Skip to main content

Overview

OneCLI connects AI agents to PostHog with a personal API key. Agents can run HogQL queries, read insights, dashboards, experiments, and session recordings, and create or update feature flags. The gateway injects the key into requests to us.posthog.com or eu.posthog.com, so your agent never sees it. Both US and EU Cloud are supported.

Setup

1

Create a personal API key

In PostHog, go to Settings > User > Personal API keys and create a key. Grant only the scopes your agents need, and include User: read so OneCLI can show which account is connected. Keys start with phx_. See Personal API keys.
2

Connect in OneCLI

Open Connections > PostHog and paste your key. OneCLI detects whether it belongs to US or EU Cloud. Under Advanced you can add an optional connection label to tell multiple PostHog accounts apart.
Project API keys (phc_) only send events and cannot read data. Use a personal API key.

What agents can do

What a connection can actually reach follows the API key: scopes you left out when creating the key return permission errors, regardless of what OneCLI allows.

Quick example

Replace 12345 with your project ID (shown in PostHog under Settings > Project). No auth header is needed, the gateway adds it:
On EU Cloud, use eu.posthog.com instead.

Disconnecting

  • In OneCLI, open Connections > PostHog and remove the connection.
  • Then delete the key in PostHog under Settings > User > Personal API keys.

Controlling access

Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked. For example, let an agent run queries but require approval before it changes a feature flag. Organization rules add guardrails on top, like rate limits. Everything is checked before credential injection, so a blocked request never reaches PostHog.