<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>HitKeep Blog</title><description>Release announcements, engineering deep dives, and deployment guides from HitKeep — single-binary, privacy-first web analytics.</description><link>https://hitkeep.com/</link><item><title>How to Build Better Google Reporting for Stakeholders</title><link>https://hitkeep.com/blog/how-to-build-better-google-reporting-for-stakeholders/</link><guid isPermaLink="true">https://hitkeep.com/blog/how-to-build-better-google-reporting-for-stakeholders/</guid><description>Build better Google reporting for stakeholders with clearer metrics, Search Console insights, AI traffic context, and decision-ready dashboards.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Stakeholders rarely need more Google data. They need clearer decisions.&lt;/p&gt;
&lt;p&gt;Most teams end up with a dashboard set that is technically rich but hard to act on: one view for SEO, one for marketing, one for executives, and a lot of unannotated changes. Better reporting starts by building one clear decision system, not a bigger set of charts.&lt;/p&gt;
&lt;h2 id=&quot;start-with-the-audience-not-the-dashboard&quot;&gt;Start with the audience, not the dashboard&lt;/h2&gt;
&lt;p&gt;Each stakeholder asks a different decision question. A single combined view rarely works for everyone.&lt;/p&gt;









































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Stakeholder&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Primary question&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Best reporting angle&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Metric focus&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Executive team&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Are we moving in the right direction?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Outcomes and risk&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Conversions, conversion quality, qualified traffic mix&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Marketing leadership&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Which channels need more or less focus?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Channel outcomes and quality&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Sources, assisted conversions, landing-page performance&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;SEO team&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Is search demand improving in meaningful ways?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Discovery and relevance&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Queries, clicks, CTR, indexed pages&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Content team&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Which pages are helping and which are stalling?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Content-to-outcome paths&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Entrances, engagement, conversion steps&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Agency or consultant&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;What changed from this period?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Before/after decision evidence&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Baselines, annotations, uplift, recommendations&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;This mapping should drive every report section. If a chart does not help someone make a decision, move it to an appendix.&lt;/p&gt;
&lt;h2 id=&quot;build-a-reporting-narrative-before-selecting-charts&quot;&gt;Build a reporting narrative before selecting charts&lt;/h2&gt;
&lt;p&gt;A stakeholder report should follow a consistent order: status, causes, risks, actions.&lt;/p&gt;
&lt;p&gt;For example, do not start with traffic and hope the reader infers impact. Start with a simple interpretation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Traffic mix improved, but growth is driven by informational demand,&lt;/li&gt;
&lt;li&gt;conversion contribution stayed flat,&lt;/li&gt;
&lt;li&gt;next actions should focus on pages and channels that move qualified outcomes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Use the same flow every cycle:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;What changed in outcomes?&lt;/li&gt;
&lt;li&gt;Which source explained the change?&lt;/li&gt;
&lt;li&gt;Which decision should happen next?&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;use-search-console-as-discovery-context-not-a-complete-story&quot;&gt;Use Search Console as discovery context, not a complete story&lt;/h2&gt;
&lt;p&gt;Search Console is often treated as an SEO utility. It is better used as a demand context layer.&lt;/p&gt;
&lt;p&gt;Use it to track:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;search demand and click-through changes,&lt;/li&gt;
&lt;li&gt;query intent shifts,&lt;/li&gt;
&lt;li&gt;and landing-page intent gaps between discovery and conversion.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But do not treat it as the whole report. It does not answer what happens after a click. Pair it with on-site analytics and outcome metrics so your team can connect demand to business results.&lt;/p&gt;
&lt;h3 id=&quot;suggested-search-console-reporting-structure&quot;&gt;Suggested Search Console reporting structure&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Demand layer:&lt;/strong&gt; impressions, clicks, CTR, and query intent.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Bridge layer:&lt;/strong&gt; landing pages, engagement, campaign context.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Outcome layer:&lt;/strong&gt; conversions, funnel completion, and business value.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That structure shows whether search visibility is producing outcomes or only activity.&lt;/p&gt;
&lt;h2 id=&quot;keep-definitions-stable-across-ga-and-analytics-signals&quot;&gt;Keep definitions stable across GA and analytics signals&lt;/h2&gt;
&lt;p&gt;If every team uses a different definition of “users,” “sessions,” or “conversion,” trust decays quickly.&lt;/p&gt;

























&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Metric&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Recommended definition&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Visits or sessions&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;A bounded interaction path in your chosen measurement model&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Engaged sessions&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;A session meeting the engagement criteria in your platform&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Conversion&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;A named outcome approved by the reporting owner&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Channel mix&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Source attribution policy, documented per channel&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;Document definitions in the report before publishing results.&lt;/p&gt;
&lt;h2 id=&quot;separate-traffic-signals-that-mean-different-things&quot;&gt;Separate traffic signals that mean different things&lt;/h2&gt;
&lt;p&gt;In 2026 reporting, one number is no longer enough. Use three streams and keep them separate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Rendered visits:&lt;/strong&gt; normal browser sessions that executed your tracker.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI-referred traffic:&lt;/strong&gt; visits introduced by AI or assistant referrers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI crawler fetches:&lt;/strong&gt; requests that may not represent human sessions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A cleaner report does not combine these into one “AI traffic” total. Keep them distinct and explain what each stream can and cannot prove.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-ai-visibility.DPXf9_ks_Z2apQEG.webp&quot; alt=&quot;HitKeep AI Visibility screen separating AI-referred visits and crawler fetches by assistant, operator, and resource type&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;HitKeep keeps AI-referred visits and crawler fetches visible as separate signals, so stakeholders do not mistake crawler activity for audience growth.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;use-recommendation-tables-not-only-raw-tables&quot;&gt;Use recommendation tables, not only raw tables&lt;/h2&gt;
&lt;p&gt;A useful report should end with action.&lt;/p&gt;













































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Section&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Include&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Decision it should support&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Executive summary&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;3 wins, 3 risks, 3 actions&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Continue, adjust, escalate&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Goal progress&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Actual vs target by owner&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Are we on pace?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Search visibility&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Query mix and click health&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Is demand moving correctly?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Traffic quality&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Source mix and engagement trend&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Are we attracting the right audience?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Conversions&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Goals, funnel health, assisted channels&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Where should the team improve next?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;AI and emerging sources&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;AI referrals and crawler activity&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Is discovery quality changing?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Recommendations&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Ranked actions with owners&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;What should happen this cycle?&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;The key is restraint. If someone needs deeper detail, provide appendices.&lt;/p&gt;
&lt;h2 id=&quot;build-a-repeatable-reporting-rhythm&quot;&gt;Build a repeatable reporting rhythm&lt;/h2&gt;
&lt;p&gt;Most teams benefit from two cadences:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Weekly short updates for execution and operations,&lt;/li&gt;
&lt;li&gt;Monthly stakeholder summaries for interpretation and decisions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A simple process is enough:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Review anomalies and tracking changes first.&lt;/li&gt;
&lt;li&gt;Confirm definitions and attribution assumptions.&lt;/li&gt;
&lt;li&gt;Add the recommendation block and owners.&lt;/li&gt;
&lt;li&gt;Publish a short decision summary at the end.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;keep-attribution-honest&quot;&gt;Keep attribution honest&lt;/h2&gt;
&lt;p&gt;Attribution is useful when its limitations are explicit.&lt;/p&gt;
&lt;p&gt;Use first-touch for acquisition understanding, last-touch for closing behavior, and outcome-based context for final recommendations. Do not pretend one metric is “the” truth.&lt;/p&gt;
&lt;h2 id=&quot;keep-an-annotation-log&quot;&gt;Keep an annotation log&lt;/h2&gt;
&lt;p&gt;Without annotations, every spike becomes noise and every dip becomes a mystery.&lt;/p&gt;
&lt;p&gt;Track campaign changes, tracking config changes, product releases, search updates, consent updates, and major site changes. That log is often the difference between a useful report and a long argument.&lt;/p&gt;
&lt;h2 id=&quot;build-from-one-reporting-workflow&quot;&gt;Build from one reporting workflow&lt;/h2&gt;
&lt;p&gt;Teams that switch between GA and privacy-first analytics can still use this framework. The practical requirement is consistency:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;one metric dictionary,&lt;/li&gt;
&lt;li&gt;one reporting cycle,&lt;/li&gt;
&lt;li&gt;explicit source mapping,&lt;/li&gt;
&lt;li&gt;and explicit caveats for AI-mediated and crawler-related behavior.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Need a platform that supports clear reporting with Search Console imports, conversion reporting, AI visibility separation, and open exports? &lt;a href=&quot;https://hitkeep.com/&quot;&gt;Use HitKeep&lt;/a&gt;.&lt;/p&gt;</content:encoded></item><item><title>HitKeep 2.13.0: Reports, Social Sign-In, and a Typed Tracker SDK</title><link>https://hitkeep.com/blog/hitkeep-2-13-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-13-0/</guid><description>HitKeep 2.13.0 adds scheduled reports, social sign-in, the typed @hitkeep/tracker SDK, prerender-safe tracking, and separate control and analytics data planes.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;If your team sends analytics to clients or stakeholders, HitKeep 2.13.0 replaces a handful of email-frequency switches with reports you can name, scope, schedule, preview, and audit. Each report has an owner, preset, sites, recipients, local delivery time, next run, and delivery history. External recipients can confirm delivery without receiving dashboard access.&lt;/p&gt;
&lt;p&gt;The same release adds Google, GitHub, and Microsoft sign-in, publishes the typed &lt;code&gt;@hitkeep/tracker&lt;/code&gt; package for framework applications, and prevents speculative prerenders from sending analytics before activation. Traffic exclusions now span instance, team, and site scopes, while default-tenant analytics move out of the shared control database and into an isolated tenant file.&lt;/p&gt;
&lt;p&gt;DuckDB operation also gains serialized checkpoints and narrow, evidence-preserving recovery paths. Country, city, provider, and ASN lookups move to block-addressable embedded assets so the runtime can decode bounded portions on demand. The dashboard moves to the MIT-licensed OptimusUI component stack so HitKeep’s UI foundation remains inspectable, modifiable, and redistributable as open source.&lt;/p&gt;
&lt;p&gt;The dashboard also brings AI crawler, AI-referred, and assistant activity into one AI Agents view. The release improves the edges around that experience too: route-critical startup failures now have a reloadable recovery page, and the login screen explains whether access ended because you signed out or because the session expired.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-ai-agents-traffic.KsPy1z6N_ZOTGpN.webp&quot; alt=&quot;HitKeep AI Agents dashboard with AI request, referral, crawl, and pageview analytics&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The canonical dashboard view combines AI requests, referrals, crawl depth, pageviews, and assistant activity in one report.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;aside aria-label=&quot;Breaking change: migrate report API clients first&quot; class=&quot;starlight-aside starlight-aside--danger&quot;&gt;&lt;p class=&quot;starlight-aside__title&quot; aria-hidden=&quot;true&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; class=&quot;starlight-aside__icon astro-xbjxoznu&quot; width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;currentColor&quot; style=&quot;--sl-icon-size: 1em;&quot;&gt;&lt;path d=&quot;M12 7a1 1 0 0 0-1 1v4a1 1 0 0 0 2 0V8a1 1 0 0 0-1-1Zm0 8a1 1 0 1 0 0 2 1 1 0 0 0 0-2Zm9.71-7.44-5.27-5.27a1.05 1.05 0 0 0-.71-.29H8.27a1.05 1.05 0 0 0-.71.29L2.29 7.56a1.05 1.05 0 0 0-.29.71v7.46c.004.265.107.518.29.71l5.27 5.27c.192.183.445.286.71.29h7.46a1.05 1.05 0 0 0 .71-.29l5.27-5.27a1.05 1.05 0 0 0 .29-.71V8.27a1.05 1.05 0 0 0-.29-.71ZM20 15.31 15.31 20H8.69L4 15.31V8.69L8.69 4h6.62L20 8.69v6.62Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;Breaking change: migrate report API clients first&lt;/p&gt;&lt;div class=&quot;starlight-aside__content&quot;&gt;&lt;p&gt;HitKeep 2.13.0 removes &lt;code&gt;GET /api/user/report-subscriptions&lt;/code&gt;, &lt;code&gt;PUT /api/user/report-subscriptions/digest&lt;/code&gt;, and &lt;code&gt;PUT /api/user/report-subscriptions/sites/{site_id}&lt;/code&gt; after automatically migrating stored report settings. The &lt;code&gt;DigestSubscription&lt;/code&gt;, &lt;code&gt;SiteReportSubscription&lt;/code&gt;, and &lt;code&gt;ReportSubscriptions&lt;/code&gt; OpenAPI schemas are also removed. Move integrations to &lt;code&gt;/api/reports&lt;/code&gt; and regenerate clients from the 2.13 OpenAPI document before upgrading.&lt;/p&gt;&lt;/div&gt;&lt;/aside&gt;
&lt;aside aria-label=&quot;Breaking change: default-tenant data migration&quot; class=&quot;starlight-aside starlight-aside--danger&quot;&gt;&lt;p class=&quot;starlight-aside__title&quot; aria-hidden=&quot;true&quot;&gt;&lt;svg aria-hidden=&quot;true&quot; class=&quot;starlight-aside__icon astro-xbjxoznu&quot; width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;currentColor&quot; style=&quot;--sl-icon-size: 1em;&quot;&gt;&lt;path d=&quot;M12 7a1 1 0 0 0-1 1v4a1 1 0 0 0 2 0V8a1 1 0 0 0-1-1Zm0 8a1 1 0 1 0 0 2 1 1 0 0 0 0-2Zm9.71-7.44-5.27-5.27a1.05 1.05 0 0 0-.71-.29H8.27a1.05 1.05 0 0 0-.71.29L2.29 7.56a1.05 1.05 0 0 0-.29.71v7.46c.004.265.107.518.29.71l5.27 5.27c.192.183.445.286.71.29h7.46a1.05 1.05 0 0 0 .71-.29l5.27-5.27a1.05 1.05 0 0 0 .29-.71V8.27a1.05 1.05 0 0 0-.29-.71ZM20 15.31 15.31 20H8.69L4 15.31V8.69L8.69 4h6.62L20 8.69v6.62Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;Breaking change: default-tenant data migration&lt;/p&gt;&lt;div class=&quot;starlight-aside__content&quot;&gt;&lt;p&gt;The first 2.13 startup moves default-tenant analytics from &lt;code&gt;hitkeep.db&lt;/code&gt; to &lt;code&gt;{data-path}/tenants/{default-tenant-id}/hitkeep.db&lt;/code&gt; and rewrites &lt;code&gt;hitkeep.db&lt;/code&gt; as the control plane. Back up the complete data path and provide enough free space for one source-database-sized tenant copy plus 512 MiB before upgrading.&lt;/p&gt;&lt;p&gt;The migration normally completes during that first startup. If automatic database recovery runs first, HitKeep exits intentionally and reports that a restart is required. Start the same 2.13 binary or container again so the mandatory split can run from a clean startup; do not switch back to an older release. After the split completes, downgrading to 2.12 or older is unsupported. Restore the complete pre-upgrade backup instead.&lt;/p&gt;&lt;/div&gt;&lt;/aside&gt;
&lt;h2 id=&quot;what-ships-in-hitkeep-2130&quot;&gt;What ships in HitKeep 2.13.0&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Configurable scheduled reports:&lt;/strong&gt; create personal or team reports with a named preset, selected or accessible sites, an IANA timezone, a local delivery time, and daily, weekly, or monthly cadence.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Stakeholder delivery without dashboard access:&lt;/strong&gt; team owners and admins can add confirmed external recipients. Consent is report-specific, expires, can be withdrawn, and does not create an account or grant site access.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Durable delivery operations:&lt;/strong&gt; preview content, send a test to yourself, inspect runs and recipient deliveries, retry failures, and distinguish SMTP acceptance from inbox delivery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Google, GitHub, and Microsoft sign-in:&lt;/strong&gt; enable only completely configured providers, use them for login or signup, link them to an existing account, and preserve invitations and MFA handoff.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Typed browser SDK:&lt;/strong&gt; install &lt;code&gt;@hitkeep/tracker&lt;/code&gt; from npm to initialize tracking, send custom and ecommerce events, manage component cleanup, and configure browser behavior without injecting a script tag.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prerender-safe collection:&lt;/strong&gt; defer pageviews, custom events, attribution, and Web Vitals until a speculative page activates, then use the activated URL and discard work for prerenders that never become visible.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Layered traffic controls:&lt;/strong&gt; apply CIDR, country, user-agent, or path exclusions at instance, team, or site scope, with inherited rules visible through effective API reads.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Safer DuckDB lifecycle:&lt;/strong&gt; serialize periodic, migration, backup, and shutdown checkpoints; retain recovery bundles before narrow repairs; and keep application WAL bypass behind explicit operator approval.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Separate default-tenant data plane:&lt;/strong&gt; migrate default analytics into its own tenant file, keep the control database metadata-only, and run all tenant catalogs through one attached DuckDB data-plane instance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Lower-overhead IP metadata:&lt;/strong&gt; decode validated country, city, provider, and ASN blocks on demand under bounded caches instead of inflating every embedded lookup table at startup.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Open-source dashboard foundation:&lt;/strong&gt; replace PrimeNG and PrimeIcons with OptimusUI, OptimusUI Themes, and OpenNG Icons under the MIT license.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI Agents dashboard:&lt;/strong&gt; combine AI requests, AI-referred visits, crawl depth, and pageview context with assistant activity and filterable evidence panels.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Conversion cohorts:&lt;/strong&gt; selecting a goal or funnel now filters dashboard KPIs, charts, dimensions, raw traffic, and exports; event-based goals can therefore measure a chosen custom event consistently across reports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Recoverable application states:&lt;/strong&gt; setup, dashboard bootstrap, and other route-critical failures show a safe error page with reload guidance, while ordinary component API errors remain local to their feature.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Accessible session-end feedback:&lt;/strong&gt; intentional sign-out and ended sessions return to login with distinct, announced status messages and safe return-URL handling.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security and dependency maintenance:&lt;/strong&gt; move Spamhaus refreshes to its JSON feeds, refresh the embedded denylist data, update Go and dashboard dependencies, fix high-severity frontend audit findings, and pin current GitHub Actions revisions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;One contributor workflow:&lt;/strong&gt; route setup, development sessions, screenshots, builds, smoke tests, and canonical QA through the repository-owned &lt;code&gt;hk&lt;/code&gt; platform and its developer MCP surface.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Release metadata that follows the artifact:&lt;/strong&gt; publish a checksummed configuration catalog with stable releases, then synchronize the public configuration reference and current-version facts only after release binaries and the Helm chart succeed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;important-platform-updates&quot;&gt;Important platform updates&lt;/h2&gt;
&lt;p&gt;HitKeep 2.13.0 also refreshes the foundations underneath the product features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;OptimusUI 1.0.0-rc.1:&lt;/strong&gt; the dashboard moves to &lt;a href=&quot;https://optimus.openng.org/&quot;&gt;OptimusUI&lt;/a&gt;, OpenNG’s &lt;a href=&quot;https://github.com/openng-org/optimus-ui&quot;&gt;community fork&lt;/a&gt; of the final MIT-licensed PrimeNG codebase. HitKeep now consumes the MIT-licensed OptimusUI components, themes, and OpenNG icon packages, keeping the shipped UI code open to inspection, modification, and redistribution.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Angular 22.0.8:&lt;/strong&gt; Angular framework and build packages move from 22.0.5 to 22.0.8, with Angular CDK moving to 22.0.6 and Angular ESLint to 22.1.0.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;duckdb-go v2.10505.0:&lt;/strong&gt; the embedded DuckDB driver moves from v2.10504.0 to v2.10505.0, with native bindings moving from v0.10504.0 to v0.10505.0. This sits alongside the serialized checkpoints and guarded recovery changes described below; HitKeep still embeds DuckDB in the single application binary.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Frontend runtime updates:&lt;/strong&gt; Web Vitals moves to 6.0, Tailwind CSS to 4.3.3, Scalar API Reference to 1.63.0, and the dashboard’s Node 24.18.0 and npm 12.0.1 requirements are pinned for reproducible installs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Backend maintenance:&lt;/strong&gt; compression, Stripe, mail, AI, cryptography, Google API, AWS SDK, gRPC, and related Go modules receive bounded dependency updates without adding a required external service.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These are implementation upgrades rather than new deployment dependencies. Self-hosted HitKeep remains one Go binary with the Angular dashboard, DuckDB, and NSQ embedded.&lt;/p&gt;
&lt;h2 id=&quot;a-typed-tracker-for-framework-applications&quot;&gt;A typed tracker for framework applications&lt;/h2&gt;
&lt;p&gt;&lt;code&gt;@hitkeep/tracker&lt;/code&gt; packages the same tracker core as &lt;code&gt;hk.js&lt;/code&gt; as a typed JavaScript module. It works with React, Next.js, Vue, Nuxt, Angular, Astro, and other bundler-based applications, with ESM and CommonJS entry points, included TypeScript declarations, and no runtime dependencies.&lt;/p&gt;
&lt;p&gt;Install the package and initialize it with the public URL or custom tracking domain that should receive browser ingest:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;sh&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;npm&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;install&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;@hitkeep/tracker&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;ts&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; { init, track } &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;@hitkeep/tracker&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;init&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;({ host: &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;https://analytics.example.com&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; });&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;track&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;signup_clicked&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, { plan: &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;pro&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; });&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;Initialization captures the first pageview and history-based SPA navigation by default. The same configuration can enable Web Vitals, disable individual automatic events, respect Do Not Track, or turn off automatic pageviews when an application wants to call &lt;code&gt;trackPageview()&lt;/code&gt; itself. Events called before &lt;code&gt;init()&lt;/code&gt; are kept in a bounded queue for the first initialization.&lt;/p&gt;
&lt;p&gt;Framework integrations can clean up listeners when their owning component unmounts. For React and the Next.js App Router, keep initialization in a client component:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;tsx&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;use client&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; { useEffect } &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;react&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; { cleanup, init } &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;@hitkeep/tracker&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;export&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;function&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Analytics&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;()&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; {&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;useEffect&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;()&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; {&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;    &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;init&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;({ host: &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;https://analytics.example.com&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; });&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;    &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;return&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; cleanup;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;}&lt;/span&gt;&lt;span style=&quot;--0:#889FB2;--1:#4D667B&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; []);&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;return&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#FF6A83;--1:#A24848&quot;&gt;null&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;}&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;Typed ecommerce helpers keep the event name and required purchase fields explicit:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;ts&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; { trackPurchase } &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;from&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;@hitkeep/tracker&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;trackPurchase&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;({&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;transaction_id: &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;order-1042&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;value: &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;49.9&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;currency: &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;EUR&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;items: [&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;    &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;{ item_id: &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;starter&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, item_name: &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;Starter plan&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, quantity: &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;1&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, price: &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;49.9&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; },&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;],&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;});&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;The package also exports visitor opt-out controls and typed helpers for &lt;code&gt;view_item&lt;/code&gt;, &lt;code&gt;add_to_cart&lt;/code&gt;, and &lt;code&gt;begin_checkout&lt;/code&gt;. It is versioned with HitKeep, so keep its major version aligned with the receiving instance. Site Settings now offers script-tag and npm installation methods with copyable examples.&lt;/p&gt;
&lt;p&gt;The package does not create a separate privacy model. It remains cookie-free by default, follows the same session storage, retry, Do Not Track, and payload behavior as &lt;code&gt;hk.js&lt;/code&gt;, and still requires a deployment-specific consent and ePrivacy assessment. See the &lt;a href=&quot;https://www.npmjs.com/package/@hitkeep/tracker&quot;&gt;&lt;code&gt;@hitkeep/tracker&lt;/code&gt; package&lt;/a&gt; and &lt;a href=&quot;https://hitkeep.com/guides/tracking/tracker-architecture/&quot;&gt;Tracker Architecture&lt;/a&gt; for the current boundary.&lt;/p&gt;
&lt;h3 id=&quot;speculative-pages-wait-for-activation&quot;&gt;Speculative pages wait for activation&lt;/h3&gt;
&lt;p&gt;Browsers can prerender a likely next page before the visitor actually opens it. HitKeep now recognizes both the current prerendering API and the legacy prerender visibility state. While a page is speculative, the tracker sends no pageview, custom event, or Web Vitals request.&lt;/p&gt;
&lt;p&gt;If the page activates, HitKeep sends the pageview first, reads campaign and QR attribution from the activated URL, and rebinds buffered events and Web Vitals to the activated path and page ID. The activation buffer is bounded, and cleanup discards it when a prerender never becomes visible. Because &lt;code&gt;hk.js&lt;/code&gt; and &lt;code&gt;@hitkeep/tracker&lt;/code&gt; share the same core, the fix applies to both installation methods.&lt;/p&gt;
&lt;h2 id=&quot;reports-become-first-class-definitions&quot;&gt;Reports become first-class definitions&lt;/h2&gt;
&lt;p&gt;The Reporting hub replaces separate digest and per-site switches with saved report definitions. Each row answers the questions an operator needs before trusting scheduled delivery: who owns the report, what it covers, who receives it, when it runs next, and how the last run ended.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/feature-email-reports.CYUj-6s4_Z2mfBAN.webp&quot; alt=&quot;HitKeep 2.13 Reporting page with a searchable table of report names, presets, scopes, sites, recipients, schedules, next runs, and recent outcomes&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Desktop reporting keeps scope, recipients, schedule, next run, recent outcome, and row actions in one searchable, sortable table.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Three presets cover different jobs:&lt;/p&gt;

























&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Preset&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Cadence&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Main content&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Site Summary&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Daily, weekly, or monthly&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Visitors, pageviews, bounce rate, session duration, goals, comparison, trend, top pages, and referrers for one site&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Portfolio Digest&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Daily, weekly, or monthly&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Pageviews, visitors, goals, deltas, and site links across selected sites or every site accessible to a personal report owner&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Opportunity Brief&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Daily or weekly&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Saved, validated Opportunity Recommendations and their cited evidence&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;Opportunity Brief does not start a model run. It reads already saved recommendations and suppresses an empty report when none passes the deterministic quality rules.&lt;/p&gt;
&lt;p&gt;Schedules use the report’s timezone rather than a server-local assumption. New reports default to 08:00 in the browser-detected timezone, allow 15-minute delivery increments, and recalculate the UTC run after schedule changes and daylight-saving transitions. Weekly reports choose a weekday. Monthly reports choose a day from 1 through 28.&lt;/p&gt;
&lt;p&gt;Personal reports belong to one user and send only to that user. Team reports use explicitly selected sites and can include members plus up to 25 external addresses. On HitKeep Cloud, external recipients are available with Pro and Business; self-hosted HitKeep does not apply that plan gate.&lt;/p&gt;
&lt;p&gt;An external address receives a seven-day, single-use confirmation that names the team, cadence, and selected domains. HitKeep stores a SHA-256 hash of the confirmation token, not the token itself. Changing the preset, sites, or frequency requires renewed consent. Renaming a report or changing only its delivery time does not. External mail contains the report content but omits dashboard and site links.&lt;/p&gt;
&lt;p&gt;The delivery worker records report runs and per-recipient outcomes before mail is attempted. SMTP failures retry after 5 minutes, 30 minutes, and 2 hours with the same &lt;code&gt;Message-ID&lt;/code&gt;. A restart catches up at most one missed occurrence inside bounded daily, weekly, or monthly windows. Delivery records retain status, attempt count, timestamps, and safe error codes, but not rendered email bodies, remote tracking images, click tracking, or a snapshot of an external email address.&lt;/p&gt;
&lt;h2 id=&quot;migrate-report-api-clients-before-upgrading&quot;&gt;Migrate report API clients before upgrading&lt;/h2&gt;
&lt;p&gt;The database migration converts existing enabled report settings into report definitions at 08:00 UTC so their previous delivery time remains unchanged. Disabled settings remain disabled and are not materialized. After that migration, the old handlers and old subscription storage are gone; requests to the removed routes return &lt;code&gt;404&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Use this mapping when updating a session-authenticated client:&lt;/p&gt;





























&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;HitKeep 2.12 operation&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;HitKeep 2.13 replacement&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;GET /api/user/report-subscriptions&lt;/code&gt;&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;GET /api/reports&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;PUT /api/user/report-subscriptions/digest&lt;/code&gt;&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;POST /api/reports&lt;/code&gt; to create, then &lt;code&gt;PATCH /api/reports/{report_id}&lt;/code&gt; to update a personal Portfolio Digest&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;PUT /api/user/report-subscriptions/sites/{site_id}&lt;/code&gt;&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;POST /api/reports&lt;/code&gt; to create, then &lt;code&gt;PATCH /api/reports/{report_id}&lt;/code&gt; to update a personal Site Summary&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;DigestSubscription&lt;/code&gt;&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;ReportSchedule&lt;/code&gt; inside &lt;code&gt;ReportDefinitionInput&lt;/code&gt; or &lt;code&gt;ReportDefinitionUpdate&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;SiteReportSubscription&lt;/code&gt; and &lt;code&gt;ReportSubscriptions&lt;/code&gt;&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;code&gt;ReportDefinition&lt;/code&gt;, &lt;code&gt;ReportRecipient&lt;/code&gt;, &lt;code&gt;ReportRun&lt;/code&gt;, and &lt;code&gt;ReportDelivery&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;The replacement surface also adds operations for preview, test send, run history, failed-run retry, external-recipient confirmation, unsubscribe, and resubscribe. Generated clients should refresh from the 2.13 OpenAPI document because the removed schemas will no longer be present.&lt;/p&gt;
&lt;p&gt;Other API changes in this release are additive. Social-authentication paths, team traffic-exclusion paths, database-status operations, and the report-definition paths are new. Existing instance and site exclusion creation payloads remain valid, including the legacy CIDR form that omits &lt;code&gt;type&lt;/code&gt;. Exclusion responses retain their existing value fields and add &lt;code&gt;scope&lt;/code&gt;, optional owner IDs, and &lt;code&gt;inherited&lt;/code&gt;.&lt;/p&gt;
&lt;h2 id=&quot;social-sign-in-without-replacing-existing-login-methods&quot;&gt;Social sign-in without replacing existing login methods&lt;/h2&gt;
