PostHog MCP Server

Official hosted MCP access to PostHog analytics, feature flags, experiments, and further product tools in an AI client.

Description

The PostHog MCP Server is PostHog’s official hosted Model Context Protocol endpoint. It connects MCP-capable clients to an existing PostHog account so a person can ask natural-language questions and use selected platform tools. The official documentation names PostHog Desktop, Claude Code, Claude Desktop, Cursor, Codex, VS Code, Windsurf, and Zed, among others. The product link in this entry therefore leads to PostHog’s MCP documentation. The listed PostHog/mcp repository is the official, MIT-licensed historical repository address; its README points to the current service, which has moved into the PostHog monorepo under services/mcp. Immediately before this seed on 2026-09-08, the GitHub API reported exactly 151 stars for that archived redirect repository. That number is a point-in-time popularity signal only, not evidence of quality, security, or suitability.

Product analytics, flags, and experiments

According to PostHog, the server can expose analytics and SQL queries, dashboards, experiments, feature flags, surveys, session replay, and error tracking. Documented examples include a trends query for daily unique signups, creation of a feature flag with a rollout and rules, and creation of an A/B experiment with variants, a metric, and an associated flag. The documentation also covers error triage, stack-trace queries, support-ticket triage, and CDP destinations. This does not mean every connection should automatically receive every capability: the current service can be scoped to product areas through features and to exact tool names through tools. Starting with a small read-only allowlist such as analytics, dashboards, or selected flags reduces both context volume and operational risk.

Hosted endpoint and local paths

The regular product service is hosted at https://mcp.posthog.com/mcp; according to PostHog, its authentication service routes accounts to the appropriate US or EU data region. This entry is consequently classified as remote. The official quick setup installs client configuration through npx @posthog/wizard@latest mcp add. The manual desktop configuration uses local npx mcp-remote as a stdio bridge to the hosted endpoint; that is not a locally running PostHog server and does not alter the data residency of the PostHog request. For custom Node clients, the current repository documents Streamable HTTP with Bearer authentication, an Accept header for JSON and SSE, and the normal MCP initialize lifecycle. A local Hono server using pnpm run dev, Redis, and port 8787 is documented only as a development path for the source project. It is not a simple self-hosting promise for normal product access.

Keys, project access, and write actions

The manual path requires a personal PostHog API key using the MCP Server preset and sends it as a Bearer token. Such a key and its effective rights open access to the PostHog organization and the project selected in the client. Store it only in secret management or the local client environment, never in a repository, prompt, chat transcript, screenshot, ticket, or committed configuration. Rotate or revoke it if exposure is possible. According to the documentation, the server can read and write across PostHog products. Feature flags, experiments, issue status, assignment rules, dashboards, CDP configuration, or other workspace objects can therefore change external state. An instruction embedded in an event name, error text, session replay, support ticket, or dashboard is untrusted data, not approval. Begin with reads, verify the target project and object ID in the PostHog UI, and require explicit human confirmation of each mutation and its expected effect.

Privacy and the model path

PostHog describes the MCP service as a proxy to the relevant PostHog instance: it does not store analytics data in the MCP server, queries run against the project, and results return directly to the AI client. Session context such as the active organization or project is stored temporarily; the current repository describes a cache keyed by the API-key hash. The service runs, according to the repository, in US and EU Kubernetes clusters; a Cloudflare Worker in front authenticates and routes but does not store sensitive data. That limits the server path, but it does not answer the model path: the connected MCP client may send tool results – including event properties, user identifiers, funnels, SQL output, replay context, or error context – to its chosen model provider. Review client, model, retention, training, DPA, and enterprise settings separately; query only required dates and fields; and redact personal or confidential data before onward transfer.

License, cost, and limits

The historical PostHog/mcp repository contains the MIT license and is archived; the current source is in the official monorepo. PostHog calls connecting and making MCP tool calls free, but notes that certain internally AI-powered tools can incur PostHog AI spend and are available only when AI data processing is enabled. This entry deliberately provides no fixed prices; check PostHog for current terms. Automation does not replace data interpretation, privacy review, approval, or change control.

FAQ

Can the server change feature flags or experiments? Yes. Official examples cover creating a flag and an A/B experiment. Scope tools and require concrete human approval before every write.

Does a local mcp-remote configuration mean the server is local? No. It is a local stdio bridge to PostHog’s hosted endpoint. The documented local Hono and Redis stack is a source-project development path.

Requirements

A PostHog account, a personal API key with the MCP Server preset or OAuth login through a supported client, and an MCP-capable client.

Installation instructions

Quick start: npx @posthog/wizard@latest mcp add. Alternatively configure the hosted endpoint https://mcp.posthog.com/mcp with a personal Bearer token in the client. Local mcp-remote is only the stdio bridge; use Streamable HTTP with JSON and SSE Accept headers for custom Node clients.

npx @posthog/wizard@latest mcp add

Authentication

OAuth through supported clients or a personal PostHog API key with the MCP Server preset as a Bearer token. Store keys only locally or in a secret store.

Required access permissions

The key and selected project determine access. According to PostHog documentation, the server can read and write; scope features and individual tools and confirm mutations with a human.

Transmitted or stored data

The hosted MCP service proxies queries to the PostHog instance; according to PostHog, analytics data is not stored in the MCP server. Temporary session context can be stored. The AI client can transmit tool results to its model provider.

Security risks

Personal API keys, broad project access, write-capable product actions, personal user and event data, prompt injection in tool results, and a separate client-to-model-provider data path.

License and costs

License
MIT
Cost
free

PostHog describes connecting and MCP tool calls as free. Some internally AI-powered tools can incur PostHog AI spend; check PostHog for current terms.

Alternatives

Not recorded yet.

At a glance

Provider
PostHog
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
GitHub stars
151
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients