# Kotzilla > Kotzilla is a French (Toulouse) developer-observability vendor for Android and Kotlin Multiplatform applications, founded by the creators of Koin — the open-source Kotlin dependency-injection framework it still maintains. The Kotzilla Platform uses Koin's containerization to map runtime telemetry onto application architecture, detecting slow startups, ANRs, crashes and slow rendering, then tracing them to the dependency graph that caused them. Kotzilla publishes no REST or GraphQL API; its only machine-readable, agent-callable surface is a hosted remote MCP server. Generated by API Evangelist on 2026-08-17 from Kotzilla's public surface. Kotzilla does not serve an llms.txt of its own (https://doc.kotzilla.io/llms.txt returns the Docusaurus HTML shell, and https://kotzilla.io/llms.txt returns 404), so this file was generated from the catalog profile rather than harvested. ## Agent surface - [Kotzilla MCP Server](https://mcp.kotzilla.io/mcp): Remote MCP endpoint, the only callable API Kotzilla publishes. 15 tools. OAuth 2.0 authorization-code + PKCE S256, dynamic client registration, refresh tokens. `tools/list` is auth-gated (401 invalid_token when anonymous). - [MCP server documentation](https://doc.kotzilla.io/docs/discover/mcpServer): What the MCP server is and the full tool list. - [MCP setup guide](https://doc.kotzilla.io/docs/getstartedCustom/mcpSetup): Client configuration for Claude Code, Cursor, Windsurf and Android Studio. - [OAuth authorization server metadata](https://mcp.kotzilla.io/.well-known/oauth-authorization-server): RFC 8414 discovery document. - [OAuth protected resource metadata](https://mcp.kotzilla.io/.well-known/oauth-protected-resource): RFC 9728 discovery document. ### MCP tools Apps: `list_apps`, `create_app` Onboarding: `guide_sdk_installation`, `generate_app_config` Telemetry: `get_platform_activity`, `get_screen_performance` Issues: `get_issues`, `get_issue_context`, `get_fix_guidance` Reporting: `generate_report` Versions: `list_app_versions`, `set_app_versions_enabled` Koin: `koin_diagnose`, `koin_search_graph`, `koin_apply_fix` Three tools mutate state: `create_app`, `set_app_versions_enabled`, `koin_apply_fix`. `koin_apply_fix` writes to the developer's source. Kotzilla documents no idempotency key, so a retried call has no published dedupe guarantee. All three are covered by the same account-level token — the OAuth scopes (`openid`, `email`, `offline_access`) are identity-only, so there is no read-only token an agent operator can issue. ## Specs - No OpenAPI. Probed `/openapi.json`, `/openapi.yaml`, `/swagger.json`, `/v1/openapi.json`, `/v3/api-docs`, `/api-docs`, `/redoc` on kotzilla.io, doc.kotzilla.io, console.kotzilla.io and mcp.kotzilla.io. The docs and console hosts return HTML app shells for every path; api.kotzilla.io does not resolve. - No GraphQL. `POST /graphql` on console.kotzilla.io returns nginx 405. - No AsyncAPI and no webhooks. Telemetry flows one way into the platform; there is no outbound customer event surface. - No A2A agent card. `/.well-known/agent-card.json` and `/.well-known/agent.json` return 404 on the hosts that answer honestly. ## SDKs and packages - [io.kotzilla:kotzilla-sdk](https://central.sonatype.com/artifact/io.kotzilla/kotzilla-sdk): Kotlin Multiplatform observability SDK. 2.3.3 (2026-08-03). - [io.kotzilla:kotzilla-core](https://central.sonatype.com/artifact/io.kotzilla/kotzilla-core): Startup-track markers. 2.3.3 (2026-08-03). - [Kotzilla Gradle plugin](https://plugins.gradle.org/plugin/io.kotzilla.kotzilla-plugin): `id("io.kotzilla.kotzilla-plugin") version "2.3.3"`. - [io.kotzilla:kotzilla-sdk-ktor3](https://central.sonatype.com/artifact/io.kotzilla/kotzilla-sdk-ktor3): Ktor 3 integration, pinned at 1.3.1 (2025-11-10) — nine months and a major version behind the core SDK. - [io.insert-koin:koin-core](https://central.sonatype.com/artifact/io.insert-koin/koin-core): Koin, the open-source Kotlin DI framework Kotzilla created and maintains. 4.2.2 (2026-06-15), Apache-2.0. - [io.insert-koin:koin-bom](https://central.sonatype.com/artifact/io.insert-koin/koin-bom): Bill of materials for the Koin family. 