{
  "data": {
    "a": {
      "slug": "heap",
      "name": "Heap",
      "vendor": "Contentsquare (Content Square, Inc.)",
      "vendorUrl": "https://www.heap.io",
      "kind": "http-api",
      "category": "product-analytics",
      "summary": "Heap is Contentsquare's product analytics service, which captures web and mobile interactions automatically. Its server-side HTTP API accepts custom events, identities, user and account properties, and user deletion requests.",
      "url": "https://www.anchorterminal.com/tools/heap",
      "markdownUrl": "https://www.anchorterminal.com/tools/heap.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/heap.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/heap.json",
      "license": "Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://heapanalytics.com",
      "packages": [
        {
          "registry": "npm",
          "name": "heap-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Track, identify and property calls need only `app_id`, the environment ID shown on the Projects page and used in the web snippet, with no secret. User deletion needs an API key that an admin generates under Account, Manage, Privacy \u0026 Security, exchanged by HTTP Basic for a temporary Bearer token. No OAuth, scopes or partner approval were found in the developer docs.",
      "pricing": "freemium",
      "pricingNotes": "Free plan up to 10,000 sessions a month with six months of history, APIs included, so an agent's owner can start without a contract. Growth is priced by estimate after signup, and Pro and Premier by quote. Whether signup asks for a card was not established (https://www.heap.io/pricing, checked 2026-10-07).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 213,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.heap.io",
      "llmsTxt": "https://developers.heap.io/llms.txt",
      "capabilities": [
        "analytics.events"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "llms-txt",
        "free-tier",
        "no-oauth",
        "write-only",
        "eu-region",
        "status-page",
        "soc2",
        "sales-led"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53,
        "grade": "D",
        "agentReady": false,
        "rank": 488,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 49,
          "maintenance": 63,
          "payments": 25,
          "reliability": 72,
          "schema": 57,
          "security": 41,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "low",
          "date": "2026-10-07"
        },
        "negative": 0,
        "verdict": "Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.",
        "bestFor": "An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.",
        "strengths": [
          "Rate limits are published. Track allows 30 requests per 30 seconds per identity, and bulk track 15,000 events a minute per environment",
          "Track and bulk track accept an `idempotency_key`, and bulk calls take up to 1,000 events or users per request",
          "llms.txt and a Markdown copy of every developer page, with an OpenAPI 3.1 fragment embedded in the reference pages we read",
          "Free plan with up to 10,000 sessions a month and six months of history, with APIs and the User Privacy API included",
          "Sub-processor list (June 2026) names AWS regions in Ireland, Frankfurt and Virginia, and the customer chooses Europe or the USA"
        ],
        "weaknesses": [
          "No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read",
          "Track, identify and property calls carry no secret. The only identifier is the environment ID that the web snippet also publishes",
          "Three incidents marked major on status.heap.io in the 90 days to 7 October 2026, one of them still open",
          "Paid plans have no public price. Growth asks for an estimate after signup, and Pro and Premier say Contact Us",
          "Error responses for track and identify are documented as a 400 with an empty object, and no 429 guidance was found"
        ],
        "agentNotes": [
          "Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same",
          "Pass one of `identity` or `user_id` on track, never both",
          "Set `idempotency_key` on every track event so a retry doesn't duplicate it",
          "Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call",
          "For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "low",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53
          }
        ],
        "editorialScores": {
          "ergonomics": 49,
          "maintenance": 63,
          "payments": 25,
          "reliability": 72,
          "schema": 57,
          "security": 41,
          "transparency": 61
        },
        "provenanceScore": 66
      },
      "connect": {
        "http": "curl -X POST \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"app_id\": \"11\",\n    \"identity\": \"alice@example.com\",\n    \"event\": \"Send Transactional Email\",\n    \"properties\": {\"subject\": \"Welcome to My App!\"}\n  }' \\\n  https://heapanalytics.com/api/track"
      },
      "letme": {
        "capability": "https://letme.dev/analytics.events",
        "tool": "https://letme.dev/heap"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Free",
