Overview
Privacy-first web analytics you host yourself, with a typed SDK and one API for ingest, reads and sign-in.
Spoar records pageviews, custom events, errors and Core Web Vitals from your sites and apps, and stores them in a Postgres database you run. It sets no cookies for visitors and never stores raw IP addresses.
It has three parts:
| Part | What it is |
|---|---|
| SDK | @spoar/sdk: a browser client, plugins, and React, Next, server and proxy entries. ESM only |
| API | One Elysia service under /v2: ingest, aggregate and visitor-level reads, speed insights, error tracking, a read-only SQL console, sign-in, projects and tokens |
| Database | Postgres (Neon in production). Every read goes through the API |
What it runs on
The browser core has no framework dependency. Anything that bundles ES modules can use it, and the framework entries add conveniences on top. Frameworks has a setup page per stack.
| Stack | What you use |
|---|---|
| Next.js 15 or later | The core, /react and /next for route templates, /proxy for the /_ra route, /server in route handlers and server actions |
| React 19 with any router | The core and /react. Pageviews follow pushState routers without extra code |
| Vite, vanilla TypeScript or JavaScript | The core and plugins |
| Vue, Svelte and SvelteKit, Astro | The core and plugins |
| Solid, Preact | The core and plugins. Dedicated guides are coming soon |
| Node, Bun, Deno, Vercel Functions, Cloudflare Workers | /server and /proxy, on any runtime with fetch and the standard Request and Response |
| Any other language | POST /v2/events with a secret key, as described in the API reference |
There is no <script src> snippet and no CommonJS build.
How data flows
- The SDK batches events in the browser and sends them to
/v2/events, directly or through a same-origin proxy path such as/_ra. - The API checks the key and origin, scores bots, enriches the event with geo, device and channel, and stores it. Raw IP addresses are never stored; a daily salted hash is used for rate limits and visitor counting.
- Reads, exports and the SQL console answer from the same tables, with access decided per project and per caller.
How it works describes each step in detail.
Where to start
Quick start
From an empty project to the first event.
Concepts
Events, pageviews, routes, visitors, sessions, consent, projects and keys.
Install the SDK
The entries and their size budgets.
Auth overview
Who can call what, sign-in, tokens and keys.
API reference
Every route, generated from the OpenAPI document.
Query console
Run read-only SQL against your projects with a token.