Website analytics
Collect opt-in browser page views with allowed origins, excluded paths and 30-day retention.
Website analytics shows browser page views, daily visitor estimates, popular paths and referring websites for web services and static sites. Collection starts off. It requires both an enabled service setting and the script installed in your website.
These measurements complement logs and resource metrics. They do not measure every HTTP request, API call, bot visit or application latency.
Enable collection deliberately
- Open the service's Analytics page.
- List the allowed HTTPS website origins, such as
https://example.comandhttps://www.example.com. Include generated and custom domains you intend to measure. - Set excluded paths for private or sensitive parts of the application, such as
/adminand/account. A path also excludes its child pages. - Review your website's privacy notice and consent requirements before enabling collection.
- Enable page-view collection and save.
- Copy the script shown in the console into the website layout, then deploy the application.
The exact snippet includes the service's public collection token:
<script
defer
src="https://dashboard.openstead.tech/api/traffic/script.js"
data-openstead-token="COPY_THE_COLLECTION_TOKEN_FROM_THE_CONSOLE"
></script>Use the console's current snippet instead of inventing a token. The token allows collection for configured origins; it grants no access to the console, files, secrets or analytics reports. Requests from an origin that is not allowed are rejected. You can configure up to 20 origins and 30 excluded paths.
Developers and greater roles can change collection settings. Viewers can read authorized aggregate reports. Protected service access retains its existing admin restriction.
Understand the report
Choose 1, 7 or 30 days. The dashboard shows page views, daily visitor estimates, identifiers seen in the last five minutes, a daily timeline, popular page paths and referring hostnames.
The script records visible page visits and client-side path changes. Its random visitor identifier exists in memory in a browser tab and resets daily; it is not a persistent person identifier. Different tabs or later visits can count separately. A 30-day visitor total must not be interpreted as 30-day unique people.
Collection uses no analytics cookies or persistent browser IDs. Stored events exclude raw IP addresses, query strings and full referrer URLs. Standard sensitive route shapes are redacted, but application-specific secrets can still appear in path segments: exclude those routes or redesign their URLs.
Do Not Track and Global Privacy Control are respected. Known bots are filtered. Browser blockers, disabled JavaScript, private signals, excluded paths and rate limits can reduce measured visits. The five-minute indicator is recent recorded activity, not a live list of connected people.
Retention and allowance
Events are retained for 30 days, with up to 5,000 page views per day per service. Additional intake limits protect the collector during bursts. When collection reaches its daily limit, additional events are rejected rather than silently purchasing an overage.
Use longer-term application instrumentation or your own exports if you need durable historical reporting. This feature does not provide request tracing, conversion attribution or raw access-log retention.
Stop, erase or rotate
Disable collection to stop accepting new events. Remove the script from your application if it is no longer needed. Existing events retain their normal expiry until erased.
An admin can use Erase collected data to remove recorded events. Erasing data does not disable collection; turn it off separately if future events should stop.
If you rotate the collection token, the old snippet loses access immediately. Copy the replacement snippet and redeploy every website that used the old token.
Troubleshoot missing page views
Check that collection is enabled, the script uses the current token, the actual HTTPS origin is allowed and the page is not excluded. Also check the browser's privacy settings, blockers and network requests, along with the daily allowance.
Do not repeatedly reload to generate an artificial count. For application failures, use deployment and runtime logs; a zero analytics count does not prove the website is unavailable.