# MCP analytics server

> Connect Claude, ChatGPT, Gemini, Cursor and other AI agents to your analytics with the Privatus Analytics MCP server: endpoint, OAuth, tokens and tool names.

Privatus Analytics runs a hosted **Model Context Protocol** server. Every [API
operation](/docs/api) you're allowed to use is an MCP tool, so an agent can
read your stats, create goals, add notes or check uptime with the same
permissions as your API token.

| | |
|---|---|
| Endpoint | `https://privatusanalytics.com/mcp` |
| Transport | Streamable HTTP (JSON responses) |
| Auth | `Authorization: Bearer pat_…` or OAuth 2.1 |

Set it up in your client: [Claude, ChatGPT, Gemini CLI, Cursor and VS Code](/docs/mcp/clients).

## Authentication

**API token.** Create a token in Workspace settings → API tokens and send
it as a Bearer token. Give the token only the permissions the agent needs.
For read-only analysis, `analytics.read` is enough. See
[Authentication](/docs/api/authentication).

**OAuth.** Clients that support MCP authorization can connect with just
the URL. The server publishes its metadata at
`/.well-known/oauth-protected-resource` and
`/.well-known/oauth-authorization-server`, supports dynamic client
registration (`/oauth/register`) and the authorization code flow with PKCE
(S256). You sign in, choose the workspace, and approve. The client
receives an API token that appears in your token list, where you can
revoke it.

## Tool names

Tools are named `<resource>_<verb>`:

| Verb | HTTP | Example |
|---|---|---|
| `list` | `GET` a collection | `sites_list`, `goals_list` |
| `get` | `GET` one record | `sites_get` |
| `create` | `POST` | `goals_create`, `notes_create` |
| `update` | `PATCH` | `sites_update` |
| `delete` | `DELETE` | `goals_delete` |
| other actions | as named | `goals_duplicate`, `stats_breakdown`, `docs_search` |

Each tool's input schema is the operation's inputs plus its path
parameters (`site_id`, `workspace_id`…). Read tools are marked
read-only and `DELETE` tools destructive, so clients can ask before
running them.

The server only lists tools your token's permissions allow. Tool calls go
through the same routes, permission checks and validation as the API.

## Start here

Agents usually begin with:

1. `workspaces_list` → your workspace id (`ws_…`).
2. `sites_list` with `workspace_id` → site ids (`pa_…`).
3. `stats_aggregate`, `stats_timeseries`, `stats_breakdown` or
   `stats_overview` with `site_id`, `period` and `filters`
   ([filter syntax](/docs/api/filters)).
4. `docs_search` and `docs_get` to read these docs.

See [Examples](/docs/mcp/examples).

## All tools

Generated from the running code. The [API reference](/docs/api) has each
tool's full input and output schema.

### API tokens

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `api_tokens_create` | `POST /workspaces/:workspace_id/api_tokens` | Create an API token (the token is returned once) | public |
| `api_tokens_delete` | `DELETE /workspaces/:workspace_id/api_tokens/:id` | Revoke an API token | public |
| `api_tokens_list` | `GET /workspaces/:workspace_id/api_tokens` | List API tokens | public |

### Account

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `account_get` | `GET /account` | Get your profile and preferences | public |
| `account_update` | `PATCH /account` | Update your profile and preferences | public |

### Affiliate program

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `affiliate_commissions_list` | `GET /account/affiliate/commissions` | List your affiliate commissions | public |
| `affiliate_signup_box_get` | `GET /account/affiliate/signup-box` | Get your affiliate signup box code and results | public |
| `affiliate_get` | `GET /account/affiliate` | Get your affiliate status, referral link and stats | public |

### Alerts

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `alerts_acknowledge` | `POST /alerts/:id/acknowledge` | Acknowledge the latest incident | `analytics.read` |
| `alerts_create` | `POST /workspaces/:workspace_id/alerts` | Create an alert | `content.write` |
| `alerts_delete` | `DELETE /alerts/:id` | Delete an alert | `content.write` |
| `alerts_history` | `GET /alerts/:id/history` | Incident history of an alert | `analytics.read` |
| `alerts_list` | `GET /workspaces/:workspace_id/alerts` | List alerts | `analytics.read` |
| `alerts_mute` | `POST /alerts/:id/mute` | Mute (or unmute) an alert’s notifications | `content.write` |
| `alerts_get` | `GET /alerts/:id` | Get an alert | `analytics.read` |
| `alerts_update` | `PATCH /alerts/:id` | Update an alert | `content.write` |
| `site_alerts_list` | `GET /sites/:site_id/alerts` | List alerts for a site | `analytics.read` |