&lt;p&gt;Self-hosted operators can configure OAuth client pairs for Google, GitHub, Microsoft, or any subset of the three. HitKeep lists only providers with a complete configuration. On managed Cloud, open social signup has its own switch, so a provider can remain available for existing accounts and invitations without allowing uninvited account creation. On self-hosted HitKeep, configuring &lt;code&gt;HITKEEP_SOCIAL_SIGNUP_ENABLED&lt;/code&gt; does not create open public signup.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/social-sign-in-providers.srhdVOI0_ZObDH5.webp&quot; alt=&quot;HitKeep sign-in screen with Google, GitHub, and Microsoft provider buttons enabled above passkey and password options&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;448&quot; height=&quot;768&quot;&gt;&lt;figcaption&gt;Each provider appears only after its client ID and client secret are both configured.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The browser flow uses short-lived, one-time state, PKCE S256, and an OIDC nonce where the provider supports OIDC. Return URLs stay inside the application. HitKeep resolves an account through the provider’s immutable identity, discards provider tokens after the exchange, and never treats an editable email address as the long-term identity key.&lt;/p&gt;
&lt;p&gt;Google and GitHub verified-email flows can complete a normal signup without another email verification step. Microsoft identities do not provide the same verified-email guarantee, so the first unauthenticated Microsoft link or signup sends a HitKeep confirmation unless an authenticated session or matching invitation already proves the account boundary.&lt;/p&gt;
&lt;p&gt;An authenticated user can link or unlink a social provider from security settings. Unlinking is refused when it would remove the last usable primary login method, and password-only fallback requires current-password confirmation. Team OIDC SSO and recovery factors do not count as primary alternatives for that guard.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://hitkeep.com/guides/security/social-sign-in/&quot;&gt;Social Sign-In guide&lt;/a&gt; provides the exact callback URLs, tabbed Google, GitHub, and Microsoft setup, Docker Compose variables, verified-email rules, invitations, MFA handoff, account linking, rollout checks, and troubleshooting.&lt;/p&gt;
&lt;h2 id=&quot;traffic-controls-follow-ownership&quot;&gt;Traffic controls follow ownership&lt;/h2&gt;
&lt;p&gt;Traffic exclusions now use the same ownership structure as the rest of HitKeep. Instance rules apply everywhere. Team rules follow every site currently owned by that team. Site rules stay attached to one site. Effective reads make inherited rules visible, but a team or site route cannot modify a rule owned by a parent scope.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/team-traffic-exclusions-inherited.Brr3hv1v_ZSnLGJ.webp&quot; alt=&quot;HitKeep 2.13 team traffic filters showing an inherited instance user-agent rule and team-owned CIDR and path rules&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1120&quot; height=&quot;529&quot;&gt;&lt;figcaption&gt;Scope labels explain why a rule applies. The inherited instance rule is visible at team scope and remains read-only there.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Rules are additive and forward-only. HitKeep evaluates instance, current-team, and site rules, then drops a record when any rule matches. There are no allow overrides, and changing a rule does not rewrite historical analytics.&lt;/p&gt;
&lt;p&gt;The two new match types cover traffic that network and country rules cannot express cleanly:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;User agent:&lt;/strong&gt; case-insensitive substring matching for monitors, known clients, or other identifiable traffic.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Path:&lt;/strong&gt; case-sensitive segment-boundary matching after query strings, fragments, duplicate slashes, trailing slashes, and dot segments are normalized. &lt;code&gt;/admin&lt;/code&gt; matches &lt;code&gt;/admin/users&lt;/code&gt;, but not &lt;code&gt;/administrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;User-agent and path values are used transiently during filtering and do not add stored visitor fields. Filtering covers browser pageviews and events, Web Vitals, trusted server ingest, AI-fetch records, and dynamic QR opens. Matching ingest keeps its normal accepted response so the API does not reveal which filter matched.&lt;/p&gt;
&lt;h2 id=&quot;analytics-leaves-the-shared-control-plane&quot;&gt;Analytics leaves the shared control plane&lt;/h2&gt;
&lt;p&gt;Version 2.13.0 completes the database boundary for the original default tenant. The shared &lt;code&gt;hitkeep.db&lt;/code&gt; keeps users, sessions, teams, memberships, sites, preferences, API clients, share links, and other ownership metadata. Analytics rows for every tenant, including the default tenant, live in tenant-local DuckDB files under &lt;code&gt;{data-path}/tenants/{tenant-id}/hitkeep.db&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The control plane resolves who can access a site and which tenant owns it. Analytics reads and writes then use the resolved tenant data plane; they do not join analytics tables back into the control database. Tenant catalogs run through the attached DuckDB data-plane layer while the control database remains metadata-only.&lt;/p&gt;
&lt;p&gt;On the first 2.13 startup, HitKeep creates the default tenant file, verifies the migrated analytics data, records durable split markers, and rewrites the shared file. Keep the complete data path available throughout the operation. Copying only &lt;code&gt;hitkeep.db&lt;/code&gt; after the upgrade produces an incomplete backup because it omits every tenant’s analytics database. The built-in backup and S3 restore paths cover the control snapshot and the tenant files derived from it.&lt;/p&gt;
&lt;p&gt;Most upgrades need only the normal process replacement. The extra restart is required only when guarded automatic recovery ran first: HitKeep exits rather than combining recovery and the mandatory split in one process. If a service manager or container policy does not restart it automatically, start the same 2.13 release again, watch the migration logs, and wait for &lt;code&gt;/readyz&lt;/code&gt; before returning traffic. Once the split markers are committed, use the complete pre-upgrade backup for rollback instead of starting 2.12 against the new layout.&lt;/p&gt;
&lt;h2 id=&quot;recovery-preserves-evidence-before-repair&quot;&gt;Recovery preserves evidence before repair&lt;/h2&gt;
&lt;p&gt;DuckDB is embedded, but it still has a write-ahead log, checkpoint behavior, indexes, and failure modes that need explicit operating rules. Version 2.13.0 serializes periodic checkpoints and requires checkpoints around migrations, before backups, and during clean shutdown. An instance operator can inspect the sanitized database state and request an immediate checkpoint from System Status or the new admin API.&lt;/p&gt;
&lt;p&gt;Automatic repair remains intentionally narrow. For the recognized non-unique-index invalidation, HitKeep first creates a permission-restricted, checksummed recovery bundle, then removes only implicated non-unique secondary indexes. Primary-key and unique indexes stay intact. A repair that finds no eligible index fails closed instead of reporting a false success.&lt;/p&gt;
&lt;p&gt;The known migration WAL failure has a separate guard. Startup migrations run before the store is published to workers, commit and checkpoint independently, and record a durable checksum for the closed base database while a migration WAL remains authoritative. HitKeep can complete migration-only WAL recovery automatically only when that checksum matches. Bypassing an application WAL remains disabled by default because committed changes may exist only in that WAL; &lt;code&gt;HITKEEP_DB_AUTO_RECOVER_WAL=true&lt;/code&gt; is an explicit availability-versus-data-loss decision.&lt;/p&gt;
&lt;p&gt;While a shared or open tenant database is recovering, &lt;code&gt;/healthz&lt;/code&gt; continues to report process liveness, while &lt;code&gt;/readyz&lt;/code&gt; and database-dependent API or ingest routes return &lt;code&gt;503&lt;/code&gt; with a stable reason and &lt;code&gt;Retry-After: 5&lt;/code&gt;. If recovery cannot preserve evidence, verify disk space, or drain open connections, HitKeep stops instead of serving partial data.&lt;/p&gt;
&lt;p&gt;Recovery bundles are local incident artifacts, not backup rotation. They can contain the same sensitive data as the live database and are never deleted automatically. Keep backing up the complete data path, including tenant databases, and keep recovery-bundle retention in the operator runbook.&lt;/p&gt;
&lt;h2 id=&quot;smaller-bounded-ip-metadata-work&quot;&gt;Smaller, bounded IP metadata work&lt;/h2&gt;
&lt;p&gt;HitKeep still derives country, region, city, provider, ASN, and ASN organization from embedded IP metadata without storing the raw visitor IP. The implementation now stores validated address directories and compressed blocks instead of inflating the full country, city, and network datasets at startup.&lt;/p&gt;
&lt;p&gt;Lookup decodes only the block needed for an address, validates length, ordering, metadata references, and checksums, and keeps decoded data under separate bounded country, city, and ASN caches. The result keeps the same analytics dimensions while reducing embedded asset size and putting an upper bound on decoded range-block memory.&lt;/p&gt;
&lt;p&gt;The bundled spam filter also moves from legacy Spamhaus feed handling to the provider’s JSON data, with schema validation and a refreshed default snapshot. Production filtering remains embedded and deterministic; a release does not need a runtime download token to start protecting ingest.&lt;/p&gt;
&lt;h2 id=&quot;contributor-and-release-workflows-become-reproducible&quot;&gt;Contributor and release workflows become reproducible&lt;/h2&gt;
&lt;p&gt;For contributors, the new &lt;code&gt;./hk&lt;/code&gt; launcher is the source of truth for toolchain diagnosis, isolated workspace state, container-only development, screenshots, builds, smokes, and QA. A central developer MCP adapter exposes those operations to supported coding clients without giving them arbitrary shell execution or source-rewrite access.&lt;/p&gt;
&lt;p&gt;Development is now one workspace session with status and event cursors. Finite setup, QA, build, and smoke operations use durable run IDs and bounded logs. That distinction lets a slow e2e or image gate continue even if one client disconnects, and lets contributors resume the exact run instead of starting a duplicate.&lt;/p&gt;
&lt;p&gt;Release preparation receives the same treatment. Release Please owns the version manifest, changelog, dashboard package versions, MCP registry version, and Helm chart version. After a stable release is created, the release workflow builds and uploads binaries, checksums, the Helm chart, and &lt;code&gt;hitkeep-configuration.json&lt;/code&gt;. Only after those artifacts succeed does it synchronize the docs repository’s machine-owned current-version and configuration files, validate the site, deploy that exact revision, and trigger the managed-cloud rollout.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-checklist&quot;&gt;Upgrade checklist&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Back up the complete HitKeep data path and verify at least one recent restore before changing the running binary.&lt;/li&gt;
&lt;li&gt;Update any client that calls the three removed report-subscription routes, then regenerate typed clients from the 2.13 OpenAPI schema.&lt;/li&gt;
&lt;li&gt;Ensure the data path has enough free space for one source-database-sized tenant copy plus 512 MiB, and confirm the service manager or container policy can restart the same 2.13 release if recovery exits first.&lt;/li&gt;
&lt;li&gt;Upgrade HitKeep and let migrations finish before accepting traffic. If HitKeep reports that automatic recovery completed and a restart is required, start the same 2.13 binary or container again and wait for &lt;code&gt;/readyz&lt;/code&gt;; do not downgrade. Existing enabled report subscriptions become reports at 08:00 UTC.&lt;/li&gt;
&lt;li&gt;Open &lt;strong&gt;Settings → Reporting&lt;/strong&gt;, verify converted reports, choose a local timezone and time where needed, and send a test through the configured SMTP transport.&lt;/li&gt;
&lt;li&gt;If you add external recipients, confirm the consent invitation in a separate browser and verify that the delivery omits dashboard links.&lt;/li&gt;
&lt;li&gt;If you enable social sign-in, register the exact callback derived from &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt;, configure only the providers you intend to expose, and test login, invitation, MFA, linking, and last-login-method protection.&lt;/li&gt;
&lt;li&gt;Review instance, team, and site traffic filters with &lt;code&gt;effective=true&lt;/code&gt; or the dashboard scope labels, especially after site transfers.&lt;/li&gt;
&lt;li&gt;Confirm &lt;code&gt;HITKEEP_DB_RECOVERY_PATH&lt;/code&gt; has suitable free space, keep application WAL bypass disabled unless incident policy explicitly accepts its loss boundary, and monitor readiness during the first restart.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;what-does-not-change&quot;&gt;What does not change&lt;/h2&gt;
&lt;p&gt;HitKeep 2.13.0 keeps the same product boundary:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;one Go binary with the Angular dashboard embedded;&lt;/li&gt;
&lt;li&gt;DuckDB for storage and NSQ running in process;&lt;/li&gt;
&lt;li&gt;no required PostgreSQL, Redis, Kafka, ClickHouse, or separate report worker;&lt;/li&gt;
&lt;li&gt;cookie-free browser tracking by default;&lt;/li&gt;
&lt;li&gt;no raw visitor IP stored in analytics;&lt;/li&gt;
&lt;li&gt;open exports and complete account takeout; and&lt;/li&gt;
&lt;li&gt;the same open-source product foundation for self-hosted and managed cloud.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Scheduled reports add durable outbound mail delivery. Social sign-in adds optional provider connections. Recovery and traffic controls harden operation. None of them add a required external database, queue, cache, or identity service.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/notifications/email-reports/&quot;&gt;Scheduled Email Reports&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/api/&quot;&gt;REST API Reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/security/social-sign-in/&quot;&gt;Configure Social Sign-In&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.npmjs.com/package/@hitkeep/tracker&quot;&gt;&lt;code&gt;@hitkeep/tracker&lt;/code&gt; on npm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/tracker-architecture/&quot;&gt;Tracker Architecture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/ip-exclusions/&quot;&gt;Traffic Exclusions and IP Filtering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/teams/&quot;&gt;Teams and Data Isolation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/disaster-recovery/&quot;&gt;Disaster Recovery Runbook&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/backups-and-restore/&quot;&gt;Backups and Restore&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/architecture/#6-data-lifecycle-and-recovery&quot;&gt;Architecture and data lifecycle&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/facts-and-limits/&quot;&gt;Runtime facts and limits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/blob/main/CONTRIBUTING.md&quot;&gt;Contributing to HitKeep&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Self-hosted HitKeep includes scheduled reports, social sign-in, the typed tracker SDK, isolated tenant analytics, layered traffic controls, and guarded recovery in the same binary. If you want managed email delivery, backups, upgrades, and regional hosting, &lt;a href=&quot;https://cloud.hitkeep.eu/signup?plan=free&amp;#x26;billing=monthly&amp;#x26;utm_source=hitkeep_docs&amp;#x26;utm_medium=referral&amp;#x26;utm_campaign=cloud_signup&amp;#x26;utm_content=docs_inline&quot;&gt;start a managed HitKeep Cloud deployment&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Follow HitKeep on &lt;a href=&quot;https://x.com/gethitkeep&quot;&gt;X&lt;/a&gt;, &lt;a href=&quot;https://bsky.app/profile/hitkeep.com&quot;&gt;Bluesky&lt;/a&gt;, and &lt;a href=&quot;https://www.linkedin.com/company/hitkeep&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt;</content:encoded></item><item><title>How to Check Site Traffic Without Google Analytics</title><link>https://hitkeep.com/blog/how-to-check-site-traffic-without-google-analytics/</link><guid isPermaLink="true">https://hitkeep.com/blog/how-to-check-site-traffic-without-google-analytics/</guid><description>Learn how to check website traffic without Google Analytics using privacy-first analytics, Search Console, server logs, UTMs, and conversion data.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;You can check site traffic without Google Analytics by combining a focused web analytics platform with the sources that answer narrower questions. Use analytics for visitors and on-site behavior, Search Console for Google Search visibility, server or CDN logs for raw requests, campaign tags for attribution, and backend records for confirmed conversions.&lt;/p&gt;
&lt;p&gt;The important distinction is ownership. For a site you control, first-party analytics and infrastructure data can provide reliable traffic and conversion trends. For somebody else’s website, no public tool can reveal exact visitor numbers; competitor tools can only estimate them.&lt;/p&gt;
&lt;h2 id=&quot;the-short-answer-choose-the-source-that-matches-the-question&quot;&gt;The short answer: choose the source that matches the question&lt;/h2&gt;
&lt;p&gt;“Website traffic” can mean several different things. Start with the decision you need to make, then use the source that can actually support it.&lt;/p&gt;













































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Question&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Metric to check&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Best source&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;How many people visited?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Visitors, sessions, pageviews&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;First-party web analytics&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Where did they come from?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Referrers, channels, campaigns&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Web analytics plus UTM tracking&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Which content attracts Google Search demand?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Clicks, impressions, queries, CTR, average position&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Google Search Console&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Which pages produce outcomes?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Goals, events, funnels, confirmed conversions&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Web analytics plus backend records&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Which bots and AI crawlers requested the site?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;User agents, paths, status codes, fetch volume&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Server, CDN, or edge logs&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Did an offline campaign create visits?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;QR scans, tagged visits, conversions&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Tagged URLs, QR campaigns, and goals&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;How much traffic does a competitor receive?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Estimated visits and search traffic&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Third-party estimates, never exact first-party data&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;No single source is perfect. Browser analytics can miss blocked or unconsented requests. Logs include bots and asset requests that are not human visits. Search Console covers Google Search rather than total traffic. A CRM or payment system confirms an outcome but may not preserve the acquisition journey.&lt;/p&gt;
&lt;p&gt;A useful Google Analytics replacement does not try to force every question into one number. It combines a small set of sources with documented definitions.&lt;/p&gt;
&lt;h2 id=&quot;first-decide-whether-you-own-the-website&quot;&gt;First, decide whether you own the website&lt;/h2&gt;
&lt;p&gt;If you own or operate the website, you can measure it directly. You can install a first-party analytics script, inspect your server or CDN logs, connect Search Console, tag campaigns, and compare recorded goals with your own business systems.&lt;/p&gt;
&lt;p&gt;If you do not control the website, you cannot see its exact visitors, sessions, revenue, or conversions unless the owner shares that data. SEO and competitive-intelligence tools can estimate traffic using rankings, clickstream samples, panels, and models. Those estimates can help compare direction or relative scale, but they are not a substitute for first-party analytics.&lt;/p&gt;
&lt;p&gt;This guide focuses on accurate measurement for a site you control. The competitor question is covered separately in the FAQ because it requires a different evidence standard.&lt;/p&gt;
&lt;h2 id=&quot;use-privacy-first-web-analytics-for-core-visitor-data&quot;&gt;Use privacy-first web analytics for core visitor data&lt;/h2&gt;
&lt;p&gt;The closest functional replacement for GA4 is a web analytics platform that records pageviews, visitors, referrers, campaigns, events, and conversions. Modern privacy-first products narrow the collection surface and often avoid analytics cookies or persistent cross-site identifiers by default.&lt;/p&gt;
&lt;p&gt;This layer should answer the questions a team checks every day:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How many visitors came today, this week, or this month?&lt;/li&gt;
&lt;li&gt;Which pages attracted and retained attention?&lt;/li&gt;
&lt;li&gt;Which referrers and campaigns performed best?&lt;/li&gt;
&lt;li&gt;Which devices, countries, or browsers changed?&lt;/li&gt;
&lt;li&gt;Which calls to action, forms, signups, or purchases converted?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;HitKeep provides these reports with &lt;a href=&quot;https://hitkeep.com/use-cases/cookieless-event-tracking/&quot;&gt;cookie-less event tracking&lt;/a&gt; by default. It also supports &lt;a href=&quot;https://hitkeep.com/guides/analytics/goals/&quot;&gt;goals&lt;/a&gt;, &lt;a href=&quot;https://hitkeep.com/guides/analytics/funnels/&quot;&gt;funnels&lt;/a&gt;, Search Console imports, open-format &lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;data takeout&lt;/a&gt;, managed EU or US cloud hosting, and a &lt;a href=&quot;https://hitkeep.com/guides/installation/&quot;&gt;single-binary self-hosted installation&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Cookie-free does not automatically mean consent-free or compliant. Storage, identifiers, event fields, purposes, retention, deployment, and jurisdiction all matter. Treat the smaller data boundary as an implementation property, not a legal conclusion.&lt;/p&gt;
&lt;p&gt;When evaluating an analytics tool, verify how it defines visitors and sessions, how it filters bots, whether referrers and campaigns remain exportable, how goals are confirmed, and whether its hosting model matches your ownership requirements.&lt;/p&gt;
&lt;h2 id=&quot;use-google-search-console-for-organic-search-traffic&quot;&gt;Use Google Search Console for organic search traffic&lt;/h2&gt;
&lt;p&gt;If the question is “How much traffic do we receive from Google Search?”, Search Console is essential. Its Performance report provides clicks, impressions, click-through rate, average position, queries, pages, countries, devices, and dates.&lt;/p&gt;
&lt;p&gt;That information begins before a visitor reaches the site. An impression can show search demand even when nobody clicks, and query data can reveal a page that ranks but needs a clearer title or more relevant answer.&lt;/p&gt;
&lt;p&gt;Search Console is useful for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;finding pages with impressions but weak click-through rates;&lt;/li&gt;
&lt;li&gt;comparing branded and non-branded discovery;&lt;/li&gt;
&lt;li&gt;spotting traffic changes after content or technical updates;&lt;/li&gt;
&lt;li&gt;finding queries that deserve a stronger section or a new article; and&lt;/li&gt;
&lt;li&gt;measuring Google Search without adding another browser script.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Its limits are equally important. Search Console does not report direct, referral, email, paid, social, or non-Google traffic, and it does not reconstruct the visitor’s full journey after the click. Google also documents why Search Console totals can differ from analytics totals.&lt;/p&gt;
&lt;p&gt;Connect the &lt;a href=&quot;https://hitkeep.com/guides/integrations/google-search-console/&quot;&gt;HitKeep Search Console integration&lt;/a&gt; when you want search visibility beside landing-page, audience, and conversion reporting.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-search-console.CSc92Uud_1y11Bk.webp&quot; alt=&quot;HitKeep Search Console report showing clicks, impressions, click-through rate, average position, queries, devices, and countries&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Search Console adds query, impression, and click context to on-site visitor and conversion reporting.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;read-server-and-cdn-logs-for-raw-request-evidence&quot;&gt;Read server and CDN logs for raw request evidence&lt;/h2&gt;
&lt;p&gt;Server, reverse-proxy, edge, and CDN logs show requests made to your infrastructure. They can include human page loads, search crawlers, AI crawlers, uptime monitors, API clients, download requests, and abusive automation.&lt;/p&gt;
&lt;p&gt;Logs are especially useful when browser analytics cannot observe the request:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;verifying that search engines reach important pages;&lt;/li&gt;
&lt;li&gt;separating crawler activity from rendered visits;&lt;/li&gt;
&lt;li&gt;finding repeated 404s, redirect loops, or failed requests;&lt;/li&gt;
&lt;li&gt;measuring downloads, feeds, or endpoints that do not run browser JavaScript; and&lt;/li&gt;
&lt;li&gt;investigating whether a spike came from people or automation.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Raw requests are not the same as visitors. One page load can request HTML, scripts, styles, images, and fonts. Bots can create large volumes, shared networks make IP-based visitor counts unreliable, and privacy protections can change network identifiers. Use logs for infrastructure and crawler truth, then aggregate and classify them before using them in a marketing report.&lt;/p&gt;
&lt;h2 id=&quot;track-campaigns-with-utms-and-qr-codes&quot;&gt;Track campaigns with UTMs and QR codes&lt;/h2&gt;
&lt;p&gt;Campaign attribution does not depend on Google Analytics. Add consistent UTM parameters to the destination URL and let your analytics tool record the campaign, source, medium, content, and term.&lt;/p&gt;
&lt;p&gt;A newsletter link might use &lt;code&gt;utm_source=newsletter&lt;/code&gt;, &lt;code&gt;utm_medium=email&lt;/code&gt;, and &lt;code&gt;utm_campaign=summer_launch&lt;/code&gt;. The naming convention matters more than the vendor. &lt;code&gt;linkedin&lt;/code&gt;, &lt;code&gt;LinkedIn&lt;/code&gt;, and &lt;code&gt;li&lt;/code&gt; will usually become separate values, so document allowed names before campaigns launch.&lt;/p&gt;
&lt;p&gt;Use the same practice for offline campaigns. Point every QR code on event signage, packaging, direct mail, or sales material to its own tagged URL. That makes the offline placement measurable through visits and downstream goals.&lt;/p&gt;
&lt;p&gt;HitKeep’s &lt;a href=&quot;https://hitkeep.com/guides/tracking/utm-parameters/&quot;&gt;UTM reporting guide&lt;/a&gt; covers the parameters and reporting flow, while QR campaigns keep distinct printed placements measurable.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-utm.CTQD_liS_1iQX8v.webp&quot; alt=&quot;HitKeep UTM report showing campaign dimensions, visitor and pageview trends, and top campaigns&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Consistent campaign tags turn email, paid, partner, and QR visits into comparable acquisition reports.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;measure-conversions-at-the-source&quot;&gt;Measure conversions at the source&lt;/h2&gt;
&lt;p&gt;Traffic becomes useful when it supports an outcome. A SaaS team may care about verified signups or demo requests. A publisher may care about accepted subscriptions. An ecommerce site may care about confirmed orders, revenue, or repeat purchases.&lt;/p&gt;
&lt;p&gt;Analytics goals and funnels explain the journey, but the source of truth for the final result is usually the system that accepted it: your backend, CRM, payment processor, form service, or email platform.&lt;/p&gt;
&lt;p&gt;For example, analytics may show 120 form-submission events while the CRM contains 112 valid leads. The difference could come from spam, duplicate clicks, rejected submissions, blocked requests, or a tracking mistake. Reconciliation exposes the gap instead of hiding it.&lt;/p&gt;
&lt;p&gt;A reliable conversion model has three layers:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Browser events describe low-risk interactions and navigation.&lt;/li&gt;
&lt;li&gt;Backend records confirm important outcomes.&lt;/li&gt;
&lt;li&gt;Referrer and campaign context explains acquisition.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Use &lt;a href=&quot;https://hitkeep.com/guides/analytics/goals/&quot;&gt;HitKeep goals&lt;/a&gt; for named outcomes and &lt;a href=&quot;https://hitkeep.com/guides/analytics/funnels/&quot;&gt;funnels&lt;/a&gt; for the steps that lead to them, then compare the totals with the system that owns the business record.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-goals.C2tKB0q7_1z7GRi.webp&quot; alt=&quot;HitKeep Goals report showing conversions, conversion rate, unique sessions, trend comparison, top pages, sources, and devices&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Goals connect traffic to outcomes; reconcile them with backend or CRM records for confirmed conversions.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;separate-ai-crawler-fetches-from-ai-referred-visits&quot;&gt;Separate AI crawler fetches from AI-referred visits&lt;/h2&gt;
&lt;p&gt;Traditional analytics assumes that a person follows a link, renders a page, and triggers a browser tracker. AI discovery breaks that into several observable events.&lt;/p&gt;
&lt;p&gt;An AI crawler may fetch a page remotely without running JavaScript. An assistant may later send a person through a recognizable referral. An AI-capable browser may render the page like a normal visit. An answer may also be produced without a new request to your site.&lt;/p&gt;
&lt;p&gt;These signals should not share one traffic bucket:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Crawler fetches&lt;/strong&gt; show that an identified automated client requested a path.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI-referred visits&lt;/strong&gt; show that a person arrived from a recognizable assistant or campaign.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Rendered visits&lt;/strong&gt; show that the page and tracker ran, but not necessarily whether an assistant helped.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Conversions&lt;/strong&gt; show that a meaningful outcome occurred.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;HitKeep’s &lt;a href=&quot;https://hitkeep.com/guides/analytics/ai-visibility/&quot;&gt;AI Visibility analytics&lt;/a&gt; keeps crawler fetches and AI-referred human visits separate. The guide to &lt;a href=&quot;https://hitkeep.com/blog/ai-browsers-web-analytics-2026/&quot;&gt;AI browsers and web analytics in 2026&lt;/a&gt; explains what browser trackers, logs, referrals, and backend events can each observe.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-ai-visibility.DPXf9_ks_Z2apQEG.webp&quot; alt=&quot;HitKeep AI Visibility report showing crawler fetches, AI-referred visits, assistants, error rate, and fetch volume&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;AI crawler fetches and AI-referred human visits stay separate because they answer different acquisition questions.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;build-a-simple-traffic-measurement-stack&quot;&gt;Build a simple traffic measurement stack&lt;/h2&gt;
&lt;p&gt;Most teams do not need ten tools. They need a few sources with clear definitions and an owner for each number.&lt;/p&gt;








































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Need&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Recommended approach&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Why it works&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Daily visitor reporting&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Privacy-first web analytics&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Clear page, referrer, campaign, and visitor trends&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Google organic visibility&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Search Console data&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Queries, impressions, clicks, CTR, and rankings&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Conversion reporting&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Goals plus backend records&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Connects acquisition to confirmed outcomes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Crawler and bot analysis&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Server or edge logs&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Captures requests that do not execute browser tracking&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Campaign attribution&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;UTMs and QR tracking&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Keeps online and offline placements comparable&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Data ownership&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Self-hosting or open exports&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Supports portability and independent verification&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;The &lt;a href=&quot;https://hitkeep.com/blog/google-analytics-vs-privacy-first-analytics-in-2026/&quot;&gt;Google Analytics vs privacy-first analytics comparison&lt;/a&gt; covers the broader choice between GA4, a privacy-first platform, and a hybrid stack.&lt;/p&gt;
&lt;h2 id=&quot;step-by-step-check-your-site-traffic-without-ga4&quot;&gt;Step by step: check your site traffic without GA4&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Install a focused analytics tool.&lt;/strong&gt; Confirm that pageviews, visitors, landing pages, and referrers appear with the definitions you expect.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Define important outcomes.&lt;/strong&gt; Create goals for accepted forms, signups, purchases, downloads, or other useful events.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Connect Search Console.&lt;/strong&gt; Compare Google Search clicks and queries with landing-page engagement and conversions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Standardize campaign URLs.&lt;/strong&gt; Define allowed UTM values for email, paid, social, partner, and QR campaigns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review server or CDN logs.&lt;/strong&gt; Look for crawlers, failed paths, redirects, downloads, and unusual request spikes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reconcile confirmed conversions.&lt;/strong&gt; Compare analytics goals with CRM, ecommerce, subscription, or form records.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Create a weekly reporting rhythm.&lt;/strong&gt; Review visitors, acquisition, top content, search trends, conversions, and anomalies using the same definitions each week.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Do not begin by rebuilding every GA4 report. Start with the recurring decisions your team actually makes, then add a report only when it changes one of those decisions.&lt;/p&gt;
&lt;h2 id=&quot;keep-your-traffic-numbers-trustworthy&quot;&gt;Keep your traffic numbers trustworthy&lt;/h2&gt;
&lt;p&gt;Document how each platform defines visitors, sessions, pageviews, events, and conversions. If the tracker is cookie-free, record how session continuity works. If you self-host, document retention, backups, access controls, updates, and exports.&lt;/p&gt;
&lt;p&gt;Separate humans from automation wherever the evidence supports it, but preserve an unknown category instead of forcing certainty. A request is not automatically a visit, and a visit is not automatically a qualified lead.&lt;/p&gt;
&lt;p&gt;Finally, use trends for marketing decisions and confirmed systems for billing or finance. Analytics is strongest when it reveals direction: organic traffic fell, email conversions improved, a pricing page gained engagement, or AI referrals increased. Consistent definitions make those changes more useful than false precision.&lt;/p&gt;
&lt;h2 id=&quot;when-should-you-still-use-google-analytics&quot;&gt;When should you still use Google Analytics?&lt;/h2&gt;
&lt;p&gt;GA4 can remain useful when Google Ads optimization, remarketing audiences, Firebase app analytics, BigQuery exports, or existing analyst workflows are central to the organization.&lt;/p&gt;
&lt;p&gt;The choice does not have to be permanent or ideological. Many teams run GA4 and a privacy-first platform in parallel while validating coverage, or retain GA4 for advertising workflows while using another system as the primary website-performance dashboard.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://hitkeep.com/vs/google-analytics/&quot;&gt;HitKeep vs Google Analytics comparison&lt;/a&gt; documents where each product is stronger and outlines a parallel migration path. Keep GA4 where it provides a capability you use; remove it only after the replacement measurement model has been tested against real decisions and confirmed outcomes.&lt;/p&gt;
&lt;h2 id=&quot;measure-traffic-on-your-own-terms&quot;&gt;Measure traffic on your own terms&lt;/h2&gt;
&lt;p&gt;Checking site traffic without Google Analytics is not about finding one magic replacement number. It is about matching each question to reliable evidence: first-party analytics for visits, Search Console for search visibility, logs for requests, tags for campaigns, and backend records for outcomes.&lt;/p&gt;
&lt;p&gt;HitKeep brings those website analytics, goals, funnels, Search Console reports, campaign data, AI visibility, and open exports into one product. You can use managed cloud with an EU or US region choice or &lt;a href=&quot;https://hitkeep.com/guides/installation/&quot;&gt;self-host the same open-source application&lt;/a&gt; when direct infrastructure control matters.&lt;/p&gt;</content:encoded></item><item><title>Google Analytics vs Privacy-First Analytics in 2026</title><link>https://hitkeep.com/blog/google-analytics-vs-privacy-first-analytics-in-2026/</link><guid isPermaLink="true">https://hitkeep.com/blog/google-analytics-vs-privacy-first-analytics-in-2026/</guid><description>Compare Google Analytics vs privacy-first analytics in 2026: consent, cookies, AI traffic, data ownership, and when to switch.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;In 2026, the choice between Google Analytics and privacy-first analytics is no longer just a tooling preference. It determines how consent affects your reporting, where analytics data is processed, how easily you can move it, and whether your measurement stack can distinguish traditional traffic from AI referrals and crawler fetches.&lt;/p&gt;
&lt;p&gt;Google Analytics 4 remains powerful, widely understood, and tightly connected to Google Ads. Privacy-first tools have also moved beyond simple pageview counters. Serious products now support goals, funnels, ecommerce events, Search Console data, open exports, AI visibility, and a choice between managed hosting and self-hosting.&lt;/p&gt;
&lt;p&gt;The answer does not have to be ideological. For many teams, the practical setup is to use privacy-first analytics as the source of truth for website performance and keep GA4 only where its advertising or advanced analysis workflows add unique value.&lt;/p&gt;
&lt;p&gt;If your immediate task is measurement rather than product selection, use the practical guide to &lt;a href=&quot;https://hitkeep.com/blog/how-to-check-site-traffic-without-google-analytics/&quot;&gt;checking site traffic without Google Analytics&lt;/a&gt; to map visitors, search visibility, server requests, campaigns, and conversions to the right source.&lt;/p&gt;
&lt;div&gt;&lt;p&gt;Reviewed July 22, 2026&lt;/p&gt;&lt;p&gt;This article was checked against current Google Analytics, Google Ads, and CNIL guidance. Product behavior and privacy rules change, so re-check the primary sources and obtain advice for your own deployment before making legal or measurement decisions.&lt;/p&gt;&lt;/div&gt;
&lt;h2 id=&quot;the-short-answer-which-approach-fits-your-team&quot;&gt;The short answer: which approach fits your team?&lt;/h2&gt;
&lt;p&gt;Choose Google Analytics when Google Ads optimization, remarketing audiences, app analytics, BigQuery workflows, and analyst-grade explorations are central to the job. Choose a privacy-first platform when cookie minimization, a smaller data boundary, operator control, and straightforward website reporting matter more.&lt;/p&gt;








































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Decision factor&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Google Analytics 4&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Privacy-first analytics&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Best fit&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Ad-heavy teams, app and web analytics, Google Ads optimization, and established analyst workflows&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Privacy-conscious teams, publishers, SaaS companies, agencies, public-sector organizations, and teams focused on first-party website outcomes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Default web tracking&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;GA4’s JavaScript tag uses first-party cookies to distinguish users and sessions; Consent Mode can alter tag and storage behavior&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Varies by product; often designed to avoid analytics cookies or persistent identifiers by default&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Data control&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Reports live in Google’s product, with raw-event export available through BigQuery&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;May offer self-hosting, regional hosting, open exports, and direct control over retention and infrastructure&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Compliance work&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Requires purpose, consent, configuration, data-sharing, and transfer review&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Can reduce the data boundary, but still requires review of the complete implementation and jurisdiction&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;AI traffic&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;AI referrals can appear through normal acquisition data; crawler fetches require server-side evidence&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Some products separate AI referrals, crawler fetches, and completed outcomes as dedicated reports&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Ecosystem&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Strongest with Google Ads, BigQuery, Looker Studio, Firebase, and Google integrations&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Strongest when transparency, portability, and independence are priorities&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;For a product-by-product feature matrix, use the &lt;a href=&quot;https://hitkeep.com/vs/google-analytics/&quot;&gt;HitKeep vs Google Analytics comparison&lt;/a&gt;. This article stays at the strategy level: what each analytics model is good at, where the evidence differs, and how to choose a source of truth.&lt;/p&gt;
&lt;h2 id=&quot;what-changed-by-2026&quot;&gt;What changed by 2026?&lt;/h2&gt;
&lt;p&gt;Four changes have moved analytics architecture beyond the marketing team.&lt;/p&gt;
&lt;p&gt;First, privacy and ePrivacy review now affects tracking design in Europe and many other jurisdictions. The useful question is not whether a vendor uses the word “privacy.” It is what the tracker stores, where the data goes, how it is combined, how long it is retained, and which controls the operator can enforce.&lt;/p&gt;
&lt;p&gt;Second, consent choices affect measurement. In basic Consent Mode, Google tags remain blocked until consent and send no data when consent is denied. In advanced Consent Mode, tags can send cookieless pings while storage is denied, and Google may use those signals for modeling when its thresholds are met. Those modes produce different evidence, and modeled outcomes are not interchangeable with directly observed events.&lt;/p&gt;
&lt;p&gt;Third, AI has changed discovery. A rendered visit, an AI-referred click, a remote crawler fetch, and a completed signup answer four different questions. A dashboard that combines them into one “AI traffic” number hides the collection boundary.&lt;/p&gt;
&lt;p&gt;Finally, more organizations want to know whether analytics can move with them. Data location, export formats, deletion, retention, and self-hosting now appear in procurement and platform reviews, not just analytics implementation tickets.&lt;/p&gt;
&lt;h2 id=&quot;where-google-analytics-is-still-strong&quot;&gt;Where Google Analytics is still strong&lt;/h2&gt;
&lt;p&gt;GA4 is especially strong when revenue operations depend on Google Ads. Linking a GA4 property to Google Ads supports audience sharing, site statistics in Ads, and advertising reporting inside Analytics. For teams optimizing substantial paid budgets, that integration can justify keeping GA4 even when another platform becomes the primary website dashboard.&lt;/p&gt;
&lt;p&gt;Google also has a broad talent and tooling ecosystem. Agencies and analysts understand GA4 concepts, and the surrounding stack includes BigQuery, Looker Studio, Firebase, tag management, and third-party connectors.&lt;/p&gt;
&lt;p&gt;GA4’s event model is flexible. Page loads, clicks, scrolls, purchases, and custom interactions can be represented as events with parameters. BigQuery Export adds a raw-event analysis path for teams that need SQL access, and Google states that customers own the data exported into their BigQuery project.&lt;/p&gt;
&lt;p&gt;Those strengths come with operational and governance choices. The standard web tag uses the &lt;code&gt;_ga&lt;/code&gt; and &lt;code&gt;_ga_&amp;#x3C;container-id&gt;&lt;/code&gt; first-party cookies by default. Consent Mode is a separate integration with a consent banner or platform; it does not provide consent by itself. GA4 also remains a proprietary service rather than infrastructure an operator can run or inspect end to end.&lt;/p&gt;
&lt;h2 id=&quot;what-privacy-first-analytics-means-in-2026&quot;&gt;What privacy-first analytics means in 2026&lt;/h2&gt;
&lt;p&gt;Privacy-first analytics is a category, not one architecture. The useful definition is a measurement system that deliberately minimizes collection and keeps the data boundary proportionate to the business questions being asked.&lt;/p&gt;
&lt;p&gt;A privacy-first platform commonly emphasizes some combination of:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;cookie-free or minimized tracking by default;&lt;/li&gt;
&lt;li&gt;fewer persistent identifiers and less cross-site or cross-product combination;&lt;/li&gt;
&lt;li&gt;explicit retention, export, and deletion controls;&lt;/li&gt;
&lt;li&gt;regional managed hosting or self-hosting;&lt;/li&gt;
&lt;li&gt;transparent collection behavior; and&lt;/li&gt;
&lt;li&gt;separate evidence for human visits, bots, AI crawlers, and conversions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The goal is not to collect nothing. Teams still need to know which campaigns work, which pages generate qualified demand, where funnels lose users, and whether search visibility produces business outcomes. The difference is starting with the minimum evidence needed for those decisions instead of building the largest possible visitor profile.&lt;/p&gt;
&lt;p&gt;France’s CNIL describes circumstances in which certain audience-measurement trackers can be exempt from consent, but only under strict conditions such as publisher-only measurement, anonymous statistics, no cross-site tracking, and no combination with other processing. That guidance is France-specific and does not make every cookie-free or privacy-first implementation exempt elsewhere.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/dashboard-comparison.DOLNPx1L_1vxfLU.webp&quot; alt=&quot;HitKeep dashboard with current and previous-period traffic, visitor, session, bounce-rate, duration, and pages-per-session comparisons&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;HitKeep keeps traffic, engagement, and period comparisons in one first-party website dashboard.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;google-analytics-vs-privacy-first-analytics-the-real-comparison&quot;&gt;Google Analytics vs privacy-first analytics: the real comparison&lt;/h2&gt;
&lt;p&gt;A useful comparison starts with the recurring decisions your team needs to make:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Which channels produce qualified visits and conversions?&lt;/li&gt;
&lt;li&gt;Which pages support acquisition or activation?&lt;/li&gt;
&lt;li&gt;Are technical SEO changes improving clicks and outcomes?&lt;/li&gt;
&lt;li&gt;Did a change in consent or tagging alter the report?&lt;/li&gt;
&lt;li&gt;Are AI assistants sending visits or only fetching content?&lt;/li&gt;
&lt;li&gt;Can we export the evidence and recompute the result ourselves?&lt;/li&gt;
&lt;/ul&gt;













































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Area&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Google Analytics&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Privacy-first analytics&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Traffic measurement&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Broad and configurable, with results affected by tag behavior, consent implementation, browser limits, blockers, and reporting configuration&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Often narrower and easier to audit, but still affected by blockers, network failures, filtering, and the product’s own session model&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Conversion tracking&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Strong for Google Ads, app events, cross-channel attribution, and audience workflows&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Strong when goals and funnels map directly to first-party business outcomes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;User identification&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Supports advanced identity, audience, and attribution workflows when configured and permitted&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Usually avoids or limits persistent personal identifiers&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Compliance posture&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Requires careful review of collection, consent signals, Ads linkage, sharing, retention, and transfers&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Can reduce exposure through minimization and operator control, but is not automatically compliant&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Data portability&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;BigQuery can export raw GA4 events into a customer-controlled project, subject to setup and limits&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Often prioritizes downloadable open formats, APIs, and complete operator-controlled takeout&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Operational complexity&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Can involve tags, Consent Mode, events, custom definitions, audiences, modeled outcomes, and linked products&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Often aims for fewer moving parts, though self-hosting adds backup, security, and upgrade responsibilities&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;AI-era reporting&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Records rendered visits and recognizable referrals; non-rendered crawler fetches need edge or origin evidence&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Some platforms make AI referrals and crawler fetches first-class but must still keep them separate&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;The distinction is one of optimization. GA4 is deeply optimized for Google’s advertising, app, and analysis ecosystem. Privacy-first analytics is usually optimized for first-party website measurement, a smaller collection boundary, and operator control.&lt;/p&gt;
&lt;h2 id=&quot;compliance-neither-label-decides-the-outcome&quot;&gt;Compliance: neither label decides the outcome&lt;/h2&gt;
&lt;p&gt;“Google Analytics is illegal” and “privacy-first analytics is compliant” are both poor decision rules.&lt;/p&gt;
&lt;p&gt;GA4 can be deployed with consent management, storage controls, retention settings, and restricted Ads use. Whether that deployment is lawful depends on its purpose, configuration, contracts, transfers, notices, and jurisdiction.&lt;/p&gt;
&lt;p&gt;A privacy-first platform can also be deployed badly. Combining analytics with identifiable CRM data, retaining detailed logs indefinitely, or adding fingerprinting defeats the point of minimized tracking. Cookie-free does not mean regulation-free, and browser storage such as &lt;code&gt;sessionStorage&lt;/code&gt; may still require ePrivacy or PECR analysis.&lt;/p&gt;
&lt;p&gt;Ask concrete questions instead:&lt;/p&gt;

































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Question&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Why it matters&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;What does the tracker read or write on the device?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Cookies, local storage, session storage, and fingerprinting can trigger different technical and legal review.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Which identifiers and event properties leave the browser?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;This defines the actual data boundary rather than the marketing label.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Where is the data stored and processed?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Residency and transfers can affect procurement and legal obligations.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Can data be combined with advertising, CRM, or cross-site profiles?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Combination changes both utility and risk.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Can operators configure retention, export, and deletion?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;These controls determine portability and lifecycle management.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Which metrics are observed and which are modeled?&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Teams need to know what kind of evidence supports a decision.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;HitKeep’s &lt;a href=&quot;https://hitkeep.com/use-cases/privacy-first-web-analytics/&quot;&gt;privacy-first analytics overview&lt;/a&gt; describes its collection boundary and the consent caveats without making a universal compliance claim.&lt;/p&gt;
&lt;h2 id=&quot;data-ownership-and-control&quot;&gt;Data ownership and control&lt;/h2&gt;
&lt;p&gt;“Ownership” is too vague unless it is broken into concrete controls.&lt;/p&gt;
&lt;p&gt;GA4 reports live inside Google’s proprietary platform. BigQuery Export creates a copy of raw GA4 event data in a customer-controlled Google Cloud project, where Google says the customer owns the exported data and manages dataset permissions. That is a meaningful portability path, but it still depends on configuring another Google Cloud service and does not make GA4 self-hosted software.&lt;/p&gt;
&lt;p&gt;Privacy-first products often compete on a different set of controls: direct file exports, APIs, configurable retention, region selection, or a self-hosted runtime. Open-source software also lets teams inspect how collection and storage work rather than relying only on vendor documentation.&lt;/p&gt;
&lt;p&gt;HitKeep supports managed EU or US deployment and self-hosting from the same open-source foundation. The self-hosted product runs as one Go binary with DuckDB and NSQ embedded. Current runtime and collection details belong in &lt;a href=&quot;https://hitkeep.com/reference/facts-and-limits/&quot;&gt;Facts and Limits&lt;/a&gt;, while the available export surfaces and portability boundaries are documented in &lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;data takeout&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Self-hosting is not automatically the better choice. It transfers upgrades, backups, monitoring, access control, TLS, and incident response to your team. Use the &lt;a href=&quot;https://hitkeep.com/use-cases/self-hosted-ga4-alternative/&quot;&gt;self-hosted GA4 alternative guide&lt;/a&gt; when infrastructure control is the reason for evaluating a switch; use &lt;a href=&quot;https://hitkeep.com/pricing/&quot;&gt;HitKeep Cloud pricing&lt;/a&gt; when the goal is to test the reporting model without owning those operations.&lt;/p&gt;
&lt;h2 id=&quot;reporting-quality-compare-definitions-before-totals&quot;&gt;Reporting quality: compare definitions before totals&lt;/h2&gt;
&lt;p&gt;More sophistication does not guarantee a more useful number. Accuracy depends on the question and on whether both tools define the metric the same way.&lt;/p&gt;
&lt;p&gt;GA4 can be the better source for Google Ads optimization, app and web identity, modeled key events, and warehouse analysis. A focused privacy-first dashboard can be easier to trust for pageviews, referrers, goals, and funnels when the team can inspect the collection rules and does not need advertising audiences.&lt;/p&gt;
&lt;p&gt;Do not expect two tools to produce identical sessions or users. They can differ because of consent state, blockers, cookie or storage rules, session timeouts, bot filtering, geography enrichment, late events, and attribution models. Validate business outcomes—accepted leads, created accounts, confirmed purchases—before debating small traffic differences.&lt;/p&gt;
&lt;p&gt;Search performance belongs beside website analytics but remains a distinct dataset. HitKeep’s &lt;a href=&quot;https://hitkeep.com/guides/integrations/google-search-console/&quot;&gt;Google Search Console integration&lt;/a&gt; imports finalized aggregate query, page, country, and device rows; it does not connect a query to an individual session.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-search-console.CSc92Uud_1y11Bk.webp&quot; alt=&quot;HitKeep Search Console report with clicks, impressions, click-through rate, average position, top queries, devices, and countries&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Search Console aggregates add search demand and click evidence without pretending that a query identifies an individual visit.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;ai-traffic-changes-the-comparison&quot;&gt;AI traffic changes the comparison&lt;/h2&gt;
&lt;p&gt;AI search, assistants, and browsers create measurement paths that traditional session reports do not fully explain.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A rendered page can execute browser analytics.&lt;/li&gt;
&lt;li&gt;A click from an assistant can arrive with a recognizable referrer.&lt;/li&gt;
&lt;li&gt;A remote crawler fetch can appear in edge, CDN, proxy, or origin logs without executing JavaScript.&lt;/li&gt;
&lt;li&gt;An answer generated without a new request to your site leaves no direct pageview.&lt;/li&gt;
&lt;li&gt;A completed signup or purchase is best confirmed by the backend that accepted it.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;GA4 can record rendered visits and some AI referrals when its tag runs and the referrer is available. Non-rendered crawler retrieval requires server-side evidence regardless of the browser analytics product.&lt;/p&gt;
&lt;p&gt;HitKeep’s &lt;a href=&quot;https://hitkeep.com/guides/analytics/ai-visibility/&quot;&gt;AI Visibility report&lt;/a&gt; keeps AI-referred visits and forwarded crawler fetches separate. Neither signal proves that an assistant cited a page or influenced a later direct visit. The &lt;a href=&quot;https://hitkeep.com/blog/ai-browsers-web-analytics-2026/&quot;&gt;AI browser tracking guide&lt;/a&gt; explains the boundary in more detail.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-ai-visibility.DPXf9_ks_Z2apQEG.webp&quot; alt=&quot;HitKeep AI Visibility report showing crawler fetches, AI-referred visits, unique assistants, error rate, filters, and fetch volume&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;AI-referred visits and crawler fetches answer different questions and should remain separate reports.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;when-to-keep-google-analytics&quot;&gt;When to keep Google Analytics&lt;/h2&gt;
&lt;p&gt;Keep GA4 when it directly supports revenue or analysis workflows that another platform does not replace:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Google Ads attribution and audience activation;&lt;/li&gt;
&lt;li&gt;app and web analytics in one property;&lt;/li&gt;
&lt;li&gt;BigQuery-first analysis;&lt;/li&gt;
&lt;li&gt;Explorations, custom dimensions, and predictive workflows;&lt;/li&gt;
&lt;li&gt;agency or stakeholder processes that depend on GA4 output; or&lt;/li&gt;
&lt;li&gt;an implementation that has already passed your legal and security review.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Keeping GA4 does not require making it the source of truth for every audience. A hybrid model can reserve GA4 for advertising and advanced analysis while a privacy-first platform handles website performance, SEO, content, and executive reporting.&lt;/p&gt;
&lt;h2 id=&quot;when-to-switch-to-privacy-first-analytics&quot;&gt;When to switch to privacy-first analytics&lt;/h2&gt;
&lt;p&gt;Make privacy-first analytics the primary platform when your organization wants to minimize identifiers, narrow third-party data sharing, choose a hosting region, self-host, or simplify reports around first-party outcomes.&lt;/p&gt;
&lt;p&gt;The approach is often a good fit for B2B SaaS companies, publishers, agencies, open-source projects, nonprofits, public-sector organizations, and teams whose website analytics questions do not require advertising-grade user profiles.&lt;/p&gt;
&lt;p&gt;Privacy should not mean giving up business measurement. Look for goals, funnels, campaign and UTM reporting, ecommerce events, Search Console data, exports, APIs, retention controls, and a documented distinction between human visits and bot or AI activity.&lt;/p&gt;
&lt;h2 id=&quot;a-practical-migration-path&quot;&gt;A practical migration path&lt;/h2&gt;
&lt;p&gt;Run both systems in parallel before changing the reporting contract.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Audit the current GA4 property.&lt;/strong&gt; Identify the events, key events, audiences, reports, BigQuery jobs, and Ads links that people actually use.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Separate advertising from business reporting.&lt;/strong&gt; Mark which workflows exist for Google Ads and which answer broader acquisition, content, conversion, and executive questions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Map the privacy requirements.&lt;/strong&gt; Review collection, consent, storage, residency, retention, vendor access, and export needs with the responsible stakeholders.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Install privacy-first analytics beside GA4.&lt;/strong&gt; Run both for at least one complete business cycle without treating raw session totals as a pass/fail test.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Align outcome definitions.&lt;/strong&gt; Make sure “lead,” “signup,” “purchase,” and funnel steps mean the same thing, and prefer backend-confirmed events for critical outcomes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Choose a source of truth per job.&lt;/strong&gt; Keep GA4 where its Ads, app, or warehouse integrations are unique; use the privacy-first platform where it provides clearer and more controllable website reporting.&lt;/li&gt;
&lt;/ol&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-funnels.42JpCKzH_ZW4LPn.webp&quot; alt=&quot;HitKeep Funnels report with entries, completions, completion rate, period deltas, filters, and trend lines&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Parallel evaluation should compare agreed funnel entries and confirmed completions, not just session totals.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;This process prevents the most common migration error: comparing two tools before agreeing on what the business actually needs to measure.&lt;/p&gt;
&lt;h2 id=&quot;final-verdict&quot;&gt;Final verdict&lt;/h2&gt;
&lt;p&gt;Google Analytics remains a strong choice in 2026 for teams invested in Google Ads, app analytics, BigQuery, and advanced attribution workflows. It is no longer the automatic answer for every website.&lt;/p&gt;
&lt;p&gt;Privacy-first analytics is a serious alternative when the primary job is understanding first-party website traffic and outcomes with a smaller data boundary and more operator control. It can also sit beside GA4 rather than replacing it immediately.&lt;/p&gt;
&lt;p&gt;Use Google Analytics where its ecosystem is uniquely valuable. Make privacy-first analytics the center of gravity when the reports need to be understandable, portable, and proportionate to the decisions your team is making.&lt;/p&gt;</content:encoded></item><item><title>AI Browser Tracking in 2026: What Web Analytics Can See</title><link>https://hitkeep.com/blog/ai-browsers-web-analytics-2026/</link><guid isPermaLink="true">https://hitkeep.com/blog/ai-browsers-web-analytics-2026/</guid><description>Learn how AI browser tracking changes pageviews, referrals, crawler visibility, and conversions across JavaScript, server logs, and backend outcome events.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;AI browser tracking is not one new analytics channel. Some AI browsers read a page already open in a person’s browser. Some navigate across tabs and click through a workflow. Others retrieve content remotely without rendering your JavaScript at all.&lt;/p&gt;
&lt;p&gt;That distinction matters more than the browser brand. A normal pageview, an AI-referred visit, a server-side crawler fetch, and a completed signup answer four different questions. Combining them into one “AI traffic” number creates a neat chart and a poor measurement system.&lt;/p&gt;
&lt;p&gt;This guide explains how AI browsers affect pageviews, attribution, events, bot filtering, and privacy-first analytics. It also gives you a practical measurement plan that works even while the products and their names keep changing.&lt;/p&gt;
&lt;h2 id=&quot;what-ai-browser-tracking-can-and-cannot-see&quot;&gt;What AI browser tracking can and cannot see&lt;/h2&gt;
&lt;p&gt;The short answer depends on how the page or outcome was reached:&lt;/p&gt;





























&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;AI-mediated activity&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Observable evidence&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;A person opens a rendered page&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;strong&gt;Browser:&lt;/strong&gt; usually visible when the tracker runs.&lt;br&gt;&lt;strong&gt;Server:&lt;/strong&gt; visible as a normal request.&lt;br&gt;&lt;strong&gt;Backend:&lt;/strong&gt; visible only if an outcome occurs.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;A person clicks an AI assistant referral&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;strong&gt;Browser:&lt;/strong&gt; usually visible, sometimes with a recognizable referrer.&lt;br&gt;&lt;strong&gt;Server:&lt;/strong&gt; visible as a normal request.&lt;br&gt;&lt;strong&gt;Backend:&lt;/strong&gt; visible only if an outcome occurs.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;A remote agent or crawler fetches a page&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;strong&gt;Browser:&lt;/strong&gt; usually invisible because JavaScript does not run.&lt;br&gt;&lt;strong&gt;Server:&lt;/strong&gt; often visible.&lt;br&gt;&lt;strong&gt;Backend:&lt;/strong&gt; usually absent.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;An assistant answers without visiting&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;strong&gt;Browser:&lt;/strong&gt; invisible.&lt;br&gt;&lt;strong&gt;Server:&lt;/strong&gt; invisible for that answer.&lt;br&gt;&lt;strong&gt;Backend:&lt;/strong&gt; absent.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;A person or agent completes a signup or purchase&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;&lt;strong&gt;Browser:&lt;/strong&gt; supporting events may be visible.&lt;br&gt;&lt;strong&gt;Server:&lt;/strong&gt; partially visible.&lt;br&gt;&lt;strong&gt;Backend:&lt;/strong&gt; the best source of truth.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;No single row identifies an “AI browser session” with certainty. Reliable AI browser analytics keeps browser pageviews, AI referrals, server-side crawler records, and confirmed outcomes separate.&lt;/p&gt;
&lt;p&gt;Use this guide to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/ai-browsers-web-analytics-2026/#separate-four-kinds-of-ai-mediated-activity&quot;&gt;Understand the four modes of AI-mediated browsing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/ai-browsers-web-analytics-2026/#pageviews-still-work-but-they-mean-less-on-their-own&quot;&gt;See what happens to pageviews and attribution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/ai-browsers-web-analytics-2026/#can-ga4-track-ai-browser-traffic&quot;&gt;Compare GA4, browser tracking, and server-side evidence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/ai-browsers-web-analytics-2026/#a-privacy-first-measurement-plan-for-ai-browsers&quot;&gt;Build a privacy-first measurement plan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/ai-browsers-web-analytics-2026/#test-the-browsers-instead-of-assuming&quot;&gt;Run a repeatable browser test&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;separate-four-kinds-of-ai-mediated-activity&quot;&gt;Separate four kinds of AI-mediated activity&lt;/h2&gt;
&lt;p&gt;Start by identifying how the content reached the model or the person. The collection path changes with it.&lt;/p&gt;
&lt;h3 id=&quot;on-page-assistance&quot;&gt;On-page assistance&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;What happened:&lt;/strong&gt; A person opened your page, then asked the browser to summarize or explain it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;What analytics can observe:&lt;/strong&gt; The rendered pageview and any normal browser events. The follow-up questions usually remain inside the browser or assistant.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;agent-navigation&quot;&gt;Agent navigation&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;What happened:&lt;/strong&gt; An assistant opened pages, clicked controls, or filled fields in a visible browser session.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;What analytics can observe:&lt;/strong&gt; Pageviews and DOM-based events may run. Your site may not have a reliable signal that an agent performed the action.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;remote-retrieval&quot;&gt;Remote retrieval&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;What happened:&lt;/strong&gt; A crawler or remote service fetched the page without running the browser tracker.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;What analytics can observe:&lt;/strong&gt; Edge, CDN, proxy, or origin logs. Client-side analytics usually sees nothing.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;answer-without-a-visit&quot;&gt;Answer without a visit&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;What happened:&lt;/strong&gt; The assistant answered from an index, memory, or previously retrieved content and never opened your site.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;What analytics can observe:&lt;/strong&gt; No direct pageview. Search reporting, later referrals, and business outcomes provide indirect context, not proof of exposure.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These modes can occur within one user task. A browser might summarize an open page, fetch another source remotely, and then navigate to a third site to complete an action. The analytics records will not necessarily share one identifier or attribution chain.&lt;/p&gt;
&lt;h2 id=&quot;which-ai-browsers-matter-in-2026&quot;&gt;Which AI browsers matter in 2026?&lt;/h2&gt;
&lt;p&gt;The dedicated alternatives are now familiar. &lt;a href=&quot;https://www.perplexity.ai/help-center/en/articles/11172798-getting-started-with-comet&quot;&gt;Perplexity describes Comet&lt;/a&gt; as a Chromium-based browser with built-in AI capabilities. &lt;a href=&quot;https://www.diabrowser.com/&quot;&gt;Dia&lt;/a&gt; focuses on working across tabs and connected services to prepare briefs, synthesize information, and answer questions from a user’s wider context.&lt;/p&gt;
&lt;p&gt;The established browsers are moving in the same direction:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.google/products-and-platforms/products/chrome/chrome-expands-india-new-zealand-canada/&quot;&gt;Gemini in Chrome&lt;/a&gt; can summarize pages, use context from multiple tabs, and work with Google services.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.microsoft.com/en-us/microsoft-copilot/browse-with-copilot&quot;&gt;Browse with Copilot&lt;/a&gt; can select, type, and navigate inside an Edge tab while the user watches or takes control.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.mozilla.org/en/firefox/how-to-use-ai-controls/&quot;&gt;Firefox AI controls&lt;/a&gt; let people disable all supported AI features or manage them individually.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://brave.com/blog/ai-browsing/&quot;&gt;Brave’s agentic browsing test&lt;/a&gt; uses a separate profile and explicit action cues, while Brave also warns that browser agents introduce privacy and security risks.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Product availability can change faster than an analytics implementation. OpenAI launched Atlas in October 2025, but its current support guidance says &lt;a href=&quot;https://help.openai.com/en/articles/20001371-evolving-atlas-into-chatgpt-for-browser-based-agentic-work&quot;&gt;Atlas will stop working on August 9, 2026&lt;/a&gt; as browser-based agentic work moves into other OpenAI surfaces.&lt;/p&gt;
&lt;p&gt;The durable trend is not a particular browser. It is the addition of an assistant that can read page context, combine information across tabs, and sometimes act inside a rendered browsing session.&lt;/p&gt;
&lt;h2 id=&quot;compare-context-control-and-data-flow-before-choosing&quot;&gt;Compare context, control, and data flow before choosing&lt;/h2&gt;
&lt;p&gt;Feature lists make AI browsers look more similar than they are. For individuals and teams, the important differences sit underneath the summary button.&lt;/p&gt;
&lt;p&gt;Ask five questions before standardizing on one:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;What context can the assistant read?&lt;/strong&gt; Distinguish the current page from other tabs, history, connected email or calendar accounts, cookies, saved credentials, local files, and form input.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;What can it do?&lt;/strong&gt; Summarizing a page has a different risk boundary from selecting, typing, navigating, submitting a form, or approving an irreversible action.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Where is the context processed and retained?&lt;/strong&gt; Check what stays on the device, what goes to the provider or its model partners, whether content can be used for product improvement, and how deletion works.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;What controls exist?&lt;/strong&gt; Look for opt-in behavior, site blocks, isolated profiles, action previews, interruption, administrator policies, and a way to disable the assistant.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Who can use the feature today?&lt;/strong&gt; Platform, region, account, rollout cohort, and subscription requirements can matter as much as the product name.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The current products show why this review matters:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.perplexity.ai/help-center/comet/en/articles/12867415-comet-assistant-privacy-data-use&quot;&gt;Comet’s privacy guidance&lt;/a&gt; says browsing history, the full tab list, cookies, passwords, local files, and typed input stay on the device by default. Requests can send the context needed for a summary or task, and some assistant context can be retained for up to 30 days. Users can disable the assistant or block it on specific sites.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.diabrowser.com/security&quot;&gt;Dia’s privacy and security documentation&lt;/a&gt; explains that relevant request context can pass through Dia’s servers and model providers. Content sharing for product improvement can be disabled, and write actions require review before they proceed.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.google.com/chrome/ai-innovations/&quot;&gt;Gemini in Chrome&lt;/a&gt; can use open-tab context and offers an agentic auto-browse mode, but current availability depends on account, subscription, and region.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.microsoft.com/en-us/microsoft-copilot/browse-with-copilot&quot;&gt;Browse with Copilot&lt;/a&gt; can select, type, and navigate in a visible Edge tab. Microsoft documents current rollout limits, access to open tabs and signed-in cookies, and warnings for sensitive workflows.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.mozilla.org/en-US/kb/firefox-ai-controls&quot;&gt;Firefox AI controls&lt;/a&gt; let people block all supported generative AI features or manage them individually.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://brave.com/blog/ai-browsing/&quot;&gt;Brave’s agentic browsing test&lt;/a&gt; is opt-in and uses an isolated browsing profile so the agent does not inherit the normal profile’s cookies and logged-in state.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For analytics teams, these differences affect test coverage and traffic quality, but they do not create a standard “AI browser” flag that a website can trust. Measure the observable request or outcome instead of inferring the assistant from the browser brand.&lt;/p&gt;
&lt;h2 id=&quot;pageviews-still-work-but-they-mean-less-on-their-own&quot;&gt;Pageviews still work, but they mean less on their own&lt;/h2&gt;
&lt;p&gt;A pageview remains a useful statement: the page rendered and the tracking code ran. AI browsers do not make that false.&lt;/p&gt;
&lt;p&gt;What changes is the relationship between the pageview and the amount of content consumed. One rendered page may support several summaries, comparisons, or questions without another navigation. At the other extreme, an assistant may extract enough information remotely that no pageview occurs.&lt;/p&gt;
&lt;p&gt;Use pageviews for reach and navigation analysis, but do not treat them as a complete measure of attention. Pair them with:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;landing pages and referrers for acquisition context;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/custom-events/&quot;&gt;custom events&lt;/a&gt; for meaningful interactions;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/goals/&quot;&gt;goals&lt;/a&gt; and &lt;a href=&quot;https://hitkeep.com/guides/analytics/funnels/&quot;&gt;funnels&lt;/a&gt; for business progress;&lt;/li&gt;
