{
  "data": {
    "a": {
      "slug": "heap",
      "name": "Heap",
      "vendor": "Contentsquare (Content Square, Inc.)",
      "vendorUrl": "https://www.heap.io",
      "kind": "http-api",
      "category": "product-analytics",
      "summary": "Heap is Contentsquare's product analytics service, which captures web and mobile interactions automatically. Its server-side HTTP API accepts custom events, identities, user and account properties, and user deletion requests.",
      "url": "https://www.anchorterminal.com/tools/heap",
      "markdownUrl": "https://www.anchorterminal.com/tools/heap.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/heap.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/heap.json",
      "license": "Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://heapanalytics.com",
      "packages": [
        {
          "registry": "npm",
          "name": "heap-api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Track, identify and property calls need only `app_id`, the environment ID shown on the Projects page and used in the web snippet, with no secret. User deletion needs an API key that an admin generates under Account, Manage, Privacy \u0026 Security, exchanged by HTTP Basic for a temporary Bearer token. No OAuth, scopes or partner approval were found in the developer docs.",
      "pricing": "freemium",
      "pricingNotes": "Free plan up to 10,000 sessions a month with six months of history, APIs included, so an agent's owner can start without a contract. Growth is priced by estimate after signup, and Pro and Premier by quote. Whether signup asks for a card was not established (https://www.heap.io/pricing, checked 2026-10-07).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 213,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.heap.io",
      "llmsTxt": "https://developers.heap.io/llms.txt",
      "capabilities": [
        "analytics.events"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "llms-txt",
        "free-tier",
        "no-oauth",
        "write-only",
        "eu-region",
        "status-page",
        "soc2",
        "sales-led"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53,
        "grade": "D",
        "agentReady": false,
        "rank": 488,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 49,
          "maintenance": 63,
          "payments": 25,
          "reliability": 72,
          "schema": 57,
          "security": 41,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "low",
          "date": "2026-10-07"
        },
        "negative": 0,
        "verdict": "Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.",
        "bestFor": "An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.",
        "strengths": [
          "Rate limits are published. Track allows 30 requests per 30 seconds per identity, and bulk track 15,000 events a minute per environment",
          "Track and bulk track accept an `idempotency_key`, and bulk calls take up to 1,000 events or users per request",
          "llms.txt and a Markdown copy of every developer page, with an OpenAPI 3.1 fragment embedded in the reference pages we read",
          "Free plan with up to 10,000 sessions a month and six months of history, with APIs and the User Privacy API included",
          "Sub-processor list (June 2026) names AWS regions in Ireland, Frankfurt and Virginia, and the customer chooses Europe or the USA"
        ],
        "weaknesses": [
          "No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read",
          "Track, identify and property calls carry no secret. The only identifier is the environment ID that the web snippet also publishes",
          "Three incidents marked major on status.heap.io in the 90 days to 7 October 2026, one of them still open",
          "Paid plans have no public price. Growth asks for an estimate after signup, and Pro and Premier say Contact Us",
          "Error responses for track and identify are documented as a 400 with an empty object, and no 429 guidance was found"
        ],
        "agentNotes": [
          "Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same",
          "Pass one of `identity` or `user_id` on track, never both",
          "Set `idempotency_key` on every track event so a retry doesn't duplicate it",
          "Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call",
          "For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "low",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53
          }
        ],
        "editorialScores": {
          "ergonomics": 49,
          "maintenance": 63,
          "payments": 25,
          "reliability": 72,
          "schema": 57,
          "security": 41,
          "transparency": 61
        },
        "provenanceScore": 66
      },
      "connect": {
        "http": "curl -X POST \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"app_id\": \"11\",\n    \"identity\": \"alice@example.com\",\n    \"event\": \"Send Transactional Email\",\n    \"properties\": {\"subject\": \"Welcome to My App!\"}\n  }' \\\n  https://heapanalytics.com/api/track"
      },
      "letme": {
        "capability": "https://letme.dev/analytics.events",
        "tool": "https://letme.dev/heap"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Free",
          "unit": "month",
          "usd": 0,
          "note": "up to 10,000 sessions a month"
        }
      ],
      "provenance": {
        "legalEntity": "Content Square, Inc.",
        "domain": "heap.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.heap.io/legal/heap-master-services-agreement",
        "privacy": "https://www.heap.io/privacy",
        "statusPage": "https://status.heap.io",
        "changelog": "https://developers.heap.io/docs/heapjs-5-changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Heap master services agreement URL redirects to Contentsquare's terms at contentsquare.com/legal/terms-conditions. The entity schedule names Content Square, Inc., 60 Hudson St, New York, for customers in the Americas, and other Contentsquare entities elsewhere.",
          "heap.io/terms is a website terms of use from Heap Inc., a Delaware corporation, last updated 30 August 2019. heap.io/privacy says the Heap policy has been consolidated into Contentsquare's.",
          "API calls go to heapanalytics.com and, for EU projects, c.eu.heap-api.com. Both are Heap domains named in the vendor's docs, not heap.io itself.",
          "www.heap.io/.well-known/security.txt and heapanalytics.com/.well-known/security.txt return 404. contentsquare.com publishes a signed security.txt that expires on 31 January 2028.",
          "RDAP has no service for .io through rdap.org, so the registration date of heap.io was not established.",
          "The only changelogs found are for the SDKs (heap.js 5, Android, iOS, React Native, Flutter). No changelog for the server-side API was found."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/heap.json",
      "live": {
        "slug": "heap",
        "probe": {
          "target": "https://heapanalytics.com",
          "method": "get",
          "lastAt": "2026-10-08T19:08:48.676585957Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 737,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 328,
          "p95ms24h": 444,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.heap.io",
          "indicator": "minor",
          "summary": "Minor Service Outage",
          "checkedAt": "2026-10-08T19:06:41.899926253Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "heap-api",
            "version": "1.0.1",
            "seenAt": "2026-10-08T16:15:35.796443098Z"
          }
        ],
        "npmWeekly": 213,
        "securityTxt": {
          "url": "https://heap.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:30.698501929Z"
        },
        "pages": [
          {
            "url": "https://developers.heap.io/docs/heapjs-5-changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:42.369829827Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "65fc0b011bef"
          },
          {
            "url": "https://www.heap.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:12.583035239Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e41474dc6c8"
          },
          {
            "url": "https://www.heap.io/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:15.159309204Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9848a05d56da"
          },
          {
            "url": "https://www.heap.io/legal/heap-master-services-agreement",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:10.261171384Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f20f9632d33b"
          }
        ],
        "updatedAt": "2026-10-08T19:08:48.676585957Z"
      }
    },
    "answer": "Statsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category.",
    "b": {
      "slug": "statsig",
      "name": "Statsig",
      "vendor": "Amplitude, Inc.",
      "vendorUrl": "https://www.statsig.com",
      "kind": "http-api",
      "category": "product-analytics",
      "summary": "Statsig is a hosted platform for feature flags, experiments and product analytics, run by Amplitude, Inc. since May 2026. Agents reach it through the Console API, which has a public OpenAPI spec, and an official hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/statsig",
      "markdownUrl": "https://www.anchorterminal.com/tools/statsig.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/statsig.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/statsig.json",
      "repo": "https://github.com/statsig-io/statsig-server-core",
      "license": "Proprietary hosted service under Statsig's self-service or enterprise terms. The SDKs and the agent skills repository on GitHub are ISC",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.statsig.com/v3/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@statsig/statsig-node-core"
        },
        {
          "registry": "npm",