### Analytics

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `stats_overview` | `GET /sites/:site_id/overview` | Site overview: metrics, chart series, top panels, live visitors and notes | `analytics.read` |
| `experiments_report` | `GET /sites/:site_id/experiments` | Experiment report: conversion rate per variant, uplift vs control and significance (two-proportion z-test) | `analytics.read` |
| `insights_get` | `GET /sites/:site_id/insights` | Notable changes vs the previous period, in plain English (biggest movers, goal conversion changes) | `analytics.read` |
| `journeys_explore` | `GET /sites/:site_id/journeys` | Journeys: top 3-step paths after a page (or any entrance), or before a page or goal | `analytics.read` |
| `pages_detail` | `GET /sites/:site_id/pages/detail` | Page detail: metrics, previous and next pages, sources, Web Vitals, events and click map for one path | `analytics.read` |
| `stats_aggregate` | `GET /sites/:site_id/stats/aggregate` | Headline metrics for a period (with comparison) | `analytics.read` |
| `stats_breakdown` | `GET /sites/:site_id/breakdown/:dimension` | Top values of a dimension (pages, sources, countries…) | `analytics.read` |
| `stats_timeseries` | `GET /sites/:site_id/stats/timeseries` | Metrics per time bucket for charts | `analytics.read` |

### Assistant

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `assistant_ask` | `POST /sites/:site_id/ask` | Ask a question in a new conversation (counts toward the monthly AI questions limit) | `analytics.read` |
| `assistant_conversations_delete` | `DELETE /sites/:site_id/ask/:id` | Delete an Ask conversation and its messages | `analytics.read` |
| `assistant_conversations_list` | `GET /sites/:site_id/ask` | List your Ask conversations for a site | `analytics.read` |
| `assistant_conversations_get` | `GET /sites/:site_id/ask/:id` | An Ask conversation: questions, answers, the queries behind them and charts | `analytics.read` |
| `assistant_ask_followup` | `POST /sites/:site_id/ask/:ask_conversation_id/messages` | Ask a follow-up question in a conversation (counts toward the monthly AI questions limit). Returns the answer. | `analytics.read` |

### Audit log

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `audit_logs_get` | `GET /workspaces/:workspace_id/audit_log` | List audit log entries (add .csv to export) | `workspace.manage` |

### Billing

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `billing_badge` | `POST /workspaces/:workspace_id/billing/badge` | Opt in or out of the badge bonus (free plan) | `billing.manage` |
| `billing_cancel` | `POST /workspaces/:workspace_id/billing/cancel` | Cancel at the end of the billing period | `billing.manage` |
| `billing_change_plan` | `POST /workspaces/:workspace_id/billing/change_plan` | Change plan, tier or interval (prorated) | `billing.manage` |
| `billing_checkout` | `POST /workspaces/:workspace_id/billing/checkout` | Start a Paddle checkout for a paid plan | `billing.manage` |
| `billing_discount` | `POST /workspaces/:workspace_id/billing/discount` | Apply for a discount program (nonprofit, education, open source or agency) | `billing.manage` |
| `billing_payment_method` | `POST /workspaces/:workspace_id/billing/payment_method` | Get a link to update the payment method | `billing.manage` |
| `billing_portal` | `POST /workspaces/:workspace_id/billing/portal` | Get a Paddle customer portal link | `billing.manage` |
| `billing_preview` | `GET /workspaces/:workspace_id/billing/preview` | Preview a plan change with proration | `billing.manage` |
| `billing_resume` | `POST /workspaces/:workspace_id/billing/resume` | Undo a scheduled cancellation or resume a pause | `billing.manage` |
| `billing_get` | `GET /workspaces/:workspace_id/billing` | Get the plan, subscription and usage | `billing.manage` |
| `billing_update` | `PATCH /workspaces/:workspace_id/billing` | Update billing emails, tax id and auto-upgrade | `billing.manage` |
| `billing_usage` | `GET /workspaces/:workspace_id/billing/usage` | Get this month's usage, forecast and per-site split | `billing.manage` |
| `billing_invoices_list` | `GET /workspaces/:workspace_id/billing/invoices` | List invoices | `billing.manage` |
| `billing_invoices_get` | `GET /workspaces/:workspace_id/billing/invoices/:id` | Get the PDF link for an invoice | `billing.manage` |

