heap.io
Heap is a product analytics platform that captures web and mobile user behavior and lets teams analyze journeys, identities, and account activity. It supports client-side and server-side event ingestion plus privacy workflows such as deleting users from a workspace.
Heap exposes two public HTTP integration surfaces: an unauthenticated server-side ingestion API for events and user/account properties, and an authenticated user deletion API that uses a temporary bearer token minted from app ID + API key via Basic auth.
- Heap server-side ingestion APIdiscovered
- Heap user deletion APIdiscovered
In the Heap app, go to Account > Manage > Privacy & Security. Heap says this page lists your app_id; for the User Deletion API it must be the Main Production environment ID.
For the User Deletion API, first call POST https://heapanalytics.com/api/public/v0/auth_token with HTTP Basic auth using app_id as the username and api_key as the password, as documented on User Deletion (Delete API). The response returns an access_token to send as Authorization: Bearer <token> on deletion endpoints.
conventions · 0/7 published
- integrations.json——
- llms.txt✗
/llms.txt - API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing