Documentation
Coming from another tool
Reading the reports
Count what matters
Machine access
From nothing to a counting site.
Registering, proving your domain, paying, the mail that opens the panel, signing in, and bringing your team along. One pass, in the order it actually happens.
Four steps to register
Registration lives at kehai.io/sign-up and reveals one decision at a time:
- The plan. Plan, billing period, and currency, nothing else. Counting is identical on every plan. What a plan changes is the visit band, how many sites and people it carries, how far back history reaches, and which report families open: Journeys, Funnels, Web Vitals, and Forecast from Growth, and Revenue, Products, and Coupons on Commerce. A year costs ten months.
- Your account. Company, your name and email, and the legal consents, each with its own line if one is missing. No password is asked here: you choose it from the mail that arrives after payment.
- Your first site. The domain, and only the domain. A public suffix like co.uk or github.io is refused with "Enter a domain you control, not a public suffix". The site's time zone is read from your browser and changed later under Settings, Site.
- The proof and the payment. A DNS record to publish, then Stripe Checkout. Card numbers never touch Kehai.
Going back preserves what you typed. After payment the account is set up while you watch, and the screen turns to "Check your email".
Prove the domain
Before checkout, Kehai hands you one TXT record to publish in your domain's DNS and looks for it every 45 seconds while the tab is open. Check now asks at once, then counts down a minute before it can be pressed again. The record can be removed after the account exists.
Why this step exists: analytics for a domain should be buyable only by whoever controls that domain. Whoever controls the DNS controls the domain, so publishing one record proves it without documents or emails. It protects you twice over: nobody else can register measurement on your domain behind your back, and the account you are paying for is provably anchored to a site that is yours, not to a typo.
Most providers publish a TXT record within minutes, a few take hours. Leaving the tab open is fine, and so is closing it: coming back, reloading, or returning from a canceled payment lands you on the same step with the same record. Registering again with the same email and domain shows the same record too, for 24 hours, so what you already published keeps counting. After that the screen says the record has expired and offers a new one.
Check your email
The message comes from hello@kehai.io, thanks you, names the site you bought, and carries one link. It works for seven days and once. Open it, choose your password, and you land in the panel on the Install screen, with your first site created and its snippet waiting. Nothing else happens to the account until that link is used.
Look in spam first, because a first message from a new sender often lands there. Then write to the operator with the address you registered: the link can be sent again.
Signing in, five ways
The door is kehai.io/sign-in: the panel lives on its own host, but this is the address people remember, and a browser that already holds a live session is sent straight through without being asked for anything. A session lasts thirty days.
| Method | What it is |
|---|---|
| password | The one you chose from the purchase mail, or from your invitation. Reset by email if it is gone |
| authenticator code | An optional six-digit TOTP challenge after the password, with backup codes for a lost phone. Set up under Profile |
| passkey | WebAuthn: your device's own screen lock in place of a password. Register, name, and remove them under Profile |
| Google, Apple | Sign in with an existing account. Either can authenticate an account that exists. Neither can create one, because accounts come from registration |
A link into the panel survives the door. Open a report address from a digest, an alert, or a colleague while signed out, and after signing in you land on that screen with its range and filters, not on Overview.
Bring your team
People are invited by email under Settings, People, and arrive with a role:
| Role | Can |
|---|---|
| owner | Everything, including retention, API keys, billing, and removing people. Exactly one per account |
| admin | All sites and shared settings, people and billing included. Initiating an ownership transfer and reading the audit log require the owner |
| viewer | Reports and permitted read-only settings for their assigned sites. Their own profile and notification preferences remain editable |
A viewer can inspect the site configuration behind their reports. Restricted changes are disabled and the screen explains the role boundary. The audit log remains owner-only.
The invited person gets a mail with one link, valid once and for seven days. A new sign-in chooses a password. Someone who already uses Kehai joins with their existing sign-in method. Membership becomes active only after acceptance. A pending invitation can be sent again from the People screen.
Secure the account, ten minutes once
- Switch on the second factor under Profile, and put the backup codes somewhere you can reach without this account: the codes exist for the day the phone is gone, and a code stored behind the very sign-in it rescues is decoration. Switching it on leaves your other browsers signed in. Each is asked for a code the next time it signs in with the password.
- Add a passkey and you sign in with the device's own screen lock. A phishing page cannot ask a passkey for anything, which is the point.
- Know the sessions list. Profile shows every signed-in device and revokes them one by one, so a laptop left somewhere stops being a question mark.
- Changing your email confirms twice, at the current address first and the new one second, and the notice about the change goes to the old address, because it is the only one that can tell whether the change was expected.
Every security-relevant change, a new passkey, a connected provider, a password change, an API key, arrives as a plain notice in your inbox with no links to click, which is deliberate: a security mail with a button is indistinguishable from the phishing it warns about. If a notice ever surprises you, the mail says exactly what to do.
What the panel asks you to do first
Once your site exists, Overview opens with one card called First steps. It lists what turns a fresh site into a working one, and each line ticks itself from the site's own data rather than from anything you click:
| Step | Counts as done when | Where |
|---|---|---|
| The tag is on the site | The first event has ever arrived, from any page | Settings, Install |
| A goal is defined | The site has at least one active goal | Settings, Goals |
| You hear about a change | You switched on a weekly or monthly report, or subscribed to an alert, for this site | Settings, Alerts |
| The team is in | A second person is on the account, invited or arrived, or a shared link exists | Settings, People |
| Search terms are connected | A Search Console property is chosen. This one is optional and never keeps the card on screen | Settings, Search Console |
The card is shown to owners and administrators, who can complete the site's setup. A done step stays on the list with a tick so you can see what is already in place. When every required step is done the card leaves on its own, without a message. Hide this puts it away at once, for you, on this site, in every browser you use, and it does not come back. Nothing about it is sent by mail, nothing counts down, and nothing in the sidebar points at it.