The PostHog connector.
Product analytics, feature flags and HogQL. Connect once with your own key. Every agent your team runs reads the same 6 tools under one permission model.
How access is governed
6
Read tools
Open by default. They run when called, and every call is logged with the endpoint, tool and capability.
0
Write tools
PostHog exposes no write tools. Nothing it does mutates external state.
0
Destructive tools
PostHog defines no destructive tools. Nothing here deletes data.
Defaults come from the capability on each tool definition, and an admin can tighten or open any tool individually. The endpoint's capability ceiling can only tighten that policy. An endpoint scoped to read never surfaces a write tool.
Every PostHog tool
6 tools, named as the agent sees them.
- list_insightsread
List the saved insights (charts) in the project. Start here to find what the team already tracks; the `id` each hit returns is what get_insight takes. Results carry no computed numbers — use get_insight for those.
- get_insightread
Get one saved insight including its query definition and its cached result rows. Takes the numeric `id` from list_insights. Set `refresh` when the cached numbers are stale and you need PostHog to recompute.
- list_feature_flagsread
List feature flags with their rollout filters and active state. Use it to answer "is flag X on, and for whom", or to audit stale flags. `key` is the string your application code checks.
- run_queryread
Run a read-only HogQL (SQL) query against the project's event data and return the rows. This is the tool for ad-hoc numbers no saved insight covers, e.g. SELECT event, count() FROM events WHERE timestamp > now() - INTERVAL 7 DAY GROUP BY event ORDER BY 2 DESC. Always add a LIMIT. Column names come back in `columns`.
- list_eventsread
List raw recent events, newest first. Use it to confirm an event is actually arriving and to inspect its property payload while debugging tracking. For aggregation use run_query instead.
- list_cohortsread
List the saved cohorts (user segments) and how many people are in each. Use it to see how the team segments users before writing a run_query that filters to one.
Use it from any agent
The same PostHog tools reach Claude Code, Cursor, Claude Desktop or your own agent through one MCP endpoint. The endpoint is scoped to a group, the token is issued per group and revocable from the dashboard, and an allowed-tool list and capability ceiling limit what it exposes. Reads run. Gated writes refuse unless an admin opens them. Destructive tools remain unavailable over MCP.
{
"mcpServers": {
"growth": {
"type": "http",
"url": "https://app.notara.ai/mcp/g/acme/growth",
"headers": {
"Authorization": "Bearer ntr_mcp_xxxxxxxxxxxxxxxxxxxx"
}
}
}
}The URL and token are placeholders. Real endpoints are issued per group from the dashboard.
Setup
- 01
Create a PostHog Personal API Key in your PostHog account (where to find it). The key is yours: Notara stores it encrypted and never sees a bill.
- 02
Paste it into the Notara dashboard. Credentials can be scoped to the workspace or to one person.
- 03
The tools appear with their capability defaults already set. Tighten or open any of them per tool, then invite the agent to a channel or issue an MCP token.
Connect PostHog once. Use it everywhere.
Use Notara directly, or bring us the workflow that needs to be redesigned and built.