&lt;li&gt;server-confirmed events for outcomes that must be accurate; and&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/ai-fetch-ingest/&quot;&gt;AI crawler fetch records&lt;/a&gt; for non-rendered retrieval.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is also why a sudden drop in pageviews does not prove that AI browsers took the traffic. Check search impressions, click-through rate, rankings, campaign changes, tracker delivery, consent behavior, and affected landing pages before assigning a cause.&lt;/p&gt;
&lt;h2 id=&quot;attribution-needs-conservative-labels&quot;&gt;Attribution needs conservative labels&lt;/h2&gt;
&lt;p&gt;An AI assistant referral is not the same thing as an AI browser session.&lt;/p&gt;
&lt;p&gt;If someone clicks a link from ChatGPT, Perplexity, Claude, or another assistant, the destination may receive a recognizable referrer. That belongs in AI referral reporting. If someone types your URL in Comet or opens a bookmark in Dia, the visit may look like any other direct or browser visit. If an assistant opens a page inside a normal tab, the referrer depends on the navigation path and browser policy.&lt;/p&gt;
&lt;p&gt;Do not manufacture certainty by labelling every visit from an AI-capable browser as “AI traffic.” Record the evidence you have:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;referrer host;&lt;/li&gt;
&lt;li&gt;campaign parameters;&lt;/li&gt;
&lt;li&gt;landing page;&lt;/li&gt;
&lt;li&gt;timestamp;&lt;/li&gt;
&lt;li&gt;user agent where your privacy policy and collection design allow it; and&lt;/li&gt;
&lt;li&gt;downstream goal or revenue outcome.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Then classify conservatively. HitKeep’s &lt;a href=&quot;https://hitkeep.com/guides/analytics/ai-visibility/&quot;&gt;AI Visibility report&lt;/a&gt; keeps AI-referred human visits separate from AI crawler fetches for this reason. A fetch shows that an identified crawler requested a path. A referral shows that a person later arrived from an assistant. Neither signal proves that the assistant cited the page or that the fetch caused the visit.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-ai-visibility.DPXf9_ks_Z2apQEG.webp&quot; alt=&quot;HitKeep AI Visibility dashboard showing separate totals for AI crawler fetches and AI-referred visits, assistant filters, fetch errors, and fetch volume&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The AI Visibility overview keeps crawler fetches and AI-referred visits as separate metrics before showing assistant filters, fetch volume, and errors.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;can-ga4-track-ai-browser-traffic&quot;&gt;Can GA4 track AI browser traffic?&lt;/h2&gt;
&lt;p&gt;GA4 can record an AI browser visit when the page renders, the Google tag runs, and the request is not blocked. It can also attribute some visits from ChatGPT, Perplexity, Claude, and similar services when the destination receives a recognizable referrer or campaign parameter.&lt;/p&gt;
&lt;p&gt;That does not make every visit in Comet, Dia, Chrome, Edge, Firefox, or Brave identifiable as AI-mediated traffic. A direct visit can still look direct, an agent action inside a rendered tab can resemble an ordinary interaction, and remote retrieval usually does not execute the Google tag.&lt;/p&gt;
&lt;p&gt;Use GA4 or another client-side analytics tool for rendered sessions and visible referrals. Use edge or origin records for crawler fetches, and use backend events for confirmed outcomes. The &lt;a href=&quot;https://hitkeep.com/vs/ai-traffic-analytics-alternative-to-ga4/&quot;&gt;AI traffic analytics alternative to GA4 comparison&lt;/a&gt; shows where HitKeep adds server-side AI crawler reporting and fetch-to-visit correlation without replacing GA4’s Google Ads, app analytics, or exploration workflows.&lt;/p&gt;
&lt;h2 id=&quot;critical-events-should-be-confirmed-on-the-server&quot;&gt;Critical events should be confirmed on the server&lt;/h2&gt;
&lt;p&gt;Browser agents can click buttons, fill forms, and move through checkout steps. Automatic browser events may record those interactions if the page and tracker run normally. They are useful for understanding the path.&lt;/p&gt;
&lt;p&gt;The final business outcome should come from the system that accepted it:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;emit a signup-complete event after the account exists;&lt;/li&gt;
&lt;li&gt;emit a purchase event after the order or payment is confirmed;&lt;/li&gt;
&lt;li&gt;record a subscription change after the billing system accepts it;&lt;/li&gt;
&lt;li&gt;record a lead after the backend accepts the form, not only when the submit button is clicked; and&lt;/li&gt;
&lt;li&gt;use idempotent event handling where retries could create duplicates.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/server-side-tracking/&quot;&gt;Server-side tracking&lt;/a&gt; gives these events a collection path that does not depend on the agent, browser extension, content blocker, page lifecycle, or client connection finishing a beacon request.&lt;/p&gt;
&lt;p&gt;This does not mean moving every interaction to the backend. Keep low-risk navigation and engagement events in the browser. Move the outcomes used for revenue, activation, provisioning, or operational decisions to the server.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-funnels.42JpCKzH_ZW4LPn.webp&quot; alt=&quot;HitKeep Funnels dashboard showing entries, completions, completion rate, period comparison, and funnel trend lines&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Funnels connect tracked steps to completions and period comparisons. Critical completion events should still come from the system that accepted the outcome.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;do-not-turn-every-assisted-session-into-a-bot&quot;&gt;Do not turn every assisted session into a bot&lt;/h2&gt;
&lt;p&gt;An AI-capable browser may still represent a person making decisions. Blocking or discarding the session because an assistant helped with the workflow can remove valid visits and conversions.&lt;/p&gt;
&lt;p&gt;Known crawler requests are different. They usually arrive through identifiable user-agent families, do not execute your browser tracker, and should be measured at the edge or origin. HitKeep’s &lt;a href=&quot;https://hitkeep.com/guides/tracking/ai-fetch-ingest/&quot;&gt;AI fetch ingest&lt;/a&gt; accepts matching crawler records separately from normal pageviews.&lt;/p&gt;
&lt;p&gt;Use a narrow classification policy:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Treat a rendered visit as a visit unless you have strong evidence that it is invalid traffic.&lt;/li&gt;
&lt;li&gt;Keep known AI crawler fetches in a separate server-side dataset.&lt;/li&gt;
&lt;li&gt;Apply &lt;a href=&quot;https://hitkeep.com/guides/tracking/spam-filtering/&quot;&gt;spam filtering&lt;/a&gt; to known abusive networks and impossible behavior.&lt;/li&gt;
&lt;li&gt;Avoid browser fingerprinting added only to guess whether an assistant was involved.&lt;/li&gt;
&lt;li&gt;Preserve an “unknown” category when the evidence does not support a stronger label.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;That approach produces less certainty on individual sessions and more trustworthy totals.&lt;/p&gt;
&lt;h2 id=&quot;a-privacy-first-measurement-plan-for-ai-browsers&quot;&gt;A privacy-first measurement plan for AI browsers&lt;/h2&gt;
&lt;p&gt;You do not need a larger tracking surface. You need a clearer mapping from business questions to evidence.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Did a page render for a visitor?&lt;/strong&gt; Use a pageview from the cookie-less browser tracker.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Did an assistant send a person to the site?&lt;/strong&gt; Use the referrer and landing page from browser tracking and AI referral reporting.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Did an AI crawler request the content?&lt;/strong&gt; Record the path, crawler family, status, and timestamp from edge, CDN, proxy, or origin logs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Did the person or agent complete an important outcome?&lt;/strong&gt; Emit a confirmed conversion event from the application or commerce backend.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Did the workflow progress before completion?&lt;/strong&gt; Use custom events and funnel steps, with server events for critical stages.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Can we recheck the classification later?&lt;/strong&gt; Keep portable event records through &lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;open exports and takeout&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Collect the minimum fields needed for those questions. A privacy-first setup should resist the temptation to add persistent identifiers or fingerprinting because browser behavior became harder to classify.&lt;/p&gt;
&lt;p&gt;HitKeep uses &lt;a href=&quot;https://hitkeep.com/use-cases/cookieless-event-tracking/&quot;&gt;cookie-less event tracking&lt;/a&gt; by default, supports browser and server-side events, and keeps AI referrals and crawler fetches as separate reports. Consent and legal requirements still depend on your full deployment, purpose, configuration, and jurisdiction.&lt;/p&gt;
&lt;h2 id=&quot;managed-cloud-or-self-hosted-analytics&quot;&gt;Managed cloud or self-hosted analytics?&lt;/h2&gt;
&lt;p&gt;The browser measurement model does not change with the deployment model. Both managed and self-hosted analytics still need browser tracking for rendered visits, server-confirmed events for critical outcomes, and edge or origin records for non-rendered crawler fetches.&lt;/p&gt;
&lt;p&gt;The choice changes which operating and governance responsibilities your team owns.&lt;/p&gt;
&lt;p&gt;Choose &lt;a href=&quot;https://hitkeep.com/pricing/&quot;&gt;HitKeep Cloud&lt;/a&gt; when you want:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;a faster pilot without operating the analytics runtime;&lt;/li&gt;
&lt;li&gt;managed upgrades, backups, SMTP, and day-two operations;&lt;/li&gt;
&lt;li&gt;a region-pinned deployment in Frankfurt or Virginia; and&lt;/li&gt;
&lt;li&gt;the same self-service export paths without managing the storage and backup infrastructure yourself.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Choose &lt;a href=&quot;https://hitkeep.com/guides/installation/&quot;&gt;self-hosted HitKeep&lt;/a&gt; when you want:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;direct control over the runtime, data directory, network boundary, backup targets, and upgrade schedule;&lt;/li&gt;
&lt;li&gt;analytics data to remain inside infrastructure you operate;&lt;/li&gt;
&lt;li&gt;a single Go binary with DuckDB and NSQ embedded instead of separate database and queue services; and&lt;/li&gt;
&lt;li&gt;the responsibility to configure retention, backups, email, TLS, monitoring, and recovery.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Neither option recovers an interaction that never reached your site. Deployment is an operating decision; the collection paths described in this article are the measurement decision.&lt;/p&gt;
&lt;h2 id=&quot;test-the-browsers-instead-of-assuming&quot;&gt;Test the browsers instead of assuming&lt;/h2&gt;
&lt;p&gt;Run a small repeatable test whenever a browser or assistant becomes important to your audience.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Open a tagged test landing page manually.&lt;/li&gt;
&lt;li&gt;Ask the assistant to summarize the page without navigating away.&lt;/li&gt;
&lt;li&gt;Ask it to open a second tagged page.&lt;/li&gt;
&lt;li&gt;Let it complete a harmless test workflow, such as a sandbox signup.&lt;/li&gt;
&lt;li&gt;Check the browser pageviews, custom events, backend confirmation, referrer, and server logs.&lt;/li&gt;
&lt;li&gt;Repeat with privacy protections or content blocking enabled.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Record the result in a dated worksheet:&lt;/p&gt;





































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Test field&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;What to record&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Product and version&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Browser, assistant feature, build, platform, account type, and region&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Page rendered&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Whether the tagged page visibly opened&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Browser tracker&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Whether the pageview and expected browser events arrived&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Referrer and campaign&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;The referrer value, campaign parameters, or absence of both&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Server request&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Whether the edge, proxy, CDN, or origin recorded a request&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Backend outcome&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Whether the application confirmed the test signup, lead, or purchase&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Controls&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Content blocking, privacy mode, isolated profile, and assistant permissions&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;Document what you observed, including the browser version and date. Do not turn one result into a permanent product assumption. AI browser features are frequently gated by platform, region, account type, rollout cohort, and user settings. This article therefore describes durable measurement boundaries instead of claiming one permanent result for every Comet, Dia, or incumbent-browser release.&lt;/p&gt;
&lt;p&gt;For crawler tests, use server logs instead of the visible browser. The &lt;a href=&quot;https://hitkeep.com/use-cases/ai-crawler-logs-vs-ai-referral-traffic/&quot;&gt;AI crawler logs versus AI referral traffic guide&lt;/a&gt; explains why those datasets answer different questions.&lt;/p&gt;
&lt;h2 id=&quot;what-to-watch-over-the-next-6-to-12-months&quot;&gt;What to watch over the next 6 to 12 months&lt;/h2&gt;
&lt;p&gt;Treat these as instrumentation watchpoints, not predictions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The gap between discovery and visits.&lt;/strong&gt; Compare search impressions, AI crawler fetches, AI referrals, pageviews, and conversions separately. A growing gap can justify investigation, but no single series proves that an assistant summarized the page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Agent identification standards.&lt;/strong&gt; Watch for stable, documented request headers, crawler identities, or opt-in browser signals. Do not build production classification around an experiment until its semantics and privacy boundary are clear.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Feature availability.&lt;/strong&gt; Record browser version, platform, region, account type, and test date. Agentic modes frequently move between experiments, subscriptions, and general availability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security and privacy controls.&lt;/strong&gt; Isolated profiles, per-site blocks, administrator policies, and model-context choices can change which events or authenticated states appear in a test.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Your ability to re-run the analysis.&lt;/strong&gt; Preserve baselines and export samples so a new classification rule can be tested against historical records instead of only future traffic.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Small, repeatable checks are more useful than a large one-time instrumentation rewrite.&lt;/p&gt;
&lt;h2 id=&quot;a-practical-30-day-checklist&quot;&gt;A practical 30-day checklist&lt;/h2&gt;
&lt;p&gt;If AI-mediated browsing is relevant to your acquisition or product flow, use this sequence:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;List the metrics that drive decisions. Remove events that nobody uses.&lt;/li&gt;
&lt;li&gt;Record a baseline by referrer, landing page, goal, and funnel before changing the tracking setup.&lt;/li&gt;
&lt;li&gt;Move signup, purchase, and other critical outcomes to server-confirmed events.&lt;/li&gt;
&lt;li&gt;Forward known AI crawler requests from the edge or origin if content discovery matters.&lt;/li&gt;
&lt;li&gt;Test the AI browsers and incumbent AI features your audience actually uses.&lt;/li&gt;
&lt;li&gt;Review false bot classifications and keep ambiguous rendered visits out of crawler totals.&lt;/li&gt;
&lt;li&gt;Export a sample dataset and confirm that the team can re-run the analysis outside the dashboard.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The aim is not to identify every model interaction. It is to preserve reliable answers about reach, acquisition, conversion, and content retrieval while the browser layer changes.&lt;/p&gt;
&lt;h2 id=&quot;where-hitkeep-fits&quot;&gt;Where HitKeep fits&lt;/h2&gt;
&lt;p&gt;HitKeep provides the measurement paths covered in this article:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;cookie-less browser pageviews and automatic outbound, download, and form events;&lt;/li&gt;
&lt;li&gt;custom browser and &lt;a href=&quot;https://hitkeep.com/guides/tracking/server-side-tracking/&quot;&gt;server-side events&lt;/a&gt;;&lt;/li&gt;
&lt;li&gt;goals, funnels, ecommerce, and UTM reporting;&lt;/li&gt;
&lt;li&gt;AI-referred visit reporting;&lt;/li&gt;
&lt;li&gt;server-side AI crawler fetch ingest and correlation views; and&lt;/li&gt;
&lt;li&gt;exports through &lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;takeout&lt;/a&gt; in CSV, Parquet, JSON, NDJSON, and XLSX where supported.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can self-host the same open-source foundation as one Go binary with embedded DuckDB and NSQ, or use &lt;a href=&quot;https://hitkeep.com/pricing/&quot;&gt;HitKeep Cloud&lt;/a&gt; in the EU or US when managed upgrades, backups, and day-two operations are the better fit.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/ai-performance/&quot;&gt;AI Performance for SEO Agencies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/ai-visibility/&quot;&gt;AI Visibility Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/use-cases/ai-crawler-logs-vs-ai-referral-traffic/&quot;&gt;AI Crawler Logs vs. AI Referral Traffic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/vs/ai-traffic-analytics-alternative-to-ga4/&quot;&gt;AI Traffic Analytics Alternative to GA4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/server-side-tracking/&quot;&gt;Server-Side Tracking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/use-cases/cookieless-event-tracking/&quot;&gt;Cookie-less Event Tracking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;Open Exports and Takeout&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.12.0: Team OIDC SSO, Invite-Aware Sign-In, And Routed Site Settings</title><link>https://hitkeep.com/blog/hitkeep-2-12-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-12-0/</guid><description>HitKeep 2.12.0 added team-scoped OIDC single sign-on, invite-aware identity provisioning, and routed site settings.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.12.0 added team-scoped OpenID Connect single sign-on, carried invitations safely through the provider flow, and gave owners a controlled path from connection testing to rollout without turning analytics access into another disconnected account lifecycle.&lt;/p&gt;
&lt;p&gt;The release also gives site settings real routes, brings password, passkey, and SSO choices into one consistent sign-in surface, and fixes two less visible but important boundaries: QR campaign data now survives site changes correctly, and cross-origin request checks use the standard browser security contract.&lt;/p&gt;
&lt;h2 id=&quot;what-shipped&quot;&gt;What Shipped&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Team OIDC SSO:&lt;/strong&gt; connect one OpenID Connect provider to a team, route allowed email domains to it, and keep the configuration within the team’s administration area.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Invite-aware access:&lt;/strong&gt; carry a pending team invitation through the provider redirect, verify the returned email, preserve the invited role, and consume only that invitation after successful authentication.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Optional trusted-domain provisioning:&lt;/strong&gt; owners and admins can let a verified user from an allowed domain join as a Member without an invitation; the option is off by default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Stronger OIDC verification:&lt;/strong&gt; use Authorization Code flow with PKCE S256, exact issuer and audience checks, nonce validation, one-time state, and a required boolean &lt;code&gt;email_verified: true&lt;/code&gt; claim.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;One authentication surface:&lt;/strong&gt; password, passkey, and SSO entry points now share the same card, feedback, loading, and error patterns across login, signup, setup, password recovery, and invitation acceptance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Routed site settings:&lt;/strong&gt; general, tracking, filtering, retention, access, and danger-zone settings have stable URLs and route-level permission checks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Addressable invitations:&lt;/strong&gt; team administrators can link directly to the invite flow instead of relying on page-local dialog state.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data and request-boundary fixes:&lt;/strong&gt; site changes preserve QR campaign data, while state-changing cross-origin requests are checked with a standard origin policy.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;configure-sso-per-team&quot;&gt;Configure SSO Per Team&lt;/h2&gt;
&lt;p&gt;Owners and admins configure SSO under &lt;strong&gt;Administration → Team → SSO&lt;/strong&gt;. The page keeps the callback URL, issuer, client credentials, allowed domains, claim mapping, connection test, and enable switch together. One team connects to one OIDC provider, and one email domain can belong to only one SSO configuration in a HitKeep instance, keeping email-based provider discovery unambiguous.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/security-sso-team-configuration.CClRiQfA_Zdw3Un.webp&quot; alt=&quot;HitKeep 2.12 team SSO settings showing an enabled OpenID Connect issuer, client ID, allowed email domains, callback URL, connection test, and save action&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1440&quot; height=&quot;1200&quot;&gt;&lt;figcaption&gt;The team SSO page presents provider configuration, domain routing, security checks, testing, and rollout controls in one place.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;HitKeep stores the client secret encrypted and never returns it to the dashboard. Leaving the field blank keeps the current secret; entering another value rotates it. The callback URL comes from the configured public URL, including any deployment path prefix, so the identity-provider registration can match the real installation exactly.&lt;/p&gt;
&lt;p&gt;The connection test validates discovery metadata before rollout. It checks that the issuer is reachable and advertises usable authorization, token, and key endpoints. A real browser sign-in is still required before announcing the integration because provider assignment, the client secret, callback matching, and ID-token claims can only be proven end to end.&lt;/p&gt;
&lt;p&gt;On HitKeep Cloud, SSO is included with the Business plan. Self-hosted HitKeep includes the feature without a plan gate. Password and passkey sign-in remain available: this release adds OIDC as an authentication method; it does not force a domain to use SSO or replace the existing recovery path.&lt;/p&gt;
&lt;h2 id=&quot;verified-identity-is-not-automatic-access&quot;&gt;Verified Identity Is Not Automatic Access&lt;/h2&gt;
&lt;p&gt;An allowed email domain tells HitKeep which identity provider to use. It does not grant membership by itself. After the provider returns a verified identity, one of these authorization paths must apply:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the person is already a member of the routed team;&lt;/li&gt;
&lt;li&gt;the person has a live invitation for that team; or&lt;/li&gt;
&lt;li&gt;an owner or admin has explicitly enabled trusted-domain auto-provisioning.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Invitation acceptance stays scoped to the invitation that started the flow. HitKeep carries the one-time token through OIDC state, requires the provider to return the same verified email address, preserves the requested team role, and does not accept other pending invitations for that address.&lt;/p&gt;
&lt;p&gt;Automatic provisioning is deliberately off by default. When enabled, a verified trusted-domain user joins as a Member. Managed-cloud seat and team limits still apply, and team membership does not silently create site permissions; those remain a separate assignment.&lt;/p&gt;
&lt;p&gt;This keeps identity verification and product authorization distinct. The identity provider proves who signed in. HitKeep still decides which team and sites that identity can access.&lt;/p&gt;
&lt;h2 id=&quot;a-clearer-sign-in-flow&quot;&gt;A Clearer Sign-In Flow&lt;/h2&gt;
&lt;p&gt;The normal login page now presents password, passkey, and SSO methods through the same interaction pattern. Choosing SSO asks for a work email first, then routes the user to the configured provider for that domain. The page can also open directly in SSO mode with a prefilled email, which makes invitation and organization-managed entry points less repetitive.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/security-sso-login.CqvpLt8B_1fvk8q.webp&quot; alt=&quot;HitKeep 2.12 sign-in page showing email and password fields with passkey and SSO login options&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1280&quot; height=&quot;900&quot;&gt;&lt;figcaption&gt;Password, passkey, and SSO remain visible choices on one sign-in surface; enabling team SSO does not remove the existing login methods.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The same auth components now appear across invitation acceptance, setup, signup, forgotten-password, and reset-password pages. Loading belongs to the action that is running, provider failures return to the right surface, and an access-denied result is distinct from a discovery or token-exchange failure.&lt;/p&gt;
&lt;p&gt;Invited users do not need to leave the invitation page to discover whether SSO is available. If the invited team has an enabled and entitled connection, the page offers &lt;strong&gt;Continue with SSO&lt;/strong&gt; and carries the invitation through the redirect. Existing password-based invitation acceptance continues to work.&lt;/p&gt;
&lt;h2 id=&quot;oidc-security-boundaries&quot;&gt;OIDC Security Boundaries&lt;/h2&gt;
&lt;p&gt;HitKeep’s OIDC relying party validates more than a successful redirect. The flow uses:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Authorization Code flow with PKCE S256;&lt;/li&gt;
&lt;li&gt;exact issuer and audience validation on the ID token;&lt;/li&gt;
&lt;li&gt;nonce validation and short-lived, one-time state;&lt;/li&gt;
&lt;li&gt;a required native boolean &lt;code&gt;email_verified: true&lt;/code&gt; claim;&lt;/li&gt;
&lt;li&gt;encrypted storage for the provider client secret;&lt;/li&gt;
&lt;li&gt;no storage of provider access or ID tokens; and&lt;/li&gt;
&lt;li&gt;team audit events for configuration changes, tests, and login outcomes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Managed HitKeep Cloud also requires HTTPS provider endpoints, rejects private and other non-public network targets, and checks redirects before following them. Self-hosted installations can reach an internal identity provider when the HitKeep host can resolve it and trusts its TLS certificate.&lt;/p&gt;
&lt;p&gt;The boundary is intentionally narrower than a full identity-governance product. Version 2.12.0 does not add SAML, SCIM, identity-provider-initiated login, group-to-role mapping, forced SSO, or continuous provider-to-HitKeep account synchronization. Removing a user at the provider prevents future SSO authentication, but operators must still remove the HitKeep membership and review any other enabled login methods.&lt;/p&gt;
&lt;h2 id=&quot;site-settings-become-addressable-pages&quot;&gt;Site Settings Become Addressable Pages&lt;/h2&gt;
&lt;p&gt;Site settings are no longer a drawer whose state disappears when the page closes. Each section now has a stable route under the selected site:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;general&lt;/li&gt;
&lt;li&gt;tracking&lt;/li&gt;
&lt;li&gt;filtering&lt;/li&gt;
&lt;li&gt;retention&lt;/li&gt;
&lt;li&gt;access&lt;/li&gt;
&lt;li&gt;danger zone&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Deep links open the requested section, browser titles describe the active page, and route guards apply the same site capabilities that control which tabs are visible. Someone without permission to manage exclusions, retention, team access, or deletion cannot bypass that boundary by typing a URL.&lt;/p&gt;
&lt;p&gt;This also removes a layer of layout state from the analytics dashboard. Settings use the same page frame, breadcrumbs, and routed-tab pattern as team administration, making the interface more predictable on reload and easier to link from support or operational documentation.&lt;/p&gt;
&lt;p&gt;The team members area received the same treatment for invitations: &lt;strong&gt;Administration → Team → Members → Invite&lt;/strong&gt; is now an addressable state, so an owner can return directly to the task without reopening a local dialog.&lt;/p&gt;
&lt;h2 id=&quot;reliability-and-security-fixes&quot;&gt;Reliability And Security Fixes&lt;/h2&gt;
&lt;p&gt;Two fixes sit below the visible product changes.&lt;/p&gt;
&lt;p&gt;Changing a site’s domain or moving site data relies on a careful shadow-row sequence because DuckDB rewrites indexed rows and does not provide cascading or deferred foreign-key behavior. Version 2.12.0 relaxes the QR parent constraints involved in that workflow and preserves QR campaigns, codes, visits, and related analytics during supported site changes.&lt;/p&gt;
&lt;p&gt;The server also replaces a custom fetch-metadata implementation with a standard cross-origin protection policy for state-changing requests. Same-origin dashboard requests keep working, approved cross-origin API behavior remains explicit, and requests that do not satisfy the browser-origin contract are rejected before reaching protected handlers.&lt;/p&gt;
&lt;h2 id=&quot;what-is-not-changing&quot;&gt;What Is Not Changing&lt;/h2&gt;
&lt;p&gt;HitKeep 2.12.0 keeps the same operating model:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;one Go binary&lt;/li&gt;
&lt;li&gt;embedded DuckDB data stores&lt;/li&gt;
&lt;li&gt;embedded NSQ queueing&lt;/li&gt;
&lt;li&gt;no required PostgreSQL, Redis, Kafka, ClickHouse, or separate identity service&lt;/li&gt;
&lt;li&gt;cookie-free browser tracking by default&lt;/li&gt;
&lt;li&gt;open export paths&lt;/li&gt;
&lt;li&gt;self-hosted and managed cloud built from the same product foundation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;OIDC adds an optional outbound connection to a team’s chosen identity provider. It does not change tracking, analytics retention, or the data collected from website visitors.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade Guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.12.0 when a team wants to use its existing OpenID Connect provider or when operators need stable links to site settings and invitation workflows.&lt;/p&gt;
&lt;p&gt;For an SSO rollout:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;upgrade HitKeep and keep at least two owner login paths available;&lt;/li&gt;
&lt;li&gt;open &lt;strong&gt;Administration → Team → SSO&lt;/strong&gt; and copy the exact callback URL;&lt;/li&gt;
&lt;li&gt;create a confidential OIDC web application using Authorization Code flow;&lt;/li&gt;
&lt;li&gt;enter the issuer, client ID, client secret, domains, and claim mappings;&lt;/li&gt;
&lt;li&gt;save with SSO disabled, run the connection test, then enable it;&lt;/li&gt;
&lt;li&gt;test a real invited or existing member in a private browser window; and&lt;/li&gt;
&lt;li&gt;review the team activity log before expanding access or enabling automatic provisioning.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If a self-hosted installation changes &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt;, update the provider callback registration. If &lt;code&gt;HITKEEP_JWT_SECRET&lt;/code&gt; changes, enter and save the OIDC client secret again because the previous encrypted value was derived from the old secret.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/security/single-sign-on/&quot;&gt;Configure OIDC Single Sign-On&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/teams/&quot;&gt;Teams and data isolation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/permissions/&quot;&gt;Permissions and roles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/security/two-factor-authentication/&quot;&gt;Two-factor authentication and passkeys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/security/&quot;&gt;HitKeep security model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/&quot;&gt;Runtime configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/pricing/&quot;&gt;HitKeep Cloud pricing&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Self-hosted HitKeep includes team OIDC SSO in the same binary as the dashboard, queue, and database. If you want managed upgrades, backups, and regional hosting alongside SSO, &lt;a href=&quot;https://cloud.hitkeep.eu/signup?plan=free&amp;#x26;billing=monthly&amp;#x26;utm_source=hitkeep_docs&amp;#x26;utm_medium=referral&amp;#x26;utm_campaign=cloud_signup&amp;#x26;utm_content=docs_inline&quot;&gt;start a managed HitKeep Cloud deployment&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Follow HitKeep on &lt;a href=&quot;https://x.com/gethitkeep&quot;&gt;X&lt;/a&gt;, &lt;a href=&quot;https://bsky.app/profile/hitkeep.com&quot;&gt;Bluesky&lt;/a&gt;, and &lt;a href=&quot;https://www.linkedin.com/company/hitkeep&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt;</content:encoded></item><item><title>HitKeep 2.11.0: Signed Webhooks, Bounded Retries, And Delivery History</title><link>https://hitkeep.com/blog/hitkeep-2-11-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-11-0/</guid><description>HitKeep 2.11.0 adds HMAC-signed outbound webhooks for site and instance events, with test delivery, bounded retries, secret rotation, and paginated delivery history.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Operational changes are useful outside an analytics dashboard. A goal conversion may need to notify billing, a completed import may unblock a migration, and a team membership change may need to update an internal system. Polling the REST API adds delay and repeated work.&lt;/p&gt;
&lt;p&gt;HitKeep 2.11.0 adds signed outbound webhooks for those workflows. Site and instance administrators can subscribe an HTTPS endpoint to the events they need, send a test delivery, rotate its signing secret, and inspect delivery attempts without adding a separate integration service to HitKeep.&lt;/p&gt;
&lt;h2 id=&quot;what-shipped&quot;&gt;What Shipped&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Site and instance webhooks:&lt;/strong&gt; subscribe one endpoint to a site’s events or use instance scope for cross-site and administrative events.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HMAC-SHA256 signatures:&lt;/strong&gt; every request signs its timestamp and exact JSON body with a secret shown only after creation or rotation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Bounded retries:&lt;/strong&gt; unsuccessful deliveries use exponential backoff, with six attempts by default and a six-hour maximum delay.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Test delivery:&lt;/strong&gt; queue a &lt;code&gt;webhook.test&lt;/code&gt; event before connecting a production workflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Delivery history:&lt;/strong&gt; inspect event type, status, attempts, response code, and creation time in a paginated, sortable table.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Focused administration:&lt;/strong&gt; search and sort configured endpoints, scan subscribed events, and open delivery, test, edit, rotate, or delete actions from the row menu.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Destination protection:&lt;/strong&gt; production endpoints require HTTPS and cannot resolve to loopback, private, link-local, multicast, documentation, or other reserved addresses.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Single-binary operation:&lt;/strong&gt; the dispatcher, retry worker, recovery sweep, and retention cleanup run inside the existing HitKeep process.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/integration-webhooks.X_9n_d0y_Z1i06jg.webp&quot; alt=&quot;HitKeep 2.11 webhook administration table showing a searchable HTTPS endpoint, subscribed operational events, enabled status, sortable columns, pagination, and row actions&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1280&quot; height=&quot;720&quot;&gt;&lt;figcaption&gt;Configured endpoints reuse HitKeep’s searchable table and row-action patterns; the event-count popover keeps larger subscriptions scannable.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;verify-the-exact-request-body&quot;&gt;Verify The Exact Request Body&lt;/h2&gt;
