Head to head · Analytics events · October 2026 research run

Heap vs Statsig

Statsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events.

Which one, for what

Heap D

Good for An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read

Statsig BB

Good for An agent that creates, updates and cleans up feature gates, dynamic configs and experiments, and reads experiment results and audit history.

Ahead on

  • Reliability, 79 against 72
  • Schema & documentation, 82 against 57
  • Agent ergonomics, 71 against 49
  • Security & auth, 74 against 41
  • Payments & pricing, 40 against 25
  • Maintenance & community, 81 against 63
  • Transparency & trust, 75 against 64

Also in its favour

  • Agent-ready, a grade of BB or better
  • Free to start without a card

Watch for

Console API errors carry only status and message, and the spec documents no 429 response

Score by category

CategoryWeight this runHeapStatsigEdge
Reliability16%207279Statsig +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25782Statsig +25
Agent ergonomics13%16.24971Statsig +22
Security & auth14%17.54174Statsig +33
Payments & pricing10%12.52540Statsig +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86381Statsig +18
Transparency & trust7%8.86475Statsig +11
Negative events≤1500
Total53 · D72.3 · BB

Facts side by side

FactHeapStatsig
KindHTTP APIHTTP API
VendorContentsquare (Content Square, Inc.)Amplitude, Inc.
Hosted endpointhttps://heapanalytics.comhttps://api.statsig.com/v3/mcp
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
Price for analytics eventsnot published$0.0001 per transaction
x402nono
LicenceProprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MITProprietary hosted service under Statsig's self-service or enterprise terms. The SDKs and the agent skills repository on GitHub are ISC
Tools exposednone18
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listedcom.statsig/statsig-mcp-server
Last release2026-10-062026-09-28
Terms last updatedno date given2025-08-04
Privacy policy last updatedcouldn't be read2026-08-31
Customer content may train modelsyesnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textyes
Popularity213 npm/wk4.2M npm/wk, 894k PyPI/wk

Verdicts

Heap

Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.

Statsig

Statsig suits agents that manage feature gates and experiments and read their results. Its MCP server has 18 default tools, OAuth, read-only access by project and role, and a confirmation on updates. Errors carry only a status and a message, no idempotency keys were found, and the privacy notice is Amplitude's and doesn't name Statsig.

Before you call either

Heap

  1. Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same
  2. Pass one of identity or user_id on track, never both
  3. Set idempotency_key on every track event so a retry doesn't duplicate it
  4. Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call
  5. For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized

Statsig

  1. Connect to https://api.statsig.com/v3/mcp. The official MCP registry entry still lists the V1 URL, which has 93 tools
  2. Call get_context first to learn the project, your permissions and the review settings
  3. Read the resource before gate_update, experiment_update or dynamic_config_update. They replace the whole resource, so resend every field you want kept
  4. Use discover_tools for partial edits, and fetch a fresh operationHandle when one expires
  5. On a 429 slow down and back off with jitter. Rejected attempts count towards the quota of about 1,800 mutations per 15 minutes

Questions

Which is better for AI agents, Heap or Statsig?

Statsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category.

Do Heap and Statsig need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Heap and Statsig without installing anything?

Yes. Heap has a hosted endpoint at https://heapanalytics.com and Statsig at https://api.statsig.com/v3/mcp.

Other comparisons with Heap or Statsig

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.