          "unit": "month",
          "usd": 0,
          "note": "up to 10,000 sessions a month"
        }
      ],
      "provenance": {
        "legalEntity": "Content Square, Inc.",
        "domain": "heap.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.heap.io/legal/heap-master-services-agreement",
        "privacy": "https://www.heap.io/privacy",
        "statusPage": "https://status.heap.io",
        "changelog": "https://developers.heap.io/docs/heapjs-5-changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Heap master services agreement URL redirects to Contentsquare's terms at contentsquare.com/legal/terms-conditions. The entity schedule names Content Square, Inc., 60 Hudson St, New York, for customers in the Americas, and other Contentsquare entities elsewhere.",
          "heap.io/terms is a website terms of use from Heap Inc., a Delaware corporation, last updated 30 August 2019. heap.io/privacy says the Heap policy has been consolidated into Contentsquare's.",
          "API calls go to heapanalytics.com and, for EU projects, c.eu.heap-api.com. Both are Heap domains named in the vendor's docs, not heap.io itself.",
          "www.heap.io/.well-known/security.txt and heapanalytics.com/.well-known/security.txt return 404. contentsquare.com publishes a signed security.txt that expires on 31 January 2028.",
          "RDAP has no service for .io through rdap.org, so the registration date of heap.io was not established.",
          "The only changelogs found are for the SDKs (heap.js 5, Android, iOS, React Native, Flutter). No changelog for the server-side API was found."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/heap.json",
      "live": {
        "slug": "heap",
        "probe": {
          "target": "https://heapanalytics.com",
          "method": "get",
          "lastAt": "2026-10-08T17:36:37.12694271Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 328,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 339,
          "p95ms24h": 444,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.heap.io",
          "indicator": "minor",
          "summary": "Minor Service Outage",
          "checkedAt": "2026-10-08T17:24:30.801472672Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "heap-api",
            "version": "1.0.1",
            "seenAt": "2026-10-08T16:15:35.796443098Z"
          }
        ],
        "npmWeekly": 213,
        "securityTxt": {
          "url": "https://heap.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:30.698501929Z"
        },
        "updatedAt": "2026-10-08T17:36:37.12694271Z"
      }
    },
    "answer": "PostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category.",
    "b": {
      "slug": "posthog",
      "name": "PostHog",
      "vendor": "PostHog Inc.",
      "vendorUrl": "https://posthog.com",
      "kind": "http-api",
      "category": "product-analytics",
      "summary": "PostHog is an open-source product analytics platform with session replay, feature flags, experiments, error tracking and a data warehouse. Agents reach PostHog Cloud through a REST API with a public OpenAPI spec and an official hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/posthog",
      "markdownUrl": "https://www.anchorterminal.com/tools/posthog.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/posthog.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/posthog.json",
      "repo": "https://github.com/PostHog/posthog",
      "license": "MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://us.posthog.com",
      "packages": [
        {
          "registry": "npm",
          "name": "posthog-node"
        },
        {
          "registry": "npm",
          "name": "posthog-js"
        },
        {
          "registry": "pypi",
          "name": "posthog"
        },
        {
          "registry": "npm",
          "name": "@posthog/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Private endpoints take a Bearer personal API key (`phx_`) that a signed-in user creates with chosen scopes and project or organisation access, or an OAuth access token. OAuth at oauth.posthog.com supports PKCE, dynamic client registration and client ID metadata documents, with no app review needed to go live. The MCP server uses OAuth by default or a personal API key made with the MCP Server preset. Project secret API keys are in beta. Capture and flag evaluation take the public project token.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with no card, covering 1 million analytics events and 1 million flag requests a month. The paid plan has no base fee and no seat charge, and bills per unit above the free allowance (analytics events from $0.00005). API and MCP calls are not billed, but personal API key queries draw on an hourly read budget that is larger on a paid plan (https://posthog.com/pricing, checked 2026-10-07).",
      "priceSummary": "$0.0001 / tx",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI spec or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 1096,
      "popularity": {
        "githubStars": 40176,
        "npmWeekly": 15243417,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://posthog.com/docs/api",
      "llmsTxt": "https://posthog.com/llms.txt",
      "openapi": "https://app.posthog.com/api/schema/",