          "name": "@statsig/js-client"
        },
        {
          "registry": "pypi",
          "name": "statsig-python-core"
        },
        {
          "registry": "npm",
          "name": "@statsig/siggy"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. The Console API takes a Console API key in the `STATSIG-API-KEY` header, created in project settings as read-only or read and write. The MCP server uses OAuth with PKCE and dynamic client registration, which issues a personal Console API key carrying the user's role, or takes a Console key in the `statsig-api-key` header. OAuth needs the organisation owner to allow personal keys for the role. Flag evaluation and event logging take a client or server SDK key.",
      "pricing": "freemium",
      "pricingNotes": "Free Developer plan with no card, covering 2 million events and 50,000 session replays a month. Pro is $150 a month with 5 million events, then $0.05 per 1,000 events. Enterprise is by contract. Flag and config checks are unlimited on every plan, and API and MCP calls are not billed. An agent can start on the free plan without a contract (https://www.statsig.com/pricing, checked 2026-10-08).",
      "priceSummary": "$150 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs corpus, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 18,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 4157066,
        "pypiWeekly": 893619,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.statsig.com/console-api/introduction",
      "llmsTxt": "https://docs.statsig.com/llms.txt",
      "openapi": "https://api.statsig.com/openapi/20240601.json",
      "registryName": "com.statsig/statsig-mcp-server",
      "capabilities": [
        "analytics.experiments",
        "analytics.flags",
        "analytics.query",
        "analytics.events"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "soc2",
        "eu-region"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 72.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 89,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 81,
          "payments": 40,
          "reliability": 79,
          "schema": 82,
          "security": 74,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Statsig suits agents that manage feature gates and experiments and read their results. Its MCP server has 18 default tools, OAuth, read-only access by project and role, and a confirmation on updates. Errors carry only a status and a message, no idempotency keys were found, and the privacy notice is Amplitude's and doesn't name Statsig.",
        "bestFor": "An agent that creates, updates and cleans up feature gates, dynamic configs and experiments, and reads experiment results and audit history.",
        "strengths": [
          "Hosted MCP server with 18 default tools and a discovery layer that replaced 93 tools on the V1 server",
          "MCP access set per project and per role as no access, read only or read and write, with a confirmation on updates",
          "Public OpenAPI 3.0 spec with 325 operations, plus llms.txt and a Markdown copy of every docs page",
          "Free Developer plan with no card and 2 million events a month, and a public overage price of $0.05 per 1,000 events on Pro",
          "Audit logs kept indefinitely and readable through the API and the `log_read` MCP tool"
        ],
        "weaknesses": [
          "Console API errors carry only `status` and `message`, and the spec documents no 429 response",
          "No idempotency keys were found, and most MCP update tools replace the whole resource",
          "The project Console API key reads and writes everything in a project unless created read-only",
          "The privacy notice is Amplitude's, last updated 31 August 2026, and doesn't name Statsig",
          "The 99.95 per cent SLA needs Enterprise premium support and covers the Console user interface"
        ],
        "agentNotes": [
          "Connect to https://api.statsig.com/v3/mcp. The official MCP registry entry still lists the V1 URL, which has 93 tools",
          "Call `get_context` first to learn the project, your permissions and the review settings",
          "Read the resource before `gate_update`, `experiment_update` or `dynamic_config_update`. They replace the whole resource, so resend every field you want kept",
          "Use `discover_tools` for partial edits, and fetch a fresh `operationHandle` when one expires",
          "On a 429 slow down and back off with jitter. Rejected attempts count towards the quota of about 1,800 mutations per 15 minutes"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 72.3
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 81,
          "payments": 40,
          "reliability": 79,
          "schema": 82,
          "security": 74,
          "transparency": 64
        },
        "provenanceScore": 85
      },
      "connect": {
        "claudeCode": "claude mcp add --transport http statsig https://api.statsig.com/v3/mcp",
        "config": {
