Skip to main content
Glama
Hitsteps
by Hitsteps
README.md
# Hitsteps MCP Server

Public metadata and setup notes for the Hitsteps remote Model Context Protocol
server.

Hitsteps exposes a hosted MCP server for analytics and website operations:

```text
https://www.hitsteps.com/mcp/
```

The current registry metadata release is `1.1.6`. This repository is
intentionally small: it contains public registry metadata and setup notes, not
the production Hitsteps PHP service, private OAuth keys, reviewer accounts,
customer data, or deployment credentials.

## Install

Use the full Hitsteps setup and security guide:

```text
https://www.hitsteps.com/plugin/?type=mcp
```

Available client paths:

- VS Code and GitHub Copilot: use the [GitHub MCP Registry](https://github.com/mcp).
- Cursor: use the [Hitsteps Cursor Directory listing](https://cursor.directory/plugins/hitsteps-web-analytics).
- Claude: use the [Claude Connector Directory listing](https://claude.ai/directory/connectors/hitsteps-web-analytics).
- ChatGPT: the directory listing is coming soon; add `https://www.hitsteps.com/mcp/` as a custom MCP server for now.
- Google Antigravity and other clients: add the remote Streamable HTTP endpoint below and complete Hitsteps OAuth.

Google Antigravity configuration:

```json
{
  "mcpServers": {
    "Hitsteps": {
      "serverUrl": "https://www.hitsteps.com/mcp/"
    }
  }
}
```

The same managed endpoint is used by every client. There is no local package,
Node.js process, desktop bridge, SSE worker, or separate customer-hosted
service to install.

## Registry Metadata

The root [`server.json`](server.json) file is the canonical public metadata for
MCP registries and galleries. It declares:

- registry name: `com.hitsteps/analytics-operations`
- display title: `Hitsteps Analytics and Operations`
- transport: Streamable HTTP
- remote endpoint: `https://www.hitsteps.com/mcp/`
- icon: `https://www.hitsteps.com/favicon.png`
- documentation: `https://www.hitsteps.com/plugin/?type=mcp`
- current metadata version: `1.1.6`

The `com.hitsteps/analytics-operations` name is domain-authenticated. Keep
this identity unless Hitsteps intentionally publishes a second
GitHub-namespaced entry such as `io.github.Hitsteps/...`.

## Authentication and Safety

Hitsteps uses OAuth for public MCP access. Users sign in on Hitsteps and
approve the requested scopes before the client receives a token. The client
configuration contains only the endpoint URL; never paste a Hitsteps password,
tracking API key, OAuth token, private key, or reviewer credential into a
client configuration or this repository.

The server rechecks the signed-in account, sub-user permissions, visible
websites, license state, feature limits, and granted OAuth scopes on every
request. Write operations require their specific scope, explicit confirmation,
and an idempotency key. Results are privacy-shaped and do not expose raw SQL,
private keys, raw visitor-profile dumps, or session-replay video.

## Validation

Validate metadata before publishing:

```sh
mcp-publisher validate
```

Publish from this repository only after domain authentication is available to
the publisher environment. Private signing keys and domain-authentication
material must stay outside this repository.

## Security Reports

Please report suspected vulnerabilities through the [Hitsteps contact
page](https://www.hitsteps.com/contact.php). Do not open public issues
containing OAuth tokens, customer analytics data, account credentials, private
keys, reviewer credentials, or raw request logs with sensitive values.