Site settings reference
A guide to every site settings tab: domains, tracking snippet, privacy, traffic and bot rules, goals, channels, alerts, sharing, integrations and deletion.
Settings at the end of a site's section in the sidebar opens the
site's settings, split into 16 tabs. Opening them needs the
sites.manage permission (Owner, Admin and Editor). Most settings are
also API operations with the same permission.
| Tab | What's there |
|---|---|
| General | Name, primary domain, additional domains (combined or separate), timezone, currency, week start, labels, site id |
| Tracking | Snippet generator, platform guides, Verify installation, server ingest key, Web Vitals sample rate |
| Privacy | DNT/GPC handling, query parameter allowlist, path masking rules, PII scrubber and custom rules, redaction log (counts only), data retention |
| Traffic rules | Block or allow lists for hostnames, paths, referrers, countries, IP ranges, user agents and events, with a live test box. See Traffic rules |
| Bots | Bot filtering on/off, 30-day bot summary by reason and country, and how many visits had no input seen. Block a spam referrer with a traffic rule. See Bot rules |
| Goals / Funnels | Your goals and funnels, with links to create and manage them |
| Events & properties | Links to manage events (rename, merge, hide, delete) and property settings. See Events explorer |
| Channels | Custom channel rules with a preview |
| Notes | Recent notes and a ready-to-copy deploy note command |
| Alerts | This site's alert rules and where they're sent |
| Sharing | Public and password links, embeds, badges, and a link to wallboard links |
| Integrations | Search Console and Bing connection status, plus links to webhooks, notification channels (Slack, Teams and more), API tokens, warehouse export, AI crawler logs and uptime |
| Imports | Recent GA4 and CSV imports and a link to start one |
| Access | Which members can see this site |
| Danger zone | Transfer the site to another workspace, reset data for a date range, delete the site |
General#
The site's identity and the defaults its reports use. One Save button stores the whole tab.
| Field | What it does |
|---|---|
| Name | The name shown in the sidebar, on All sites and in reports. Up to 100 characters |
| Primary domain | The site's main hostname, for example example.com. A pasted URL is reduced to its hostname. A domain can belong to only one active site |
| Timezone | The timezone that days and date ranges are counted in. Changing it regroups all history at once. See Timezones |
| Currency | A three-letter code such as USD. Revenue sent in another currency is converted to it. A new site starts with the workspace's currency |
| Week starts on | Monday or Sunday |
| Additional domains | Other hostnames that send data to this site, one per line or separated by commas |
| Multiple domains | Combined (the default): one visit can span all the domains, and reports show them together. Separate: each domain starts its own visits, and you compare them with a hostname filter |
| Labels | Comma separated tags. Filter sites by label on the All sites page |
| Site id | The pa_… id used in the snippet's data-site and in API paths, with a Copy button. It never changes |
Hits are accepted only from the primary domain, the additional domains
and any of their subdomains (www., shop. and so on). Hits from other
hostnames are dropped. Cross-domain and subdomains
explains when to combine domains and when to create separate sites.
Through the API, these are fields of PATCH /sites/<site id> (MCP:
sites_update).
Tracking#
Everything needed to get data in: the snippet, install help, a check that it works, the key for server-side events and Web Vitals sampling.
Snippet generator#
Choose options and the snippet below them updates. Paste it into the
<head> of every page. Each option becomes one attribute of the script
tag:
| Option | Attribute | Effect |
|---|---|---|
| Modules | data-modules |
engage (time on page and scroll depth, on by default), auto (outbound links, file downloads, form submits and 404s), vitals (Core Web Vitals, sampled) and clicks (aggregate element click counts). See Modules |
| Single-page apps | data-spa |
Automatic (history and hash, the default), History API only, Hash routing (keeps the #fragment) or Off. See Single-page apps |
| Manual pageviews only | data-manual |
The script sends no pageview by itself. See Manual mode |
| Only track on hostnames | data-domains |
Runs the tracker only on the hostnames you list |
| Exclude paths | data-exclude |
Skips matching paths, for example /admin/*, /preview/* |
| Keep query parameters | data-params |
Sends the listed query parameters with page URLs, for example page, ref. They are stored only when the Privacy tab allows them too |
| Mask paths | data-mask |
Rewrites paths in the browser, for example /u/*->/u/:id |
The last four are covered in Exclusions and masking, and Script attributes lists every attribute.
Note: The generator only builds a snippet. Its choices are not saved with the site, so the form is back on the defaults the next time you open the tab. What counts is the snippet on your pages.
Platform guides#
Short steps and ready code (already holding your site id) for HTML, WordPress, Shopify, Webflow, Next.js, Nuxt, Google Tag Manager, Ghost, Squarespace, Wix and Framer. The install guides cover these and more platforms in detail.
Verify installation#
Enter a page URL (the homepage is filled in) and click Verify. We fetch the page and report whether the script is there, whether it carries this site's id, and whether a Content-Security-Policy or Referrer-Policy header gets in the way. The URL must be on the site's primary or additional domains. The section shows when the site was last verified. See Verify your installation.
Server ingest key#
The key for sending events from your servers to POST /api/events.