          "mcpServers": {
            "statsig": {
              "url": "https://api.statsig.com/v3/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/analytics.experiments",
        "tool": "https://letme.dev/statsig"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 150,
          "note": "5 million events and 100,000 session replays included"
        },
        {
          "item": "Metered event",
          "unit": "tx",
          "usd": 0.00005,
          "note": "Pro plan, above 5 million a month"
        }
      ],
      "provenance": {
        "legalEntity": "Amplitude, Inc.",
        "domain": "statsig.com",
        "domainRegistered": "1998-12-29",
        "endpointOnVendorDomain": true,
        "terms": "https://www.statsig.com/terms",
        "privacy": "https://amplitude.com/privacy",
        "statusPage": "https://status.statsig.com",
        "changelog": "https://www.statsig.com/updates",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The self-service subscription agreement at statsig.com/terms, effective 4 August 2025, names Amplitude, Inc. as the party called Statsig. The enterprise terms (effective 18 February 2026) and the DPA do the same.",
          "statsig.com/privacy redirects to amplitude.com/privacy, a notice last updated 31 August 2026 that covers Amplitude, Inc. and its affiliates and doesn't name Statsig. It says it does not apply to end-user data that customers send to the product.",
          "statsig.com/legal/subprocessors redirects to amplitude.com/subprocessor-list, last updated 13 May 2026, which marks the providers used for Statsig-branded services.",
          "The MCP server answers at api.statsig.com. The Console API answers at statsigapi.net, a second domain the vendor's docs name.",
          "www.statsig.com/.well-known/security.txt returns 404.",
          "RDAP for statsig.com gives a registration date of 1998-12-29."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/statsig.json",
      "live": {
        "slug": "statsig",
        "probe": {
          "target": "https://api.statsig.com/v3/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:08:59.357008357Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 42,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 42,
          "p95ms24h": 78,
          "samples24h": 19,
          "samples30d": 19,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 19,
              "ok": 19
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.statsig.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:07:00.240933873Z"
        },
        "pages": [
          {
            "url": "https://www.statsig.com/updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:46.247718302Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3bba7a8e7236"
          },
          {
            "url": "https://www.statsig.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:41.954344318Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d0e8593f7c0e"
          },
          {
            "url": "https://www.statsig.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:44.722171717Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "dc465dc5a41d"
          }
        ],
        "updatedAt": "2026-10-08T19:08:59.357008357Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Contentsquare (Content Square, Inc.)",
        "b": "Amplitude, Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://heapanalytics.com",
        "b": "https://api.statsig.com/v3/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "not published",
        "b": "$0.0001 per transaction",
        "name": "Price for analytics events"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT",
        "b": "Proprietary hosted service under Statsig's self-service or enterprise terms. The SDKs and the agent skills repository on GitHub are ISC",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "18",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.statsig/statsig-mcp-server",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-06",
        "b": "2026-09-28",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2025-08-04",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-08-31",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "213 npm/wk",
        "b": "4.2M npm/wk, 894k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Statsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category.",
        "question": "Which is better for AI agents, Heap or Statsig?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Heap and Statsig need an API key?"
      },
      {
        "answer": "Yes. Heap has a hosted endpoint at https://heapanalytics.com and Statsig at https://api.statsig.com/v3/mcp.",
        "question": "Can an agent call Heap and Statsig without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.",
        "slug": "heap",
        "watchFor": "No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read"
      },
      {
        "aheadOn": [