### Campaigns

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `campaign_costs_create` | `POST /sites/:site_id/campaigns/costs` | Set the spend for a campaign in a month | `content.write` |
| `campaign_costs_delete` | `DELETE /sites/:site_id/campaigns/costs/:id` | Delete a campaign cost entry | `content.write` |
| `campaign_costs_import` | `POST /sites/:site_id/campaigns/costs/import` | Import campaign costs from CSV (campaign,month,amount[,currency]) | `content.write` |
| `campaign_costs_list` | `GET /sites/:site_id/campaigns/costs` | List campaign cost entries | `analytics.read` |
| `campaign_costs_update` | `PATCH /sites/:site_id/campaigns/costs/:id` | Change a campaign cost entry | `content.write` |
| `campaigns_builder` | `GET /sites/:site_id/campaigns/builder` | Build and validate a UTM-tagged URL | `analytics.read` |
| `campaigns_hygiene` | `GET /sites/:site_id/campaigns/hygiene` | UTM hygiene: near-duplicate values, style issues and unknown sources | `analytics.read` |
| `campaigns_list` | `GET /sites/:site_id/campaigns` | Campaign rollup with conversions, revenue, cost, CPA and ROAS | `analytics.read` |
| `links_create` | `POST /sites/:site_id/campaigns/links` | Save a UTM-tagged link to the library | `content.write` |
| `links_delete` | `DELETE /sites/:site_id/campaigns/links/:id` | Delete a saved link | `content.write` |
| `links_list` | `GET /sites/:site_id/campaigns/links` | List saved campaign links | `analytics.read` |
| `links_qr` | `GET /sites/:site_id/campaigns/links/:id/qr` | QR code (SVG) for a saved link | `analytics.read` |
| `links_get` | `GET /sites/:site_id/campaigns/links/:id` | Get a saved campaign link | `analytics.read` |
| `links_update` | `PATCH /sites/:site_id/campaigns/links/:id` | Change a saved link | `content.write` |

### Channel rules

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `channel_rules_create` | `POST /sites/:site_id/channel_rules` | Add a channel rule | `sites.manage` |
| `channel_rules_delete` | `DELETE /sites/:site_id/channel_rules/:id` | Delete a channel rule | `sites.manage` |
| `channel_rules_list` | `GET /sites/:site_id/channel_rules` | List channel rules in order | `analytics.read` |
| `channel_rules_move` | `PATCH /sites/:site_id/channel_rules/:id/move` | Move a channel rule up or down | `sites.manage` |
| `channel_rules_preview` | `POST /sites/:site_id/channel_rules/preview` | Preview the channel for a sample referrer and UTM tags | `analytics.read` |
| `channel_rules_update` | `PATCH /sites/:site_id/channel_rules/:id` | Change a channel rule | `sites.manage` |

### Crawlers

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `crawlers_cloudflare_connect` | `POST /sites/:site_id/crawlers/connection` | Sync AI crawler hits from a Cloudflare zone (needs a Cloudflare grant from the browser) | `sites.manage` |
| `crawlers_cloudflare_disconnect` | `DELETE /sites/:site_id/crawlers/connection` | Disconnect Cloudflare and delete the crawler hits it imported | `sites.manage` |
| `crawlers_cloudflare_sync` | `POST /sites/:site_id/crawlers/sync` | Import crawler hits from Cloudflare now | `sites.manage` |
| `crawlers_cloudflare_zones` | `GET /sites/:site_id/crawlers/zones` | List the Cloudflare zones you can connect (needs a Cloudflare grant from the browser) | `sites.manage` |
| `crawlers_report` | `GET /sites/:site_id/crawlers` | AI crawlers report: hits by crawler over time, top paths per crawler, by category | `analytics.read` |

### Dashboards

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `dashboards_card` | `GET /workspaces/:workspace_id/dashboards/:id/cards/:index` | Data for one card of a custom dashboard | `analytics.read` |
| `dashboards_create` | `POST /workspaces/:workspace_id/dashboards` | Create a custom dashboard | `content.write` |
| `dashboards_delete` | `DELETE /workspaces/:workspace_id/dashboards/:id` | Delete a custom dashboard | `content.write` |
| `dashboards_list` | `GET /workspaces/:workspace_id/dashboards` | List custom dashboards | `analytics.read` |
| `dashboards_get` | `GET /workspaces/:workspace_id/dashboards/:id` | Get a custom dashboard and its cards | `analytics.read` |
| `dashboards_update` | `PATCH /workspaces/:workspace_id/dashboards/:id` | Rename a custom dashboard or replace its cards | `content.write` |