- Create key shows the key once, with a ready
curlexample. We store only a hash of it, and afterward the tab shows just the key's prefix. - Rotate key replaces it. The old key stops working immediately.
- Revoke removes it.
See Ingest keys.
Web Vitals sampling#
Sample rate (%) is the share of page loads that report Core Web
Vitals when the vitals module is on. Free: up to 10%. Paid plans: any
rate up to 100%. If the workspace moves to a plan with a lower maximum,
that maximum applies without editing the site. Web Vitals don't count
toward your event allowance. See
Performance.
Through the API: GET /sites/<site id>/tracking/snippet
(tracking_snippet), POST /sites/<site id>/tracking/verify
(tracking_verify), POST and DELETE /sites/<site id>/tracking/ingest_key
(tracking_ingest_key_rotate, tracking_ingest_key_revoke), and the
vitals_sample_rate field of sites_update.
Privacy#
What is dropped, shortened or redacted before anything is stored, and how long data is kept. The first four sections are one form with a single Save button. Signals, URL rules and the scrubber apply to hits received after you save. Stored data is not rewritten.
Visitor signals#
| Setting | Default | Effect |
|---|---|---|
| Honor Global Privacy Control (GPC) | On | Hits from browsers that send GPC are dropped |
| Honor Do Not Track (DNT) | Off | Hits from browsers that send DNT are dropped |
See DNT and GPC.
URLs#
- Allowed query parameters: comma separated, for example
page, lang. Query strings are removed before storage, except UTM tags,refand the parameters you allow here. The tracker also removes other parameters in the browser, so list the same names in the snippet'sdata-params. - Path masks: rows of a pattern and a replacement. A
*matches exactly one path segment, so the pattern/u/*/settingswith the replacement/u/:id/settingsstores every user's settings page as one path. The first mask that matches a path is used. Add mask adds a row.
Path masks are applied on our servers. The snippet's data-mask does
the same in the browser, before the path is sent.
PII scrubber#
Scrub personal data (on by default) redacts personal data from paths, referrers and event properties before storage. The tab lists the built-in rules, which PII scrubbing describes one by one.
Custom redaction rules add your own: a rule name and a regular
expression per row, for example order_id and ORD-\d{6}. Matches are
replaced with [redacted]. A pattern that is not a valid regular
expression is refused when you save.
Data retention#
Data older than the chosen age is deleted automatically, once a day.
| Choice | Meaning |
|---|---|
| Plan default | Keep data as long as the plan allows |
| 3, 6, 12, 13, 24, 36 or 60 months | Delete this site's data sooner than the plan would |
Only ages within the plan's limit are offered. Free: up to 6 months. Paid plans keep data without a limit, so every choice is available. The age in force is always the shorter of this setting and the plan's limit.
Redaction log#
How often each scrubber rule redacted something in the last 30 days. The redacted values themselves are never stored.
Through the API, the privacy settings are the honor_gpc, honor_dnt,
allowed_params, path_masks, pii_scrubber, redaction_rules and
retention_months fields of sites_update.
Integrations#
This tab has nothing to save. It shows what the site is connected to and links to the tools that work with it.
Search Console and Bing lists Google Search Console and Bing Webmaster Tools, each with the connected property or "Not connected". Connect (or Open) goes to the site's Search page for that provider. See Search Console and Bing.
More integrations links to:
| Link | What it is | Guide |
|---|---|---|
| Webhooks | Send workspace events to your own endpoint | Webhooks |
| Notification channels | Email, Slack, Teams, Discord and more, used by alerts | Alerts |
| API tokens and MCP | For the JSON API and AI agents | Authentication, MCP |
| Warehouse export (Business) | Daily export to S3, BigQuery or Snowflake | Exports |
| AI crawlers | Server log ingest for AI crawler visits | AI crawlers |
| Uptime checks | Monitor this site and its SSL certificate | Uptime |
The first four open workspace pages, which need their own permissions. The last two open pages of this site. Plugins for WordPress, Shopify, Cloudflare, Google Tag Manager and more are in the install guides.
Access#
Who can see this site, member by member. Using it needs the
members.manage permission (Owner and Admin). Without it, the tab shows
a message instead of the list.
| Column | Shows |
|---|---|
| Member | Name and email |
| Role | The member's role, with "all sites" when they see every site |
| Can see this site | A checkbox, or Always for owners and admins |
- Owners and admins see every site. Their access can't be removed here.
- Other members see either all sites or only the sites granted to them.
- Ticking or clearing a checkbox saves at once.
- Clearing it for a member with "all sites" switches them to a list of the workspace's other sites. From then on, new sites are not added to their list automatically.
- You can't change a member who holds permissions you don't have.
A member without access to a site can't see it anywhere, including in lists, exports and the API. See Roles and permissions and Teams.
Through the API: GET and PATCH /sites/<site id>/access (MCP:
sites_access_list, sites_access_update).
Danger zone#
- Transfer: send the site to another workspace. Someone with permission there accepts. The site id, data and settings move with it, so the snippet doesn't change.
- Reset data deletes events for a date range. It can't be undone.
- Delete site: confirm by typing the domain. The site is soft-deleted for 7 days (collection stops), then permanently deleted.