          "Reliability, 79 against 72",
          "Schema \u0026 documentation, 82 against 57",
          "Agent ergonomics, 71 against 49",
          "Security \u0026 auth, 74 against 41",
          "Payments \u0026 pricing, 40 against 25",
          "Maintenance \u0026 community, 81 against 63",
          "Transparency \u0026 trust, 75 against 64"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Free to start without a card"
        ],
        "goodFor": "An agent that creates, updates and cleans up feature gates, dynamic configs and experiments, and reads experiment results and audit history.",
        "slug": "statsig",
        "watchFor": "Console API errors carry only `status` and `message`, and the spec documents no 429 response"
      }
    ],
    "job": {
      "capability": "analytics.events",
      "name": "Analytics events"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amplitude-vs-statsig.json",
        "title": "Amplitude vs Statsig",
        "url": "https://www.anchorterminal.com/compare/amplitude-vs-statsig"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mixpanel-vs-statsig.json",
        "title": "Mixpanel vs Statsig",
        "url": "https://www.anchorterminal.com/compare/mixpanel-vs-statsig"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pendo-vs-statsig.json",
        "title": "Pendo vs Statsig",
        "url": "https://www.anchorterminal.com/compare/pendo-vs-statsig"
      },
      {
        "json": "https://www.anchorterminal.com/compare/posthog-vs-statsig.json",
        "title": "PostHog vs Statsig",
        "url": "https://www.anchorterminal.com/compare/posthog-vs-statsig"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amplitude-vs-heap.json",
        "title": "Amplitude vs Heap",
        "url": "https://www.anchorterminal.com/compare/amplitude-vs-heap"
      },
      {
        "json": "https://www.anchorterminal.com/compare/growthbook-vs-heap.json",
        "title": "GrowthBook vs Heap",
        "url": "https://www.anchorterminal.com/compare/growthbook-vs-heap"
      },
      {
        "json": "https://www.anchorterminal.com/compare/heap-vs-mixpanel.json",
        "title": "Heap vs Mixpanel",
        "url": "https://www.anchorterminal.com/compare/heap-vs-mixpanel"
      },
      {
        "json": "https://www.anchorterminal.com/compare/heap-vs-pendo.json",
        "title": "Heap vs Pendo",
        "url": "https://www.anchorterminal.com/compare/heap-vs-pendo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/heap-vs-posthog.json",
        "title": "Heap vs PostHog",
        "url": "https://www.anchorterminal.com/compare/heap-vs-posthog"
      },
      {
        "json": "https://www.anchorterminal.com/compare/growthbook-vs-statsig.json",
        "title": "GrowthBook vs Statsig",
        "url": "https://www.anchorterminal.com/compare/growthbook-vs-statsig"
      },
      {
        "json": "https://www.anchorterminal.com/compare/launchdarkly-vs-statsig.json",
        "title": "LaunchDarkly vs Statsig",
        "url": "https://www.anchorterminal.com/compare/launchdarkly-vs-statsig"
      }
    ],
    "scores": [
      {
        "by": 7,
        "edge": "statsig",
        "heap": 72,
        "key": "reliability",
        "name": "Reliability",
        "statsig": 79,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "edge": "statsig",
        "heap": 57,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "statsig": 82,
        "weight": 13
      },
      {
        "by": 22,
        "edge": "statsig",
        "heap": 49,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "statsig": 71,
        "weight": 13
      },
      {
        "by": 33,
        "edge": "statsig",
        "heap": 41,
        "key": "security",
        "name": "Security \u0026 auth",
        "statsig": 74,
        "weight": 14
      },
      {
        "by": 15,
        "edge": "statsig",
        "heap": 25,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "statsig": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 18,
        "edge": "statsig",
        "heap": 63,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "statsig": 81,
        "weight": 7
      },
      {
        "by": 11,
        "edge": "statsig",
        "heap": 64,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "statsig": 75,
        "weight": 7
      }
    ],
    "summary": "Statsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events.",
    "verdicts": {
      "heap": "Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.",
      "statsig": "Statsig suits agents that manage feature gates and experiments and read their results. Its MCP server has 18 default tools, OAuth, read-only access by project and role, and a confirmation on updates. Errors carry only a status and a message, no idempotency keys were found, and the privacy notice is Amplitude's and doesn't name Statsig."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/heap-vs-statsig",
    "json": "https://www.anchorterminal.com/compare/heap-vs-statsig.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/heap-vs-statsig.md",