### Documentation

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `docs_api` | `GET /docs/api` | List every API operation and MCP tool | public |
| `docs_list` | `GET /docs` | List documentation pages | public |
| `docs_openapi` | `GET /openapi` | OpenAPI 3.1 document for the whole API | public |
| `docs_search` | `GET /docs/search` | Search the documentation | public |
| `docs_get` | `GET /docs/:section/:page` | Read a documentation page (Markdown and HTML) | public |

### Email reports

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `email_report_recipients_delete` | `DELETE /recipients/:id` | Remove a recipient from an email report | `content.write` |
| `email_report_recipients_list` | `GET /reports/:report_id/recipients` | List the recipients of an email report with their status | `analytics.read` |
| `email_report_recipients_resend` | `POST /recipients/:id/resend` | Resend a pending report invite | `content.write` |
| `email_reports_create` | `POST /workspaces/:workspace_id/reports` | Create an email report | `content.write` |
| `email_reports_deliveries` | `GET /reports/:id/deliveries` | Delivery log of an email report | `analytics.read` |
| `email_reports_delete` | `DELETE /reports/:id` | Delete an email report | `content.write` |
| `email_reports_list` | `GET /workspaces/:workspace_id/reports` | List email reports | `analytics.read` |
| `email_reports_send_test` | `POST /reports/:id/send_test` | Send an email report now as a test | `content.write` |
| `email_reports_get` | `GET /reports/:id` | Get an email report | `analytics.read` |
| `email_reports_update` | `PATCH /reports/:id` | Update an email report | `content.write` |

### Events

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `event_properties_list` | `GET /sites/:site_id/events/properties` | List event property keys seen in the last 30 days | `analytics.read` |
| `event_properties_update` | `PATCH /sites/:site_id/events/properties` | Rename or hide an event property key | `sites.manage` |
| `events_delete` | `DELETE /sites/:site_id/events` | Delete an event and its history (runs in the background, confirm by typing the name) | `sites.manage` |
| `events_list` | `GET /sites/:site_id/events` | List events with completions, visits, conversion rate and first/last seen | `analytics.read` |
| `events_merge` | `POST /sites/:site_id/events/merge` | Merge several events into one display name | `sites.manage` |
| `events_get` | `GET /sites/:site_id/events/detail` | One event: chart, property pivot, number property aggregates, pages and sources | `analytics.read` |
| `events_update` | `PATCH /sites/:site_id/events/settings` | Rename, hide or unhide an event, or set its currency | `sites.manage` |

### Exports

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `exports_create` | `POST /workspaces/:workspace_id/exports` | Queue an export (built in the background) | `analytics.export` |
| `exports_delete` | `DELETE /exports/:id` | Delete an export and its file | `analytics.export` |
| `exports_download` | `GET /exports/:id/download` | Get a signed link to the file (valid 10 minutes) | `analytics.export` |
| `exports_list` | `GET /workspaces/:workspace_id/exports` | List exports (the job queue) | `analytics.export` |
| `exports_preview` | `POST /workspaces/:workspace_id/exports/preview` | Preview an export: first 20 rows and the estimated row count | `analytics.export` |
| `exports_get` | `GET /exports/:id` | Get an export and its status | `analytics.export` |

### Funnels

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `funnels_create` | `POST /sites/:site_id/funnels` | Create a funnel | `content.write` |
| `funnels_delete` | `DELETE /sites/:site_id/funnels/:id` | Delete a funnel | `content.write` |
| `funnels_list` | `GET /sites/:site_id/funnels` | List funnels with entries, completions and rate | `analytics.read` |
| `funnels_get` | `GET /sites/:site_id/funnels/:id` | Funnel report: step counts, conversion, drop-off, time between steps and where visits went instead | `analytics.read` |
| `funnels_update` | `PATCH /sites/:site_id/funnels/:id` | Update a funnel | `content.write` |

### Goals

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `goals_archive` | `POST /sites/:site_id/goals/:id/archive` | Archive a goal (hidden from reports) | `content.write` |
| `goals_create` | `POST /sites/:site_id/goals` | Create a goal | `content.write` |
| `goals_delete` | `DELETE /sites/:site_id/goals/:id` | Delete a goal (data is kept) | `content.write` |
| `goals_duplicate` | `POST /sites/:site_id/goals/:id/duplicate` | Copy a goal | `content.write` |
| `goals_list` | `GET /sites/:site_id/goals` | List goals with completions, conversions, rate and value for a period | `analytics.read` |
| `goals_get` | `GET /sites/:site_id/goals/:id` | Goal report: metrics, chart, breakdowns and the journey to converting | `analytics.read` |
| `goals_unarchive` | `POST /sites/:site_id/goals/:id/unarchive` | Restore an archived goal | `content.write` |
| `goals_update` | `PATCH /sites/:site_id/goals/:id` | Update a goal | `content.write` |