&lt;p&gt;Each delivery includes a Unix timestamp and a &lt;code&gt;v1&lt;/code&gt; HMAC-SHA256 signature. Verify the original bytes before decoding JSON; parsing and re-serializing the body can change whitespace or key ordering and invalidate the signature.&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;go&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;body&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;err&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;:=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;io&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;ReadAll&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;io&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;LimitReader&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;r&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;Body&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;1&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;&amp;#x3C;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;20&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;))&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;if&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;err&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;!=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#FF6A83;--1:#A24848&quot;&gt;nil&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; {&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;http&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Error&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;w&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;invalid body&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;http&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;StatusBadRequest&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;return&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;}&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;timestamp&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;:=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;r&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;Header&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Get&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;X-HitKeep-Timestamp&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;signature&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;:=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;strings&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;TrimPrefix&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;r&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;Header&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Get&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;X-HitKeep-Signature&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;),&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;v1=&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;provided&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;err&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;:=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;hex&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;DecodeString&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;signature&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;if&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;err&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;!=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#FF6A83;--1:#A24848&quot;&gt;nil&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; {&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;http&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Error&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;w&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;invalid signature&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;http&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;StatusUnauthorized&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;return&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;}&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;mac&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;:=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;hmac&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;New&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;sha256&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;New&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, []&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;byte&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;signingSecret&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;))&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;mac&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Write&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;([]&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;byte&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;timestamp&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;+&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;))&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;mac&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Write&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;body&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;if&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;!&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;hmac&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Equal&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;mac&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Sum&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#FF6A83;--1:#A24848&quot;&gt;nil&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;), &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;provided&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;) {&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;http&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;Error&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;w&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;invalid signature&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;http&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;StatusUnauthorized&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;return&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;}&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;Receivers should also reject stale timestamps and persist &lt;code&gt;X-HitKeep-Event-ID&lt;/code&gt; or &lt;code&gt;X-HitKeep-Delivery-ID&lt;/code&gt; before returning success. Delivery is at least once, and events may arrive out of order, so downstream processing must be idempotent.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://hitkeep.com/guides/integrations/webhooks/&quot;&gt;signed webhook guide&lt;/a&gt; includes a complete Go receiver with timestamp validation and the full request-header contract.&lt;/p&gt;
&lt;h2 id=&quot;events-at-the-right-scope&quot;&gt;Events At The Right Scope&lt;/h2&gt;
&lt;p&gt;Site webhooks cover lifecycle, goal, import, and test events for one site:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;site.updated&lt;/code&gt; and &lt;code&gt;site.deleted&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;goal.created&lt;/code&gt;, &lt;code&gt;goal.updated&lt;/code&gt;, &lt;code&gt;goal.deleted&lt;/code&gt;, and &lt;code&gt;goal.converted&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;import.completed&lt;/code&gt; and &lt;code&gt;import.failed&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;webhook.test&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Instance webhooks can subscribe to every site event plus &lt;code&gt;site.created&lt;/code&gt;, user lifecycle events, team lifecycle events, and team membership changes. The dashboard loads the valid event catalog for the selected scope, and the API rejects invalid combinations.&lt;/p&gt;
&lt;p&gt;This is deliberately an operational event surface, not a raw analytics stream. Webhook payloads do not export pageview histories, visitor records, form contents, or Ask AI conversations. Use &lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;open exports and takeout&lt;/a&gt; when another system needs analytics data rather than a notification that an operational change happened.&lt;/p&gt;
&lt;h2 id=&quot;one-time-secrets-and-rotation&quot;&gt;One-Time Secrets And Rotation&lt;/h2&gt;
&lt;p&gt;Creating a webhook returns its signing secret once. The dashboard presents it through the same one-time credential pattern used for API client tokens: copy it into the receiver’s secret store before leaving the page.&lt;/p&gt;
&lt;p&gt;Rotation replaces the configured secret and re-signs pending, retrying, and processing delivery records with the new value. A request already in flight may still carry the previous signature, so receivers that rotate during active delivery should allow a short overlap window.&lt;/p&gt;
&lt;p&gt;Webhook administration remains a human dashboard workflow. Instance owners and administrators can manage instance webhooks. Site owners and administrators can manage a site’s webhooks. Editors, viewers, instance users, and delegated API clients cannot create endpoints or rotate secrets. The &lt;a href=&quot;https://hitkeep.com/guides/admin/permissions/&quot;&gt;roles and permissions guide&lt;/a&gt; documents the complete boundary.&lt;/p&gt;
&lt;h2 id=&quot;retries-without-an-unbounded-queue&quot;&gt;Retries Without An Unbounded Queue&lt;/h2&gt;
&lt;p&gt;Any &lt;code&gt;2xx&lt;/code&gt; response marks a delivery successful. Timeouts, connection failures, and non-&lt;code&gt;2xx&lt;/code&gt; responses retry with exponential backoff. The defaults keep failure bounded:&lt;/p&gt;









































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Behavior&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Default&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Request timeout&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;10 seconds&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Maximum attempts&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;6 total attempts&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Initial retry delay&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;30 seconds&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Maximum retry delay&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;6 hours&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Global delivery concurrency&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;8&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Per-endpoint concurrency&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Delivery-history retention&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;30 days&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Recovery sweep&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Every 30 seconds&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;Operators can tune these limits through the &lt;a href=&quot;https://hitkeep.com/reference/configuration/#outbound-webhook-delivery&quot;&gt;outbound webhook configuration&lt;/a&gt;. The default per-endpoint concurrency of one prevents one slow receiver from being flooded, while the global limit keeps outbound work predictable inside the single process.&lt;/p&gt;
&lt;p&gt;Delivery history stores outcomes and attempt metadata, not saved response bodies or secrets. The dashboard exposes that history in a paginated and sortable table, so a failed endpoint can be diagnosed without turning the UI into a raw payload archive.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/integration-webhook-deliveries.OU4qcerD_Zw9P0R.webp&quot; alt=&quot;HitKeep 2.11 delivery history showing a successful signed webhook.test request with one attempt and an HTTP 204 response&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1280&quot; height=&quot;720&quot;&gt;&lt;figcaption&gt;A successful test delivery records the event, terminal status, attempt count, response code, and creation time without retaining the response body or signing secret.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;safer-outbound-destinations&quot;&gt;Safer Outbound Destinations&lt;/h2&gt;
&lt;p&gt;An outbound webhook feature creates a server-side request boundary, so endpoint validation happens both when an administrator saves the URL and immediately before delivery. Production destinations must use HTTPS. HitKeep does not follow redirects, does not inherit proxy settings for webhook delivery, and blocks hostnames that resolve to non-public address space.&lt;/p&gt;
&lt;p&gt;Self-hosted developers can explicitly enable HTTP and private targets with &lt;code&gt;HITKEEP_WEBHOOK_ALLOW_DEVELOPMENT_TARGETS=true&lt;/code&gt;. That flag removes the destination protections intended to prevent server-side request forgery and should never be enabled in production. The &lt;a href=&quot;https://hitkeep.com/reference/security/&quot;&gt;security reference&lt;/a&gt; covers webhook delivery alongside HitKeep’s other optional outbound connections.&lt;/p&gt;
&lt;h2 id=&quot;what-is-not-changing&quot;&gt;What Is Not Changing&lt;/h2&gt;
&lt;p&gt;HitKeep 2.11.0 keeps the same operating model:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;one Go binary&lt;/li&gt;
&lt;li&gt;embedded DuckDB data stores&lt;/li&gt;
&lt;li&gt;embedded NSQ queueing&lt;/li&gt;
&lt;li&gt;no required PostgreSQL, Redis, Kafka, ClickHouse, or separate integration service&lt;/li&gt;
&lt;li&gt;cookie-free browser tracking by default&lt;/li&gt;
&lt;li&gt;open export paths&lt;/li&gt;
&lt;li&gt;self-hosted and managed cloud built from the same product foundation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Webhooks add outbound operational delivery; they do not change browser tracking or broaden the stored analytics data model.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade Guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.11.0 when another system needs to react to HitKeep goal, import, site, team, or user changes without polling.&lt;/p&gt;
&lt;p&gt;After upgrading:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Open &lt;strong&gt;Integration → Webhooks&lt;/strong&gt; and choose site or instance scope.&lt;/li&gt;
&lt;li&gt;Create an HTTPS endpoint and subscribe only to the events the receiver needs.&lt;/li&gt;
&lt;li&gt;Store the one-time signing secret outside HitKeep.&lt;/li&gt;
&lt;li&gt;Send a test event and verify the timestamp, signature, and delivery ID.&lt;/li&gt;
&lt;li&gt;Confirm the delivery appears as successful in delivery history.&lt;/li&gt;
&lt;li&gt;Review retry, concurrency, and retention defaults before enabling a high-volume workflow.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/webhooks/&quot;&gt;Configure and verify signed outbound webhooks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/permissions/&quot;&gt;Webhook roles and permissions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/#outbound-webhook-delivery&quot;&gt;Outbound webhook configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/security/&quot;&gt;HitKeep security model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/facts-and-limits/&quot;&gt;Runtime facts and product limits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/support/roadmap/&quot;&gt;Public roadmap&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Self-hosted HitKeep includes webhook delivery in the same binary as the dashboard, queue, and database. If you want signed operational delivery without managing upgrades, backups, and worker operations, &lt;a href=&quot;https://cloud.hitkeep.eu/signup?plan=free&amp;#x26;billing=monthly&amp;#x26;utm_source=hitkeep_docs&amp;#x26;utm_medium=referral&amp;#x26;utm_campaign=cloud_signup&amp;#x26;utm_content=docs_inline&quot;&gt;start a managed HitKeep Cloud deployment&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Follow HitKeep on &lt;a href=&quot;https://x.com/gethitkeep&quot;&gt;X&lt;/a&gt;, &lt;a href=&quot;https://bsky.app/profile/hitkeep.com&quot;&gt;Bluesky&lt;/a&gt;, and &lt;a href=&quot;https://www.linkedin.com/company/hitkeep&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt;</content:encoded></item><item><title>HitKeep 2.10.0: Custom Tracking Domains, Team Admin Pages, And Chart Preferences</title><link>https://hitkeep.com/blog/hitkeep-2-10-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-10-0/</guid><description>HitKeep 2.10.0 ships team-verified custom tracking domains with managed TLS, addressable team admin pages, a chart style toggle with remembered preferences, and cloud plan polish.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.10.0 lets teams serve the tracker and ingest endpoints from their own verified hostnames, turns the team administration area into real addressable pages, remembers your chart style and report preferences, and tightens the cloud plan surface.&lt;/p&gt;
&lt;h2 id=&quot;what-shipped&quot;&gt;What Shipped&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Custom tracking domains:&lt;/strong&gt; team admins verify their own tracker hostnames with a DNS TXT record; active domains serve &lt;code&gt;hk.js&lt;/code&gt;, &lt;code&gt;hk-vitals.js&lt;/code&gt;, and browser ingest for every site in the team.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Managed TLS for tracking domains:&lt;/strong&gt; HitKeep Cloud issues on-demand certificates after DNS verification; self-hosted setups get documented Caddy, nginx, and Traefik examples.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Team admin pages:&lt;/strong&gt; overview, members, API clients, custom domains, branding, activity, and danger zone are now routed subpages with their own URLs and browser titles.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tables with dialogs:&lt;/strong&gt; custom domains and API clients use the same table-plus-dialog management pattern, with validity shown as per-check icons.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Chart style toggle:&lt;/strong&gt; switch charts between area, line, and bars with an icon control; the choice applies to every chart and is remembered, alongside the report range and overview sort order.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud plan polish:&lt;/strong&gt; a clearer plan comparison with locale-aware prices, usage-aware free plan notices, and a focused upgrade path from banner, sidebar, and lifecycle emails.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixes:&lt;/strong&gt; search field icons align with the theme again, the multi-site overview gets proper hover feedback, and the free plan notice no longer competes with itself.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;custom-tracking-domains&quot;&gt;Custom Tracking Domains&lt;/h2&gt;
&lt;p&gt;Serving analytics from a third-party hostname is a common reason measurement quietly degrades. HitKeep 2.10.0 lets a team register its own tracker hostnames, prove ownership with a DNS TXT record, and then serve the tracker scripts and ingest endpoints from that first-party domain.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/admin-team-custom-domains.DyIbb2A4_Z1gsck2.webp&quot; alt=&quot;HitKeep team custom domains table showing a verified tracking domain with ownership, DNS target, and TLS check icons plus row actions&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Custom domains are managed in a table: per-check validity icons for ownership, DNS target, and TLS, with verify, DNS setup, and delete as row actions.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Adding a domain opens a DNS setup dialog with the exact records to copy: the &lt;code&gt;_hitkeep-tracking&lt;/code&gt; TXT record for ownership and the CNAME, A, or AAAA target for routing. Verification checks all three concerns separately, so a half-finished DNS change is visible as exactly that.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/feature-custom-domain-setup.D_vuN6FG_1OSWxj.webp&quot; alt=&quot;HitKeep DNS setup dialog listing the TXT name, TXT value, and DNS target records with copy buttons and verification status&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The DNS setup dialog shows copyable records and the current verification state for each check.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Once a domain is active, site tracking snippets can be generated against it, and browser ingest accepts traffic through it for every site in the owning team. Cross-team use is rejected at the API: a domain verified by one team never ingests for another team’s sites.&lt;/p&gt;
&lt;p&gt;On HitKeep Cloud, TLS is part of the feature: after DNS verification, certificates are issued on demand for the custom hostname. Custom tracking domains are available on the Pro plan and higher in the cloud; self-hosted deployments get the feature without restriction, with &lt;a href=&quot;https://hitkeep.com/guides/tracking/custom-tracking-domains/&quot;&gt;Caddy, nginx, and Traefik examples&lt;/a&gt; in the repository.&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#919F9F;--1:#5F636F&quot;&gt;# Self-hosted configuration&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_CUSTOM_TRACKING_DNS_TARGET&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;analytics.example.com&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;   &lt;/span&gt;&lt;span style=&quot;--0:#919F9F;--1:#5F636F&quot;&gt;# host or IP your domains must point at&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_CUSTOM_TRACKING_TLS_MODE&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;external&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;                  &lt;/span&gt;&lt;span style=&quot;--0:#919F9F;--1:#5F636F&quot;&gt;# or caddy-on-demand&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_CADDY_TLS_ASK_TOKEN&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;...&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;                            &lt;/span&gt;&lt;span style=&quot;--0:#919F9F;--1:#5F636F&quot;&gt;# protects the Caddy on-demand TLS ask endpoint&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;h2 id=&quot;team-administration-gets-real-pages&quot;&gt;Team Administration Gets Real Pages&lt;/h2&gt;
&lt;p&gt;The team area used to be one page with query-parameter tabs. In 2.10.0 every section is a routed subpage: &lt;code&gt;/admin/team/members&lt;/code&gt;, &lt;code&gt;/admin/team/custom-domains&lt;/code&gt;, &lt;code&gt;/admin/team/branding&lt;/code&gt;, and so on. Deep links work, browser titles are descriptive, and the activity page enforces its audit permission on the route itself.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/admin-team-members.Byj4AZUy_ZHWQoJ.webp&quot; alt=&quot;HitKeep team members page showing the routed team admin tabs, a searchable members table with roles, and pending invites&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Members, invites, API clients, and custom domains share the same searchable table pattern with row actions.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The pages also share one design language now. API clients and custom domains use the same table-plus-dialog pattern, status is a color-coded icon rather than prose, and the danger zone matches its site-level counterpart card for card.&lt;/p&gt;
&lt;h2 id=&quot;chart-style-and-remembered-preferences&quot;&gt;Chart Style And Remembered Preferences&lt;/h2&gt;
&lt;p&gt;Analytics charts get a three-way style toggle — area, line, bars — rendered as an icon control above the plot instead of a dropdown over it. The selection applies to every chart in the dashboard at once and is remembered per browser.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/dashboard-overview.C-D6Gj-G_1FmtsR.webp&quot; alt=&quot;HitKeep dashboard with the traffic chart and the area, line, and bars style toggle above the plot&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The chart style toggle sits above the plot and applies to all charts, including comparisons and trend lines.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The same preference layer now covers the report range and the multi-site overview sort order, so the dashboard reopens the way you left it. The overview cards also picked up proper hover feedback: the card lifts, the sparkline deepens, and keyboard focus receives the same treatment.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/dashboard-sites-overview.DdnRQUB7_1Bl88.webp&quot; alt=&quot;HitKeep multi-site overview with sort control, search, and site cards showing sparklines and metrics&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The overview remembers your sort order and search stays a keystroke away.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;cloud-plans-and-upgrade-flow&quot;&gt;Cloud Plans And Upgrade Flow&lt;/h2&gt;
&lt;p&gt;For HitKeep Cloud, the plan comparison inside the team overview was rebuilt: a section header, a highlighted recommended plan, a custom-domains feature line, and locale-aware prices — €15 in English locales renders as 15 € in German. The free plan notice became usage-aware: when a team fills 80% or more of its site or member allowance, the banner switches to the exhausted limit and resurfaces even if the time-based notice was dismissed. A matching lifecycle email reaches owners who are not in the dashboard.&lt;/p&gt;
&lt;p&gt;Every upgrade surface — banner, sidebar chip, plan page, lifecycle emails — now leads to the same plan comparison instead of jumping straight into a checkout. The comparison page states plainly that HitKeep is fully open source, including every paid feature, with sponsoring and self-hosting as first-class alternatives.&lt;/p&gt;
&lt;p&gt;None of this appears on self-hosted deployments: plan gating, notices, upsell emails, and the sidebar chip are managed-cloud surfaces only.&lt;/p&gt;
&lt;h2 id=&quot;bug-fixes-and-ui-polish&quot;&gt;Bug Fixes And UI Polish&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;search field icons across all tables align with the OptimusUI theme again&lt;/li&gt;
&lt;li&gt;the signup page states the essentials up front: no credit card, region-pinned data, export or self-host anytime&lt;/li&gt;
&lt;li&gt;the free plan retention notice consolidated three competing actions into one&lt;/li&gt;
&lt;li&gt;the seeded demo covers custom domains, so screenshots and e2e tests exercise the real flow&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;what-is-not-changing&quot;&gt;What Is Not Changing&lt;/h2&gt;
&lt;p&gt;HitKeep keeps the same operating model:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;one Go binary&lt;/li&gt;
&lt;li&gt;embedded DuckDB data stores&lt;/li&gt;
&lt;li&gt;embedded NSQ queueing&lt;/li&gt;
&lt;li&gt;no required PostgreSQL, Redis, Kafka, ClickHouse, or hosted analytics dependency&lt;/li&gt;
&lt;li&gt;cookie-free browser tracking by default&lt;/li&gt;
&lt;li&gt;open export paths&lt;/li&gt;
&lt;li&gt;self-hosted and managed cloud built from the same product foundation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Custom tracking domains do not change the tracking model. The tracker still sets no analytics cookies, respects Do Not Track, and serves the same &lt;code&gt;hk.js&lt;/code&gt; — only the hostname it loads from becomes yours.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade Guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.10.0 if you want first-party tracking hostnames, the reworked team administration area, or remembered chart and report preferences.&lt;/p&gt;
&lt;p&gt;After upgrading, check:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the new &lt;code&gt;custom_tracking_domains&lt;/code&gt; table is created by the automatic migration&lt;/li&gt;
&lt;li&gt;&lt;code&gt;HITKEEP_CUSTOM_TRACKING_DNS_TARGET&lt;/code&gt; if your deployment serves custom tracking domains&lt;/li&gt;
&lt;li&gt;&lt;code&gt;HITKEEP_CUSTOM_TRACKING_TLS_MODE&lt;/code&gt; and the reverse-proxy examples if you terminate TLS yourself&lt;/li&gt;
&lt;li&gt;deep links into &lt;code&gt;/admin/team/...&lt;/code&gt; used in internal runbooks or bookmarks (legacy tab URLs redirect)&lt;/li&gt;
&lt;li&gt;the chart style toggle and remembered report range on your most-used dashboards&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/custom-tracking-domains/&quot;&gt;Custom Tracking Domains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/tracker-architecture/&quot;&gt;Tracker Architecture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/teams/&quot;&gt;Teams and Analytics Data Isolation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/pricing/&quot;&gt;HitKeep Cloud Pricing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/&quot;&gt;Configuration Reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/support/roadmap/&quot;&gt;Public Roadmap&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Follow HitKeep on &lt;a href=&quot;https://x.com/gethitkeep&quot;&gt;X&lt;/a&gt;, &lt;a href=&quot;https://bsky.app/profile/hitkeep.com&quot;&gt;Bluesky&lt;/a&gt;, and &lt;a href=&quot;https://www.linkedin.com/company/hitkeep&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt;</content:encoded></item><item><title>HitKeep 2.9.0: Ask AI, Site Overview, And Better Analytics Charts</title><link>https://hitkeep.com/blog/hitkeep-2-9-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-9-0/</guid><description>HitKeep 2.9.0 ships experimental Ask AI, a new site overview, ECharts-based charts, more report ranges, hosted setup polish, and dashboard bug fixes.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.9.0 adds the experimental Ask AI dashboard assistant, a new multi-site overview, ECharts-based charts, more time range presets, and a round of dashboard fixes.&lt;/p&gt;
&lt;h2 id=&quot;what-shipped&quot;&gt;What Shipped&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Experimental Ask AI:&lt;/strong&gt; a dashboard drawer can answer site-scoped analytics questions, show tool-call progress, cite aggregate results, render small charts or tables, and offer safe dashboard actions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;New overview page:&lt;/strong&gt; the dashboard gets a lighter place to compare sites before opening a specific analytics report.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ECharts charts:&lt;/strong&gt; analytics charts move from Chart.js to ECharts for clearer rendering, better accessibility hooks, and a shared chart option layer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;More time ranges:&lt;/strong&gt; the range toolbar now supports Today, Yesterday, 24h, 7d, 30d, additional presets, and custom ranges.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Searchable selectors:&lt;/strong&gt; range and language selectors are easier to scan when the list grows.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud setup polish:&lt;/strong&gt; hosted cloud signup now carries region choice into the signup flow and exposes hosted integration discovery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Team and site workflow fixes:&lt;/strong&gt; invite links survive the login flow, site owners can reset stats from the dashboard, QR share mode exposes QR navigation, and seeded demo data better matches the current day.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;UI maintenance:&lt;/strong&gt; the favicon and primary logo were replaced with optimized SVGs, dashboard screenshots were refreshed, mail footer social badges were simplified, and frontend dependencies were updated.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;experimental-ask-ai&quot;&gt;Experimental Ask AI&lt;/h2&gt;
&lt;p&gt;Ask AI is the first dashboard-session assistant in HitKeep. It appears as a drawer inside the authenticated dashboard and uses the active site as its scope. A user can ask a question such as “How many hits did I get from ChatGPT in the last 14 days?”, then see which aggregate analytics tools were read before the answer appears.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/feature-ask-ai-empty.DAT1VKFp_httpL.webp&quot; alt=&quot;HitKeep Ask AI drawer open on a site dashboard with suggested prompts and an empty chat input&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Ask AI opens from the dashboard sidebar and starts with suggested prompts for the active site.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/feature-ask-ai-answer.Dpw_ywQ1_Z19ErPx.webp&quot; alt=&quot;HitKeep Ask AI answer showing a ChatGPT traffic question, completed site overview and AI visibility tool calls, citations, a table, and an Open AI visibility action&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Tool-call chips, citations, table output, and safe dashboard actions make the answer auditable from the UI.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Ask AI is experimental, optional, and disabled by default. Self-hosted operators must enable both the shared AI route and the Ask AI feature flag:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_ENABLED&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;true&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_ASK_AI_ENABLED&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;true&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_PROVIDER&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;openai-compatible&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_MODEL&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;your-model-or-gateway-route&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;Ask AI is dashboard-session only. It does not add a public MCP tool, does not accept API client bearer tokens, and does not expose a saved history tab. MCP remains a separate read-only aggregate API client surface.&lt;/p&gt;
&lt;p&gt;The assistant is also intentionally narrow about stored data. Public docs and user-facing exports do not expose raw prompts, provider secrets, full model responses, provider headers, raw external error bodies, or unrestricted tool payloads. Saved audit metadata uses safe fields such as hashes, tool names, status, counts, usage, and error categories.&lt;/p&gt;
&lt;h2 id=&quot;new-overview-page&quot;&gt;New Overview Page&lt;/h2&gt;
&lt;p&gt;HitKeep 2.9.0 adds a new overview surface for operators who manage more than one site. It gives the dashboard a light entry point before the user drills into a specific report. The overview uses lightweight site metrics and compact chart visualizations so teams can spot which site needs attention first.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/dashboard-sites-overview.DdnRQUB7_1Bl88.webp&quot; alt=&quot;HitKeep Overview page showing the 30-day range, site filter, sort control, and multi-site metric cards with sparklines and empty traffic states&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The new Overview page lists every accessible site with filter and sort controls, 30-day metrics, sparklines, and direct links into each site dashboard.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The site reset workflow also became more explicit. Site owners can reset stats from the dashboard, while API clients cannot use that destructive dashboard-session path. That keeps cleanup available to operators without turning reset into a machine-token workflow.&lt;/p&gt;
&lt;h2 id=&quot;better-charts-and-more-time-ranges&quot;&gt;Better Charts And More Time Ranges&lt;/h2&gt;
&lt;p&gt;Analytics charts now use ECharts through a shared HitKeep chart option layer. The dashboard keeps the same product questions: pageviews, visitors, comparison overlays, goal and funnel movement, ecommerce trends, AI visibility, and Web Vitals. The charting library change is about rendering, readability, and maintainability rather than changing the analytics model.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/dashboard-comparison.DOLNPx1L_1vxfLU.webp&quot; alt=&quot;HitKeep analytics dashboard with Today selected, KPI delta badges, an ECharts traffic chart, and previous-period comparison overlays&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;ECharts renders the main traffic series, trend line, and previous-period overlays while KPI cards keep the selected range comparison visible.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The range toolbar now covers short windows, calendar-style presets, and longer report windows in one control set. Today is useful during setup and launches. Yesterday, 24h, 7d, 30d, and the expanded preset list cover recurring reporting. Custom still handles exact campaign or incident windows.&lt;/p&gt;
&lt;h2 id=&quot;cloud-teams-and-setup-polish&quot;&gt;Cloud, Teams, And Setup Polish&lt;/h2&gt;
&lt;p&gt;The hosted cloud signup flow now carries region choice into signup instead of making the user pick it later. Hosted integration discovery also gives cloud deployments a clearer way to expose available hosted integration paths.&lt;/p&gt;
&lt;p&gt;Team invite handling is less fragile. Invite links now survive the login flow, so existing users can sign in and land back on the pending invite. New invited users can set a password for the invited email address and start in the team that invited them.&lt;/p&gt;
&lt;p&gt;The setup path also picked up smaller fixes: brand clicks return to the app root, QR share mode exposes QR navigation, and demo seed data now keeps AI visibility, UTM, and QR examples visible for the current day.&lt;/p&gt;
&lt;h2 id=&quot;bug-fixes-and-ui-polish&quot;&gt;Bug Fixes And UI Polish&lt;/h2&gt;
&lt;p&gt;This release includes a wide dashboard asset refresh and several focused fixes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the language selector overlay stays above the settings card&lt;/li&gt;
&lt;li&gt;the favicon and primary logo now use optimized SVG assets&lt;/li&gt;
&lt;li&gt;the mail footer keeps legal and social links without heavy badge styling&lt;/li&gt;
&lt;li&gt;seeded dashboard end-to-end tests are more stable&lt;/li&gt;
&lt;li&gt;Go modules and frontend packages were refreshed&lt;/li&gt;
&lt;li&gt;Helm chart release metadata now follows HitKeep Release Cadence&lt;/li&gt;
&lt;li&gt;the MCP registry and README point readers toward the analytics MCP use-case page&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These are maintenance changes, but they matter for the daily experience: fewer overlay surprises, better current-day demo states, cleaner branding, and less screenshot drift between the product and docs.&lt;/p&gt;
&lt;h2 id=&quot;what-is-not-changing&quot;&gt;What Is Not Changing&lt;/h2&gt;
&lt;p&gt;HitKeep keeps the same operating model:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;one Go binary&lt;/li&gt;
&lt;li&gt;embedded DuckDB data stores&lt;/li&gt;
&lt;li&gt;embedded NSQ queueing&lt;/li&gt;
&lt;li&gt;no required PostgreSQL, Redis, Kafka, ClickHouse, or hosted analytics dependency&lt;/li&gt;
&lt;li&gt;cookie-free browser tracking by default&lt;/li&gt;
&lt;li&gt;open export paths&lt;/li&gt;
&lt;li&gt;self-hosted and managed cloud built from the same product foundation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Ask AI does not turn HitKeep into a write-capable automation layer. It is a human dashboard assistant for aggregate analytics questions. MCP remains read-only, aggregate-only, and separate from the dashboard-session Ask AI drawer.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade Guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.9.0 if you want to try the experimental Ask AI drawer, use the new overview surface, get the ECharts chart migration, or use the expanded report ranges.&lt;/p&gt;
&lt;p&gt;After upgrading, check:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Ask AI visibility and disabled states on self-hosted instances&lt;/li&gt;
&lt;li&gt;AI provider configuration and budget limits if you enable Ask AI&lt;/li&gt;
&lt;li&gt;the new overview page with multiple sites&lt;/li&gt;
&lt;li&gt;better chart rendering on dashboard, goals, funnels, ecommerce, Web Vitals, AI visibility, and UTM reports&lt;/li&gt;
&lt;li&gt;Today, Yesterday, 24h, 7d, 30d, More ranges, and Custom range behavior&lt;/li&gt;
&lt;li&gt;invite acceptance after login&lt;/li&gt;
&lt;li&gt;owner-only site stats reset&lt;/li&gt;
&lt;li&gt;QR share navigation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For production Ask AI use, route provider traffic through an AI gateway or provider policy layer that can enforce detailed quotas, model allowlists, key isolation, audit logging, redaction, and network controls. HitKeep’s built-in request and token caps are a local process-level safeguard, not a complete provider policy system.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/ask-ai/&quot;&gt;Ask AI Analytics Assistant&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/ai-model-configuration/&quot;&gt;AI Model Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/comparison/&quot;&gt;Period-over-Period Analytics Comparison&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/teams/&quot;&gt;Teams and Analytics Data Isolation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/&quot;&gt;Configuration Reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/support/roadmap/&quot;&gt;Public Roadmap&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Follow HitKeep on &lt;a href=&quot;https://x.com/gethitkeep&quot;&gt;X&lt;/a&gt;, &lt;a href=&quot;https://bsky.app/profile/hitkeep.com&quot;&gt;Bluesky&lt;/a&gt;, and &lt;a href=&quot;https://www.linkedin.com/company/hitkeep&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt;</content:encoded></item><item><title>HitKeep 2.8.0: QR Campaigns, Portuguese, And Agent-Ready Analytics</title><link>https://hitkeep.com/blog/hitkeep-2-8-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-8-0/</guid><description>HitKeep 2.8.0 ships dynamic QR campaigns, Portuguese dashboard localization, and AI assistant enablement through Agent Skills, MCP Registry metadata, and public contributor guidance.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.8.0 adds dynamic QR campaigns for offline attribution, Portuguese dashboard localization, and clearer AI assistant enablement through the optional MCP server, the official MCP Registry entry, HitKeep Agent Skills, and public contributor guidance.&lt;/p&gt;
