# Site settings reference

> A guide to every site settings tab: domains, tracking snippet, privacy, traffic and bot rules, goals, channels, alerts, sharing, integrations and deletion.

**Settings** at the end of a site's section in the sidebar opens the
site's settings, split into 16 tabs. Opening them needs the
`sites.manage` permission (Owner, Admin and Editor). Most settings are
also [API operations](/docs/api) with the same permission.

| Tab | What's there |
|---|---|
| [**General**](/docs/dashboard/site-settings#general) | Name, primary domain, additional domains (combined or separate), timezone, currency, week start, labels, site id |
| [**Tracking**](/docs/dashboard/site-settings#tracking) | Snippet generator, platform guides, **Verify installation**, [server ingest key](/docs/server-side/ingest-keys), Web Vitals sample rate |
| [**Privacy**](/docs/dashboard/site-settings#privacy) | [DNT/GPC handling](/docs/privacy/dnt-gpc), query parameter allowlist, path masking rules, [PII scrubber](/docs/privacy/pii-scrubbing) and custom rules, redaction log (counts only), data retention |
| **Traffic rules** | Block or allow lists for hostnames, paths, referrers, countries, IP ranges, user agents and events, with a live test box. See [Traffic rules](/docs/privacy/traffic-rules) |
| **Bots** | Bot filtering on/off, 30-day bot summary by reason and country, and how many visits had [no input seen](/docs/server-side/bots#visits-with-no-input-seen). Block a spam referrer with a [traffic rule](/docs/privacy/traffic-rules). See [Bot rules](/docs/server-side/bots) |
| **Goals** / **Funnels** | Your [goals](/docs/features/goals) and [funnels](/docs/features/funnels), with links to create and manage them |
| **Events & properties** | Links to manage events (rename, merge, hide, delete) and property settings. See [Events explorer](/docs/dashboard/events#managing-events) |
| **Channels** | Custom [channel rules](/docs/metrics/channels#custom-channel-rules) with a preview |
| **Notes** | Recent [notes](/docs/dashboard/notes) and a ready-to-copy deploy note command |
| **Alerts** | This site's [alert rules](/docs/reports/alerts) and where they're sent |
| **Sharing** | [Public and password links, embeds, badges](/docs/reports/sharing), and a link to wallboard links |
| [**Integrations**](/docs/dashboard/site-settings#integrations) | [Search Console and Bing](/docs/features/search-console) connection status, plus links to webhooks, notification channels (Slack, Teams and more), API tokens, warehouse export, [AI crawler logs](/docs/features/ai-crawlers) and uptime |
| **Imports** | Recent [GA4 and CSV imports](/docs/reports/imports) and a link to start one |
| [**Access**](/docs/dashboard/site-settings#access) | Which members can see this site |
| [**Danger zone**](/docs/dashboard/site-settings#danger-zone) | Transfer the site to another workspace, reset data for a date range, delete the site |

## General

The site's identity and the defaults its reports use. One **Save** button
stores the whole tab.

| Field | What it does |
|---|---|
| **Name** | The name shown in the sidebar, on [All sites](/docs/dashboard/all-sites) and in reports. Up to 100 characters |
| **Primary domain** | The site's main hostname, for example `example.com`. A pasted URL is reduced to its hostname. A domain can belong to only one active site |
| **Timezone** | The timezone that days and date ranges are counted in. Changing it regroups all history at once. See [Timezones](/docs/troubleshooting/timezones) |
| **Currency** | A three-letter code such as `USD`. [Revenue](/docs/events/revenue#multi-currency) sent in another currency is converted to it. A new site starts with the workspace's currency |
| **Week starts on** | Monday or Sunday |
| **Additional domains** | Other hostnames that send data to this site, one per line or separated by commas |
| **Multiple domains** | **Combined** (the default): one visit can span all the domains, and reports show them together. **Separate**: each domain starts its own visits, and you compare them with a hostname filter |
| **Labels** | Comma separated tags. Filter sites by label on the All sites page |
| **Site id** | The `pa_…` id used in the snippet's `data-site` and in API paths, with a **Copy** button. It never changes |

Hits are accepted only from the primary domain, the additional domains
and any of their subdomains (`www.`, `shop.` and so on). Hits from other
hostnames are dropped. [Cross-domain and subdomains](/docs/troubleshooting/cross-domain)
explains when to combine domains and when to create separate sites.