### Help and feedback

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `support_message_send` | `POST /help` | Send a question or feedback to the Privatus Analytics team | public |

### Imports

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `imports_google_properties` | `GET /sites/:site_id/imports/google/properties` | List Google Analytics 4 properties to import | `sites.manage` |
| `imports_create` | `POST /sites/:site_id/imports` | Start an import (GA4 property or CSV upload) | `sites.manage` |
| `imports_delete` | `DELETE /sites/:site_id/imports/:id` | Delete an import and all its imported data | `sites.manage` |
| `imports_list` | `GET /sites/:site_id/imports` | List imports for a site | `analytics.read` |
| `imports_get` | `GET /sites/:site_id/imports/:id` | Get an import and its status | `analytics.read` |

### Live

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `live_get` | `GET /sites/:site_id/live` | Live visitors, activity stream and what is popular right now (last 30 minutes) | `analytics.read` |
| `live_wallboard` | `GET /sites/:site_id/live/wallboard` | Wallboard cards (live and today) for one or more sites | `analytics.read` |
| `wallboard_links_create` | `POST /sites/:site_id/live/wallboard/links` | Create a wallboard link (read-only, revocable) | `sites.manage` |
| `wallboard_links_delete` | `DELETE /sites/:site_id/live/wallboard/links/:id` | Revoke a wallboard link | `sites.manage` |
| `wallboard_links_list` | `GET /sites/:site_id/live/wallboard/links` | List wallboard links for a site | `sites.manage` |

### Members

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `invitations_create` | `POST /workspaces/:workspace_id/invitations` | Invite people by email | `members.manage` |
| `invitations_delete` | `DELETE /workspaces/:workspace_id/invitations/:id` | Revoke a pending invitation | `members.manage` |
| `invitations_list` | `GET /workspaces/:workspace_id/invitations` | List pending invitations | `members.manage` |
| `members_delete` | `DELETE /workspaces/:workspace_id/members/:id` | Remove a member (or leave the workspace) | public |
| `members_list` | `GET /workspaces/:workspace_id/members` | List workspace members | public |
| `members_update` | `PATCH /workspaces/:workspace_id/members/:id` | Change a member's role or site access | `members.manage` |
| `ownership_transfers_create` | `POST /workspaces/:workspace_id/ownership_transfer` | Transfer workspace ownership to another member (owner only, you become an admin) | public |

### Notes

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `notes_create` | `POST /sites/:site_id/notes` | Add a note to a site (use source "deploy" for release webhooks) | `content.write` |
| `notes_delete` | `DELETE /sites/:site_id/notes/:id` | Delete a note | `content.write` |
| `notes_list` | `GET /sites/:site_id/notes` | List notes for a site (including workspace-wide notes) | `analytics.read` |
| `notes_get` | `GET /sites/:site_id/notes/:id` | Get a note | `analytics.read` |
| `notes_update` | `PATCH /sites/:site_id/notes/:id` | Edit a note | `content.write` |
| `workspace_notes_create` | `POST /workspaces/:workspace_id/notes` | Add a workspace-wide note (shown on every site) | `content.write` |
| `workspace_notes_delete` | `DELETE /workspaces/:workspace_id/notes/:id` | Delete a workspace note | `content.write` |
| `workspace_notes_list` | `GET /workspaces/:workspace_id/notes` | List notes across a workspace | `analytics.read` |
| `workspace_notes_update` | `PATCH /workspaces/:workspace_id/notes/:id` | Edit a workspace note | `content.write` |

### Notification channels

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `notification_channels_create` | `POST /workspaces/:workspace_id/channels` | Add a notification channel | `content.write` |
| `notification_channels_delete` | `DELETE /channels/:id` | Delete a notification channel | `content.write` |
| `notification_channels_list` | `GET /workspaces/:workspace_id/channels` | List notification channels | `analytics.read` |
| `notification_channels_send_test` | `POST /channels/:id/send_test` | Send a test message through a channel | `content.write` |
| `notification_channels_get` | `GET /channels/:id` | Get a notification channel | `analytics.read` |
| `notification_channels_update` | `PATCH /channels/:id` | Update a notification channel | `content.write` |
| `push_subscriptions_create` | `POST /push_subscription` | Register a browser for push notifications | public |
| `push_subscriptions_delete` | `DELETE /push_subscription` | Remove a browser push registration | public |