      "registryName": "io.github.PostHog/mcp",
      "capabilities": [
        "analytics.query",
        "analytics.events",
        "analytics.funnels",
        "analytics.experiments",
        "analytics.flags",
        "observability.errors",
        "observability.logs"
      ],
      "tags": [
        "official",
        "hosted",
        "open-source",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "free-tier",
        "no-card",
        "eu-region",
        "status-page",
        "soc2",
        "typescript",
        "python"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.4,
        "grade": "B",
        "agentReady": false,
        "rank": 171,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 89,
          "payments": 40,
          "reliability": 74,
          "schema": 81,
          "security": 84,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -7,
        "negativeNotes": [
          "-3: 2025-11-24. Malicious versions of posthog-node, posthog-js and six other npm packages were published with a stolen token after an attacker took CI secrets through a pull request workflow. PostHog removed them in about five hours and published a post-mortem on 26 November 2025, so the deduction is reduced (https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem).",
          "-2: 2026-05-29, disclosed 2026-06-02 as PSA-2026-00001 (critical). Researchers used an unsandboxed, outdated Chromium to reach a US Cloud pod and read internal production credentials. PostHog says no customer data was accessed and the credentials were rotated. Fixed and documented (https://posthog.com/handbook/company/security-advisories).",
          "-2: 2026-07-11 to 2026-08-04, disclosed 2026-08-21 as PSA-2026-00002 (high). Customer-run nginx proxies set up as PostHog's guide showed sent traffic to released AWS addresses, and a researcher read traffic from six EU customers. The report sat in triage for five weeks. Fixed and documented (https://posthog.com/handbook/company/security-advisories)."
        ],
        "verdict": "PostHog suits agents that need to query product data and manage flags or experiments. Its hosted MCP server has OAuth scopes, a read-only mode and a one-tool CLI mode over 1,096 tools. The status page shows 31 incidents in 90 days, four on analytics queries, and three security incidents were disclosed in the last year.",
        "bestFor": "An agent that answers product questions in SQL or with funnel, retention and trends queries, and that manages feature flags, experiments and error tracking in the same project.",
        "strengths": [
          "Public OpenAPI 3.1 spec with 2,347 operations and a scope on most of them, plus llms.txt and a Markdown copy of every docs page",
          "Hosted MCP server with OAuth, a read-only switch, filters by product area or tool name and pinning to one project",
          "CLI mode registers one `exec` tool that searches, inspects and calls the 1,096 tools on demand",
          "Free plan without a card, with 1 million analytics events and 1 million flag requests a month, and public per-unit prices above that",
          "MIT source outside the `ee` directory, a public SOC 2 Type 2 report and a public security advisories page"
        ],
        "weaknesses": [
          "31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures",
          "Three security incidents in twelve months, among them malicious npm SDK versions on 24 November 2025",
          "API queries stop at 10 seconds of execution, three at a time per project, with an hourly read budget on personal API keys",
          "No API versioning or deprecation policy was found, and the query docs reserve the right to restrict export-like queries without notice",
          "Customer content can be used to train PostHog's own models unless the customer opts out in settings"
        ],
        "agentNotes": [
          "Add `?readonly=true` or the `x-posthog-read-only` header to the MCP URL unless the task needs writes",
          "Pin the session with `x-posthog-project-id`, which also removes the `switch-project` and `switch-organization` tools",
          "In CLI mode run `info \u003ctool\u003e` once before `call`, and send one `exec` command per request",
          "On a 429 with code `api_queries_budget_exceeded`, wait for `Retry-After` and read `X-PostHog-Query-Budget-Remaining-Bytes`",
          "Page SQL results by keyset on `timestamp`. `OFFSET` returns 400 for personal API keys, and results cap at 50,000 rows"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.4
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 89,
          "payments": 40,
          "reliability": 74,
          "schema": 81,
          "security": 84,
          "transparency": 71
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npx @posthog/wizard mcp add",
        "http": "curl \\\n  -H 'Content-Type: application/json' \\\n  -H \"Authorization: Bearer $POSTHOG_PERSONAL_API_KEY\" \\\n  https://us.posthog.com/api/projects/:project_id/query/ \\\n  -d '{\"query\": {\"kind\": \"HogQLQuery\", \"query\": \"select event, count() from events group by event limit 100\"}}'",
        "claudeCode": "claude mcp add --transport http posthog https://mcp.posthog.com/mcp -s user",
        "config": {
