Headless Platform
Run Ours Privacy headlessly: manage sources, destinations, consent, experiments, and reporting through the REST API, MCP server, and SDKs without logging in to the dashboard.
Ours Privacy is headless: almost everything you can do in the dashboard, you can also do through the Platform REST API, the MCP server, or a platform SDK. Use this page to understand what headless access covers and which interface fits your team.
Headless means your team, your scripts, or your AI agents operate the platform without logging in to the dashboard. The dashboard stays available for anyone who wants it; nothing about headless use locks you out of the UI.
Looking for headless experiments or a headless CMS? Rendering A/B test variants in your own app is covered in Headless Experiments and Headless Personalization. Installing Ours Privacy on Contentful, Sanity, and similar platforms is covered in Headless CMS Integration.
Why run it headlessly
- Let AI agents do the setup. Connect Claude, ChatGPT, or Codex to the MCP server and ask for a destination, a consent banner, or an experiment in plain language.
- Keep configuration in code. Script sources, mappings, and consent rules, review them in pull requests, and publish from CI/CD.
- Manage many accounts at once. Agencies and multi-brand teams can roll the same setup out across accounts with one script instead of repeating clicks.
- Pull reporting into your own tools. Read attribution, funnels, web analytics, and consent analytics into a warehouse, BI tool, or internal dashboard.
- Keep the same controls. Every call uses a scoped, expiring API key and the same permission model as your organization's roles, so headless access fits HIPAA-regulated workflows without a separate access path.
Choose an interface
All three interfaces call the same API, use the same API keys, and reach the same resources.
| Interface | Best for | Start here |
|---|---|---|
| MCP server | AI assistants and agents working by natural-language prompt | MCP Server (platform) |
| REST API | Any language, curl, CI/CD jobs, and custom tooling | API Quickstart |
| Platform SDKs | Typed Node.js / TypeScript and Go code | Platform SDKs |
A headless MCP session looks like this:
claude mcp add --transport http oursprivacy https://ai.oursprivacy.com/mcp \
--header "Authorization: Bearer YOUR_API_KEY"The same account from a script:
import OursPrivacyPlatform from '@oursprivacy/platform-sdk';
const client = new OursPrivacyPlatform({ apiKey: process.env['OURS_PRIVACY_API_KEY'] });
const destinations = await client.destinations.list();
console.log(destinations.data);What you can manage headlessly
| Area | What's covered |
|---|---|
| Event pipeline | Sources, allowed events, data governance, mappings, and destinations |
| Publishing | Versions: review the draft diff, publish, and roll back |
| Consent | CMP settings and consent analytics |
| Experimentation | Experiments, variants, experiment settings, and personalization properties |
| Tag Manager | Containers, tags, triggers, variables, and folders |
| Reporting | Attribution, funnels, web analytics, heatmaps, session replays, and locations |
| Content and media | Short links, videos, and translation widgets |
| Web Scanner | Scanners and scanner rules |
Collecting events is headless already: the Web SDK, mobile SDKs, and server-side ingest SDKs send data without anyone opening the dashboard. See the SDK Overview for the full list.
How changes go live
Headless changes follow the same draft-and-publish flow as the dashboard. Creating or editing a destination, mapping, or consent setting writes to a draft. Nothing reaches your live site until you publish a new version, which you can also do by API or MCP. Experiments are the exception: they go live when you start them.
Because every change is versioned, you can diff the draft before publishing and roll back to an earlier version if something looks wrong.
What still happens in the dashboard
A few one-time steps stay in the dashboard so that access is always granted by a person:
- API keys. An organization admin creates each key, picks its scopes, and sets its expiration under Settings → API Keys. See Authentication.
- Enabling API access. If you don't see the API Keys section, contact your account representative to turn it on.
After a key exists, day-to-day work can run entirely headless.
Next Steps
- Authentication: create the scoped API key every headless interface needs.
- MCP Server (platform): connect Claude, ChatGPT, or Codex to your account.
- API Quickstart: make your first REST calls with
curl. - Manage Experiments with AI: run an experiment end to end by prompt.
How is this guide?