### Performance

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `performance_report` | `GET /sites/:site_id/performance` | Web Vitals: p75 scorecard, daily trend and breakdowns by page, device, browser and country | `analytics.read` |

### Plans

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `plans_list` | `GET /plans` | List plans, prices and limits | public |

### Roles

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `roles_create` | `POST /workspaces/:workspace_id/roles` | Create a custom role | `members.manage` |
| `roles_delete` | `DELETE /workspaces/:workspace_id/roles/:id` | Delete a custom role (must be unused) | `members.manage` |
| `roles_list` | `GET /workspaces/:workspace_id/roles` | List custom roles | public |
| `roles_update` | `PATCH /workspaces/:workspace_id/roles/:id` | Update a custom role | `members.manage` |

### SSO

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `sso_activate` | `POST /workspaces/:workspace_id/sso/activate` | Activate a tested SSO configuration | `workspace.manage` |
| `sso_deactivate` | `POST /workspaces/:workspace_id/sso/deactivate` | Turn SSO off (back to draft) | `workspace.manage` |
| `sso_get` | `GET /workspaces/:workspace_id/sso` | Get SSO settings | `workspace.manage` |
| `sso_update` | `PATCH /workspaces/:workspace_id/sso` | Create or update SSO settings | `workspace.manage` |

### Search

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `search_report` | `GET /sites/:site_id/search` | Search report: clicks, impressions, CTR, position, top queries/pages, landing pages and opportunities | `analytics.read` |
| `search_connect` | `POST /sites/:site_id/search/connections` | Connect a Search Console property or Bing site | `sites.manage` |
| `search_disconnect` | `DELETE /sites/:site_id/search/connections/:provider` | Disconnect Search Console or Bing and delete its data | `sites.manage` |
| `search_properties` | `POST /sites/:site_id/search/properties` | List properties you can connect (Search Console needs a Google grant from the browser) | `sites.manage` |
| `search_sync` | `POST /sites/:site_id/search/sync` | Import search data now | `sites.manage` |

### Segments

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `segments_create` | `POST /sites/:site_id/segments` | Save filters as a segment | `content.write` |
| `segments_delete` | `DELETE /sites/:site_id/segments/:id` | Delete a segment | `content.write` |
| `segments_list` | `GET /sites/:site_id/segments` | List segments you can use on a site | `analytics.read` |
| `segments_preview` | `POST /sites/:site_id/segments/preview` | Describe filters in plain English and count the visitors they matched in the last 30 days | `analytics.read` |
| `segments_get` | `GET /sites/:site_id/segments/:id` | Get a segment | `analytics.read` |
| `segments_update` | `PATCH /sites/:site_id/segments/:id` | Rename a segment or change its filters or sharing | `content.write` |

### Sharing

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `shared_links_create` | `POST /sites/:site_id/shared_links` | Create a share link | `sites.manage` |
| `shared_links_delete` | `DELETE /sites/:site_id/shared_links/:id` | Revoke a share link | `sites.manage` |
| `shared_links_list` | `GET /sites/:site_id/shared_links` | List share links | `sites.manage` |
| `shared_links_update` | `PATCH /sites/:site_id/shared_links/:id` | Change a share link | `sites.manage` |
| `shares_breakdown` | `GET /share/:token/breakdown/:dimension` | Top values of a shared dimension | public |
| `shares_overview` | `GET /share/:token` | Shared dashboard overview for a share token | public |

### Sites

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `sites_reset_data` | `POST /sites/:site_id/data_reset` | Delete all events and visits in a date range (runs in the background, cannot be undone) | `sites.manage` |
| `sites_filter_stats` | `GET /sites/:site_id/filter_stats` | Filtered traffic summary: bots, traffic rules or PII redactions by reason and country (counts only) | `analytics.read` |
| `sites_access_list` | `GET /sites/:site_id/access` | List members and whether they can see this site | `members.manage` |
| `sites_access_update` | `PATCH /sites/:site_id/access` | Grant or remove one member's access to this site | `members.manage` |
| `sites_favorite` | `POST /sites/:site_id/favorite` | Star a site (pinned first on All sites) | `analytics.read` |
| `sites_unfavorite` | `DELETE /sites/:site_id/favorite` | Unstar a site | `analytics.read` |
| `sites_setup_get` | `GET /sites/:site_id/setup` | Installation status and snippet for a site | `analytics.read` |
| `site_transfers_accept` | `POST /transfers/:token/accept` | Accept a site transfer into one of your workspaces | public |
| `sites_transfer_start` | `POST /sites/:site_id/transfer` | Start transferring a site to another workspace (emails the recipient) | `sites.manage` |
| `sites_transfer_cancel` | `DELETE /sites/:site_id/transfer` | Cancel a pending site transfer | `sites.manage` |
| `site_transfers_get` | `GET /transfers/:token` | Get a pending transfer from its emailed token | public |
| `sites_create` | `POST /workspaces/:workspace_id/sites` | Add a site | `sites.manage` |
| `sites_delete` | `DELETE /sites/:id` | Delete a site (purged after 7 days) | `sites.manage` |
| `sites_list` | `GET /workspaces/:workspace_id/sites` | List sites in a workspace | `analytics.read` |
| `sites_get` | `GET /sites/:id` | Get a site and all its settings | `analytics.read` |
| `sites_update` | `PATCH /sites/:id` | Update site settings | `sites.manage` |

