Sign inSign up

pascalebeier/hitkeep

By pascalebeier

•Updated about 4 hours ago

HitKeep is privacy-first analytics for humans and AI agents, self-hosted or in managed cloud.

Image
Web servers
Monitoring & observability
Web analytics
0

10K+

pascalebeier/hitkeep repository overview

⁠HitKeep

AI-native, sovereign, privacy-first web analytics in one binary.

HitKeep is a 100% open-source web analytics platform licensed under MIT. Analyze traffic, conversions, ecommerce, Search Console, Web Vitals, AI crawlers, AI referrals, and chatbot outcomes—without operating a separate database, queue, or cache.

Website⁠ · Documentation⁠ · Source code⁠ · Managed cloud⁠

Latest release MIT license OpenSSF Best Practices

HitKeep dashboard showing traffic, conversion reports, setup progress, and analytics navigation

⁠Why HitKeep

  • 100% open source: Custom tracking domains, team SSO, exports, APIs, webhooks, permissions, and AI analytics are part of the public MIT-licensed product.
  • Full data sovereignty: Keep analytics on your infrastructure and export your data in open formats whenever you need it.
  • AI-native analytics: Measure AI crawler activity, AI-referred visitors, and chatbot outcomes as separate signals. Ask AI answers questions using cited aggregate evidence.
  • Privacy by default: Cookieless tracking, Do Not Track support, and no cross-site visitor identity.
  • One small stack: The Go application embeds its Angular dashboard, DuckDB storage, and NSQ queue.

The image runs as a non-root user, includes a built-in health check, and supports linux/amd64 and linux/arm64.

⁠Quick Start

Create a long random secret in your password manager, replace the placeholder below, and start HitKeep:

docker run -d \
  --name hitkeep \
  --restart unless-stopped \
  -p 8080:8080 \
  -v hitkeep_data:/var/lib/hitkeep/data \
  -e HITKEEP_PUBLIC_URL=http://localhost:8080 \
  -e HITKEEP_JWT_SECRET='replace-with-a-long-random-secret' \
  pascalebeier/hitkeep:latest

Open http://localhost:8080⁠ and create the first account.

Keep HITKEEP_JWT_SECRET private and unchanged across restarts. The named Docker volume preserves the DuckDB database, archives, and backups when the container is replaced.

For a production deployment with HTTPS, reverse-proxy configuration, and separate data volumes, use the maintained Docker Compose guide⁠.

⁠Configuration

VariablePurpose
HITKEEP_PUBLIC_URLExact browser-visible URL of the instance, including any path prefix
HITKEEP_JWT_SECRETStable private secret used to sign authentication sessions
HITKEEP_TRUSTED_PROXIESTrusted reverse-proxy network CIDRs
HITKEEP_DB_PATHDuckDB database location
HITKEEP_DATA_PATHPersistent application data directory
HITKEEP_ARCHIVE_PATHRetention archive directory
HITKEEP_BACKUP_PATHAutomatic backup directory

See the configuration reference⁠ for email, social sign-in, Search Console, custom tracking domains, AI providers, MCP, backups, and other settings.

Health endpoints are available at:

  • /healthz for process health
  • /readyz for readiness

⁠Image Tags

  • latest — latest stable release
  • X.Y.Z — exact release; recommended for repeatable production deployments
  • X.Y — latest patch release in a minor series
  • X — latest release in a major series
  • snapshot or main — current development build; not recommended for production

Browse all available tags on Docker Hub⁠ and review GitHub Releases⁠ before upgrading.

Back up persistent data before an upgrade. See Backups and Restore⁠ for the supported workflow.

⁠Track Your First Site

Create a site in HitKeep, then add the tracker to your website:

<script async src="https://analytics.example.com/hk.js"></script>

Replace analytics.example.com with your HitKeep domain. Pageviews, outbound clicks, downloads, and form submissions begin flowing automatically.

Use custom events⁠ for actions such as signups, purchases, and qualified leads.

⁠Documentation and Support

Want to support independent open-source analytics? Fund HitKeep on GitHub Sponsors⁠ or make a one-time contribution⁠.

⁠License

HitKeep is distributed under the MIT License⁠.

Tag summary

Content type

Image

Digest

sha256:32eddbc0d…

Size

85.9 MB

Last updated

about 4 hours ago

docker pull pascalebeier/hitkeep:sha-9b5ad6a