&lt;h2 id=&quot;what-shipped&quot;&gt;What Shipped&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;QR campaigns:&lt;/strong&gt; create dynamic QR codes under &lt;strong&gt;UTM -&gt; QR codes&lt;/strong&gt;, attach UTM and custom query parameters, export print artwork, share QR-only analytics, and export QR-scoped data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Portuguese dashboard localization:&lt;/strong&gt; the dashboard language set now includes English, German, Spanish, French, Italian, Dutch, and Portuguese.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Agent-ready analytics:&lt;/strong&gt; the optional MCP server remains read-only and aggregate-only, with official Agent Skills that teach assistants how to use HitKeep analytics safely.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MCP Registry metadata:&lt;/strong&gt; the HitKeep MCP server is listed as &lt;code&gt;io.github.PascaleBeier/hitkeep&lt;/code&gt;, so compatible clients and directory tooling can identify the official endpoint shape.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Public AI contributor guidance:&lt;/strong&gt; &lt;code&gt;AGENTS.md&lt;/code&gt;, &lt;code&gt;CLAUDE.md&lt;/code&gt;, the pull request template, and the public &lt;code&gt;hitkeep-i18n&lt;/code&gt; skill now explain the safe paths for AI-assisted contributions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;GoAI validation coverage:&lt;/strong&gt; the AI output storage boundary has focused regression coverage for structured output, raw provider payload rejection, and cited evidence validation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;qr-campaigns&quot;&gt;QR Campaigns&lt;/h2&gt;
&lt;p&gt;QR campaigns are for offline links that still need campaign attribution. A saved QR campaign gets a dynamic HitKeep redirect URL under &lt;code&gt;/q/{token}&lt;/code&gt;. That redirect records a QR open when allowed, then sends the visitor to the configured destination URL with UTM fields, custom parameters, and the reserved &lt;code&gt;hk_qr&lt;/code&gt; attribution parameter.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/qr-campaigns-list.B11rJz2A_Z4KVDk.webp&quot; alt=&quot;HitKeep QR campaigns table filtered to a conference booth poster campaign with destination URL, campaign name, graphic status, updated time, and row actions&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1680&quot; height=&quot;1050&quot;&gt;&lt;figcaption&gt;The QR campaigns table lives under UTM, alongside the existing campaign workflow.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/qr-campaigns-editor.CDjrdNVY_WMPHG.webp&quot; alt=&quot;HitKeep QR campaign editor with destination fields, UTM campaign fields, custom parameters, style controls, QR preview, redirect URL, and final tracked URL&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1440&quot; height=&quot;1024&quot;&gt;&lt;figcaption&gt;The editor keeps the dynamic redirect URL, final tracked URL, UTM fields, custom parameters, and QR styling visible before the artwork goes to print.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The dashboard separates redirect opens from tracked pageviews. Opens answer “how often was the QR token used?” Pageviews and visitors answer “how much tracked traffic arrived after the redirect?” That distinction matters because a scan can fail to become a tracked pageview when the destination page has no tracker, the visitor leaves early, the tracker is blocked, or privacy and traffic filters suppress the request.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/qr-campaigns-analytics.XCne3iWH_2kCGDT.webp&quot; alt=&quot;HitKeep QR campaign analytics showing QR artwork, redirect URL, final tracked URL, opens, pageviews, visitors, and a QR opens time series&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1440&quot; height=&quot;1024&quot;&gt;&lt;figcaption&gt;Each QR campaign has its own analytics view with the artwork, redirect URL, tracked destination URL, open count, downstream pageviews, visitors, and export controls.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Each saved QR campaign can be exported as SVG or PNG artwork. PNG exports are available at 1024, 2048, and 4096 px. Optional center images can be PNG, JPEG, or WebP up to 2 MiB.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/qr-campaigns-share-links.B0pOSKOw_Z1ETXBH.webp&quot; alt=&quot;HitKeep QR share links dialog listing read-only QR analytics share URLs with token hints, creation dates, search, actions, and pagination&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1440&quot; height=&quot;1024&quot;&gt;&lt;figcaption&gt;QR-only share links expose a read-only view for one QR campaign and its exports, without opening the rest of the dashboard.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;portuguese-localization&quot;&gt;Portuguese Localization&lt;/h2&gt;
&lt;p&gt;Portuguese joins the built-in dashboard languages. Users can select it from the same profile language setting as the other supported languages, and the selected locale follows the user across sessions and devices.&lt;/p&gt;
&lt;p&gt;The supported dashboard languages are now:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;English&lt;/li&gt;
&lt;li&gt;German&lt;/li&gt;
&lt;li&gt;Spanish&lt;/li&gt;
&lt;li&gt;French&lt;/li&gt;
&lt;li&gt;Italian&lt;/li&gt;
&lt;li&gt;Dutch&lt;/li&gt;
&lt;li&gt;Portuguese&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;ai-enablement&quot;&gt;AI Enablement&lt;/h2&gt;
&lt;p&gt;The AI-facing work in this release is about governed access, better assistant instructions, and safer contribution paths, not a new write-capable automation layer.&lt;/p&gt;
&lt;p&gt;HitKeep MCP stays optional, leader-only, and disabled by default. When enabled, it accepts scoped API client bearer tokens and exposes read-only aggregate analytics, docs lookup, and help resources. It does not accept dashboard cookies and does not expose raw hit exports, billing, site administration, goal mutation, funnel mutation, or write workflows.&lt;/p&gt;
&lt;p&gt;The official HitKeep Agent Skills complement MCP. They teach compatible assistants how to ask useful analytics questions, which HitKeep MCP tools to call, and where the privacy boundary is. That makes assistant answers easier to audit because the skill layer is public while the analytics token remains private and revocable.&lt;/p&gt;
&lt;p&gt;For contributors, the new public agent guidance documents the MCP read-only boundary, skill maintenance rules, dashboard localization workflow, and GoAI structured-output expectations. GoAI-backed Opportunity output must stay key-based and deterministic: saved model output should contain localization keys, interpolation params, cited evidence IDs, detector metadata, status, and safe audit metadata rather than raw prompts, raw provider responses, external error bodies, provider headers, or secrets.&lt;/p&gt;
&lt;p&gt;The release also adds direct storage-boundary regression coverage for AI run output. That test keeps the public rule honest: stored AI output must be a JSON object, must reject raw provider payload shapes, and must cite evidence that was actually supplied to the run.&lt;/p&gt;
&lt;h2 id=&quot;what-is-not-changing&quot;&gt;What Is Not Changing&lt;/h2&gt;
&lt;p&gt;HitKeep still keeps the same operating model:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;one Go binary&lt;/li&gt;
&lt;li&gt;embedded DuckDB data stores&lt;/li&gt;
&lt;li&gt;embedded NSQ queueing&lt;/li&gt;
&lt;li&gt;no required PostgreSQL, Redis, Kafka, ClickHouse, or hosted analytics dependency&lt;/li&gt;
&lt;li&gt;cookie-free browser tracking by default&lt;/li&gt;
&lt;li&gt;open export paths&lt;/li&gt;
&lt;li&gt;self-hosted and managed cloud built from the same product foundation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;QR campaigns do not turn HitKeep into an ad platform. MCP and Agent Skills do not give assistants write access to analytics or admin actions.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade Guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.8.0 if you want QR campaign creation and analytics, Portuguese dashboard localization, or the new public AI contributor guidance and skill pack updates.&lt;/p&gt;
&lt;p&gt;After upgrading, check QR campaign creation, scan redirects, destination tracking, QR-only share links, Portuguese dashboard copy, and MCP client setup with a scoped API client token.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/qr-campaigns/&quot;&gt;QR Campaigns&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/utm-parameters/&quot;&gt;UTM Parameters&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/localization/&quot;&gt;Localizing the UI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;Official MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/hitkeep-agent-skills/&quot;&gt;HitKeep Agent Skills&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/ai-development/&quot;&gt;AI Development With HitKeep&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/security/api-clients/&quot;&gt;API Clients&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>How to Measure AI Overviews Traffic Loss</title><link>https://hitkeep.com/blog/google-ai-search-backlash-measure-ai-overviews-traffic-loss/</link><guid isPermaLink="true">https://hitkeep.com/blog/google-ai-search-backlash-measure-ai-overviews-traffic-loss/</guid><description>Use Search Console impressions, organic clicks, AI referrals, and conversions to measure whether Google AI Overviews are reducing traffic to your site.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Your search traffic chart changed shape this spring, and the usual explanations do not cover it. Google is rolling out an AI-first search experience, a visible share of users is protesting by moving to no-AI alternatives, and AI Overviews answer queries before anyone clicks a result. All three shifts land in the same place: the referral data reaching your site.&lt;/p&gt;
&lt;p&gt;This post covers what is actually happening, with the numbers from the reporting, and shows how to detect the shift in your own analytics instead of guessing.&lt;/p&gt;
&lt;h2 id=&quot;users-are-moving-to-duckduckgo-and-no-ai-search&quot;&gt;Users are moving to DuckDuckGo and no-AI search&lt;/h2&gt;
&lt;p&gt;The pattern is consistent across multiple outlets. &lt;a href=&quot;https://techcrunch.com/2026/06/01/duckduckgo-makes-its-no-ai-search-engine-easier-to-access-as-its-traffic-booms&quot;&gt;TechCrunch reported&lt;/a&gt; that “DuckDuckGo noted a 30% increase in web visits to its no-AI search page week-over-week,” alongside new Chrome and Firefox extensions that make the no-AI experience a default. &lt;a href=&quot;https://independent.co.uk/tech/duckduckgo-ai-google-search-b2986989.html&quot;&gt;The Independent reported&lt;/a&gt; that DuckDuckGo app installs rose by nearly a third after Google’s AI updates, quoting CEO Gabriel Weinberg: “Google is force-feeding AI with no way to opt out.”&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://gizmodo.com/duckduckgos-doing-numbers-after-pitching-itself-as-the-home-of-ai-free-web-searches-2000765927&quot;&gt;Gizmodo&lt;/a&gt; tied the growth to user frustration with AI-generated answers and declining result quality. &lt;a href=&quot;https://wideopencountry.com/internet-users-begin-turning-backs-on-google-in-protest&quot;&gt;Wide Open Country&lt;/a&gt; cited Pubity data putting DuckDuckGo’s traffic increase at 300% since Google’s changes, and noted a parallel rise in the Vivaldi browser.&lt;/p&gt;
&lt;p&gt;Keep the scale honest: per Statcounter, DuckDuckGo holds roughly 0.7% global market share against Google’s 90%+. Nobody is dethroning Google this quarter. Acquisition analysis cares about your referral mix rather than global market share, though, and a few percentage points moving between engines is enough to break attribution assumptions and weekly dashboards.&lt;/p&gt;
&lt;h2 id=&quot;ai-overviews-reduce-clicks-to-source-sites&quot;&gt;AI Overviews reduce clicks to source sites&lt;/h2&gt;
&lt;p&gt;The second shift is structural. When Google answers a query inline with an AI Overview, the click to the source page often never happens. &lt;a href=&quot;https://extremetech.com/internet/how-to-search-in-the-era-of-ai&quot;&gt;ExtremeTech&lt;/a&gt; called the AI-first model potentially “disastrous for both the company and the broader internet ecosystem” precisely because it starves source sites of visits.&lt;/p&gt;
&lt;p&gt;The trust dimension makes it worse. A &lt;a href=&quot;https://bbc.com/future/article/20260519-google-tackles-attempts-to-hack-its-ai-results&quot;&gt;BBC investigation&lt;/a&gt; showed how easily AI answers can be manipulated, quoting SEO expert Lily Ray: “You should assume that you’re being manipulated until they have better systems in place.” The same reporting notes that 2.5 billion people see Google’s AI Overviews each month. Broad exposure plus visible skepticism drives users to test alternatives, and it should drive publishers to recheck their numbers.&lt;/p&gt;
&lt;h2 id=&quot;check-your-own-referral-mix-first&quot;&gt;Check your own referral mix first&lt;/h2&gt;
&lt;p&gt;Before changing strategy, measure. If you have raw analytics data, the first check takes minutes. With a &lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;HitKeep Parquet export&lt;/a&gt;, it is one DuckDB query:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;sql&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#919F9F;--1:#5F636F&quot;&gt;-- Referral mix by search engine, week over week&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;SELECT&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;date_trunc(&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;week&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;timestamp&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;) &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;AS&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;week&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;CASE&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;    &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;WHEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; referrer ILIKE &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;%google%&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;     &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;THEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;google&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;    &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;WHEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; referrer ILIKE &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;%duckduckgo%&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;THEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;duckduckgo&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;    &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;WHEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; referrer ILIKE &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;%bing%&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;       &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;THEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;bing&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;    &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;WHEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; referrer &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;                 &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;THEN&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;direct&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;    &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;ELSE&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;other&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;END&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;AS&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; source,&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;count&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA;--1:#096E72&quot;&gt;*&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;) &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;AS&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; pageviews&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;FROM&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;pageviews.parquet&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&apos;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;GROUP BY&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;1&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;2&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;ORDER BY&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;1&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;DESC&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;, &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;3&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;DESC&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt;;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;You are looking for three symptoms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Google share falling while direct or other engines rise.&lt;/strong&gt; That is a signal of a possible channel shift, not proof that users migrated. Investigate campaign changes, tracking gaps, and affected landing pages before attributing the cause.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search Console impressions flat or rising while clicks fall.&lt;/strong&gt; That is consistent with more zero-click results, including AI Overviews, but it does not identify the cause by itself. Check affected queries and the search-result layout before attributing the change.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Stable sessions but worse downstream conversion from organic.&lt;/strong&gt; That points to a change in channel quality rather than lost acquisition, and the two problems need different fixes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In the dashboard, &lt;a href=&quot;https://hitkeep.com/guides/analytics/comparison/&quot;&gt;period-over-period comparison&lt;/a&gt; against the weeks before Google’s rollout gives you the same answer without exporting anything.&lt;/p&gt;
&lt;h2 id=&quot;instrument-funnels-and-events&quot;&gt;Instrument funnels and events&lt;/h2&gt;
&lt;p&gt;A total-sessions chart hides structural change. To tell an acquisition drop apart from a channel-mix shift, you need event-level visibility:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/custom-events/&quot;&gt;Custom events&lt;/a&gt; for signup steps, key outbound clicks, and downloads, so conversion is measured independently of pageviews.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/funnels/&quot;&gt;Funnels&lt;/a&gt; segmented by referrer, so you can see whether DuckDuckGo arrivals reach step two of onboarding at a different rate than Google arrivals.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/utm-parameters/&quot;&gt;UTM reporting&lt;/a&gt; for the channels you control, so paid and owned traffic does not blur the organic picture.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/spam-filtering/&quot;&gt;Bot and spam filtering&lt;/a&gt; at collection time. Bot traffic masquerades as referral shifts, and a small real change in channel mix can look much bigger than it is when bots skew the data.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;None of this requires analytics cookies. HitKeep records referrers and events with &lt;a href=&quot;https://hitkeep.com/use-cases/cookieless-event-tracking/&quot;&gt;cookie-less tracking&lt;/a&gt; by default. Your consent and legal-basis analysis still depends on the full site configuration and jurisdiction. That matters here because the same backlash pushing users toward DuckDuckGo is privacy sentiment. Collecting more data than the analysis needs would be the wrong response.&lt;/p&gt;
&lt;h2 id=&quot;track-ai-assistants-as-their-own-channel&quot;&gt;Track AI assistants as their own channel&lt;/h2&gt;
&lt;p&gt;Search engines are only half of the new referral landscape. ChatGPT, Perplexity, and Claude cite and link sources, and their crawlers fetch your pages before any human visit shows up. The BBC’s reporting notes more than a billion people use AI chatbots regularly. That audience never appears in a classic search report.&lt;/p&gt;
&lt;p&gt;HitKeep treats this as its own reporting surface: &lt;a href=&quot;https://hitkeep.com/guides/analytics/ai-visibility/&quot;&gt;AI visibility analytics&lt;/a&gt; separates AI referral traffic from search referrals, and &lt;a href=&quot;https://hitkeep.com/guides/tracking/ai-fetch-ingest/&quot;&gt;AI fetch ingest&lt;/a&gt; records GPTBot, ClaudeBot, and PerplexityBot fetches from your edge or origin logs.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-ai-visibility.DPXf9_ks_Z2apQEG.webp&quot; alt=&quot;HitKeep AI visibility overview with fetch KPI cards, assistant filters, and crawl demand reporting&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;HitKeep’s AI visibility report separates assistant referrals and AI crawler fetches from regular search traffic.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;If Google’s AI answers may be taking clicks, seeing which systems fetch your content and which assistants later send referred visits adds useful context. Those are separate signals; neither one proves that a page was cited in an AI answer.&lt;/p&gt;
&lt;h2 id=&quot;run-the-measurement-stack-you-can-trust&quot;&gt;Run the measurement stack you can trust&lt;/h2&gt;
&lt;p&gt;When the search layer changes overnight, the analytics layer has to be something you can inspect and rely on. HitKeep is built for that case: a single Go binary with embedded DuckDB and NSQ, so there is no external database, cache, or queue to operate. &lt;a href=&quot;https://hitkeep.com/reference/configuration/&quot;&gt;Retention is configurable&lt;/a&gt; to your compliance constraints, and open exports in JSON, CSV, and Parquet support ad-hoc analysis like the query above. The &lt;a href=&quot;https://hitkeep.com/use-cases/self-hosted-ga4-alternative/&quot;&gt;self-hosted GA4 alternative guide&lt;/a&gt; covers the setup. One fair caveat from it: if your business depends on Google Ads attribution or BigQuery exports, a Google-native stack may remain essential.&lt;/p&gt;
&lt;p&gt;If you want the same measurement without running infrastructure, &lt;a href=&quot;https://hitkeep.com/pricing/&quot;&gt;HitKeep Cloud&lt;/a&gt; uses HitKeep’s shared open-source analytics foundation in region-pinned EU (Frankfurt) or US (Virginia) infrastructure with managed updates and backups. That helps when the team that needs these answers this week has no time to operate another service.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/ai-visibility/&quot;&gt;AI Visibility Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/use-cases/ai-crawler-logs-vs-ai-referral-traffic/&quot;&gt;AI Crawler Logs vs. AI Referral Traffic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/use-cases/cookieless-event-tracking/&quot;&gt;Cookie-less Event Tracking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;Open Exports and Takeout&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/use-cases/self-hosted-ga4-alternative/&quot;&gt;Self-Hosted GA4 Alternative&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.7.0: Smoother Realtime Analytics</title><link>https://hitkeep.com/blog/hitkeep-2-7-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-7-0/</guid><description>HitKeep 2.7.0 makes analytics dashboards refresh from site-scoped realtime signals without blanking visible reports, with Angular 22, Go 1.26.4, and an AI fetch ingest fix.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.7.0 makes analytics dashboards update faster after new data arrives, without turning every live update into a full visual reload. When HitKeep accepts new traffic, event, ecommerce, Web Vitals, AI visibility, import, goal, funnel, or Opportunity data, the active dashboard can receive a site-scoped realtime signal and refresh the affected reports instead of waiting for the next polling cycle.&lt;/p&gt;
&lt;p&gt;That matters most during setup, launches, campaigns, debugging, and demos. You can open the dashboard, trigger a pageview or event, and see the relevant report refresh as soon as the write path publishes the change. Existing KPI cards and charts stay on screen while the dashboard fetches fresh aggregates in the background, then changed metrics get a brief live-update highlight.&lt;/p&gt;
&lt;p&gt;This release also moves the dashboard to Angular 22, updates Go release builds to 1.26.4, fixes AI fetch ingest for non-browser forwarders, and marks internal dashboard routes clearly in the OpenAPI output.&lt;/p&gt;
&lt;h2 id=&quot;what-changed&quot;&gt;What changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Faster dashboard updates:&lt;/strong&gt; active reports refresh from site-scoped change signals after accepted writes. They no longer have to wait for the next periodic refresh when the realtime stream is open.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Smoother live updates:&lt;/strong&gt; the dashboard keeps existing stats, KPI cards, and charts visible during realtime refreshes. Changed KPI values receive a short visual highlight after the refreshed aggregates arrive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Less unnecessary reloading:&lt;/strong&gt; each page registers the data types it cares about. Events pages refresh for event and ecommerce changes, Web Vitals pages refresh for Web Vitals changes, and overview pages can listen to the full analytics set. Manual refreshes and filter changes still show the normal loading state.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Shared dashboard support:&lt;/strong&gt; share links use their own site-scoped realtime stream, so read-only shared reports can receive the same refresh signals as authenticated dashboard views.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reconnect and resync behavior:&lt;/strong&gt; the realtime broker keeps a short per-site event history, supports &lt;code&gt;Last-Event-ID&lt;/code&gt; replay, sends heartbeats, and asks the dashboard to resync when a client misses too much history.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Polling fallback:&lt;/strong&gt; dashboard pages still fall back to a periodic refresh when EventSource is unavailable, blocked by a proxy, or not open.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Angular 22:&lt;/strong&gt; the dashboard build, tests, and dependencies are updated for Angular 22.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Go 1.26.4:&lt;/strong&gt; release binaries, Docker images, development containers, and CI now use the Go version declared in &lt;code&gt;go.mod&lt;/code&gt;, currently Go 1.26.4.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI fetch ingest fix:&lt;/strong&gt; server-side AI fetch forwarders that do not send browser fetch metadata can post authenticated crawler records without being rejected by the browser request-isolation fallback.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internal API docs:&lt;/strong&gt; realtime stream endpoints and the dashboard bootstrap endpoint are marked with &lt;code&gt;x-internal: true&lt;/code&gt; in OpenAPI so generated docs can separate dashboard internals from the public API contract.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;where-you-will-feel-the-speedup&quot;&gt;Where You Will Feel The Speedup&lt;/h2&gt;
&lt;p&gt;Before this release, dashboard freshness depended on each view’s normal reload behavior. In practice, that meant an operator could send a test hit or event and still wait for a polling cycle before the visible report caught up.&lt;/p&gt;
&lt;p&gt;In 2.7.0, HitKeep publishes a realtime change event after the accepted write path completes. When the dashboard has an open stream for that site, it can schedule the relevant report refresh immediately. The refreshed data still comes from the normal aggregate report APIs, so charts, tables, exports, permissions, tenant isolation, and retention behavior stay on the same code paths as before.&lt;/p&gt;
&lt;p&gt;The dashboard now treats realtime refreshes differently from manual reloads. A manual refresh, site change, or filter change can still show loading feedback because the visible question changed. A realtime update keeps the current report painted, fetches the latest aggregates in the background, and highlights only KPI cards whose values changed. The result is easier to scan during active traffic because the page does not blink back into skeleton states for every accepted hit.&lt;/p&gt;
&lt;p&gt;This is especially useful for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tracking setup:&lt;/strong&gt; confirm that a newly installed &lt;code&gt;hk.js&lt;/code&gt; snippet sends pageviews without repeatedly pressing refresh.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Custom events:&lt;/strong&gt; fire a test event and watch the Events dashboard update when the ingest consumer writes it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Campaign checks:&lt;/strong&gt; keep overview, UTM, ecommerce, and goal views open during a launch and see fresh activity sooner.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI visibility:&lt;/strong&gt; forward AI fetch records from edge or origin logs and let the AI visibility dashboard refresh when new crawler rows arrive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Shared reports:&lt;/strong&gt; send a read-only dashboard link and let viewers see current aggregate reports without giving them dashboard access.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;what-realtime-means-here&quot;&gt;What Realtime Means Here&lt;/h2&gt;
&lt;p&gt;Realtime in 2.7.0 means realtime refresh signals, not a separate streaming analytics database. HitKeep still serves normal aggregate reports from the embedded DuckDB stores. The realtime stream only tells the dashboard when data changed and which report families should reload. The dashboard decides whether that refresh should be visible loading or a quiet background update.&lt;/p&gt;
&lt;p&gt;That design keeps the single-binary deployment model intact. There is no Redis, Kafka, hosted pub/sub service, browser analytics vendor, or second database to run.&lt;/p&gt;
&lt;p&gt;The covered dashboard areas include overview traffic, events, ecommerce, goals, funnels, UTM, Web Vitals, AI visibility, AI chatbot analytics, and Opportunities. Imported historical rows remain separate from native realtime views where the source data does not contain native HitKeep event streams.&lt;/p&gt;
&lt;h2 id=&quot;reliability-and-fallbacks&quot;&gt;Reliability And Fallbacks&lt;/h2&gt;
&lt;p&gt;The stream is scoped to one site. Authenticated dashboard views use &lt;code&gt;/api/sites/{id}/realtime&lt;/code&gt;, and read-only share links use &lt;code&gt;/api/share/{token}/sites/{id}/realtime&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The server sends heartbeats to keep compatible proxy connections open. If a browser reconnects with &lt;code&gt;Last-Event-ID&lt;/code&gt;, the broker can replay recent site events. If the browser missed too much history, HitKeep sends a resync event so the dashboard reloads instead of trying to patch around stale state.&lt;/p&gt;
&lt;p&gt;If EventSource is unavailable, blocked, or disconnected, the dashboard uses the polling fallback. Realtime improves freshness when available, but it is not required for the dashboard to work.&lt;/p&gt;
&lt;h2 id=&quot;compatibility-notes&quot;&gt;Compatibility Notes&lt;/h2&gt;
&lt;p&gt;The realtime stream routes and dashboard bootstrap route are internal HitKeep dashboard routes. They are now visible as internal operations in OpenAPI, but they are not part of the public semver contract:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;GET /api/sites/{id}/realtime&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;GET /api/share/{token}/sites/{id}/realtime&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;GET /api/user/bootstrap&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Public API clients should not depend on those route shapes, EventSource payloads, replay behavior, or bootstrap response fields. They may change in a minor release when the dashboard needs a different internal contract.&lt;/p&gt;
&lt;p&gt;The public analytics APIs remain the supported integration surface for site reports, exports, AI visibility, Web Vitals, MCP-read access, takeout, and server-side ingest.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade Guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.7.0 if you want dashboard reports to refresh sooner after new analytics writes, Angular 22 runtime maintenance, Go 1.26.4 release artifacts, or the AI fetch ingest fix for server-side log forwarders.&lt;/p&gt;
&lt;p&gt;No new external services are required. Realtime refresh runs inside the existing HitKeep binary. If a proxy or browser blocks EventSource, the dashboard keeps using the polling fallback.&lt;/p&gt;
&lt;p&gt;For AI fetch forwarders, keep using scoped API client tokens and the documented &lt;code&gt;POST /api/sites/{site_id}/ingest/ai-fetch&lt;/code&gt; endpoint. The fix only changes request-isolation handling for non-browser clients. It does not make AI fetch ingest public or unauthenticated.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/tech-stack/&quot;&gt;Tech Stack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/ai-fetch-ingest/&quot;&gt;AI Fetch Ingest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/ai-visibility/&quot;&gt;AI Visibility Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/web-vitals/&quot;&gt;Web Vitals Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;Open Exports and Takeout&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;Official MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.6.1: Web Vitals Dedup And Maintenance</title><link>https://hitkeep.com/blog/hitkeep-2-6-1/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-6-1/</guid><description>HitKeep 2.6.1 is a maintenance patch for Web Vitals metric identity, dashboard site selectors, dependency updates, refreshed IP metadata, and MCP registry metadata.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.6.1 was published on June 1, 2026. It is a maintenance patch on top of &lt;a href=&quot;https://hitkeep.com/blog/hitkeep-2-6-0/&quot;&gt;HitKeep 2.6.0&lt;/a&gt; and keeps the city, provider, ASN, Web Vitals, MCP, and export surfaces compatible.&lt;/p&gt;
&lt;p&gt;The main product fix is Web Vitals metric identity. The tracker now sends the metric ID emitted by the Web Vitals library, and the ingest path stores it with the Web Vitals sample. This gives HitKeep a stable metric identity for duplicate handling when a browser reports metric updates for the same page session.&lt;/p&gt;
&lt;h2 id=&quot;what-changed&quot;&gt;What changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Web Vitals metric IDs:&lt;/strong&gt; &lt;code&gt;hk-vitals.js&lt;/code&gt; sends the metric ID, ingest accepts it, and Web Vitals rows can store it as optional &lt;code&gt;metric_id&lt;/code&gt; data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dashboard site selectors:&lt;/strong&gt; API-client, settings, and UTM builder site selectors share the same site option component, favicon treatment, and domain sorting.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dependency maintenance:&lt;/strong&gt; Go modules, dashboard dependencies, and GitHub Actions were refreshed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IP metadata refresh:&lt;/strong&gt; embedded IP metadata assets were refreshed for release builds.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MCP registry metadata:&lt;/strong&gt; &lt;code&gt;server.json&lt;/code&gt; advertises the 2.6.1 MCP package version.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.6.1 if you use Web Vitals reporting, want the latest dependency refresh, or publish HitKeep MCP metadata to tooling catalogs.&lt;/p&gt;
&lt;p&gt;The Web Vitals schema change is additive. Existing Web Vitals rows do not need backfill. Older samples may have no metric ID, while new samples can preserve the metric ID sent by the tracker.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/hitkeep-2-6-0/&quot;&gt;HitKeep 2.6.0 release post&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/web-vitals/&quot;&gt;Web Vitals Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;Official MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/releases/tag/v2.6.1&quot;&gt;GitHub Release v2.6.1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.6.0: City And Network Analytics</title><link>https://hitkeep.com/blog/hitkeep-2-6-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-6-0/</guid><description>HitKeep 2.6.0 adds city, provider, ASN, and country exclusion support across analytics dashboards, exports, lifecycle tools, MCP, and the public API.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.6.0 adds city, provider, ASN, and ASN organization reporting to accepted hits. The new dimensions appear in dashboards, filters, Opportunities, shared reports, MCP responses, takeouts, and the public API.&lt;/p&gt;
&lt;p&gt;The privacy boundary stays the same. HitKeep resolves visitor IP addresses transiently, stores derived analytics metadata, and still does not store raw visitor IP addresses on hit records.&lt;/p&gt;
&lt;p&gt;This release also replaces the old country-only &lt;code&gt;iploc&lt;/code&gt; dependency with embedded lookup data generated from IP2Location LITE country, city, and ASN datasets. Runtime lookup does not download data.&lt;/p&gt;
&lt;p&gt;HitKeep uses the IP2Location LITE database for IP geolocation. See &lt;a href=&quot;https://www.ip2location.com/&quot;&gt;IP2Location&lt;/a&gt; and &lt;a href=&quot;https://lite.ip2location.com/&quot;&gt;IP2Location LITE&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;what-changed&quot;&gt;What Changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;City and network metadata:&lt;/strong&gt; accepted browser and server-side hits can store region, city, provider, ASN, and ASN organization fields beside country.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dashboard filters:&lt;/strong&gt; country and city live under Location. Provider and ASN live under Network. Clicking a row applies the same reversible filter behavior as other metric cards.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;More report context:&lt;/strong&gt; dashboard, events, goals, funnels, ecommerce, Web Vitals, AI visibility, and chatbot analytics can show the new dimensions where the report has matching data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Opportunities:&lt;/strong&gt; traffic quality, ecommerce, Web Vitals, and AI visibility Opportunities can cite aggregate city, provider, and ASN evidence without storing raw IP addresses, user agents, or visitor rows.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MCP and shared dashboards:&lt;/strong&gt; governed read-only surfaces can expose aggregate city/provider/ASN context without visitor-level data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Lifecycle coverage:&lt;/strong&gt; takeout, hit exports, retention archives, deletion/reset, and backup/restore include the new hit metadata consistently.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Country traffic exclusions:&lt;/strong&gt; site and instance exclusions support country rules beside IP/CIDR rules. Country exclusions affect new incoming traffic only.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/global_filters.DsN5WBeZ_19wfQT.webp&quot; alt=&quot;HitKeep Global Filters table showing IP/CIDR and country traffic exclusion rules&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1120&quot; height=&quot;529&quot;&gt;&lt;figcaption&gt;2.6.0 also extends traffic exclusions with country rules at the site and instance level, while keeping exclusions ingest-time and non-retroactive.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;dashboard-groups&quot;&gt;Dashboard Groups&lt;/h2&gt;
&lt;p&gt;Metric-card reports now use the same information architecture:&lt;/p&gt;





























&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th align=&quot;left&quot;&gt;Group&lt;/th&gt;&lt;th align=&quot;left&quot;&gt;Typical cards&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Content&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Pages, landing pages, exit pages, paths, event names, chatbot surfaces, AI resource types&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Acquisition&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Sources, referrers, campaigns, UTM source, medium, campaign, content, and term&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Audience&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Devices, browsers, and languages&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Location&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Countries and cities&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td align=&quot;left&quot;&gt;Network&lt;/td&gt;&lt;td align=&quot;left&quot;&gt;Providers and ASNs&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;City stays with country because both answer “where.” Provider and ASN stay together because both answer “which network.” Empty groups are hidden.&lt;/p&gt;