4.2.2. - [Koin Dependency Injection (Official) IDE plugin](https://plugins.jetbrains.com/plugin/26131): JetBrains Marketplace, vendor Kotzilla. 1.6.0 (2026-08-03). No npm, PyPI, NuGet, RubyGems, crates.io or Go packages. The `npx -y mcp-remote` line in Kotzilla's setup docs installs the third-party mcp-remote bridge, not a Kotzilla package. ## SDK API Kotzilla's "SDK features & API" documentation describes a Kotlin in-process API, not an HTTP API: `KotzillaSDK.log(message)`, `KotzillaSDK.logError(message, error)`, `KotzillaSDK.trace(name) {}`, `KotzillaSDK.suspendTrace(name) {}`, `KotzillaSDK.setProperties(vararg)`, `KotzillaSDK.setUserId(userId)`, `KotzillaSDK.setVersionCode(...)`, `KotzillaCoreSDK.mark(label, track)`, `KotzillaStartup.mark(...)`, plus the consent surface `setConsent(...)`, `getConsent()`, `forgetMe()`. ## Docs - [Documentation](https://doc.kotzilla.io/): Docusaurus documentation root. - [Platform overview](https://doc.kotzilla.io/docs/discover/overview/): The four components — Koin IDE Plugin, Kotzilla SDK, Kotzilla Console, Kotzilla MCP Server. - [Get started with the demo app](https://doc.kotzilla.io/docs/getstartedNIA/setup): Evaluate with the NowInAndroid sample before instrumenting your own app. - [Get started with your app](https://doc.kotzilla.io/docs/getstartedCustom/overview): Android, Compose, KMP, CMP and no-Koin setup paths. - [SDK features & API](https://doc.kotzilla.io/docs/settings/apiUse): The Kotlin SDK API surface. - [Privacy and consent](https://doc.kotzilla.io/docs/settings/privacyConsent): Consent gates, `forgetMe()`, GDPR posture. - [SDK data collection](https://doc.kotzilla.io/docs/discover/sdkData): What the SDK collects and what it explicitly does not. - [SDK changelog](https://doc.kotzilla.io/docs/releaseNotes/changelogSDK): Dated release notes, roughly fortnightly. - [Version upgrades](https://doc.kotzilla.io/docs/releaseNotes/versionUpgrades): Semver policy, breaking changes, gradual deprecation. - [License](https://doc.kotzilla.io/docs/discover/license): Kotzilla Platform License 1.0 EULA (proprietary — distinct from Koin's Apache-2.0). - [FAQ](https://doc.kotzilla.io/docs/discover/faq) - [Maven repository setup](https://doc.kotzilla.io/docs/settings/repository) ## Product and commercial - [Website](https://kotzilla.io/) - [Console](https://console.kotzilla.io/) and [sign up](https://console.kotzilla.io/signup) - [Sandbox](https://console.kotzilla.io/sandbox-home) - [Pricing](https://kotzilla.io/pricing): Starter free (500k events, ~250 sessions, 1 user, 15 days retention, USA region). Enterprise is custom-priced — no public number, and EU data residency is Enterprise-only. - [Koin LTS](https://kotzilla.io/koin-lts): Paid long-term support for Koin 3.5 on Kotlin 1.x, committed "until at least June 2026". - [Blog](https://blog.kotzilla.io/) ([RSS](https://blog.kotzilla.io/rss.xml)) - [Terms and conditions](https://kotzilla.io/terms-and-conditions) - [Privacy policy](https://kotzilla.io/privacy-policy) - [Contact](https://kotzilla.io/contact-us) - [Support: Slack community](https://join.slack.com/t/cloud-inject/shared_invite/zt-28grcrqc7-zHPUy9XCVZ1mNwE_afUZYw) - [About](https://kotzilla.io/about-us) ## Source code - [Kotzilla GitHub organization](https://github.com/kotzilla-io): Samples, workshops and instrumented forks (Apache-2.0). The Kotzilla SDK itself is not open source. - [Koin GitHub organization](https://github.com/InsertKoinIO): Koin, Apache-2.0, maintained by Kotzilla. - [Koin website](https://insert-koin.io/) ## Known gaps - No status page. `status.kotzilla.io` does not resolve; `kotzilla.statuspage.io` returns 200 but redirects to Atlassian's marketing site and is not a Kotzilla status page. - No security.txt, no vulnerability-disclosure program, no trust center, no SOC 2 or ISO 27001. - No published SLA figure; "Premium Support with SLA" is Enterprise-only. - No changelog for the MCP server, Console or IDE plugin — only the SDK. - No published rate limits or rate-limit response headers; only plan-level event quotas. - DNSSEC not enabled and no CAA records on kotzilla.io; DMARC policy is `quarantine` rather than `reject`.