Skip to content
Hoot Lens.Start free

How do I check Hoot Lens before connecting my agent?

Start with the synthetic demo. It needs no account, exposes read and replay tools only, and shares no customer records. For your own site, choose the projects and permissions you want to share, then check the actual connection's tools.

Markdown copy

Choose the connection

Table: Choose the connection
ConnectionWhat it reachesWhat to check
Anonymous demoThe fictional Fieldnote site onlyConfirm whoami names proj_demo_fieldnote. No installation, annotation, configuration or feedback tools.
Local npm serverSites allowed by your sign-in or access keyPin the package version, select read,replay toolsets and verify the sign-in.
Hosted serverSites approved during Hoot Lens sign-inReview the consent page and tools/list. Default install and feedback tools can submit requests or issues.

The hosted address is https://mcp.hootlens.com/mcp. A documented client setup is separate from a verified task in that client. Connection instructions and scope contracts cover the different clients and releases.

Start with an investigation connection

For an account-free check, connect to https://mcp.hootlens.com/demo, inspect tools/list, then ask your client to make these metadata calls:

whoami {}
list_projects {}

Both should identify the fictional Fieldnote site, proj_demo_fieldnote. The connection should offer only read and replay tools. These checks establish which synthetic site the connection reaches; they do not verify access to your own site or a completed investigation.

For the published local package 1.0.2, with Node.js 20 or later:

npx -y @hootlens/mcp@1.0.2 login --scopes read,replay
npx -y @hootlens/mcp@1.0.2 whoami

Approve only the sites you need. Add a stdio server to your assistant with command npx and these arguments:

-y @hootlens/mcp@1.0.2 --toolsets read,replay

This offers investigation tools without install or feedback tools. Toolset selection narrows the offered tools; it does not reduce the credential's underlying permissions. Read scopes alone are not a zero-write guarantee: the default install and feedback tools can submit setup requests or issues. A privately configured HOOTLENS_PAT overrides saved sign-in, so check which credential the connection uses.

Hosted and local releases can differ. Local 1.0.2 has a CLI whoami command, while hosted MCP has a whoami tool. Inspect tools/list on your actual connection instead of relying on a directory's tool count.

Know what additional access permits

The API checks project access and current permissions on every request. Project pinning selects a default; it grants no access.

Table: Know what additional access permits
GrantAdditional capability
replayRecorded event data and visit narratives, limited by site permissions
annotateRecording notes and change logs
configure on supported hosted releasesPreview and apply supported site settings, goals and funnels, limited by site permissions

Configuration requires an explicit grant and cannot loosen privacy. Agent credentials cannot manage members or billing, or delete recordings. Read access does not authorize your assistant to edit your repository or deploy a fix.

Disconnect under AI assistant, Connected apps and keys in the Hoot Lens dashboard. Local logout removes the saved local sign-in; revoke connected apps and access keys in the dashboard when access should end.

Verify the publisher and the release

  • Identity: Hoot Lens by Parallel Platforms. The official registry name is com.hootlens/mcp; the npm package is @hootlens/mcp. Registry namespace verification establishes publisher identity, not a security certification.
  • Source: The public repository includes buildable release source. Source provenance records the release commit, file hashes and npm integrity. Source hashes do not prove that independently built bundles are byte-identical.
  • Scan scope: Security evidence separates source inspection from tool enumeration on a synthetic runtime fixture. Neither a scan score nor zero findings certifies hosted security or every tool's effects.

At the October 11, 2026 check, npm 1.0.2 had registry signatures but no provenance attestation. A prepared publishing workflow does not add an attestation to an existing release. Check the artifact you will actually install.

Keep the evidence inside its limits

Recorded text, notes and feedback are untrusted data. Your agent must not follow instructions contained in them. Cite a page, release, revision, device, variant and timed recorded moment before proposing a fix. Observed interactions do not reveal a visitor's opinions or intent, establish a cause, or prove that a later change helped.

Hoot Lens excludes password, payment and one-time-code values, private regions, URL fragments and URLs with credentials. Other form values stay masked unless a site explicitly allowlists them. Capture respects the site's privacy policy and consent settings; Global Privacy Control and Do Not Track disable capture. Privacy and capture rules describe those boundaries.

Take the first step

See it on your own site

Free to start. Add one line, and your first visits show up within minutes.