### Status pages

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `status_page_posts_create` | `POST /status_pages/:status_page_id/posts` | Post an incident update (emails subscribers) | `uptime.manage` |
| `status_page_posts_delete` | `DELETE /status_pages/:status_page_id/posts/:id` | Delete a status page post | `uptime.manage` |
| `status_page_posts_list` | `GET /status_pages/:status_page_id/posts` | List posts on a status page | `analytics.read` |
| `status_page_posts_update` | `PATCH /status_pages/:status_page_id/posts/:id` | Edit a status page post | `uptime.manage` |
| `status_page_subscribers_delete` | `DELETE /status_pages/:status_page_id/subscribers/:id` | Remove a subscriber | `uptime.manage` |
| `status_page_subscribers_list` | `GET /status_pages/:status_page_id/subscribers` | List subscribers of a status page | `uptime.manage` |
| `status_pages_create` | `POST /workspaces/:workspace_id/status_pages` | Create a status page | `uptime.manage` |
| `status_pages_delete` | `DELETE /status_pages/:id` | Delete a status page | `uptime.manage` |
| `status_pages_list` | `GET /workspaces/:workspace_id/status_pages` | List status pages | `analytics.read` |
| `status_pages_get` | `GET /status_pages/:id` | Get a status page | `analytics.read` |
| `status_pages_update` | `PATCH /status_pages/:id` | Change a status page | `uptime.manage` |

### Tracking

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `tracking_ingest_key_rotate` | `POST /sites/:site_id/tracking/ingest_key` | Create or rotate the server ingest key (shown once) | `sites.manage` |
| `tracking_ingest_key_revoke` | `DELETE /sites/:site_id/tracking/ingest_key` | Revoke the server ingest key | `sites.manage` |
| `tracking_verify` | `POST /sites/:site_id/tracking/verify` | Check the tracker is installed on the site (script tag, site id, CSP and referrer policy) | `sites.manage` |
| `tracking_snippet` | `GET /sites/:site_id/tracking/snippet` | Build the tracking snippet for chosen options | `analytics.read` |

### Traffic rules

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `traffic_rules_create` | `POST /sites/:site_id/traffic_rules` | Add a traffic rule | `sites.manage` |
| `traffic_rules_delete` | `DELETE /sites/:site_id/traffic_rules/:id` | Delete a traffic rule | `sites.manage` |
| `traffic_rules_list` | `GET /sites/:site_id/traffic_rules` | List traffic rules | `analytics.read` |
| `traffic_rules_test` | `POST /sites/:site_id/traffic_rules/test` | Test whether a hit would be counted with the site's current rules | `analytics.read` |
| `traffic_rules_update` | `PATCH /sites/:site_id/traffic_rules/:id` | Change a traffic rule | `sites.manage` |

### Uptime

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `uptime_checks_create` | `POST /sites/:site_id/uptime` | Add an uptime check for a site | `uptime.manage` |
| `uptime_checks_delete` | `DELETE /uptime/checks/:id` | Delete an uptime check and its history | `uptime.manage` |
| `uptime_checks_list` | `GET /sites/:site_id/uptime` | List a site's uptime checks | `analytics.read` |
| `uptime_checks_pause` | `POST /uptime/checks/:id/pause` | Pause an uptime check | `uptime.manage` |
| `uptime_checks_resume` | `POST /uptime/checks/:id/resume` | Resume a paused uptime check | `uptime.manage` |
| `uptime_checks_get` | `GET /uptime/checks/:id` | Get an uptime check: uptime 24h/7d/30d, response times and incidents | `analytics.read` |
| `uptime_checks_update` | `PATCH /uptime/checks/:id` | Change an uptime check | `uptime.manage` |
| `workspace_uptime_checks_create` | `POST /workspaces/:workspace_id/uptime` | Add a workspace uptime check (not tied to a site) | `uptime.manage` |
| `workspace_uptime_checks_list` | `GET /workspaces/:workspace_id/uptime` | List all uptime checks in a workspace | `analytics.read` |

