# MCP prompts and JSON-RPC examples

> Example prompts that work well with the Privatus Analytics MCP server, the tools an agent picks for them, and raw JSON-RPC calls for testing a token.

## Prompts

- "Which pages on example.com got the most visitors from AI assistants
  last month, and how did that change from the month before?"
- "Compare signup conversion rate by channel for the last 90 days."
- "Create a goal for visits to /thank-you on example.com." (needs
  `content.write`)
- "Add a note on today's date: 'Launched new pricing page'."
- "Are any of my uptime checks down right now?"
- "How do I track outbound links with Privatus Analytics?" (uses `docs_search`)

The agent picks the tools, for example `stats_breakdown` with
`dimension=page`, `period=last_month`, `compare=previous_period` and
`filters=[["channel","is","ai_assistants"]]`.

## Raw JSON-RPC

Useful for checking a token or building your own client.

List tools:

```sh
curl https://privatusanalytics.com/mcp \
  -H "Authorization: Bearer $PRIVATUS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
```

Call a tool:

```sh
curl https://privatusanalytics.com/mcp \
  -H "Authorization: Bearer $PRIVATUS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{
    "jsonrpc": "2.0", "id": 2, "method": "tools/call",
    "params": {
      "name": "stats_aggregate",
      "arguments": { "site_id": "pa_7Q2K9XH3AB", "period": "7d", "compare": "previous_period" }
    }
  }'
```

The result's `content[0].text` is the same JSON the API returns
(`{"data": …}`), also provided as `structuredContent`. Errors come back
with `isError: true` and the API's error body.

## Good practice

- Use a dedicated token per agent, with the smallest set of permissions
  and sites, and an expiry date.
- Write tools (create, update, delete) show up only when the token has the
  permission. Keep agents on `analytics.read` unless they need more.
- Everything an agent changes is in the [audit log](/docs/teams/audit-log)
  under the token's member.
