query
Run a flexible ad-hoc analytics query with custom metrics, filters, grouping, date ranges, and privacy-first customer email lookup. This is the most powerful endpoint — use it when other tools don't answer the question.
Examples of questions this tool answers:
"How many signups from Germany this week?" → filters: [{field:"event",op:"eq",value:"signup"},{field:"country",op:"eq",value:"DE"}]
"Which events contain 'page' in the name?" → filters: [{field:"event",op:"contains",value:"page"}], group_by: ["event"]
"Daily unique users for the last 30 days" → metrics: ["unique_users"], group_by: ["date"], date_from: "30d"
"Events per country" → group_by: ["country"]
Filter operators: eq, neq, gt, lt, gte, lte, contains Filterable fields: event, user_id, date, country, session_id, timestamp, and any properties.* field (e.g. properties.path) For customer-specific reads, use the top-level email input instead of hashing locally. Raw email is sent only in the authenticated HTTPS POST body; the server matches via a project-scoped HMAC index and does not store raw email in event rows or profile traits. Built-in fields are a closed list. Event properties such as referrer, utm_source, path, browser, and hostname must be queried as properties.referrer, properties.utm_source, properties.path, properties.browser, and properties.hostname. Invalid filter fields fail loudly and return /properties-style guidance instead of being silently ignored. Group by: event, date, user_id, session_id, country Metrics: event_count, unique_users, session_count, bounce_rate, avg_duration Count modes: raw, session_then_user. The default for event_count is session_then_user for activation-safe counting: session-backed rows count by session, no-session rows fall back to user only when that user has no session-backed row in the same group, and fully anonymous rows fall back to event id. count_mode is ignored when event_count is not requested.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| No | Filter by server-side scoped HMAC email lookup. Raw email is sent only in the authenticated HTTPS POST body and is not stored in event rows or profile traits. | ||
| limit | No | Max results (default 100, max 1000) | |
| order | No | Sort direction | desc |
| date_to | No | End date (ISO 8601). Defaults to today. | |
| filters | No | Filters to apply | |
| metrics | No | Metrics to compute | |
| project | Yes | Project name | |
| group_by | No | Fields to group results by | |
| order_by | No | Field to sort by | |
| date_from | No | Start date (ISO 8601 or Nd shorthand like '30d'). Defaults to 7 days ago. | |
| count_mode | No | How event_count is aggregated. Default for event_count: session_then_user. Session-backed rows count by session, no-session rows fall back to user only when that user has no session-backed row in the same group, and fully anonymous rows fall back to event id. Ignored for queries without event_count. Use raw for ingestion/debugging counts. |