&lt;h2 id=&quot;data-and-attribution&quot;&gt;Data And Attribution&lt;/h2&gt;
&lt;p&gt;HitKeep’s embedded lookup assets are generated from IP2Location LITE data. They keep country lookup quality aligned with the previous &lt;code&gt;iploc&lt;/code&gt; source and add city, provider, and ASN lookup for IPv4 and IPv6 addresses.&lt;/p&gt;
&lt;p&gt;Maintainers refresh the embedded assets before public release:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;IP2LOCATION_DOWNLOAD_TOKEN&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;...&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;go&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;run&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;./cmd/ipmeta-generate&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;The generator downloads upstream data, writes compressed runtime lookup assets, and discards the raw ZIP/BIN payloads. Production binaries embed only the runtime assets.&lt;/p&gt;
&lt;h2 id=&quot;privacy-and-lifecycle&quot;&gt;Privacy And Lifecycle&lt;/h2&gt;
&lt;p&gt;City, provider, and ASN fields are derived analytics data. They follow the same lifecycle as hits:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;site takeout and user takeout include the fields&lt;/li&gt;
&lt;li&gt;filtered hit exports include the fields&lt;/li&gt;
&lt;li&gt;retention archives keep the fields in archived hit rows&lt;/li&gt;
&lt;li&gt;site deletion, site reset, and analytics cleanup remove the fields with the hit rows&lt;/li&gt;
&lt;li&gt;backup and restore preserve the fields because they are normal database columns&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;HitKeep still does not add raw visitor IP storage.&lt;/p&gt;
&lt;h2 id=&quot;compatibility-notes&quot;&gt;Compatibility Notes&lt;/h2&gt;
&lt;div&gt;&lt;p&gt;API compatibility&lt;/p&gt;&lt;p&gt;Most JSON analytics response changes in 2.6.0 are additive. API clients with strict schemas should still review these compatibility-impacting changes before upgrading:&lt;/p&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Exclusion rule responses are now typed.&lt;/strong&gt; &lt;code&gt;GET /api/admin/exclusions&lt;/code&gt; and &lt;code&gt;GET /api/sites/{id}/exclusions&lt;/code&gt; can return CIDR rules with &lt;code&gt;type: &quot;cidr&quot;&lt;/code&gt; and &lt;code&gt;cidr&lt;/code&gt;, or country rules with &lt;code&gt;type: &quot;country&quot;&lt;/code&gt; and &lt;code&gt;country_code&lt;/code&gt;. Existing &lt;code&gt;POST&lt;/code&gt; requests that send only &lt;code&gt;cidr&lt;/code&gt; still work and are treated as CIDR rules, but list clients should stop assuming every row has a &lt;code&gt;cidr&lt;/code&gt; value.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hit exports and takeouts add geo/network fields.&lt;/strong&gt; Hit rows can now include &lt;code&gt;region&lt;/code&gt;, &lt;code&gt;city&lt;/code&gt;, &lt;code&gt;provider&lt;/code&gt;, &lt;code&gt;asn&lt;/code&gt;, and &lt;code&gt;asn_org&lt;/code&gt;. JSON clients that ignore unknown fields should keep working. Fixed-column CSV/XLSX readers and strict Parquet, JSON, or NDJSON schema consumers should update their mappings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI chatbot export now recognizes audience filters.&lt;/strong&gt; &lt;code&gt;/api/sites/{id}/ai-chatbots/export&lt;/code&gt; accepts repeatable &lt;code&gt;filter=type:value&lt;/code&gt; hit-dimension filters. Clients that previously sent unrelated &lt;code&gt;filter&lt;/code&gt;, &lt;code&gt;filter_type&lt;/code&gt;, or &lt;code&gt;filter_value&lt;/code&gt; query parameters should rename or remove them because invalid filter input can now return &lt;code&gt;400&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div&gt;&lt;p&gt;Hit metadata migration&lt;/p&gt;&lt;p&gt;There is also a schema migration for &lt;code&gt;hits&lt;/code&gt;. Historical rows are not backfilled, so old rows may have country-only or empty city/network metadata. New accepted hits receive derived metadata when the resolved IP has a matching lookup row.&lt;/p&gt;&lt;/div&gt;
&lt;div&gt;&lt;p&gt;Trusted proxy accuracy&lt;/p&gt;&lt;p&gt;If you self-host behind a reverse proxy, review &lt;a href=&quot;https://hitkeep.com/guides/installation/trusted-proxies/&quot;&gt;Trusted Proxies&lt;/a&gt;. Correct trusted-proxy configuration affects rate limiting, IP exclusions, spam checks, and derived country, region, city, provider, and ASN accuracy.&lt;/p&gt;&lt;/div&gt;
&lt;div&gt;&lt;p&gt;Release metadata refresh&lt;/p&gt;&lt;p&gt;Operators who mirror release workflows should set the &lt;code&gt;IP2LOCATION_DOWNLOAD_TOKEN&lt;/code&gt; secret before running the metadata refresh workflow. Runtime deployments do not need the token.&lt;/p&gt;&lt;/div&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/facts-and-limits/&quot;&gt;Facts and Limits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/tech-stack/&quot;&gt;Tech Stack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/installation/trusted-proxies/&quot;&gt;Trusted Proxies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/ip-exclusions/&quot;&gt;Traffic Exclusions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/events/&quot;&gt;Events Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/goals/&quot;&gt;Goals Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/funnels/&quot;&gt;Funnels Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/ecommerce/&quot;&gt;Ecommerce Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/web-vitals/&quot;&gt;Web Vitals Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/opportunities/&quot;&gt;Opportunity Recommendations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;Official MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;Analytics with Open Exports&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.5.1: Dashboard Refresh And Clearer API-Client Grants</title><link>https://hitkeep.com/blog/hitkeep-2-5-1/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-5-1/</guid><description>HitKeep 2.5.1 refreshes dashboard navigation, API-client site grants, token rotation, shared Web Vitals reports, dialogs, and dark-mode polish.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.5.1 is prepared as a dashboard and API-client clarity patch. The release keeps the 2.5.0 analytics surface intact while making navigation, table actions, dialogs, API-client grants, token rotation, and dark-mode Opportunity Recommendations easier to understand. It also exposes aggregate Web Vitals reports in read-only share mode and fixes stale AI provider warnings in system status.&lt;/p&gt;
&lt;p&gt;Under the hood, it contains a few permission audit bugfixes.&lt;/p&gt;
&lt;p&gt;The important API-client wording change is &lt;code&gt;site grants&lt;/code&gt;. A client without a site grant can still be useful for permitted instance or admin APIs, but site analytics, MCP tools, and ingest access require an explicit site grant. That was the intended API-client model before this patch. The UI now says it plainly.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/release-2-5-1-api-clients-card.UfVgx22q_1tn8OY.webp&quot; alt=&quot;HitKeep API Clients settings card with a table, search field, site grant tag, row actions menu trigger, and create and team-management actions&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2120&quot; height=&quot;724&quot;&gt;&lt;figcaption&gt;The API-client settings page now leads with a table. Creation and editing happen in dialogs, and row actions use the same menu pattern as other settings tables.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/release-2-5-1-api-client-grants-dialog.FPoM8g5Q_1DAHSV.webp&quot; alt=&quot;HitKeep Add API client dialog showing client name, instance role, expiration, explicit site grants, role selector, add grant, cancel, and create client controls&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1344&quot; height=&quot;1000&quot;&gt;&lt;figcaption&gt;API-client creation now says what the grant does: site analytics, MCP, and ingest access require an explicit site grant.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/release-2-5-1-team-api-clients.COyOo1ew_1nFxlC.webp&quot; alt=&quot;HitKeep Team API clients settings section showing a team-owned token, site grant, add API client action, and table row actions&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2376&quot; height=&quot;696&quot;&gt;&lt;figcaption&gt;Team-owned clients use the same grant language and table actions as personal clients, but the owner is the active team.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/release-2-5-1-opportunities-dark.BcASOMFI_Z1Vzsrs.webp&quot; alt=&quot;HitKeep Opportunities page in dark mode with readable filter rails, opportunity cards, status badges, evidence rows, and action buttons&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2632&quot; height=&quot;1834&quot;&gt;&lt;figcaption&gt;The Opportunities page was cleaned up in dark mode so cards, filters, badges, and evidence text stay readable.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/release-2-5-1-api-clients-mobile.DqV7WsYG_Jklnp.webp&quot; alt=&quot;Mobile HitKeep API Clients page showing header controls, manage team API clients, add API client, search, and the API-client table&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;780&quot; height=&quot;1800&quot;&gt;&lt;figcaption&gt;On small screens, the API-client page keeps the team-management link visible above the table instead of burying it below scrolled content.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;what-changed&quot;&gt;What changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Sidebar navigation:&lt;/strong&gt; related destinations are grouped as collapsible items. &lt;code&gt;UTM&lt;/code&gt; can reveal &lt;code&gt;UTM Builder&lt;/code&gt;, and &lt;code&gt;API Clients&lt;/code&gt; can reveal &lt;code&gt;API Reference&lt;/code&gt;, while the parent labels remain normal navigation links.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reusable row actions:&lt;/strong&gt; settings and admin tables now use a shared OptimusUI popup menu for row actions instead of inline button stacks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Consistent dialogs:&lt;/strong&gt; create and edit flows use the same dialog shell, footer order, close behavior, Escape behavior, and submit/cancel treatment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;API-client settings:&lt;/strong&gt; the page is table-first. Add and edit flows open in dialogs, site grants are labelled as grants, active/revoked/expired state is shown beside the client name, and team API clients are reachable when the user has permission.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Explicit site-grant wording:&lt;/strong&gt; empty site grants are shown as no site access. The form says that site analytics, MCP, and ingest access require a site grant.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Token rotation:&lt;/strong&gt; personal and team API clients can roll tokens. Rotation returns the new token once and invalidates the previous token immediately.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit coverage:&lt;/strong&gt; API-client create, update, revoke, reactivate, delete, and rotate actions are recorded without token material or token hashes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Shared Web Vitals:&lt;/strong&gt; share links now include the Web Vitals report, with the same aggregate p75 cards, trends, page rows, and visitor-context breakdowns available to authenticated viewers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mobile settings flow:&lt;/strong&gt; page actions move above the table on narrow screens, so users do not need to scroll past rows before finding the main action.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dark-mode Opportunity Recommendations:&lt;/strong&gt; the filter rail, opportunity cards, evidence rows, status badges, and action buttons were tuned so the page no longer mixes light card styling into dark mode.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Settings polish:&lt;/strong&gt; inline CRUD feedback was moved closer to the changed resource, so users see save, rotate, revoke, and delete outcomes where they acted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;api-client-grants&quot;&gt;API-client grants&lt;/h2&gt;
&lt;p&gt;API clients now use grant language consistently to address some feedback:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;site_roles&lt;/code&gt; are grants, not optional restrictions.&lt;/li&gt;
&lt;li&gt;A client with no site grants has no site-data access.&lt;/li&gt;
&lt;li&gt;Site analytics, site-scoped MCP tools, and ingest require an explicit site grant.&lt;/li&gt;
&lt;li&gt;Instance/admin-only API clients can still have no site grants.&lt;/li&gt;
&lt;li&gt;Personal clients are capped to the creating user’s access.&lt;/li&gt;
&lt;li&gt;Team clients are owned by the team and appear in the team API-client section.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is a clarity and hardening patch for the existing model. If an integration already had site grants, no change is needed.&lt;/p&gt;
&lt;h2 id=&quot;compatibility-note&quot;&gt;Compatibility note&lt;/h2&gt;
&lt;p&gt;Review API clients that call site analytics, MCP tools, or server-side ingest. Add the required site grants before or during the upgrade.&lt;/p&gt;
&lt;p&gt;Most clients used for site data already needed grants to be useful. The hardening also closes paths where delegated owner/admin API clients could satisfy site-scoped checks through instance role alone. Treat those as over-broad tokens and add the intended site grants explicitly.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;That has always worked like this and is not breaking&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Token rotation is optional. Adding a grant does not reveal an existing token and does not require rolling it.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.5.1 for the dashboard refresh, API-client grant wording, token rotation, audit coverage, share-mode Web Vitals reports, and stale AI provider warning cleanup.&lt;/p&gt;
&lt;p&gt;Before upgrading integrations that use API clients for site data, check that each client has a grant for every site it should access. Clients used only for instance/admin APIs can remain without site grants.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/security/api-clients/&quot;&gt;API Clients&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/permissions/&quot;&gt;Roles and Permissions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;MCP Analytics Access&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/opportunities/&quot;&gt;Opportunity Recommendations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/web-vitals/&quot;&gt;Web Vitals Analytics&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.5.0: Web Vitals, Opportunities, And Subdirectory Installs</title><link>https://hitkeep.com/blog/hitkeep-2-5-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-5-0/</guid><description>HitKeep 2.5.0 prepares Web Vitals analytics, Opportunity Recommendations, subdirectory installs, Web Vitals MCP aggregates, and dashboard polish.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.5.0 is in release-candidate review for &lt;a href=&quot;https://hitkeep.com/guides/analytics/web-vitals/&quot;&gt;Web Vitals analytics&lt;/a&gt; and &lt;a href=&quot;https://hitkeep.com/guides/analytics/opportunities/&quot;&gt;Opportunity Recommendations&lt;/a&gt;. The release candidate adds opt-in LCP, INP, CLS, FCP, and TTFB reporting beside traffic analytics, plus a saved recommendations inbox for setup gaps, traffic signals, search visibility, AI visibility, ecommerce activity, conversion signals, and performance issues backed by aggregate evidence already in HitKeep.&lt;/p&gt;
&lt;p&gt;It also hardens self-hosted deployments that mount HitKeep below an existing domain path, such as &lt;code&gt;https://www.example.net/hitkeep/&lt;/code&gt;. Dashboard navigation, static assets, API calls, the API reference, tracker bundles, browser ingest, email links, share links, billing redirects, and OAuth callbacks now derive their public paths from &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The product promise is deliberately narrow: HitKeep shows privacy-preserving performance signals and evidence-backed recommendations. It does not collect Web Vitals attribution payloads, promise revenue lift, claim financial upside, or infer causal attribution.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-web-vitals.sOa6lsyi_ZO3dtx.webp&quot; alt=&quot;HitKeep Web Vitals report showing p75 metric cards, threshold bars, rating mix bars, filters, and the trend chart&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Web Vitals cards show p75 values, thresholds, rating mix, and the selected metric trend without enabling Web Vitals by default.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-opportunities.SThTpN9l_R3exK.webp&quot; alt=&quot;HitKeep Opportunities page showing prioritized recommendation cards with evidence, status filters, and a selected recommendation detail drawer&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Opportunity cards use stable translation keys and cited aggregate evidence, so the same saved recommendation can render safely in every supported dashboard language.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;what-is-prepared&quot;&gt;What Is Prepared&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Opt-in Web Vitals collection:&lt;/strong&gt; the default &lt;code&gt;hk.js&lt;/code&gt; snippet stays lean. Sites load the same-origin &lt;code&gt;hk-vitals.js&lt;/code&gt; split bundle only when Web Vitals are enabled in tracking settings or &lt;code&gt;data-enable-web-vitals=&quot;true&quot;&lt;/code&gt; is present.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Web Vitals dashboard:&lt;/strong&gt; site teams can inspect p75 cards, threshold bars, rating mix, trends, searchable path selection, paginated page breakdowns, and browser, country, language, and device context for LCP, INP, CLS, FCP, and TTFB.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Privacy-preserving samples:&lt;/strong&gt; HitKeep stores metric, value, server-derived rating, normalized path, navigation type, session/page IDs, tracker source/version, and server receipt time. It strips query strings and hashes and does not store attribution/debug payloads, selectors, text, or resource URLs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Lifecycle coverage:&lt;/strong&gt; Web Vitals samples are tenant-local and covered by site deletion, user deletion, archival, retention, takeout exports, and read-only MCP aggregate access.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Opportunity inbox:&lt;/strong&gt; every site can list saved recommendations, filter by status, open the evidence drawer, dismiss items, mark them done, and regenerate them when the user has &lt;code&gt;site.manage_data&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Evidence-first generation:&lt;/strong&gt; deterministic detectors decide the candidate type, impact, confidence, score, status, route params, and evidence IDs. Web Vitals detectors can create Performance Opportunities from poor or needs-work metric evidence. AI is optional and can only decorate the detector-approved candidate.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Provider-agnostic AI model configuration:&lt;/strong&gt; self-hosted operators can configure their chosen provider, model, gateway route, timeout, and local budgets through &lt;code&gt;HITKEEP_AI_*&lt;/code&gt; settings without dashboard-secret editing in this first slice.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Local budgets and audit records:&lt;/strong&gt; HitKeep enforces request and token caps before provider calls, records safe run metadata, stores lifecycle events, and avoids persisting raw prompts or raw provider payloads.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;System Status visibility:&lt;/strong&gt; instance owners can see whether AI is enabled and configured, which provider/model label is active, whether the config is cloud-managed or self-hosted, current usage and cap state, and the last safe success/error category.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Subdirectory install support:&lt;/strong&gt; operators can set &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt; to a path-prefixed URL. HitKeep serves the dashboard base href, app-owned static assets, API reference iframe, &lt;code&gt;hk.js&lt;/code&gt;, &lt;code&gt;hk-vitals.js&lt;/code&gt;, ingest routes, and generated public links below that prefix.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Public-safe surfaces:&lt;/strong&gt; saved Opportunities appear in dashboard APIs, share mode, takeout exports, read-only MCP output, and the regular daily, weekly, or monthly email reports without exposing provider secrets or unrestricted tool execution. Web Vitals dashboard APIs and MCP tools return aggregate reporting data only.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Localization-safe API:&lt;/strong&gt; customer-facing copy is stored as translation keys plus interpolation params. The API does not persist full English recommendation text as the durable contract.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;guardrails&quot;&gt;Guardrails&lt;/h2&gt;
&lt;p&gt;Web Vitals collection is opt-in. HitKeep derives ratings on the server from standard thresholds, stores samples in the tenant analytics store, and keeps the tracker payload compact. The Web Vitals feature is for aggregate page-performance reporting, not user-level profiling or debugging traces.&lt;/p&gt;
&lt;p&gt;Opportunity Recommendations use aggregate evidence only. Traffic-source recommendations must cite source-specific counts, not total site pageviews. Setup suggestions need a clear page, event, goal, or funnel signal and are suppressed when matching configuration already exists.&lt;/p&gt;
&lt;p&gt;The validator rejects provider output that invents evidence IDs, adds trailing prose after JSON, uses removed money/upside params, references unsupported fields, or makes claims outside the detector contract.&lt;/p&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade Guidance&lt;/h2&gt;
&lt;p&gt;Web Vitals are off by default. Enable them from &lt;strong&gt;Site Settings &gt; Tracking&lt;/strong&gt; for a site, or add &lt;code&gt;data-enable-web-vitals=&quot;true&quot;&lt;/code&gt; to that site’s tracking snippet. The main tracker only loads &lt;code&gt;hk-vitals.js&lt;/code&gt; from the same origin when the opt-in flag is present.&lt;/p&gt;
&lt;p&gt;For subdirectory installs, set &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt; to the full external URL, including the path prefix, and keep the reverse proxy route aligned with that prefix:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_PUBLIC_URL&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;https://www.example.net/hitkeep/&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;In path-prefix mode, public app and API routes are served below the configured prefix. Root &lt;code&gt;/healthz&lt;/code&gt; and &lt;code&gt;/readyz&lt;/code&gt; remain available for local probes.&lt;/p&gt;
&lt;p&gt;Self-hosted instances can leave AI disabled. With &lt;code&gt;HITKEEP_AI_ENABLED=false&lt;/code&gt;, HitKeep still runs deterministic detector logic and stores recommendations that do not need provider enrichment.&lt;/p&gt;
&lt;p&gt;To enable provider enrichment on self-hosted instances, configure the HitKeep provider/model route, timeout, request cap, token cap, and budget window through &lt;code&gt;HITKEEP_AI_*&lt;/code&gt; variables. Configure provider credentials with the selected goAI provider’s native environment variables.&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_ENABLED&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;true&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_PROVIDER&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;openai&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_MODEL&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;your-json-capable-model&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;OPENAI_API_KEY&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;provider_key_from_your_secret_store&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_REQUEST_LIMIT&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;100&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_TOKEN_LIMIT&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;100000&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_AI_BUDGET_WINDOW&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;1440&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;For OpenAI-compatible gateways, set &lt;code&gt;HITKEEP_AI_PROVIDER=openai-compatible&lt;/code&gt; and &lt;code&gt;HITKEEP_AI_BASE_URL&lt;/code&gt; for the gateway endpoint. Set &lt;code&gt;HITKEEP_AI_API_KEY&lt;/code&gt; only if that gateway requires a bearer token. See &lt;a href=&quot;https://hitkeep.com/guides/admin/ai-model-configuration/&quot;&gt;AI Model Configuration&lt;/a&gt; for model-selection guidance, setup examples, token-budget sizing, and the System Status fields operators should verify before release.&lt;/p&gt;
&lt;h2 id=&quot;out-of-scope&quot;&gt;Out Of Scope&lt;/h2&gt;
&lt;p&gt;This release candidate does not add Web Vitals attribution/debug fields, sampling controls, external performance vendors, share-link Web Vitals reports, dashboard-secret editing for provider keys, customer-defined detectors, write-capable MCP tools, or financial upside predictions. Ecommerce analytics can still report factual revenue metrics, but Opportunity Recommendations do not position themselves around money claims.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/web-vitals/&quot;&gt;Web Vitals Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/opportunities/&quot;&gt;Opportunity Recommendations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/ai-model-configuration/&quot;&gt;AI Model Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/#optional-ai-model-configuration&quot;&gt;AI model configuration reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/#public-url-path-prefixes&quot;&gt;Public URL path prefixes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/tracker-architecture/&quot;&gt;Tracker Architecture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/system-administration/&quot;&gt;System Status and Settings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/permissions/&quot;&gt;Roles and Permissions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;MCP Analytics Access&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;Open Exports and Takeout&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.4.2: Site Export Dropdown Fix</title><link>https://hitkeep.com/blog/hitkeep-2-4-2/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-4-2/</guid><description>HitKeep 2.4.2 fixes site export format dropdown actions so site-specific takeout downloads reliably start from the dashboard.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.4.2 is a focused patch release for dashboard exports. It fixes the site-specific export format dropdown so choosing CSV, XLSX, Parquet, JSON, or NDJSON starts the matching site takeout download.&lt;/p&gt;
&lt;p&gt;The all-sites export dropdown already worked. This patch keeps that behavior unchanged and tightens the site-row path that calls &lt;code&gt;/api/sites/{id}/takeout?format=&amp;#x3C;format&gt;&lt;/code&gt;.&lt;/p&gt;
&lt;div&gt;&lt;p&gt;Release pipeline note&lt;/p&gt;&lt;p&gt;This patch is intentionally small and follows 2.4.1 quickly. It fixes the site export menu bug and exercises the release pipeline with a narrow change.&lt;/p&gt;&lt;/div&gt;
&lt;h2 id=&quot;what-changed&quot;&gt;What changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Site export menu actions:&lt;/strong&gt; site export dropdown items stay bound to the intended site row while the menu is open.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Alternate formats:&lt;/strong&gt; CSV, XLSX, Parquet, JSON, and NDJSON remain available for site-specific takeout downloads.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Global exports unchanged:&lt;/strong&gt; the all-sites export dropdown still calls &lt;code&gt;/api/user/takeout?format=&amp;#x3C;format&gt;&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Regression coverage:&lt;/strong&gt; focused unit coverage checks repeated site menu reads, and seeded Playwright coverage verifies all-sites and per-site JSON downloads in the German dashboard at the reported desktop viewport.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.4.2 if users rely on site-specific exports from the Import &amp;#x26; Export page.&lt;/p&gt;
&lt;p&gt;No backend export schema, takeout endpoint, permission model, or supported format changes are included in this patch.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/takeout/&quot;&gt;Open Exports and Takeout&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/releases/tag/v2.4.2&quot;&gt;GitHub Release v2.4.2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/hitkeep-2-4-1/&quot;&gt;HitKeep 2.4.1 release notes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.4.1: MCP Reliability And Go Security Fixes</title><link>https://hitkeep.com/blog/hitkeep-2-4-1/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-4-1/</guid><description>HitKeep 2.4.1 fixes MCP startup behind reverse proxies and updates release builds to Go 1.26.3 for standard-library security fixes.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.4.1 is a focused patch release for operators who enable the optional MCP server behind a reverse proxy. It also updates HitKeep release builds to Go 1.26.3 after &lt;code&gt;govulncheck&lt;/code&gt; reported called vulnerabilities in the Go 1.26.2 standard library.&lt;/p&gt;
&lt;p&gt;The release fixes MCP Streamable HTTP initialization when HitKeep listens on loopback, such as &lt;code&gt;127.0.0.1:8080&lt;/code&gt;, and a reverse proxy exposes the public &lt;code&gt;/mcp&lt;/code&gt; endpoint. Valid MCP clients should now initialize through the configured public host instead of receiving a plain-text host-header &lt;code&gt;403&lt;/code&gt; before HitKeep can validate the bearer token.&lt;/p&gt;
&lt;h2 id=&quot;what-changed&quot;&gt;What changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Reverse-proxied MCP initialization:&lt;/strong&gt; HitKeep now validates MCP request hosts against &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt; before handing the request to the MCP Go SDK.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Public host support:&lt;/strong&gt; deployments that publish &lt;code&gt;/mcp&lt;/code&gt; at a public hostname can initialize MCP clients while keeping HitKeep bound to loopback.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Local development preserved:&lt;/strong&gt; loopback hosts such as &lt;code&gt;localhost&lt;/code&gt;, &lt;code&gt;127.0.0.1&lt;/code&gt;, and &lt;code&gt;::1&lt;/code&gt; continue to work for local MCP clients.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Host validation kept explicit:&lt;/strong&gt; unexpected hosts still receive &lt;code&gt;403 Forbidden&lt;/code&gt;; missing or invalid bearer tokens on valid hosts receive &lt;code&gt;401 Unauthorized&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No MCP schema changes:&lt;/strong&gt; MCP tools, resources, bearer token format, API-client scopes, and dashboard API behavior are unchanged.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Go 1.26.3 release builds:&lt;/strong&gt; Linux binaries, Docker images, and CI now use Go 1.26.3. This clears the standard-library &lt;code&gt;govulncheck&lt;/code&gt; findings that affected Go 1.26.2.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade guidance&lt;/h2&gt;
&lt;p&gt;Upgrade to 2.4.1 if you enable MCP and expose HitKeep through a reverse proxy, or if you want release artifacts built with Go 1.26.3.&lt;/p&gt;
&lt;p&gt;Make sure &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt; matches the externally visible origin:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_PUBLIC_URL&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;https://analytics.example.com&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_MCP_ENABLED&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;true&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_MCP_PATH&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;/mcp&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;The simplest proxy setup preserves the original &lt;code&gt;Host&lt;/code&gt; header. If your proxy rewrites the upstream &lt;code&gt;Host&lt;/code&gt; to a loopback address, configure explicit &lt;code&gt;HITKEEP_TRUSTED_PROXIES&lt;/code&gt; CIDRs and forward the public host with &lt;code&gt;X-Forwarded-Host&lt;/code&gt; or the standard &lt;code&gt;Forwarded&lt;/code&gt; header.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;Official MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/installation/trusted-proxies/&quot;&gt;Trusted Proxies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/releases/tag/v2.4.1&quot;&gt;GitHub Release v2.4.1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/hitkeep-2-4-0/&quot;&gt;HitKeep 2.4.0 release notes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.4.0: Imports, Search Console, MCP Reporting, Server-Side Ingest, And Dutch Localization</title><link>https://hitkeep.com/blog/hitkeep-2-4-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-4-0/</guid><description>HitKeep 2.4.0 ships Plausible and Simple Analytics imports, Google Search Console integration, Search Console MCP reporting, server-side tracking, Dutch localization, and focused reliability and UX fixes.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.4.0 was published on May 6, 2026. It ships historical imports for Plausible and Simple Analytics, Google Search Console Search Analytics import, read-only Search Console reporting through MCP, authenticated server-side tracking with original timestamp and visitor IP context for derived country, region, city, provider, and ASN metadata, Dutch dashboard and email localization, and focused reliability and UX fixes from the 2.4.0 changelog.&lt;/p&gt;
&lt;p&gt;The import system is aggregate-first. Plausible exports and Simple Analytics datapoints are migration history, not full-fidelity native HitKeep sessions. Imported data appears in compatible dashboard and event reports, while realtime, hourly, and relationship-heavy filtered views keep native data separate and explain when imported rows are excluded.&lt;/p&gt;
&lt;h2 id=&quot;what-shipped-in-240&quot;&gt;What shipped in 2.4.0&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Importables framework:&lt;/strong&gt; a provider model for future importers, with Plausible and Simple Analytics as the first providers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Plausible ZIP and CSV input:&lt;/strong&gt; upload one Plausible export ZIP or loose CSV files whose headers match supported Plausible schemas.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Simple Analytics datapoints input:&lt;/strong&gt; upload any CSV whose header matches the Simple Analytics &lt;strong&gt;All&lt;/strong&gt; datapoints export.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mandatory validation:&lt;/strong&gt; validation scans staged files row by row and returns a manifest before analytics rows are committed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Historical dashboard coverage:&lt;/strong&gt; imported traffic, page, source, device, location, and provider-specific dimension aggregates appear in compatible daily and monthly reports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Imported event coverage:&lt;/strong&gt; Plausible custom events and URL-style properties appear in compatible Events views.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Google Search Console integration:&lt;/strong&gt; connect a team to Google Search Console with read-only OAuth, map a site to a Search Console property, and import finalized Search Analytics aggregates.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search Console drilldown:&lt;/strong&gt; authenticated site dashboards show clicks, impressions, CTR, average position, trends, top queries, top pages, and country/device breakdowns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search Console MCP reporting:&lt;/strong&gt; approved MCP clients can check Search Console mapping and sync status, then read imported overview, series, query, page, country, and device aggregates for scoped sites.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CLI and REST API:&lt;/strong&gt; the dashboard flow uses the same chunked upload, validation, start, status, list, and delete lifecycle as the CLI and API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Import history and deletion:&lt;/strong&gt; completed imports can be inspected and deleted, including their imported aggregate rows.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Server-side pageview and event ingest:&lt;/strong&gt; scoped API clients can send trusted pageviews and custom events with an explicit RFC3339 timestamp and transient visitor IP context for derived IP metadata.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Server-to-server request behavior:&lt;/strong&gt; the server-side ingest endpoints do not require browser &lt;code&gt;Origin&lt;/code&gt; or &lt;code&gt;Referer&lt;/code&gt; headers, use the ingest rate limiter, and forward safely from follower nodes to the leader in clustered deployments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dutch dashboard and email localization:&lt;/strong&gt; Dutch (&lt;code&gt;nl&lt;/code&gt;) becomes selectable in user preferences, auto-detects from Dutch browser and request languages, and covers the localized transactional and analytics report emails.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reliability and UX fixes:&lt;/strong&gt; 2.4.0 also optimizes the healthcheck endpoint, sets the Docker healthcheck interval to 30 seconds, consolidates frontend and auth bootstrap behavior, refreshes the May IP location data, clarifies server-side pageview copy, unifies copy actions for team, site, and user IDs, and consolidates import and export UI behavior.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;google-search-console-integration&quot;&gt;Google Search Console Integration&lt;/h2&gt;
&lt;p&gt;Search Console import is for teams that want organic search query data beside HitKeep’s normal site analytics without exposing that data through public dashboards.&lt;/p&gt;
&lt;p&gt;Team owners and admins connect Google Search Console through read-only OAuth. HitKeep stores the team connection, lists available Search Console properties, and lets an admin map one property to a HitKeep site. Viewers can see the mapping state, but they cannot connect, map, unmap, disconnect, or request syncs.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/integration-google-search-console.BnKaa6nX_2vx3Oa.webp&quot; alt=&quot;HitKeep Google Search Console integration page with connected account, property mapping, sync status, and manual sync controls&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The integration page keeps connection, property mapping, and sync status in the same team-scoped workflow.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The import uses Google’s official generated Search Console client behind HitKeep’s own adapter. It requests the read-only Search Console scope and imports finalized aggregate Search Analytics rows. Tokens, OAuth codes, client secrets, and raw Google payloads stay out of API responses, logs, audits, seed data, exports, and public share surfaces.&lt;/p&gt;
