MCP server
Let your own assistant answer questions from your analytics. Your key, your model, your data — trckable pays for nothing and sends nothing anywhere.
npx trckable mcpIt has no dependencies, and every tool is read-only.
Connecting it
Create a read-only key in your account → API keys, then add the server to your assistant's configuration:
{
"mcpServers": {
"trckable": {
"command": "npx",
"args": ["-y", "trckable", "mcp"],
"env": {
"TRCKABLE_HOST": "https://stats.example.com",
"TRCKABLE_API_KEY": "tkb_live_…"
}
}
}
}The tools
| Tool | |
|---|---|
trckable_sites | Which sites exist |
trckable_overview | Visitors, pageviews, bounce, session time, revenue |
trckable_sources | Channels, referrers, campaigns |
trckable_pages | Entry, top and exit pages |
trckable_audience | Countries, devices, browsers |
trckable_goals | Goals and conversion |
trckable_revenue | Money, by any dimension |
trckable_realtime | Who is on the site now |
Dates follow each site's timezone. Periods can be relative — 7d, mtd,
lastmonth — or exact from and to dates, with an optional comparison.
Why it is safe to point a model at this
Paths, referrers, UTM parameters and goal properties are written by whoever visits your site. That makes them attacker-controlled text, and an assistant reading them is exactly the situation prompt injection was invented for.
Two things make it safe rather than hopeful:
- Every tool is read-only. There is no write path to abuse, so the worst a poisoned referrer can achieve is a wrong sentence.
- Tool results are fenced as untrusted data, with a nonce, so text that looks like an instruction is presented as what it is: a row from your database.
The model never writes SQL and never chooses which site it can see. The server enforces scoping, not the prompt.
Asking inside trckable
The same tool layer will power an optional Peek panel in the dashboard. It is off until you add an AI key of your own — Anthropic, any OpenAI-compatible endpoint, or a local Ollama — so it costs nothing and weighs nothing until you want it. It is not built yet; the MCP server is, and it works today with any assistant you already use.