          "mcpServers": {
            "posthog": {
              "url": "https://mcp.posthog.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/analytics.query",
        "tool": "https://letme.dev/posthog"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Product analytics event",
          "unit": "tx",
          "usd": 0.00005,
          "note": "1 to 2 million a month, first 1 million free, lower above"
        },
        {
          "item": "Feature flag request",
          "unit": "tx",
          "usd": 0.0001,
          "note": "1 to 2 million a month, first 1 million free, lower above"
        },
        {
          "item": "Session recording",
          "unit": "tx",
          "usd": 0.005,
          "note": "5,001 to 15,000 a month, first 5,000 free"
        },
        {
          "item": "Data warehouse row",
          "unit": "record",
          "usd": 0.000015,
          "note": "1 to 10 million a month, first 1 million free"
        },
        {
          "item": "Boost package",
          "unit": "month",
          "usd": 250
        },
        {
          "item": "Scale package",
          "unit": "month",
          "usd": 750
        },
        {
          "item": "Enterprise package",
          "unit": "month",
          "usd": 2000
        }
      ],
      "provenance": {
        "legalEntity": "PostHog Inc. (formerly Hiberly Inc.)",
        "domain": "posthog.com",
        "domainRegistered": "2020-01-23",
        "endpointOnVendorDomain": true,
        "terms": "https://posthog.com/terms",
        "privacy": "https://posthog.com/privacy",
        "statusPage": "https://www.posthogstatus.com",
        "changelog": "https://posthog.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-07",
        "notes": [
          "The privacy policy names PostHog Inc., formerly known as Hiberly Inc., and its subsidiaries. The security handbook names Hiberly Ltd. as the UK entity.",
          "posthog.com/.well-known/security.txt expires 2027-08-30 and points to the security handbook. The copy on us.posthog.com expired 2024-03-14.",
          "status.posthog.com redirects to www.posthogstatus.com.",
          "RDAP for posthog.com gives a registration date of 2020-01-23.",
          "The API, OAuth server and MCP server answer on posthog.com subdomains."
        ],
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/posthog.json",
      "live": {
        "slug": "posthog",
        "probe": {
          "target": "https://us.posthog.com",
          "method": "get",
          "lastAt": "2026-10-08T17:36:43.149834398Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 349,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 369,
          "p95ms24h": 484,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.posthogstatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T15:37:10.780428214Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "PostHog/posthog",
            "version": "posthog-cli/v0.18.10",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:26:05.264718319Z"
          },
          {
            "registry": "npm",
            "name": "@posthog/cli",
            "version": "0.18.10",
            "seenAt": "2026-10-08T16:26:03.360315129Z"
          },
          {
            "registry": "npm",
            "name": "posthog-js",
            "version": "1.438.2",
            "seenAt": "2026-10-08T16:26:01.219902492Z"
          },
          {
            "registry": "npm",
            "name": "posthog-node",
            "version": "5.55.0",
            "seenAt": "2026-10-08T16:26:00.932213759Z"
          },
          {
            "registry": "pypi",
            "name": "posthog",
            "version": "7.66.0",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:26:03.179505005Z"
          }
        ],
        "githubStars": 40189,
        "npmWeekly": 15243417,
        "pypiWeekly": 10625439,
        "securityTxt": {
          "url": "https://posthog.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-08-30T00:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:33.305841715Z"
        },
        "updatedAt": "2026-10-08T17:36:43.149834398Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Contentsquare (Content Square, Inc.)",
        "b": "PostHog Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://heapanalytics.com",
        "b": "https://us.posthog.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "not published",
        "b": "$0.0001 per transaction",
        "name": "Price for analytics events"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT",
        "b": "MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "1096",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "io.github.PostHog/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-06",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2026-06-29",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-06-29",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "213 npm/wk",
        "b": "40k stars, 15.2M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "PostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category.",
        "question": "Which is better for AI agents, Heap or PostHog?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Heap and PostHog need an API key?"