&lt;p&gt;Sync is tenant-scoped. A manual sync request should give immediate feedback in the dashboard, while the worker imports rows through the same in-process runtime used by self-hosted and cloud deployments. Recurring syncs recheck recent completed days because Search Console data can settle after initial availability.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-search-console.CSc92Uud_1y11Bk.webp&quot; alt=&quot;HitKeep Search Console drilldown showing clicks, impressions, CTR, average position, query trends, pages, countries, and devices&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Search Console reports stay inside authenticated dashboards and are excluded from share-mode dashboards.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The report surface is aggregate-first: overview metrics, daily series, top queries, top pages, and country/device breakdowns. It does not claim query-to-session attribution because Search Console does not provide that relationship. Use GA4 or another attribution system if your workflow depends on connecting individual search queries to sessions or conversions.&lt;/p&gt;
&lt;p&gt;The optional &lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;HitKeep MCP server&lt;/a&gt; also reads the imported Search Console rows for approved assistants and internal reporting tools. Two read-only tools cover the workflow: &lt;code&gt;hitkeep_get_search_console_status&lt;/code&gt; reports mapping state, property URI, safe permission level, sync state, imported date range, and attention reason; &lt;code&gt;hitkeep_get_search_console&lt;/code&gt; returns imported overview and daily series by default, with query, page, country, and device sections only when requested.&lt;/p&gt;
&lt;p&gt;MCP does not call Google live, refresh OAuth credentials, or trigger Search Console syncs. If the last sync failed or needs attention, MCP can still return older imported rows with warnings such as &lt;code&gt;search_console_sync_failed&lt;/code&gt;, &lt;code&gt;search_console_sync_needs_attention&lt;/code&gt;, or requested-range warnings. Healthy reports return an empty &lt;code&gt;warnings&lt;/code&gt; array.&lt;/p&gt;
&lt;h2 id=&quot;server-side-tracking&quot;&gt;Server-Side Tracking&lt;/h2&gt;
&lt;p&gt;2.4.0 makes server-side tracking a first-class ingest path for log replay, edge workers, backend services, and no-JavaScript collection. The API-client-only endpoints accept one pageview or custom event at a time:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;POST /api/ingest/server/pageview&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;POST /api/ingest/server/event&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The submitted URL resolves the HitKeep site by hostname. The API client still needs &lt;code&gt;site.manage_data&lt;/code&gt; for that site, so a token scoped to one site cannot write records for another domain.&lt;/p&gt;
&lt;p&gt;Each record can carry the original RFC3339 timestamp from the log source. HitKeep stores that timestamp as the analytics time, which means replayed records land in the correct daily and monthly buckets instead of using the time the import worker happened to send the request.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;visitor_ip&lt;/code&gt; field is trusted transient context. HitKeep uses it for IP exclusions, spam filtering, and country, region, city, provider, and ASN lookup. It stores the derived analytics fields and does not store the raw visitor IP.&lt;/p&gt;
&lt;p&gt;These endpoints are meant for server-to-server clients. They do not require browser &lt;code&gt;Origin&lt;/code&gt; or &lt;code&gt;Referer&lt;/code&gt; headers, and they use the ingest rate limiter instead of the normal dashboard API limiter because log forwarders and edge workers often send bursts from one IP. In clustered deployments, follower nodes forward these requests to the leader before authentication and persistence.&lt;/p&gt;
&lt;p&gt;2.4.0 does not add a public batch request format. The HTTP contract stays one record per request for now, while the existing NSQ and DuckDB write path batches persistence internally.&lt;/p&gt;
&lt;h2 id=&quot;imports-page&quot;&gt;Imports Page&lt;/h2&gt;
&lt;p&gt;The Imports page lives with the selected site’s analytics workflow. It is available to users with &lt;code&gt;site.manage_data&lt;/code&gt;, which includes site owners, site admins, effective team owners and admins, instance owners, and instance admins.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/imports-plausible-provider.CHx4-v6B_ZGzwmm.webp&quot; alt=&quot;HitKeep Imports page showing the first step where a site-scoped importer can be selected&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1440&quot; height=&quot;1024&quot;&gt;&lt;figcaption&gt;The import flow starts by choosing the site-scoped importer.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;After choosing Plausible, HitKeep accepts the normal Plausible export ZIP directly. If a team already unpacked the archive, the same flow accepts loose CSV files whose headers match supported Plausible export schemas. Partial imports are allowed when at least one recognized dataset validates.&lt;/p&gt;
&lt;p&gt;After choosing Simple Analytics, HitKeep expects a CSV with the &lt;strong&gt;All&lt;/strong&gt; datapoints header from the Simple Analytics export page. Use the All export rather than a single report export so HitKeep can validate the pageview rows, dates, paths, referrers, devices, countries, and UTM source data together. HitKeep uses the selected site domain, not the filename, to suppress self-referrers from imported source reports.&lt;/p&gt;
&lt;h2 id=&quot;validation-before-commit&quot;&gt;Validation Before Commit&lt;/h2&gt;
&lt;p&gt;Validation is mandatory. It does not write final analytics rows. It stages the files, scans each CSV row, checks headers and values, computes the date range, records skipped rows, and produces a compact manifest for review.&lt;/p&gt;
&lt;p&gt;The Plausible manifest shows accepted files, ignored files, missing optional files, dataset counts, rows accepted and skipped, estimated pageviews and events, event names, property keys, and warnings when Plausible aggregates cannot prove a relationship.&lt;/p&gt;
&lt;p&gt;The Simple Analytics manifest shows the accepted datapoints CSV, the imported date range, accepted and skipped rows, estimated traffic metrics, and unsupported datapoint types. That review step is important because Simple Analytics exports do not contain every native HitKeep dimension.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/imports-plausible-zip-review._1zRaegh_k88Cr.webp&quot; alt=&quot;HitKeep Plausible validation manifest with accepted rows, datasets, event coverage, and warnings&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1440&quot; height=&quot;1024&quot;&gt;&lt;figcaption&gt;The validation manifest gives site admins a concrete review step before the import starts.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;compatible-historical-reports&quot;&gt;Compatible Historical Reports&lt;/h2&gt;
&lt;p&gt;After confirmation, HitKeep imports the rows in small transactions and tags them with the import id, provider, source file, date, dimension or event key, and metrics. The UI updates import history as the job moves through validation, running, completed, failed, and deleted states.&lt;/p&gt;
&lt;p&gt;Imported Plausible traffic is daily-grain aggregate data. It is included where the query can use it safely:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;visitors, visits, pageviews, bounces, visit duration, pages per session&lt;/li&gt;
&lt;li&gt;pages, entry pages, exit pages, sources, devices, browsers, operating systems, and countries&lt;/li&gt;
&lt;li&gt;daily and monthly chart buckets&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Imported Simple Analytics traffic is built from the All datapoints CSV. It is included in compatible historical reports for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;visitors, visits, pageviews, and visit duration totals&lt;/li&gt;
&lt;li&gt;pages, sources, devices, countries, browser names, language codes, and UTM source when those fields exist in the CSV&lt;/li&gt;
&lt;li&gt;daily and monthly chart buckets&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Imported rows are excluded from realtime and hourly views because the migration exports do not contain native HitKeep event streams. If a filter requires raw session relationships the source export cannot prove, HitKeep returns native data and an &lt;code&gt;imported_excluded&lt;/code&gt; reason instead of fabricating precision.&lt;/p&gt;
&lt;p&gt;Validation also checks for native HitKeep data already present in the imported date range. The default policy is &lt;code&gt;skip_native_day&lt;/code&gt;: overlapping traffic days and matching event/day pairs are reported in the manifest and skipped during import so historical rows do not double count data HitKeep has already tracked.&lt;/p&gt;
&lt;h2 id=&quot;events-and-source-limits&quot;&gt;Events And Source Limits&lt;/h2&gt;
&lt;p&gt;Plausible custom events are imported into compatible Events reports. Event names, event totals, event visitors, and property breakdowns are available when the CSV data proves the relationship. Plausible system events that match HitKeep automatic events, such as &lt;code&gt;Outbound Link: Click&lt;/code&gt;, are normalized to HitKeep names like &lt;code&gt;outbound_click&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Simple Analytics imports focus on pageview history. HitKeep imports browser and language breakdowns when the datapoints CSV includes &lt;code&gt;browser_name&lt;/code&gt; and &lt;code&gt;lang_language&lt;/code&gt;, but it does not invent bounce counts, native HitKeep events, goals, funnels, ecommerce activity, or conversion relationships from the export. Unsupported datapoint types are reported during validation so the site admin sees the coverage before importing.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/imports-plausible-events-report.mS4gOKqh_Z2MwQQ.webp&quot; alt=&quot;HitKeep Events dashboard showing imported Plausible outbound link events with a URL property breakdown&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1440&quot; height=&quot;1024&quot;&gt;&lt;figcaption&gt;Imported Plausible events appear in the Events dashboard, including URL property breakdowns where the export supports them.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;For Plausible property files that do not include an event name, HitKeep imports the property aggregate as unattributed coverage and shows a warning in the validation manifest. Those rows no longer inflate queryable event totals. The review step separates queryable custom events from preserved custom property aggregates, and the Events dashboard explains that Plausible exports do not contain event-level source, browser, device, country, or language relationships.&lt;/p&gt;
&lt;p&gt;Event goals with matching imported Plausible custom events include imported visitors as historical conversions where aggregate math is safe. Filtered, comparison, hourly, and audience-dimension views continue to show explicit imported-data limitation reasons instead of synthesizing relationships the export cannot prove.&lt;/p&gt;
&lt;h2 id=&quot;cli-and-api&quot;&gt;CLI And API&lt;/h2&gt;
&lt;p&gt;The dashboard uses the same resumable upload protocol as the CLI and REST API. That matters for large exports and repeatable operations, especially self-hosted instances with long-lived historical data. Imports now run through a restart-recoverable in-process runner: queued or interrupted jobs with staged files are picked back up on startup, while jobs whose staged files are missing fail with a clear error.&lt;/p&gt;
&lt;p&gt;The CLI reuses &lt;code&gt;HITKEEP_PUBLIC_URL&lt;/code&gt; when it is already set, and otherwise talks to &lt;code&gt;http://localhost:8080&lt;/code&gt;. Use &lt;code&gt;--url&lt;/code&gt; only when importing into a remote instance from another machine.&lt;/p&gt;
&lt;p&gt;For Plausible, validate and import the export ZIP:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;export&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;HITKEEP_API_TOKEN&lt;/span&gt;&lt;span style=&quot;--0:#C792EA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;hk_api_...&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;validate&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;plausible&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--file&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;plausible-export.zip&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;plausible&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--file&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;plausible-export.zip&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--wait&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;Loose Plausible CSV files and export directories work from the CLI too:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;validate&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;plausible&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--file&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;imported_visitors.csv&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--file&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;imported_custom_events.csv&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;plausible&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--dir&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;./plausible-export&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--yes&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--wait&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;For Simple Analytics, validate and import the All datapoints CSV:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;validate&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;simpleanalytics&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--file&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;simple-analytics-export.csv&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;
&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;simpleanalytics&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--file&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;simple-analytics-export.csv&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--wait&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;The lifecycle commands are:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;start&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--import-id&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;import-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--wait&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;status&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--import-id&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;import-id&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;list&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;import&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;delete&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--site&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;site-id&gt;&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;--import-id&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;&amp;#x3C;import-id&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;The REST API exposes the same flow: list importers, create upload, upload file chunks, validate, start, fetch status, list history, and delete. See the &lt;a href=&quot;https://hitkeep.com/api/#tag/imports&quot;&gt;Imports API reference&lt;/a&gt; for the endpoint list.&lt;/p&gt;
&lt;h2 id=&quot;built-for-large-sources&quot;&gt;Built For Large Sources&lt;/h2&gt;
&lt;p&gt;The Plausible and Simple Analytics importers stream work row by row. They do not call &lt;code&gt;ParseMultipartForm&lt;/code&gt;, do not hold full CSV files in memory, and do not build an in-memory manifest of every row. Plausible ZIP files are staged on disk, recognized entries are scanned sequentially, and loose CSV files are scanned sequentially.&lt;/p&gt;
&lt;p&gt;The default staged import limit is 100 GiB and can be changed with &lt;code&gt;HITKEEP_IMPORT_MAX_STAGE_BYTES&lt;/code&gt;. Import upload requests use the normal API rate limiter, so operators only have one authenticated API budget to tune.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read More&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/vs/plausible/&quot;&gt;Plausible comparison&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/vs/simple-analytics/&quot;&gt;Simple Analytics comparison&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/google-search-console/&quot;&gt;Google Search Console integration guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;Official MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/import-plausible/&quot;&gt;Plausible import guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/data/import-simple-analytics/&quot;&gt;Simple Analytics import guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/server-side-tracking/&quot;&gt;Server-side tracking and historical replay&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/events/&quot;&gt;Event Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/#imports-apisitesimports/&quot;&gt;Configuration Reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/api/#tag/imports&quot;&gt;Imports API reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/releases&quot;&gt;GitHub Releases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/releases/tag/v2.4.0&quot;&gt;GitHub Release v2.4.0&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.3.1: Clearer System Status For Backups, Workers, And Rejected Traffic</title><link>https://hitkeep.com/blog/hitkeep-2-3-1/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-3-1/</guid><description>HitKeep 2.3.1 improves System Status visibility for backup worker runs, degraded worker health, spam and rejected traffic counters, and managed cloud status links.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.3.1 tightens the operational visibility added in 2.3.0. It is a small patch release for instance owners and cloud operators who rely on System Status to answer a simple question: is the instance healthy right now?&lt;/p&gt;
&lt;p&gt;The release does not add a new analytics surface. It makes existing status data clearer for backups, worker connectivity, spam filtering, rejected ingest requests, and managed cloud operations.&lt;/p&gt;
&lt;h2 id=&quot;what-changed&quot;&gt;What changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Backup worker status:&lt;/strong&gt; System Status now reports backup success, failures, recent failure count, last error, and next run time from the live backup worker.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Worker health:&lt;/strong&gt; leader instances now surface degraded NSQ worker connectivity instead of looking healthy when the producer is unavailable or failing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Spam and rejection counters:&lt;/strong&gt; dropped spam hits, dropped spam events, rejected pageview ingest requests, rejected event ingest requests, and rejected AI fetch requests now increment system counters.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Managed cloud status link:&lt;/strong&gt; managed cloud admin settings now link directly to &lt;a href=&quot;https://status.hitkeep.com/&quot;&gt;status.hitkeep.com&lt;/a&gt; for hosted incident status.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Maintenance refreshes:&lt;/strong&gt; the release also includes Go dependency updates and refreshed dashboard screenshots.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/admin-system-status.C40SWcBN_ZkQaFi.webp&quot; alt=&quot;HitKeep System Status page showing health, runtime, enabled features, storage, tenant databases, and refreshable status cards&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;HitKeep 2.3.1 makes the System Status data behind this view more complete for operational checks.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;upgrade-guidance&quot;&gt;Upgrade guidance&lt;/h2&gt;
&lt;p&gt;All 2.3.0 operators should upgrade to 2.3.1. The update is especially useful for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;managed cloud deployments&lt;/li&gt;
&lt;li&gt;instances using automatic S3 or filesystem backups&lt;/li&gt;
&lt;li&gt;high-traffic self-hosted instances where rejected or spam traffic should be visible&lt;/li&gt;
&lt;li&gt;clustered deployments where worker health needs to be explicit&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Use the normal release artifacts from GitHub. There are no extra migration steps for this patch.&lt;/p&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/system-administration/&quot;&gt;System Status and Settings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/spam-filtering/&quot;&gt;Bot and Spam Filtering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/blog/hitkeep-2-3-0/&quot;&gt;HitKeep 2.3.0 release post&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/changelog/&quot;&gt;Changelog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/releases/tag/v2.3.1&quot;&gt;GitHub Release v2.3.1&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item><item><title>HitKeep 2.3.0: MCP, WordPress, More Events, Installation &amp; Activation Center</title><link>https://hitkeep.com/blog/hitkeep-2-3-0/</link><guid isPermaLink="true">https://hitkeep.com/blog/hitkeep-2-3-0/</guid><description>HitKeep 2.3.0 adds the Installation &amp; Activation Center, MCP analytics access, WordPress tracking, automatic events, System Status operations, and session expiry warnings.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;HitKeep 2.3.0 is built around the Installation &amp;#x26; Activation Center: HitKeep now tells you whether tracking is actually live, guides new users to their first value, and lets instance owners see which teams and sites are active.&lt;/p&gt;
&lt;p&gt;The activation work ships with the rest of the 2.3.0 release: read-only MCP analytics access, a first-party WordPress plugin, automatic outbound click, file download, and form submit events, a dedicated System Status area for operations and audit visibility, and a warning before dashboard sessions expire. The release keeps to HitKeep’s existing shape: one tracker, one event pipeline, one permission model, and the same single-binary runtime for cloud and self-hosted deployments.&lt;/p&gt;
&lt;h2 id=&quot;what-shipped&quot;&gt;What shipped&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Live Tracking Verifier:&lt;/strong&gt; Site Settings now shows whether tracking is waiting, live, dormant, or receiving traffic from a mismatched hostname.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud onboarding checklist:&lt;/strong&gt; the dashboard computes setup progress from real product state instead of asking users to tick fake boxes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Instance owner Activation view:&lt;/strong&gt; System Status now shows which teams and sites are live, waiting, dormant, or missing recent automatic events.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tracker metadata hooks:&lt;/strong&gt; &lt;code&gt;hk.js&lt;/code&gt; reports itself as the source by default, with snippet attributes for WordPress and future SDK versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Read-only MCP analytics access:&lt;/strong&gt; approved assistants and internal tools can query scoped aggregate analytics without dashboard cookies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;First-party WordPress plugin:&lt;/strong&gt; WordPress sites can install the normal HitKeep tracker without editing theme templates or adding a tag manager.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automatic tracker events:&lt;/strong&gt; &lt;code&gt;hk.js&lt;/code&gt; records outbound clicks, file downloads, and form submissions through the existing event pipeline.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;System Status operations:&lt;/strong&gt; instance owners and admins get health, storage, tenant footprint, backup, spam filter, mail test, and audit visibility in one area.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Session expiry warning:&lt;/strong&gt; dashboard users get a clear warning and stay-signed-in action before their session expires.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;installation--activation-center&quot;&gt;Installation &amp;#x26; Activation Center&lt;/h2&gt;
&lt;p&gt;The new verifier card lives in Site Settings → Tracking. It shows first and last hit timestamps, last event, detected hostname, last automatic event, tracker source, tracker version, and a refresh action. New installs poll briefly while waiting for the first accepted hit, then flip to live when data arrives.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/feature-site-tracking.CZgMSKQI_3avJR.webp&quot; alt=&quot;HitKeep Site Settings tracking verifier showing live tracking status, first hit, last hit, detected hostname, automatic event, and tracker source&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The Live Tracking Verifier gives site owners a direct answer to the first install question: is tracking actually live?&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The dashboard checklist uses the same operational state. Creating a site, receiving the first hit, seeing automatic events, inviting a teammate, and scheduling reports complete automatically when the underlying product state exists.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/dashboard-overview.C-D6Gj-G_1FmtsR.webp&quot; alt=&quot;HitKeep dashboard onboarding checklist showing completed setup steps and one remaining scheduled report action&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The onboarding checklist is compact and dismissible, so new users know the next useful action without a wizard.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;For operators, System Status now includes an Activation tab. Instance owners can see team, owner email, site domain, activation status, first and last hit, last event, and 24-hour/7-day aggregate counts. The table is intentionally operational: no IPs, user agents, paths, session IDs, raw referrers, or visitor journeys.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/admin-system-activation.BteZuhYQ_BRSlg.webp&quot; alt=&quot;HitKeep System Status Activation tab showing team and site activation statuses with aggregate hit and event counts&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Instance owners can spot live, waiting, and dormant users without opening tenant databases or impersonating users.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;mcp-for-governed-analytics-access&quot;&gt;MCP for governed analytics access&lt;/h2&gt;
&lt;p&gt;HitKeep now includes an optional &lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;MCP server&lt;/a&gt; on the main HTTP server. It is built for teams that want approved assistants or internal tools to answer analytics questions through HitKeep’s permission model.&lt;/p&gt;
&lt;p&gt;It is disabled by default. When enabled, it mounts at &lt;code&gt;/mcp&lt;/code&gt; and accepts existing API client bearer tokens. It does not accept dashboard cookies.&lt;/p&gt;
&lt;p&gt;The v1 MCP surface is intentionally read-only. Assistants and internal reporting tools can list visible sites, fetch aggregate overview metrics, inspect event breakdowns, query ecommerce summaries, read AI visibility analytics, and fetch HitKeep docs as Markdown.&lt;/p&gt;
&lt;p&gt;It does not expose raw hit exports, write tools, billing operations, site creation, or instance administration.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/mcp.DkXmA_bp_T1TEw.webp&quot; alt=&quot;AI assistant showing a HitKeep MCP analytics summary with aggregate page, event, and access-scope details&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1600&quot; height=&quot;1466&quot;&gt;&lt;figcaption&gt;MCP lets approved assistants answer analytics questions from aggregate HitKeep data while staying inside scoped, read-only API client access.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;link rel=&quot;stylesheet&quot; href=&quot;https://hitkeep.com/_astro/ec.v4551.css&quot;&gt;&lt;figure class=&quot;frame is-terminal not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;span class=&quot;title&quot;&gt;&lt;/span&gt;&lt;span class=&quot;sr-only&quot;&gt;Terminal window&lt;/span&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;hitkeep&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;-mcp-enabled&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#F78C6C;--1:#AA0982&quot;&gt;\&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#82AAFF;--1:#3B61B0&quot;&gt;-mcp-path&lt;/span&gt;&lt;span style=&quot;--0:#D6DEEB;--1:#403F53&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#3B61B0&quot;&gt;/mcp&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;This keeps MCP aligned with the same access model as the REST API: scoped API clients, site permissions, API rate limits, and tenant-aware analytics stores. Cloud and self-hosted deployments use the same contract.&lt;/p&gt;
&lt;h2 id=&quot;a-first-party-wordpress-plugin&quot;&gt;A first-party WordPress plugin&lt;/h2&gt;
&lt;p&gt;The new &lt;a href=&quot;https://hitkeep.com/guides/integrations/wordpress/&quot;&gt;WordPress integration&lt;/a&gt; installs the normal HitKeep tracker without editing a theme template or adding a tag manager.&lt;/p&gt;
&lt;p&gt;The plugin stays thin on purpose. WordPress is only the installation point:&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;text&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--0:#d6deeb;--1:#403f53&quot;&gt;WordPress page -&gt; hk.js -&gt; HitKeep /ingest and /ingest/event -&gt; DuckDB&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;It does not create WordPress analytics tables, set analytics cookies, or send traffic to a third-party analytics backend. Site owners choose EU Cloud, US Cloud, or a self-hosted HitKeep URL, and the plugin loads &lt;code&gt;hk.js&lt;/code&gt; from that instance.&lt;/p&gt;
&lt;p&gt;The defaults are conservative. Logged-in WordPress users are not tracked, Do Not Track is respected, and pageviews plus automatic events are enabled for public visitors. Site owners can inspect the generated snippet before saving.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/wordpress-plugin-settings.Ca85dNG3_ZqVQiy.webp&quot; alt=&quot;HitKeep WordPress settings screen with connection mode cards, tracking coverage toggles, redirect tracking, and snippet preview&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1244&quot; height=&quot;2170&quot;&gt;&lt;figcaption&gt;The WordPress settings screen keeps the instance connection, privacy defaults, automatic event controls, optional redirect tracking, and generated snippet preview in one place.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/wordpress-plugin-listing.zzRZbbMB_1oTLwT.webp&quot; alt=&quot;WordPress plugins screen showing HitKeep Analytics installed and active&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1280&quot; height=&quot;964&quot;&gt;&lt;figcaption&gt;The plugin installs through the normal WordPress plugin workflow and can be opened from the standard admin screen.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;automatic-events-from-the-tracker&quot;&gt;Automatic events from the tracker&lt;/h2&gt;
&lt;p&gt;HitKeep’s browser tracker now records three built-in &lt;a href=&quot;https://hitkeep.com/guides/tracking/automatic-events/&quot;&gt;automatic events&lt;/a&gt; with the default snippet:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;outbound_click&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;file_download&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;form_submit&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These events use the existing event pipeline and dashboard. There is no separate schema, second ingestion route, or extra reporting product. The same Events page handles manual product events and automatic tracker events.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/analytics-events.CRjIOP7j_ZfXvWO.webp&quot; alt=&quot;HitKeep Events dashboard showing event totals, timeseries, and event breakdowns&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Automatic events land in the existing Events dashboard, so outbound clicks, downloads, and form submissions can be analyzed next to manual events.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The payloads are deliberately narrow. HitKeep strips query strings and hashes and does not capture link text, form field values, or request bodies.&lt;/p&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;html&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--1:#8844AE&quot;&gt;&lt;span style=&quot;--0:#7FDBCA&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;--0:#CAECE6&quot;&gt;script&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;async&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA;--1:#8844AE&quot;&gt; &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;src&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;https://your-hitkeep.example/hk.js&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--1:#8844AE&quot;&gt;&lt;span style=&quot;--0:#7FDBCA&quot;&gt;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;--0:#CAECE6&quot;&gt;script&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;p&gt;If a site needs a narrower tracking surface, you can disable event classes from the dashboard tracking settings or with snippet attributes:&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/feature-site-tracking.CZgMSKQI_3avJR.webp&quot; alt=&quot;HitKeep site tracking settings showing automatic event toggles for outbound links, downloads, and forms&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;Tracking settings make automatic event coverage explicit and adjustable per site.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;div class=&quot;expressive-code&quot;&gt;&lt;figure class=&quot;frame not-content&quot;&gt;&lt;figcaption class=&quot;header&quot;&gt;&lt;/figcaption&gt;&lt;pre data-language=&quot;html&quot;&gt;&lt;code&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--1:#8844AE&quot;&gt;&lt;span style=&quot;--0:#7FDBCA&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;--0:#CAECE6&quot;&gt;script&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;async&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;src&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;https://your-hitkeep.example/hk.js&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;data-disable-outbound-tracking&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;true&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;data-disable-download-tracking&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;true&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span class=&quot;indent&quot;&gt;  &lt;/span&gt;&lt;span style=&quot;--0:#C5E478;--1:#3B61B0&quot;&gt;data-disable-form-tracking&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA;--1:#8844AE&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;span style=&quot;--0:#ECC48D;--1:#984E4D&quot;&gt;true&lt;/span&gt;&lt;span style=&quot;--0:#D9F5DD;--1:#111111&quot;&gt;&quot;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;ec-line&quot;&gt;&lt;div class=&quot;code&quot;&gt;&lt;span style=&quot;--1:#8844AE&quot;&gt;&lt;span style=&quot;--0:#7FDBCA&quot;&gt;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;--0:#CAECE6&quot;&gt;script&lt;/span&gt;&lt;span style=&quot;--0:#7FDBCA&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class=&quot;copy&quot;&gt;&lt;div aria-live=&quot;polite&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/figure&gt;&lt;/div&gt;
&lt;h2 id=&quot;a-system-status-page-for-real-operators&quot;&gt;A system status page for real operators&lt;/h2&gt;
&lt;p&gt;HitKeep now has a dedicated &lt;a href=&quot;https://hitkeep.com/guides/admin/system-administration/&quot;&gt;System Status and Settings&lt;/a&gt; area for instance owners and admins. System Status is its own sidebar item. System Settings stays focused on users, sites, teams, and global filters.&lt;/p&gt;
&lt;p&gt;System Status shows what the instance is doing: version, health checks, storage paths, tenant database sizes, recent hit volume, enabled features such as MCP and backups, LRU cache pressure, automatic backup state, spam database freshness, mail delivery configuration, and instance audit activity.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/admin-system-status.C40SWcBN_ZkQaFi.webp&quot; alt=&quot;HitKeep System Status page showing health, runtime, enabled features, storage, tenant databases, and refreshable status cards&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;System Status gives operators a direct view of runtime health, storage, tenant database footprint, ingestion volume, and cache state.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The Operations tab separates passive refreshes from real maintenance actions. Refreshing a status card reloads that card. Refreshing the spam database downloads and rebuilds the configured spam lists. Sending a test email uses the configured mail transport and sends an actual message to the specified recipient.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/admin-system-operations.BA2rl5Ap_EjjEc.webp&quot; alt=&quot;HitKeep System Status operations tab showing backup status, spam filter status with manual refresh, and mail transport diagnostics&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The Operations tab makes backups, spam filter freshness, and mail delivery testable without asking operators to inspect logs first.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Sensitive actions are written to the instance audit log with actor, action, target, outcome, IP address, user agent, request ID, and details where available.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/admin-system-audit.DW0n7_sl_rEPLp.webp&quot; alt=&quot;HitKeep instance audit log showing mail test and spam refresh entries with actor, outcome, and details&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The instance audit log records maintenance actions such as spam database refreshes and mail tests.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The result is less guesswork during operations. Admins can check whether automatic backups are configured, whether the spam database is stale, whether the mail transport works, and which maintenance actions were attempted.&lt;/p&gt;
&lt;h2 id=&quot;a-clearer-timeout-warning&quot;&gt;A clearer timeout warning&lt;/h2&gt;
&lt;p&gt;Dashboard sessions now warn users before they expire.&lt;/p&gt;
&lt;p&gt;When the session enters the configured warning window, HitKeep shows the remaining time, the instance session policy, and two clear actions: stay signed in or sign out.&lt;/p&gt;
&lt;p&gt;The goal is to support teams that review dashboard behavior against timed-session accessibility expectations, including WCAG 2.1 Success Criterion 2.2.1 (Timing Adjustable) and EN 301 549, the standard used with the EU Web Accessibility Directive. The warning gives users a simple way to extend the session before timeout while still respecting the instance’s configured session policy.&lt;/p&gt;
&lt;figure class=&quot;hk-guide-screenshot&quot;&gt;&lt;img src=&quot;https://hitkeep.com/_astro/session-expiry-warning.CnXL3Irg_Z2rfOik.webp&quot; alt=&quot;HitKeep dashboard session expiry warning dialog with sign out and stay signed in actions&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2880&quot; height=&quot;2048&quot;&gt;&lt;figcaption&gt;The session expiry dialog gives users a clear choice before the dashboard signs them out.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;read-more&quot;&gt;Read more&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/pricing/&quot;&gt;HitKeep Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/use-cases/&quot;&gt;HitKeep Use Cases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/mcp/&quot;&gt;Official MCP Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/integrations/wordpress/&quot;&gt;WordPress Integration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/tracking/automatic-events/&quot;&gt;Automatic Events&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/analytics/events/&quot;&gt;Event Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/guides/admin/system-administration/&quot;&gt;System Status and Settings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/reference/configuration/#optional-mcp-route/&quot;&gt;Configuration Reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://hitkeep.com/changelog/&quot;&gt;Changelog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/PascaleBeier/hitkeep/releases&quot;&gt;GitHub Releases&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded></item></channel></rss>