400 on 106 and 403 on 23, and no 429. The docs ask for exponential backoff with jitter on 429 - Pagination: `limit` and `page` on 49 list operations with `itemsPerPage`, `totalItems` and `nextPage`. The Logs Explorer query takes `limit` up to 1,000 and an `after` cursor - Free tier: Developer plan, no card. 2 million events and 50,000 session replays a month, unlimited flag and config checks, unlimited seats, 1 year of analytics retention - Paid: Pro $150 a month with 5 million events, then $0.05 per 1,000 events, 100,000 session replays and change reviews. Enterprise by contract with Warehouse Native, SSO, role-based access, EU hosting and the SLA - SDKs: Server core SDKs 0.23.1 (28 September 2026) for Node, Python, Java, Go, Rust, PHP, .NET, Elixir and C++, and @statsig/js-client 3.33.5 (27 August 2026), all ISC. They cover evaluation and logging, not the Console API - Audit: Audit logs for every entity in a project, kept indefinitely, with filters by entity, tag, action and user. Readable at /console/v1/audit_logs and through the `log_read` MCP tool - Certifications: SOC 2 Type II per the security page, which also names a bug bounty programme. HIPAA eligibility on Enterprise with a BAA. No security.txt - Status: https://status.statsig.com on Statuspage, 14 components, among them Console, Console API, Config Delivery API and Log Event API - Data: Amplitude's sub-processor list of 13 May 2026 names Google for US hosting of Statsig-branded services, plus MongoDB and Microsoft Azure. EU hosting is an Enterprise option. Warehouse Native runs analysis in the customer's warehouse - Ownership: The terms and DPA name Amplitude, Inc. Statsig's blog says it joined Amplitude on 5 May 2026 and that the original team is now at OpenAI - Prices: Pro plan $150 per month (plan); Metered event $0.0001 per transaction - Scores: Reliability 79, Performance pending, Schema & documentation 82, Agent ergonomics 71, Security & auth 74, Payments & pricing 40, Task success pending, Maintenance & community 81, Transparency & trust 75 · total over the 7 assessed categories - Why: Reliability, Graded on the hosted service with the hosted lines. · Schema & documentation, Public OpenAPI 3.0 spec for Console API version 20240601 with 209 paths and 325 operations, and typed MCP tools per the tool reference (25). · Agent ergonomics, The MCP V3 server shows 18 default tools, which is 15 on the checklist. · Security & auth, OAuth for the MCP server with PKCE, dynamic client registration and a device code grant, issuing personal Console API keys that carry the us… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest product update is dated 12 September 2026 and the server SDKs released 0.23.1 on 28 September 2026 (30). · Transparency & trust, Closed hosted service under a published self-service agreement and enterprise terms. - Sources: 31, open questions: 11, both in the full twin - Capabilities: analytics.experiments, analytics.flags, analytics.query, analytics.events - JSON: https://www.anchorterminal.com/api/v1/tools/statsig.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/statsig.svg` or a link to https://www.anchorterminal.com/tools/statsig from a page on statsig.com or one of its subdomains, or the README of github.com/statsig-io/statsig-server-core, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect to https://api.statsig.com/v3/mcp. The official MCP registry entry still lists the V1 URL, which has 93 tools 2. Call `get_context` first to learn the project, your permissions and the review settings 3. Read the resource before `gate_update`, `experiment_update` or `dynamic_config_update`. They replace the whole resource, so resend every field you want kept 4. Use `discover_tools` for partial edits, and fetch a fresh `operationHandle` when one expires 5. On a 429 slow down and back off with jitter. Rejected attempts count towards the quota of about 1,800 mutations per 15 minutes ## Connect ```bash claude mcp add --transport http statsig https://api.statsig.com/v3/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/statsig ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | GrowthBook | BB | 70.1 | analytics.experiments, analytics.flags, analytics.query, analytics.events | https://www.anchorterminal.com/tools/growthbook.min.md | | PostHog | B | 68.4 | analytics.query, analytics.events, analytics.experiments, analytics.flags | https://www.anchorterminal.com/tools/posthog.min.md | | Amplitude | B | 66.2 | analytics.query, analytics.experiments, analytics.flags, analytics.events | https://www.anchorterminal.com/tools/amplitude.min.md | | Mixpanel | B | 62 | analytics.query, analytics.events, analytics.experiments, analytics.flags | https://www.anchorterminal.com/tools/mixpanel.min.md | | Optimizely Experimentation | B | 62.6 | analytics.experiments, analytics.flags, analytics.query | https://www.anchorterminal.com/tools/optimizely.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)