umami-mcp
English | 한국어
umami-mcp
Model Context Protocol server for the current Umami Analytics v3.3 API. It supports self-hosted username/password authentication and Umami Cloud API keys, and exposes analytics, collection, administration, and newer v3 feature families such as boards, links, pixels, segments, session replay, shares, exports, performance, and revenue.
This version intentionally does not claim every private Umami route. Its tools track the documented API and the public v3.3.1 server contracts.
Requirements
Node.js 18 or newer
Umami v3.3-compatible self-hosted instance, or an Umami Cloud API key
Installation
npm install -g @mikusnuz/umami-mcpOr run it directly:
npx -y @mikusnuz/umami-mcpConfiguration
Self-hosted
{
"mcpServers": {
"umami": {
"command": "npx",
"args": ["-y", "@mikusnuz/umami-mcp"],
"env": {
"UMAMI_URL": "https://analytics.example.com",
"UMAMI_USERNAME": "admin",
"UMAMI_PASSWORD": "your-password"
}
}
}
}UMAMI_URL is the instance origin. A trailing /api is accepted, but is not
required.
Umami Cloud
{
"mcpServers": {
"umami": {
"command": "npx",
"args": ["-y", "@mikusnuz/umami-mcp"],
"env": {
"UMAMI_API_KEY": "your-cloud-api-key"
}
}
}
}Cloud management calls default to https://api.umami.is/v1; tool paths are
translated from self-hosted /api/... paths to Cloud /v1/... paths. Set
UMAMI_URL to https://api.umami.is/v1/us or
https://api.umami.is/v1/eu when an explicit Cloud region is required.
Environment variables
Variable | When required | Description |
| Self-hosted | Instance origin; optional for Cloud |
| Self-hosted | Login username |
| Self-hosted | Login password |
| Cloud | Bearer API key |
| Optional | Separate host for public collection/share/heartbeat/recorder routes |
For Cloud, the collector defaults to https://cloud.umami.is. For self-hosted
Umami it defaults to UMAMI_URL.
Authentication and public routes
Management and analytics tools send a bearer token. The client logs in to a self-hosted instance lazily and caches the returned JWT; Cloud uses the API key as the bearer credential.
The public collection routes do not require credentials:
send_event,send_identify,send_performancebatch_events(raw JSON array, up to 500 items)heartbeat,get_share,get_recorder_config
If self-hosted login reports that two-factor authentication is required, call
complete_two_factor_login with a current TOTP or backup code, then retry the
original tool. Setup and policy tools are also exposed for self-hosted Umami.
Umami Cloud does not expose /me/password, /users, or /users/* through an
API key. Those tools are for self-hosted instances.
Tool groups
Area | Representative tools |
Websites |
|
Analytics |
|
Event/session data | event values, fields, properties, values, session activity |
Collection | event/pageview, identify, performance, raw batch, link/pixel events |
Reports | saved-report CRUD and |
Boards | list, CRUD, clone, and team boards |
Links and pixels | list, CRUD, charts, and collection events |
Segments | segment/cohort list and CRUD |
Replay | recorder config, replay list/detail, saved replays, session replays |
Shares and export | public share resolution, managed website shares, update/delete, CSV ZIP export |
Revenue | stats, chart, metrics, and revenue sessions |
Users and teams | current admin-user and team membership/transfer routes |
2FA | login completion, enrollment, disable, and admin enforcement policies |
Realtime |
|
Use MCP tools/list for the complete, machine-readable list and schemas.
Important v3 contract details
A pageview is sent as
{ "type": "event" }with no eventname; the oldpageviewtype is no longer valid./api/batchreceives the event objects as a raw array, not{ "events": [...] }. The tool returns Umami'sprocessed,errors, and per-itemdetailsfields and marks partial failures as an MCP error result.Collector calls set a stable non-bot
User-Agentheader as required by Umami;send_eventand batch items may also supply the visitor'suserAgentand trusted server-sideipin the payload.Analytics URL filters and page metrics use
path; the oldurlmetric was removed. Host aggregation useshostname.Supported time units are
minute,hour,day,month, andyear.get_event_seriesandget_sessions_weeklyrequire an IANA timezone.list_reportsrequireswebsiteId; report execution sends{ websiteId, type, filters, parameters }.Team website membership is changed through
transfer_website; the removed team-website POST/DELETE routes are not exposed.
Development
npm install
npm testnpm test builds the TypeScript server, checks Cloud/self-hosted URL and auth
behavior, verifies raw public batch requests and the 2FA login flow, and
validates key MCP schemas.
Official references
License
MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mikusnuz/umami-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server