# GoatCounter > Open-source, privacy-friendly web analytics, offered as a free donation-supported hosted > service at goatcounter.com and as a self-hostable Go binary. The JSON API — unversioned and > prefixed with /api/v0 — lets you count pageviews from a backend, read dashboard statistics, > export raw data, and manage sites and users. Authentication is a per-site API key sent as an > HTTP bearer token. Rate limit is 4 requests/second. Generated by API Evangelist on 2026-08-13 from the GoatCounter public documentation and the provider-published OpenAPI 2.0 document. GoatCounter does not serve an llms.txt of its own (https://www.goatcounter.com/llms.txt returned 404 on 2026-08-13). ## Critical facts an agent needs before calling this API - The API is served from the account's OWN subdomain, not a shared api host: `https://{code}.goatcounter.com/api/v0`. The marketing hosts do not serve it — `www.goatcounter.com/api/v0/me` returns 404 and `goatcounter.com/api/v0/me` returns 301. Self-hosted instances use their own hostname. - Auth: `Authorization: Bearer `. HTTP Basic also works with an empty username and the key as the password. 401 = key missing or wrong; 403 = key lacks the permission. - `Content-Type: application/json` is required on every request. - Rate limit: 4 requests/second, signalled by `X-Rate-Limit-Limit`, `X-Rate-Limit-Remaining` and `X-Rate-Limit-Reset`. The status code returned on exhaustion is not documented. - Errors are NOT problem+json. A failure returns either `{"error": "string"}` or `{"errors": {"field": ["msg"]}}` — never both. Only 400, 401 and 403 are documented. - There is NO idempotency key. Retrying `POST /api/v0/count` will double-count the batch. - Exports are asynchronous: create, poll until `finished_at` is non-null, then download. ## Specs - [OpenAPI 2.0 (provider-published)](https://www.goatcounter.com/api.json): The document GoatCounter generates from its own source with kommentaar. 13 paths, 16 operations, 27 definitions. - [API reference console](https://www.goatcounter.com/api2.html): RapiDoc rendering of the above. Viewing it at `https://{code}.goatcounter.com/api2.html` enables the "try" feature. ## APIs - [Pageviews](https://www.goatcounter.com/help/api): `POST /api/v0/count` — send a batch of pageviews or events from a backend. Higher rate limits than the browser endpoint, allows extra fields, and accepts `no_sessions`. - [Statistics](https://www.goatcounter.com/help/api): `GET /api/v0/stats/total`, `/stats/hits`, `/stats/hits/{path_id}`, `/stats/{page}`, `/stats/{page}/{id}` — totals, per-path hits, referrals, and browser/system/location/language/size/campaign breakdowns. - [Exports](https://www.goatcounter.com/help/api): `POST /api/v0/export`, `GET /api/v0/export/{id}`, `GET /api/v0/export/{id}/download` — asynchronous CSV/JSON export with a `last_hit_id` cursor for incremental sync. - [Sites](https://www.goatcounter.com/help/api): `GET/PUT /api/v0/sites`, `GET/POST/PATCH /api/v0/sites/{id}` — list, create and update tracked sites. - [Paths](https://www.goatcounter.com/help/api): `GET /api/v0/paths` — every tracked path, paginated with `limit` and `after`. - [Users](https://www.goatcounter.com/help/api): `GET /api/v0/me` — the current user and the permissions on the API key being used. ## Docs - [JSON API guide](https://www.goatcounter.com/help/api): auth, rate limits, errors, and worked shell examples for backend counting and CSV export. - [Getting started](https://www.goatcounter.com/help/start) - [Documentation index](https://www.goatcounter.com/help) - [JavaScript API](https://www.goatcounter.com/help/js): the `window.goatcounter` settings and methods exposed by count.js. - [Tracking pixel](https://www.goatcounter.com/help/pixel): the no-JavaScript `` route and its stable query parameters. - [Visitor counter](https://www.goatcounter.com/help/visitor-counter): the embeddable public count widget. - [count.js versions and SRI](https://www.goatcounter.com/help/countjs-versions) - [Content-Security-Policy](https://www.goatcounter.com/help/csp) - [JSON exports](https://www.goatcounter.com/help/export-json) and [CSV exports](https://www.goatcounter.com/help/export) - [FAQ](https://www.goatcounter.com/help/faq) ## Client-side integration - Script tag: `` — unpinned, floats to latest. - Pinned with SRI: `//gc.zgo.at/count.v5.js` (9 June 2025), integrity `sha384-atnOLvQb9t+jTSipvd75X2yginT4PjVbqDdlJAmxMm+wYElFmeR6EmLP5bYeoRVQ`. ## Source, CLI and packages - [GitHub](https://github.com/arp242/goatcounter): the whole application, EUPL-1.2 (modified); count.js is ISC. - [Go module](https://pkg.go.dev/zgo.at/goatcounter/v2): `zgo.at/goatcounter/v2` v2.7.0 (2025-12-15). This is the server + CLI, not an API client library. - [Docker](https://hub.docker.com/r/arp242/goatcounter): official image `arp242/goatcounter`. - [CHANGELOG](https://github.com/arp242/goatcounter/blob/main/CHANGELOG.md) - CLI commands: `serve`, `import`, `dashboard`, `db`, `monitor`, `version`, `help`. `goatcounter dashboard` is the provider's reference consumer of the stats endpoints. ## What GoatCounter does not publish Recorded so an agent stops looking: no MCP server, no A2A agent card (every `/.well-known/agent-card.json` and `/.well-known/agent.json` probe returned 404), no webhooks or event stream, no AsyncAPI, no GraphQL, no gRPC/protobuf, no OAuth or OIDC (API keys only), no `/.well-known/` documents at all, no paid plans or enterprise tier, no SLA, no deprecation policy, no SOC 2 / ISO 27001 / trust center, and no first-party npm, PyPI, RubyGems or crates package. ## Commercial - [Pricing](https://www.goatcounter.com/#pricing): free for reasonable public usage; funded by donations via [GitHub Sponsors](https://github.com/sponsors/arp242) and NLnet NGI0. Self-host for serious or high-volume use. - [Sign up](https://www.goatcounter.com/signup) — self-serve, no sales gate. - [Terms of use](https://www.goatcounter.com/help/terms) · [Privacy policy](https://www.goatcounter.com/help/privacy) · [GDPR consent notices](https://www.goatcounter.com/help/gdpr) - [Contact](https://www.goatcounter.com/contact) · support@goatcounter.com · [Issues](https://github.com/arp242/goatcounter/issues) - [Service status](https://www.goatcounter.com/status) — JSON: version, uptime, database.