      },
      {
        "answer": "Yes. Heap has a hosted endpoint at https://heapanalytics.com and PostHog at https://us.posthog.com.",
        "question": "Can an agent call Heap and PostHog without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Heap. PostHog is open source (MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms).",
        "question": "Are Heap and PostHog open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "No incidents deducted, where PostHog loses 7 points for them"
        ],
        "goodFor": "An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.",
        "slug": "heap",
        "watchFor": "No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 81 against 57",
          "Agent ergonomics, 78 against 49",
          "Security \u0026 auth, 84 against 41",
          "Payments \u0026 pricing, 40 against 25",
          "Maintenance \u0026 community, 89 against 63",
          "Transparency \u0026 trust, 83 against 64"
        ],
        "also": [
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "An agent that answers product questions in SQL or with funnel, retention and trends queries, and that manages feature flags, experiments and error tracking in the same project.",
        "slug": "posthog",
        "watchFor": "31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures"
      }
    ],
    "job": {
      "capability": "analytics.events",
      "name": "Analytics events"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amplitude-vs-posthog.json",
        "title": "Amplitude vs PostHog",
        "url": "https://www.anchorterminal.com/compare/amplitude-vs-posthog"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mixpanel-vs-posthog.json",
        "title": "Mixpanel vs PostHog",
        "url": "https://www.anchorterminal.com/compare/mixpanel-vs-posthog"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pendo-vs-posthog.json",
        "title": "Pendo vs PostHog",
        "url": "https://www.anchorterminal.com/compare/pendo-vs-posthog"
      },
      {
        "json": "https://www.anchorterminal.com/compare/posthog-vs-statsig.json",
        "title": "PostHog vs Statsig",
        "url": "https://www.anchorterminal.com/compare/posthog-vs-statsig"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amplitude-vs-heap.json",
        "title": "Amplitude vs Heap",
        "url": "https://www.anchorterminal.com/compare/amplitude-vs-heap"
      },
      {
        "json": "https://www.anchorterminal.com/compare/growthbook-vs-heap.json",
        "title": "GrowthBook vs Heap",
        "url": "https://www.anchorterminal.com/compare/growthbook-vs-heap"
      },
      {
        "json": "https://www.anchorterminal.com/compare/heap-vs-mixpanel.json",
        "title": "Heap vs Mixpanel",
        "url": "https://www.anchorterminal.com/compare/heap-vs-mixpanel"
      },
      {
        "json": "https://www.anchorterminal.com/compare/heap-vs-pendo.json",
        "title": "Heap vs Pendo",
        "url": "https://www.anchorterminal.com/compare/heap-vs-pendo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/heap-vs-statsig.json",
        "title": "Heap vs Statsig",
        "url": "https://www.anchorterminal.com/compare/heap-vs-statsig"
      },
      {
        "json": "https://www.anchorterminal.com/compare/growthbook-vs-posthog.json",
        "title": "GrowthBook vs PostHog",
        "url": "https://www.anchorterminal.com/compare/growthbook-vs-posthog"
      },
      {
        "json": "https://www.anchorterminal.com/compare/launchdarkly-vs-posthog.json",
        "title": "LaunchDarkly vs PostHog",
        "url": "https://www.anchorterminal.com/compare/launchdarkly-vs-posthog"
      }
    ],
    "scores": [
      {
        "by": 2,
        "edge": "posthog",
        "heap": 72,
        "key": "reliability",
        "name": "Reliability",
        "posthog": 74,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 24,
        "edge": "posthog",
        "heap": 57,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "posthog": 81,
        "weight": 13
      },
      {
        "by": 29,
        "edge": "posthog",
        "heap": 49,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "posthog": 78,
        "weight": 13
      },
      {
        "by": 43,
