# MCP limits, privacy and errors

> Rate limits and size limits of Mrkr's MCP server, what data an assistant can and cannot see, and how to fix connection, permission and query errors.

Section: AI assistants (MCP). Canonical page: https://mrkr.app/docs/integrations/mcp-troubleshooting. Last updated: 2026-10-05.

What the Mrkr MCP server limits, what it never shares, and what each error means.

## Limits

| Limit | Value |
| --- | --- |
| Requests | 120 per minute per connection. Over the limit returns `429` with `Retry-After` in seconds. |
| Request body | 64 KiB, one JSON-RPC message per POST. Batches are rejected. |
| Tool result | 200,000 bytes. Narrow the period, lower `limit` or add filters. |
| Period | Up to 366 days. |
| Rows | `limit` 1 to 100, `offset` up to 1000. |
| Filters | 20 values per dimension, 70 expanded values in total. |
| Time buckets | 744 per `get_timeseries` call. |
| Sites per connection | 1 to 100. |

## Privacy and data access

An assistant sees only the sites and permissions you approved, and never more than you can see in Mrkr yourself.

### Never available through MCP

- Session replay recordings.
- Billing, invoices, plan details and team membership.
- Stripe credentials, API keys, OAuth secrets, public share tokens and proxy details.
- Deleting sites or collected data, changing team permissions, sharing or proxy setup. The only deletes are saved funnels, chart annotations and campaign links, with `analytics:write`.
- Raw data exports. Tools return bounded aggregates and pages, not a full event dump.
- Sites you did not approve for that connection.

### Shared only with the matching permission

- `visitors:read`: individual visitor IDs, their visits, approximate city and coordinates, time to first purchase, and visitor samples in funnel drop-off.
- `events:read`: event names, property values and up to 20 recent samples per event. These hold whatever your site sends, so keep personal data out of event properties.
- `settings:read`: domain, tracking mode, replay settings and excluded paths.

`analytics:read` alone returns aggregates only: counts, rates, rankings and trends, with no individual visitor IDs. Mrkr records every change made through MCP (tool, site, app, user and the names of changed fields). It never stores access tokens or the values you sent.

## Errors and fixes

Connection errors come back as HTTP status codes with a JSON body `{ "error": "<code>", "message": "..." }`, before any tool runs. Everything else, including permission problems on a single call, comes back as a normal MCP result with `isError: true` and a message that says what to change.

| Status and code | Message (excerpt) | Fix |
| --- | --- | --- |
| 401 `invalid_token` | Connect with OAuth before calling Mrkr tools. | The client sent no token. Finish the sign-in, or remove and re-add the server. |
| 401 `invalid_token` | The OAuth access token has expired or is invalid. | Let the client refresh, or reconnect. |
| 401 `invalid_token` | The OAuth token was not issued for this MCP resource. | The client must request `resource=https://mrkr.app/mcp`. Use the exact URL, no trailing slash. |
| 403 `consent_required` | Reconnect this client and approve site access in Mrkr. | The connection was revoked or never approved. Connect again. |
| 403 `insufficient_scope` | This token has no approved Mrkr permissions. | Reconnect and select at least one permission. |
| 429 `rate_limited` | This connection has reached 120 requests per minute. | Wait for `Retry-After` seconds. Combine questions into fewer calls. |
| 400 or 413 `invalid_request` | Send one JSON-RPC message per request; batches are not supported. / MCP request exceeds 64 KiB. | Send messages one at a time and keep arguments small. |
| 403 `forbidden_origin` | Use the canonical MCP URL and an approved browser origin. | Browser-based clients must be allowlisted. Desktop and server clients are not affected. |
| 405 | Mrkr uses stateless Streamable HTTP. Send MCP requests with POST. | There is no SSE stream. Configure the client for Streamable HTTP, not SSE. |
| 503 `unavailable` | MCP authentication is temporarily unavailable. | Retry in a minute. If it persists, contact hi@mrkr.app. |

### Tool errors

| Message (excerpt) | Fix |
| --- | --- |
| site_id is required. Accessible sites: ... | The connection has several sites. Pass one of the listed IDs or domains. |
| No approved site matches "..." | Use an ID or domain from `list_sites`, or edit the connection to add the site. |
| Site site_... is not approved for this connection. | Same as above. The message lists the sites you can use. |
| This connection needs events:write permission, which was not granted. | Reconnect the client and approve that permission. Editing a connection cannot add one. |
| Your current workspace role does not permit this action. Changes need owner or admin access to the site. | Ask a workspace owner to make the change or to change your role. |
| The demo site is read-only. | Use one of your own sites for changes. |
| Reconnect this client and approve site access in Mrkr. | The connection was revoked. Connect again. |
| The result is too large. Narrow the range, lower the limit or add filters. | Shorten the period, lower `limit` or add `filters`. |
| That is N buckets; the maximum is 744. | Use a larger `interval` or a shorter period. |
| ... only available with interval "day". | Sub-day intervals support `visitors` and `revenue` only. |
| The range spans N days; the maximum is 366. | Split the question into several periods. |
| range "7d" cannot be combined with from/to. | Use a preset, or `from` and `to`, not both. |
| Too many combined filters. | Use fewer filter values. |
| Funnel ... was not found | Use an `id` from `list_funnels`. The message lists them. |
| "..." is an automatic measurement. Only custom event names can be configured. | Configure your own custom events only. |
| Input validation error: Invalid arguments for tool get_breakdown: ... | An argument has the wrong name, type or value. Unknown fields are rejected too. Check the tool's parameter table. |
| Invalid funnel: condition on "plan" needs a value. | Fix the step or exclusion the message names. |
| Mrkr could not complete this request. Retry, or narrow the range or filters. | A temporary failure. Retry once, then narrow the query. |

## Common questions

**The assistant says it has no Mrkr tools.**

Sign-in did not finish, or the connection was revoked. Reconnect from the client. In Claude Code, run `/mcp` and authenticate.

**Some tools are missing.**

Assistants only see tools their permissions allow. `list_visitors` needs `visitors:read`, for example. `list_sites` shows the connection's `permissions`. See the [scope table](https://mrkr.app/docs/integrations/mcp#permissions-scopes).

**Numbers differ from the dashboard.**

Check the time zone, the dates, the filters and the currency. MCP uses the `timezone` you pass, default UTC; pass the same zone your dashboard uses.

**My site is missing from list_sites.**

It was not selected for this connection, or you lost access in Mrkr. Edit the connection in [AI connections](https://mrkr.app/dashboard/settings?tab=mcp) to add it.

**Can I connect the public demo?**

No. MCP only reaches sites in workspaces you belong to.

**Does using MCP count toward my plan?**

No. Only tracked pageviews count. See [what counts](https://mrkr.app/docs/billing/what-counts-as-an-event).