Through the API, these are fields of `PATCH /sites/<site id>` (MCP:
`sites_update`).

## Tracking

Everything needed to get data in: the snippet, install help, a check that
it works, the key for server-side events and Web Vitals sampling.

### Snippet generator

Choose options and the snippet below them updates. Paste it into the
`<head>` of every page. Each option becomes one attribute of the script
tag:

| Option | Attribute | Effect |
|---|---|---|
| **Modules** | `data-modules` | `engage` (time on page and scroll depth, on by default), `auto` (outbound links, file downloads, form submits and 404s), `vitals` (Core Web Vitals, sampled) and `clicks` (aggregate element click counts). See [Modules](/docs/tracker/modules) |
| **Single-page apps** | `data-spa` | Automatic (history and hash, the default), History API only, Hash routing (keeps the `#fragment`) or Off. See [Single-page apps](/docs/tracker/spa) |
| **Manual pageviews only** | `data-manual` | The script sends no pageview by itself. See [Manual mode](/docs/tracker/manual-mode) |
| **Only track on hostnames** | `data-domains` | Runs the tracker only on the hostnames you list |
| **Exclude paths** | `data-exclude` | Skips matching paths, for example `/admin/*, /preview/*` |
| **Keep query parameters** | `data-params` | Sends the listed query parameters with page URLs, for example `page, ref`. They are stored only when the [Privacy](/docs/dashboard/site-settings#privacy) tab allows them too |
| **Mask paths** | `data-mask` | Rewrites paths in the browser, for example `/u/*->/u/:id` |

The last four are covered in
[Exclusions and masking](/docs/tracker/exclusions-and-masking), and
[Script attributes](/docs/tracker/attributes) lists every attribute.

> **Note:** The generator only builds a snippet. Its choices are not
> saved with the site, so the form is back on the defaults the next time
> you open the tab. What counts is the snippet on your pages.

### Platform guides

Short steps and ready code (already holding your site id) for HTML,
WordPress, Shopify, Webflow, Next.js, Nuxt, Google Tag Manager, Ghost,
Squarespace, Wix and Framer. The [install guides](/docs/install) cover
these and more platforms in detail.

### Verify installation

Enter a page URL (the homepage is filled in) and click **Verify**. We
fetch the page and report whether the script is there, whether it carries
this site's id, and whether a Content-Security-Policy or Referrer-Policy
header gets in the way. The URL must be on the site's primary or
additional domains. The section shows when the site was last verified.
See [Verify your installation](/docs/getting-started/verify-installation).

### Server ingest key

The key for sending events from your servers to `POST /api/events`.

- **Create key** shows the key once, with a ready `curl` example. We store
  only a hash of it, and afterward the tab shows just the key's prefix.
- **Rotate key** replaces it. The old key stops working immediately.
- **Revoke** removes it.

See [Ingest keys](/docs/server-side/ingest-keys).

### Web Vitals sampling

**Sample rate (%)** is the share of page loads that report Core Web
Vitals when the `vitals` module is on. Free: up to 10%. Paid plans: any
rate up to 100%. If the workspace moves to a plan with a lower maximum,
that maximum applies without editing the site. Web Vitals don't count
toward your event allowance. See
[Performance](/docs/features/performance).

Through the API: `GET /sites/<site id>/tracking/snippet`
(`tracking_snippet`), `POST /sites/<site id>/tracking/verify`
(`tracking_verify`), `POST` and `DELETE /sites/<site id>/tracking/ingest_key`
(`tracking_ingest_key_rotate`, `tracking_ingest_key_revoke`), and the
`vitals_sample_rate` field of `sites_update`.

## Privacy

What is dropped, shortened or redacted before anything is stored, and how
long data is kept. The first four sections are one form with a single
**Save** button. Signals, URL rules and the scrubber apply to hits
received after you save. Stored data is not rewritten.

### Visitor signals

| Setting | Default | Effect |
|---|---|---|
| **Honor Global Privacy Control (GPC)** | On | Hits from browsers that send GPC are dropped |
| **Honor Do Not Track (DNT)** | Off | Hits from browsers that send DNT are dropped |

See [DNT and GPC](/docs/privacy/dnt-gpc).

