PostHog for AI agents

PostHog is an open-source product analytics platform for tracking user behavior, running experiments, and understanding funnels. Product teams use it to decide what to build next and reduce churn. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

AnalyticsAPI keyMCP + RESTposthog.com
AUDIT LOG · POSTHOGPOLICY: acme-support
09:41:07 · claude · u_8f2read
posthog.list_alerts
List alerts for project✓ allowed · 212ms
09:41:08 · claude · u_8f2read
posthog.get_dataset
Get dataset details✓ allowed · 164ms
09:41:09 · claude · u_8f2write
posthog.create_alert
Create alert✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
posthog.delete_alert
Delete alert✕ blocked · policy: deny
EVERY POSTHOG CALL, ON THE RECORD
01 · USE CASES

What agents do in PostHog.

01

Capture a product event

Send a tracked event, like a feature click, so it shows up in funnels and dashboards.

02

Check feature flag status read-only

Look up a feature flag's rollout state before deciding whether to expand it.

03

Bulk delete feature flags with approval

Remove a batch of unused feature flags only after an engineering lead confirms the cleanup.

02 · ACTIONS

507 PostHog actions, graded by risk.

Every PostHog action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

250

Look things up. Allowed by default.

  • posthog.get_dataset
    Get dataset details
  • posthog.list_alerts
    List alerts for project
  • posthog.get_datasets
    Get Datasets
  • posthog.get_evaluation
    Get Evaluation
  • posthog.get_web_vitals
    Get web vitals
  • posthog.list_endpoints
    List endpoints for project
  • posthog.list_notebooks
    List notebooks with filters and pagination
  • posthog.get_app_metrics
    Retrieve app metrics by ids
  • posthog.get_evaluations
    Get evaluations for project
  • posthog.get_file_system
    Get file system
  • posthog.get_logs_values
    Get log field values
  • posthog.get_conversation
    Get conversation
  • posthog.get_dataset_item
    Get Dataset Item
  • posthog.get_hog_function
    Get hog function
  • posthog.get_organization
    Fetch organization details by uuid
  • posthog.get_product_tour
    Get product tour
+ 234 MORE

write

197

Create and change things. Allow, or ask the user first.

  • posthog.create_alert
    Create alert
  • posthog.create_batch
    Create Batch
  • posthog.update_alert
    Update alert (full replacement)
  • posthog.create_dataset
    Create Dataset
  • posthog.update_dataset
    Update Datasets
  • posthog.create_endpoint
    Create endpoint
  • posthog.update_endpoint
    Update endpoint
  • posthog.create_ai_insight
    Create Max AI insight and query
  • posthog.create_evaluation
    Create Evaluation
  • posthog.update_evaluation
    Update evaluation
  • posthog.update_experiment
    Update experiment details
  • posthog.create_file_system
    Create file system
  • posthog.create_logs_export
    Create Logs Export
  • posthog.create_person_path
    Create person path with format option
  • posthog.update_file_system
    Update file system
  • posthog.create_batch_export
    Create batch export
+ 181 MORE

destructive

60

Delete, cancel or archive. Ask first, or deny outright.

  • posthog.delete_alert
    Delete alert
  • posthog.delete_person
    Delete person and optionally associated events
  • posthog.delete_survey
    Delete survey by id
  • posthog.delete_insight
    Delete insight
  • posthog.delete_endpoint
    Delete endpoint
  • posthog.delete_file_system
    Delete file system
  • posthog.delete_organization
    Delete organization by uuid
  • posthog.delete_product_tour
    Delete product tours
  • posthog.delete_project_query
    Remove specific project query
  • posthog.delete_project_member
    Remove explicit project member by uuid
  • posthog.delete_web_experiment
    Delete web experiment
  • posthog.delete_person_property
    Delete person property
  • posthog.delete_role_membership
    Remove rolemembership by uuid
  • posthog.archive_survey_response
    Archive survey response
  • posthog.cancel_project_insights
    Cancel insights for a project
  • posthog.delete_insight_variable
    Delete insight variables
+ 44 MORE
03 · HOW IT WORKS

PostHog in three steps.

  1. 01Your users connect PostHogThey add their PostHog api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create alert” can wait for the user, and “delete alert” can be denied outright.
  3. 03Any agent can actYour agent calls PostHog through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('posthog', {
  read: 'allow',
  write: 'ask',        // create_alert
  destructive: 'deny',  // delete_alert
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How PostHog connects.

Users add their PostHog api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same PostHog connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use PostHog from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

PostHog and Arc0, answered.

Q01

Can I use PostHog with Claude, ChatGPT or Cursor?

Yes. Connect PostHog to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the PostHog actions you allow.

Q02

How do users connect PostHog?

Users add their PostHog api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which PostHog actions can my agent take?

507 in total: 250 read, 197 write and 60 destructive, such as “create alert”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in PostHog?

Yes. Actions like “delete alert” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call PostHog too?

Yes. The same PostHog connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug PostHog into your agent.

Your users connect PostHog once, under your brand. Your agent gets 507 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan