Ask your analytics a question instead of hunting for the report.
You already have an editor open with an agent in it. Connect StepMetrics once and that agent can answer what happened on your site, using the same numbers your dashboard shows.
Ask from your editor
Opening a dashboard is a context switch, and the report you want is usually three filters deep. With StepMetrics connected over MCP, you ask in the conversation you are already having: which pages gained traffic this week, where signups drop out, whether that spike was bots, what a visit looked like before someone left.
The agent picks the right query itself. You do not have to know which report holds the answer, which is most of what makes an analytics tool tiring to use.
Same numbers as the dashboard
This is the part that decides whether any of it is worth trusting. The MCP tools call the same query functions the dashboard calls. Not a copy of the logic, the same code. So "visitors" means one thing in this product, and a number your agent reads back is the number on the screen.
It is enforced by tests rather than by care, including one whose name is MCP and REST cannot disagree. An agent that quietly invents a second definition of a metric is worse than no agent, because you would act on it.
Read-only access
A read key is offered twenty-eight tools and not one of them creates, deletes or mints anything. That is a property of what gets registered, not a rule the model is asked to respect. "The model would not do that" is not a security control.
The exceptions are the ignore list, which can add or remove an address so you can stop counting your own visits by asking; your Dashboard page, whose shared metrics and charts an agent can build for you; the funnels, rates such as signups per 1,000 engaged visitors, and event checks that warn you when an event stops arriving, which an agent can set up while it works out why people leave; and revoking one of your workspace's keys, say one you pasted somewhere by mistake. Those tools exist only for an edit key - the kind the dashboard's Connect agent screen gives your agent - or an admin key. An edit key still cannot create keys, revoke an admin key, delete your data or sites, or touch billing, and a read key never sees those tools at all.
Scoped to your account
Which sites a key can read comes from the key itself, never from something the agent passes in. Ask about a site belonging to someone else's account and the answer is that it does not exist, which is the same answer you get for a site that genuinely does not exist. There is nothing to probe.
What you can ask
Traffic and visitors over any period, with the previous period alongside. Top pages and where visitors came from, including what your Direct traffic is made of. Live activity. Conversions, rates and funnel drop-off. How many new visitors came back within 7 and 30 days, by source. A breakdown by country, device or browser. The recorded pageviews and events inside a single visit. Which addresses you are ignoring. Every one of these can be narrowed to a segment, so "only mobile visitors from Hacker News" is a question you can ask out loud.
If you build with models yourself, the same connection reports your own agent runs: model calls, tool calls, tokens and what they cost. Agent and LLM cost tracking.
Supported clients
Claude Code and Cursor have short setup pages here, and any MCP client can connect the same way. Your agent can also install the tracker on your site, so setup and the first question live in one conversation.
Connect Claude Code · Connect Cursor · Connection details in the docs
Included on every plan
Read-only MCP access comes with Free, along with 200,000 events a month. It is not an upgrade and there is no per-seat charge for pointing an agent at your own data.
Try it on your site.
Add your first site for free. See where visitors come from, what they look at, and how many take the next step.
No credit card required.