### URLs

- **Allowed query parameters**: comma separated, for example
  `page, lang`. Query strings are removed before storage, except UTM
  tags, `ref` and the parameters you allow here. The tracker also removes
  other parameters in the browser, so list the same names in the
  snippet's
  [`data-params`](/docs/tracker/exclusions-and-masking#keep-query-parameters-data-params).
- **Path masks**: rows of a pattern and a replacement. A `*` matches
  exactly one path segment, so the pattern `/u/*/settings` with the
  replacement `/u/:id/settings` stores every user's settings page as one
  path. The first mask that matches a path is used. **Add mask** adds a
  row.

Path masks are applied on our servers. The snippet's `data-mask` does
the same in the browser, before the path is sent.

### PII scrubber

**Scrub personal data** (on by default) redacts personal data from
paths, referrers and event properties before storage. The tab lists the
built-in rules, which [PII scrubbing](/docs/privacy/pii-scrubbing)
describes one by one.

**Custom redaction rules** add your own: a rule name and a regular
expression per row, for example `order_id` and `ORD-\d{6}`. Matches are
replaced with `[redacted]`. A pattern that is not a valid regular
expression is refused when you save.

### Data retention

Data older than the chosen age is deleted automatically, once a day.

| Choice | Meaning |
|---|---|
| **Plan default** | Keep data as long as the plan allows |
| 3, 6, 12, 13, 24, 36 or 60 months | Delete this site's data sooner than the plan would |

Only ages within the plan's limit are offered. Free: up to 6 months. Paid
plans keep data without a limit, so every choice is available. The age
in force is always the shorter of this setting and the plan's limit.

### Redaction log

How often each scrubber rule redacted something in the last 30 days. The
redacted values themselves are never stored.

Through the API, the privacy settings are the `honor_gpc`, `honor_dnt`,
`allowed_params`, `path_masks`, `pii_scrubber`, `redaction_rules` and
`retention_months` fields of `sites_update`.

## Integrations

This tab has nothing to save. It shows what the site is connected to and
links to the tools that work with it.

**Search Console and Bing** lists Google Search Console and Bing
Webmaster Tools, each with the connected property or "Not connected".
**Connect** (or **Open**) goes to the site's Search page for that
provider. See [Search Console and Bing](/docs/features/search-console).

**More integrations** links to:

| Link | What it is | Guide |
|---|---|---|
| **Webhooks** | Send workspace events to your own endpoint | [Webhooks](/docs/api/webhooks) |
| **Notification channels** | Email, Slack, Teams, Discord and more, used by alerts | [Alerts](/docs/reports/alerts) |
| **API tokens and MCP** | For the JSON API and AI agents | [Authentication](/docs/api/authentication), [MCP](/docs/mcp) |
| **Warehouse export** (Business) | Daily export to S3, BigQuery or Snowflake | [Exports](/docs/reports/exports) |
| **AI crawlers** | Server log ingest for AI crawler visits | [AI crawlers](/docs/features/ai-crawlers) |
| **Uptime checks** | Monitor this site and its SSL certificate | [Uptime](/docs/features/uptime) |

The first four open workspace pages, which need their own permissions.
The last two open pages of this site. Plugins for WordPress, Shopify,
Cloudflare, Google Tag Manager and more are in the
[install guides](/docs/install).

## Access

**Who can see this site**, member by member. Using it needs the
`members.manage` permission (Owner and Admin). Without it, the tab shows
a message instead of the list.

| Column | Shows |
|---|---|
| **Member** | Name and email |
| **Role** | The member's role, with "all sites" when they see every site |
| **Can see this site** | A checkbox, or **Always** for owners and admins |

- Owners and admins see every site. Their access can't be removed here.
- Other members see either all sites or only the sites granted to them.
- Ticking or clearing a checkbox saves at once.
- Clearing it for a member with "all sites" switches them to a list of
  the workspace's other sites. From then on, new sites are not added to
  their list automatically.
- You can't change a member who holds permissions you don't have.

A member without access to a site can't see it anywhere, including in
lists, exports and the API. See [Roles and permissions](/docs/teams/roles)
and [Teams](/docs/teams).

Through the API: `GET` and `PATCH /sites/<site id>/access` (MCP:
`sites_access_list`, `sites_access_update`).

## Danger zone

- **Transfer**: send the site to another workspace. Someone with
  permission there accepts. The site id, data and settings move with it,
  so the snippet doesn't change.
- **Reset data** deletes events for a date range. It can't be undone.
- **Delete site**: confirm by typing the domain. The site is soft-deleted
  for 7 days (collection stops), then permanently deleted.
