Hitsteps
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@HitstepsShow me my website's analytics for the last 7 days."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Hitsteps MCP Server
Public metadata and setup notes for the Hitsteps remote Model Context Protocol server.
Hitsteps exposes a hosted MCP server for analytics and website operations:
https://www.hitsteps.com/mcp/The current registry metadata release is 1.1.6. This repository is
intentionally small: it contains public registry metadata and setup notes, not
the production Hitsteps PHP service, private OAuth keys, reviewer accounts,
customer data, or deployment credentials.
Install
Use the full Hitsteps setup and security guide:
https://www.hitsteps.com/plugin/?type=mcpAvailable client paths:
VS Code and GitHub Copilot: use the GitHub MCP Registry.
Cursor: use the Hitsteps Cursor Directory listing.
Claude: use the Claude Connector Directory listing.
ChatGPT: the directory listing is coming soon; add
https://www.hitsteps.com/mcp/as a custom MCP server for now.Google Antigravity and other clients: add the remote Streamable HTTP endpoint below and complete Hitsteps OAuth.
Google Antigravity configuration:
{
"mcpServers": {
"Hitsteps": {
"serverUrl": "https://www.hitsteps.com/mcp/"
}
}
}The same managed endpoint is used by every client. There is no local package, Node.js process, desktop bridge, SSE worker, or separate customer-hosted service to install.
Related MCP server: mcp-opiny
Registry Metadata
The root server.json file is the canonical public metadata for
MCP registries and galleries. It declares:
registry name:
com.hitsteps/analytics-operationsdisplay title:
Hitsteps Analytics and Operationstransport: Streamable HTTP
remote endpoint:
https://www.hitsteps.com/mcp/icon:
https://www.hitsteps.com/favicon.pngdocumentation:
https://www.hitsteps.com/plugin/?type=mcpcurrent metadata version:
1.1.6
The com.hitsteps/analytics-operations name is domain-authenticated. Keep
this identity unless Hitsteps intentionally publishes a second
GitHub-namespaced entry such as io.github.Hitsteps/....
Authentication and Safety
Hitsteps uses OAuth for public MCP access. Users sign in on Hitsteps and approve the requested scopes before the client receives a token. The client configuration contains only the endpoint URL; never paste a Hitsteps password, tracking API key, OAuth token, private key, or reviewer credential into a client configuration or this repository.
The server rechecks the signed-in account, sub-user permissions, visible websites, license state, feature limits, and granted OAuth scopes on every request. Write operations require their specific scope, explicit confirmation, and an idempotency key. Results are privacy-shaped and do not expose raw SQL, private keys, raw visitor-profile dumps, or session-replay video.
Validation
Validate metadata before publishing:
mcp-publisher validatePublish from this repository only after domain authentication is available to the publisher environment. Private signing keys and domain-authentication material must stay outside this repository.
Security Reports
Please report suspected vulnerabilities through the Hitsteps contact page. Do not open public issues containing OAuth tokens, customer analytics data, account credentials, private keys, reviewer credentials, or raw request logs with sensitive values.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Remote MCP server for HTML-to-PDF and screenshots with OAuth and API-key auth.
Access Kernel's cloud-based browsers and app actions via MCP (remote HTTP + OAuth).
Streamable HTTP MCP server for Google Calendar and Sheets with OAuth login.
Query, browse, and automate OmegaAI workspaces from any MCP client. Streamable HTTP with OAuth 2.0.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables MCP client interaction via streamable HTTP, providing example tools (echo, getPostsByUser) and resources (posts, users) with pluggable authentication providers.6MIT
- FlicenseNot gradedqualityDmaintenanceEnables interaction with the Opiny API through MCP, supporting both local STDIO and remote HTTP Stream transports.-
- AlicenseNot gradedqualityCmaintenanceWraps Okta's stdio MCP server to be accessible remotely via Streamable HTTP with OAuth authentication, and adds native Okta Admin API tools for application management.Apache 2.0
- AlicenseNot gradedqualityBmaintenanceBridge that lets stdio-only MCP clients connect to remote MCP servers with OAuth and other auth support, enabling local clients to use remote, authorized MCP servers.24353MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Hitsteps/MCP'
If you have feedback or need assistance with the MCP directory API, please join our Discord server