> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# PostHog Integration: Product Analytics for Agents

> Agents can query events, read insights and dashboards, and manage feature flags in PostHog. Connect with a personal API key, US or EU Cloud.

## Overview

OneCLI connects AI agents to PostHog with a personal API key. Agents can run HogQL queries, read insights, dashboards, experiments, and session recordings, and create or update feature flags. The gateway injects the key into requests to `us.posthog.com` or `eu.posthog.com`, so your agent never sees it. Both US and EU Cloud are supported.

## Setup

<Steps>
  <Step title="Create a personal API key">
    In PostHog, go to **Settings** > **User** > **Personal API keys** and create a key. Grant only the scopes your agents need, and include **User: read** so OneCLI can show which account is connected. Keys start with `phx_`. See [Personal API keys](https://posthog.com/docs/api/personal-api-keys).
  </Step>

  <Step title="Connect in OneCLI">
    Open **Connections** > **PostHog** and paste your key. OneCLI detects whether it belongs to US or EU Cloud. Under **Advanced** you can add an optional connection label to tell multiple PostHog accounts apart.
  </Step>
</Steps>

<Warning>
  Project API keys (`phc_`) only send events and cannot read data. Use a personal API key.
</Warning>

## What agents can do

| Area | Description |
| - | - |
| **Queries** | Run HogQL, trends, and funnel queries over events |
| **Insights and dashboards** | Read, create, and update insights and dashboards |
| **Feature flags** | View flags and change rollout or conditions |
| **Experiments and surveys** | View experiments, results, and surveys |
| **Persons and cohorts** | Look up persons and cohorts |
| **Session recordings** | List and view session replays |
| **Annotations** | View and add annotations |
| **Error tracking** | View error tracking issues |

What a connection can actually reach follows the API key: scopes you left out when creating the key return permission errors, regardless of what OneCLI allows.

## Quick example

Replace `12345` with your project ID (shown in PostHog under **Settings** > **Project**). No auth header is needed, the gateway adds it:

```bash theme={null}
# Count yesterday's pageviews with HogQL
curl -s -X POST "https://us.posthog.com/api/projects/12345/query/" \
  -H "Content-Type: application/json" \
  -d '{"query": {"kind": "HogQLQuery", "query": "select count() from events where event = '\''$pageview'\'' and timestamp > now() - interval 1 day"}}'

# List feature flags
curl -s "https://us.posthog.com/api/projects/12345/feature_flags/"
```

On EU Cloud, use `eu.posthog.com` instead.

## Disconnecting

* In OneCLI, open **Connections** > **PostHog** and remove the connection.
* Then delete the key in PostHog under **Settings** > **User** > **Personal API keys**.

## Controlling access

Access is per agent: [grant](/docs/guides/agent-access) the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked. For example, let an agent run queries but require approval before it changes a feature flag. Organization [rules](/docs/guides/rules) add guardrails on top, like rate limits. Everything is checked before credential injection, so a blocked request never reaches PostHog.
