Head to head · Analytics events · October 2026 research run

Heap vs PostHog

PostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events.

Which one, for what

Heap D

Good for An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.

Also in its favour

  • No incidents deducted, where PostHog loses 7 points for them

Watch for

No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read

PostHog B

Good for An agent that answers product questions in SQL or with funnel, retention and trends queries, and that manages feature flags, experiments and error tracking in the same project.

Ahead on

  • Schema & documentation, 81 against 57
  • Agent ergonomics, 78 against 49
  • Security & auth, 84 against 41
  • Payments & pricing, 40 against 25
  • Maintenance & community, 89 against 63
  • Transparency & trust, 83 against 64

Also in its favour

  • Free to start without a card
  • Open source

Watch for

31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures

Score by category

CategoryWeight this runHeapPostHogEdge
Reliability16%207274PostHog +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25781PostHog +24
Agent ergonomics13%16.24978PostHog +29
Security & auth14%17.54184PostHog +43
Payments & pricing10%12.52540PostHog +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86389PostHog +26
Transparency & trust7%8.86483PostHog +19
Negative events≤150-7
Total53 · D68.4 · B

Facts side by side

FactHeapPostHog
KindHTTP APIHTTP API
VendorContentsquare (Content Square, Inc.)PostHog Inc.
Hosted endpointhttps://heapanalytics.comhttps://us.posthog.com
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
Price for analytics eventsnot published$0.0001 per transaction
x402nono
LicenceProprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MITMIT for the repository outside the ee directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms
Tools exposednone1096
Read-only variant documentednoyes
llms.txtyesyes
MCP registrynot listedio.github.PostHog/mcp
Last release2026-10-062026-10-05
Terms last updatedno date given2026-06-29
Privacy policy last updatedcouldn't be read2026-06-29
Customer content may train modelsyesyes, with an opt-out
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity213 npm/wk40k stars, 15.2M npm/wk

Verdicts

Heap

Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.

PostHog

PostHog suits agents that need to query product data and manage flags or experiments. Its hosted MCP server has OAuth scopes, a read-only mode and a one-tool CLI mode over 1,096 tools. The status page shows 31 incidents in 90 days, four on analytics queries, and three security incidents were disclosed in the last year.

Before you call either

Heap

  1. Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same
  2. Pass one of identity or user_id on track, never both
  3. Set idempotency_key on every track event so a retry doesn't duplicate it
  4. Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call
  5. For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized

PostHog

  1. Add ?readonly=true or the x-posthog-read-only header to the MCP URL unless the task needs writes
  2. Pin the session with x-posthog-project-id, which also removes the switch-project and switch-organization tools
  3. In CLI mode run info <tool> once before call, and send one exec command per request
  4. On a 429 with code api_queries_budget_exceeded, wait for Retry-After and read X-PostHog-Query-Budget-Remaining-Bytes
  5. Page SQL results by keyset on timestamp. OFFSET returns 400 for personal API keys, and results cap at 50,000 rows

Questions

Which is better for AI agents, Heap or PostHog?

PostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category.

Do Heap and PostHog need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Heap and PostHog without installing anything?

Yes. Heap has a hosted endpoint at https://heapanalytics.com and PostHog at https://us.posthog.com.

Are Heap and PostHog open source?

No open-source release is listed for Heap. PostHog is open source (MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms).

Other comparisons with Heap or PostHog

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.