        "edge": "posthog",
        "heap": 41,
        "key": "security",
        "name": "Security \u0026 auth",
        "posthog": 84,
        "weight": 14
      },
      {
        "by": 15,
        "edge": "posthog",
        "heap": 25,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "posthog": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 26,
        "edge": "posthog",
        "heap": 63,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "posthog": 89,
        "weight": 7
      },
      {
        "by": 19,
        "edge": "posthog",
        "heap": 64,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "posthog": 83,
        "weight": 7
      }
    ],
    "summary": "PostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events.",
    "verdicts": {
      "heap": "Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.",
      "posthog": "PostHog suits agents that need to query product data and manage flags or experiments. Its hosted MCP server has OAuth scopes, a read-only mode and a one-tool CLI mode over 1,096 tools. The status page shows 31 incidents in 90 days, four on analytics queries, and three security incidents were disclosed in the last year."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/heap-vs-posthog",
    "json": "https://www.anchorterminal.com/compare/heap-vs-posthog.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/heap-vs-posthog.md",
    "slim": "https://www.anchorterminal.com/compare/heap-vs-posthog.min.md"
  },
  "markdown": "PostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events.\n\n- Heap: grade D, 53/100, rank #488 of 629. Markdown https://www.anchorterminal.com/tools/heap.md · JSON https://www.anchorterminal.com/api/v1/tools/heap.json\n- PostHog: grade B, 68.4/100, rank #171 of 629. Markdown https://www.anchorterminal.com/tools/posthog.md · JSON https://www.anchorterminal.com/api/v1/tools/posthog.json\n\n## Which one, for what\n\n### Heap (D)\n\nGood for: An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.\n\nAlso in its favour:\n- No incidents deducted, where PostHog loses 7 points for them\n\nWatch for: No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read\n\n### PostHog (B)\n\nGood for: An agent that answers product questions in SQL or with funnel, retention and trends queries, and that manages feature flags, experiments and error tracking in the same project.\n\nAhead on:\n- Schema \u0026 documentation, 81 against 57\n- Agent ergonomics, 78 against 49\n- Security \u0026 auth, 84 against 41\n- Payments \u0026 pricing, 40 against 25\n- Maintenance \u0026 community, 89 against 63\n- Transparency \u0026 trust, 83 against 64\n\nAlso in its favour:\n- Free to start without a card\n- Open source\n\nWatch for: 31 incidents on the status page between 9 July and 6 October 2026, four of them analytics query timeouts or failures\n\n\n## Score by category\n\n| Category | Weight | Heap | PostHog | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 72 | 74 | PostHog +2 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 57 | 81 | PostHog +24 |\n| Agent ergonomics | 13% (16.2 this run) | 49 | 78 | PostHog +29 |\n| Security \u0026 auth | 14% (17.5 this run) | 41 | 84 | PostHog +43 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 40 | PostHog +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 63 | 89 | PostHog +26 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 83 | PostHog +19 |\n| Negative events | ≤15 | 0 | -7 | |\n| **Total** | | **53 · D** | **68.4 · B** | |\n\n## Facts side by side\n\n| Fact | Heap | PostHog |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Contentsquare (Content Square, Inc.) | PostHog Inc. |\n| Hosted endpoint | `https://heapanalytics.com` | `https://us.posthog.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| Price for analytics events | not published | $0.0001 per transaction |\n| x402 | no | no |\n| Licence | Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT | MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms |\n| Tools exposed | none | 1096 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `io.github.PostHog/mcp` |\n| Last release | 2026-10-06 | 2026-10-05 |\n| Terms last updated | no date given | 2026-06-29 |\n| Privacy policy last updated | couldn't be read | 2026-06-29 |\n| Customer content may train models | yes | yes, with an opt-out |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 213 npm/wk | 40k stars, 15.2M npm/wk |\n\n## Verdicts\n\n**Heap.** Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.\n\n**PostHog.** PostHog suits agents that need to query product data and manage flags or experiments. Its hosted MCP server has OAuth scopes, a read-only mode and a one-tool CLI mode over 1,096 tools. The status page shows 31 incidents in 90 days, four on analytics queries, and three security incidents were disclosed in the last year.\n\n## Before you call either\n\n### Heap\n\n1. Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same\n2. Pass one of `identity` or `user_id` on track, never both\n3. Set `idempotency_key` on every track event so a retry doesn't duplicate it\n4. Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call\n5. For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized\n\n### PostHog\n\n1. Add `?readonly=true` or the `x-posthog-read-only` header to the MCP URL unless the task needs writes\n2. Pin the session with `x-posthog-project-id`, which also removes the `switch-project` and `switch-organization` tools\n3. In CLI mode run `info \u003ctool\u003e` once before `call`, and send one `exec` command per request\n4. On a 429 with code `api_queries_budget_exceeded`, wait for `Retry-After` and read `X-PostHog-Query-Budget-Remaining-Bytes`\n5. Page SQL results by keyset on `timestamp`. `OFFSET` returns 400 for personal API keys, and results cap at 50,000 rows\n\n## Questions\n\n### Which is better for AI agents, Heap or PostHog?\n\nPostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category.\n\n### Do Heap and PostHog need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Heap and PostHog without installing anything?\n\nYes. Heap has a hosted endpoint at https://heapanalytics.com and PostHog at https://us.posthog.com.\n\n### Are Heap and PostHog open source?\n\nNo open-source release is listed for Heap. PostHog is open source (MIT for the repository outside the `ee` directory, which has its own licence. PostHog Cloud is a hosted service under PostHog's terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/heap-vs-posthog.json, and with the fewest tokens: https://www.anchorterminal.com/compare/heap-vs-posthog.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"heap\", \"b\": \"posthog\"}`. From a terminal: `anchor compare heap posthog`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/heap.json and https://www.anchorterminal.com/api/v1/tools/posthog.json\n\n## Other comparisons with Heap or PostHog\n\n- [Amplitude vs PostHog](https://www.anchorterminal.com/compare/amplitude-vs-posthog.md)\n- [Mixpanel vs PostHog](https://www.anchorterminal.com/compare/mixpanel-vs-posthog.md)\n- [Pendo vs PostHog](https://www.anchorterminal.com/compare/pendo-vs-posthog.md)\n- [PostHog vs Statsig](https://www.anchorterminal.com/compare/posthog-vs-statsig.md)\n- [Amplitude vs Heap](https://www.anchorterminal.com/compare/amplitude-vs-heap.md)\n- [GrowthBook vs Heap](https://www.anchorterminal.com/compare/growthbook-vs-heap.md)\n- [Heap vs Mixpanel](https://www.anchorterminal.com/compare/heap-vs-mixpanel.md)\n- [Heap vs Pendo](https://www.anchorterminal.com/compare/heap-vs-pendo.md)\n- [Heap vs Statsig](https://www.anchorterminal.com/compare/heap-vs-statsig.md)\n- [GrowthBook vs PostHog](https://www.anchorterminal.com/compare/growthbook-vs-posthog.md)\n- [LaunchDarkly vs PostHog](https://www.anchorterminal.com/compare/launchdarkly-vs-posthog.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Heap vs PostHog",
        "url": ""
      }
    ],
    "description": "PostHog scores 68.4 (B) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Heap D 53",
      "PostHog B 68.4",
      "scores"
    ],
    "h1": "Heap vs PostHog",
    "image": "https://www.anchorterminal.com/assets/og/compare-heap-vs-posthog.png",
    "path": "/compare/heap-vs-posthog",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Heap vs PostHog for AI agents, D 53 vs B 68.4 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/heap-vs-posthog"
  },
  "tokens": {
    "markdown": 2100,
    "slim": 730
  },
  "version": 1
}