### Warehouse sync

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `warehouse_destinations_create` | `POST /workspaces/:workspace_id/warehouses` | Add a warehouse destination | `workspace.manage` |
| `warehouse_destinations_delete` | `DELETE /warehouses/:id` | Delete a warehouse destination | `workspace.manage` |
| `warehouse_destinations_list` | `GET /workspaces/:workspace_id/warehouses` | List warehouse destinations | `workspace.manage` |
| `warehouse_destinations_get` | `GET /warehouses/:id` | Get a warehouse destination (no secrets) | `workspace.manage` |
| `warehouse_destinations_sync` | `POST /warehouses/:id/sync` | Queue a sync of one day now | `workspace.manage` |
| `warehouse_destinations_update` | `PATCH /warehouses/:id` | Update a warehouse destination (blank secrets are kept) | `workspace.manage` |

### Webhooks

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `webhook_deliveries_list` | `GET /workspaces/:workspace_id/webhooks/:webhook_id/deliveries` | List deliveries for a webhook | `workspace.manage` |
| `webhook_deliveries_redeliver` | `POST /workspaces/:workspace_id/webhooks/:webhook_id/deliveries/:id/redeliver` | Send a delivery again | `workspace.manage` |
| `webhooks_create` | `POST /workspaces/:workspace_id/webhooks` | Add a webhook endpoint | `workspace.manage` |
| `webhooks_delete` | `DELETE /workspaces/:workspace_id/webhooks/:id` | Delete a webhook | `workspace.manage` |
| `webhooks_list` | `GET /workspaces/:workspace_id/webhooks` | List webhooks | `workspace.manage` |
| `webhooks_get` | `GET /workspaces/:workspace_id/webhooks/:id` | Get a webhook | `workspace.manage` |
| `webhooks_test` | `POST /workspaces/:workspace_id/webhooks/:id/test` | Send a test delivery | `workspace.manage` |
| `webhooks_update` | `PATCH /workspaces/:workspace_id/webhooks/:id` | Update a webhook (events, URL, enabled, rotate secret) | `workspace.manage` |

### Website

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `changelog_list` | `GET /changelog` | List changelog entries | public |
| `changelog_get` | `GET /changelog/:id` | Get a changelog entry | public |
| `pricing_get` | `GET /pricing` | Get plans, prices and plan limits | public |
| `status_get` | `GET /status` | Get the current system status | public |
| `tools_consent_gap` | `GET /tools/consent-gap` | Estimate traffic missed by consent-based analytics | public |
| `tools_header_check` | `GET /tools/header-checker` | Check a page’s Referrer-Policy and CSP for analytics | public |
| `tools_privacy_policy` | `GET /tools/privacy-policy-generator` | Draft a privacy-policy paragraph for Privatus Analytics | public |
| `tools_qr_code` | `GET /tools/qr-code` | Generate a QR code as SVG | public |
| `tools_tracker_scan` | `GET /tools/tracker-scanner` | List cookies and known trackers on a page | public |
| `tools_utm_builder` | `GET /tools/utm-builder` | Build a campaign URL with UTM parameters | public |

### Workspaces

| Tool | Endpoint | Summary | Permission |
|---|---|---|---|
| `white_label_get` | `GET /workspaces/:workspace_id/white_label` | Get the white label brand | `workspace.manage` |
| `white_label_update` | `PATCH /workspaces/:workspace_id/white_label` | Set the white label brand for shared dashboards and email reports (Business) | `workspace.manage` |
| `workspace_security_get` | `GET /workspaces/:workspace_id/security` | Get workspace security settings | `workspace.manage` |
| `workspace_security_update` | `PATCH /workspaces/:workspace_id/security` | Update workspace security settings (2FA, login methods, session lifetime, IP allowlist, support access) | `workspace.manage` |
| `workspaces_delete` | `DELETE /workspaces/:id` | Delete a workspace and all its sites (owner only, cancels any subscription) | `workspace.manage` |
| `workspaces_list` | `GET /workspaces` | List your workspaces | public |
| `workspaces_get` | `GET /workspaces/:id` | Get a workspace | public |
| `workspaces_update` | `PATCH /workspaces/:id` | Update workspace settings | `workspace.manage` |
