You can also restrict the session to
read-only MCP tools
, limit it to specific MCP tools or feature categories using
MCP tool filtering
, and pin the agent to a specific organization or project to limit blast radius.
Advanced configuration
Using an API key instead of OAuth
If your MCP client doesn't support OAuth, you can authenticate manually:
Create a
personal API key
using the
MCP Server
preset (this scopes access to a specific project)
Add the
Authorization: Bearer YOUR_API_KEY
header to your MCP configuration
Example for Cursor (add to
.cursor/mcp.json
):
JSON
PostHog AI
{
"mcpServers"
:
{
"posthog"
:
{
"url"
:
"https://mcp.posthog.com/mcp"
,
"headers"
:
{
"Authorization"
:
"Bearer phx_your_api_key_here"
}
}
}
}
Pinning to a specific organization or project

We've tested and documented setup for Claude Code, Claude Desktop, Cursor, Codex, VS Code, Windsurf, and Zed. The
PostHog Wizard
can install the server into most of these in one command.
Do I need to create an API key?
No, OAuth is the recommended path and works out of the box with the wizard. If your client doesn't support OAuth, you can use a
personal API key
with the
MCP Server
preset – see the
API key authentication
section below.
Can I use more than one PostHog account, organization, or project at the same time?
Yes, but add one MCP connection for each. A single connection signs in as one account and has one active organization and project. See
working with multiple accounts, organizations, or projects
.
Can my organization manage MCP access centrally through our IdP?
Yes.