    "slim": "https://www.anchorterminal.com/compare/heap-vs-statsig.min.md"
  },
  "markdown": "Statsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events.\n\n- Heap: grade D, 53/100, rank #488 of 629. Markdown https://www.anchorterminal.com/tools/heap.md · JSON https://www.anchorterminal.com/api/v1/tools/heap.json\n- Statsig: grade BB, 72.3/100, rank #89 of 629. Markdown https://www.anchorterminal.com/tools/statsig.md · JSON https://www.anchorterminal.com/api/v1/tools/statsig.json\n\n## Which one, for what\n\n### Heap (D)\n\nGood for: An agent that records backend events or enriches user and account properties in a company's existing Heap project, or that files privacy deletions.\n\nWatch for: No query, export or definitions endpoint in the developer reference. Reading results needs the app, Heap Connect or the MCP server we couldn't read\n\n### Statsig (BB)\n\nGood for: An agent that creates, updates and cleans up feature gates, dynamic configs and experiments, and reads experiment results and audit history.\n\nAhead on:\n- Reliability, 79 against 72\n- Schema \u0026 documentation, 82 against 57\n- Agent ergonomics, 71 against 49\n- Security \u0026 auth, 74 against 41\n- Payments \u0026 pricing, 40 against 25\n- Maintenance \u0026 community, 81 against 63\n- Transparency \u0026 trust, 75 against 64\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Free to start without a card\n\nWatch for: Console API errors carry only `status` and `message`, and the spec documents no 429 response\n\n\n## Score by category\n\n| Category | Weight | Heap | Statsig | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 72 | 79 | Statsig +7 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 57 | 82 | Statsig +25 |\n| Agent ergonomics | 13% (16.2 this run) | 49 | 71 | Statsig +22 |\n| Security \u0026 auth | 14% (17.5 this run) | 41 | 74 | Statsig +33 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 40 | Statsig +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 63 | 81 | Statsig +18 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 75 | Statsig +11 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **53 · D** | **72.3 · BB** | |\n\n## Facts side by side\n\n| Fact | Heap | Statsig |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Contentsquare (Content Square, Inc.) | Amplitude, Inc. |\n| Hosted endpoint | `https://heapanalytics.com` | `https://api.statsig.com/v3/mcp` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| Price for analytics events | not published | $0.0001 per transaction |\n| x402 | no | no |\n| Licence | Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT | Proprietary hosted service under Statsig's self-service or enterprise terms. The SDKs and the agent skills repository on GitHub are ISC |\n| Tools exposed | none | 18 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `com.statsig/statsig-mcp-server` |\n| Last release | 2026-10-06 | 2026-09-28 |\n| Terms last updated | no date given | 2025-08-04 |\n| Privacy policy last updated | couldn't be read | 2026-08-31 |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 213 npm/wk | 4.2M npm/wk, 894k PyPI/wk |\n\n## Verdicts\n\n**Heap.** Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded.\n\n**Statsig.** Statsig suits agents that manage feature gates and experiments and read their results. Its MCP server has 18 default tools, OAuth, read-only access by project and role, and a confirmation on updates. Errors carry only a status and a message, no idempotency keys were found, and the privacy notice is Amplitude's and doesn't name Statsig.\n\n## Before you call either\n\n### Heap\n\n1. Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same\n2. Pass one of `identity` or `user_id` on track, never both\n3. Set `idempotency_key` on every track event so a retry doesn't duplicate it\n4. Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call\n5. For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized\n\n### Statsig\n\n1. Connect to https://api.statsig.com/v3/mcp. The official MCP registry entry still lists the V1 URL, which has 93 tools\n2. Call `get_context` first to learn the project, your permissions and the review settings\n3. Read the resource before `gate_update`, `experiment_update` or `dynamic_config_update`. They replace the whole resource, so resend every field you want kept\n4. Use `discover_tools` for partial edits, and fetch a fresh `operationHandle` when one expires\n5. On a 429 slow down and back off with jitter. Rejected attempts count towards the quota of about 1,800 mutations per 15 minutes\n\n## Questions\n\n### Which is better for AI agents, Heap or Statsig?\n\nStatsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category.\n\n### Do Heap and Statsig need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Heap and Statsig without installing anything?\n\nYes. Heap has a hosted endpoint at https://heapanalytics.com and Statsig at https://api.statsig.com/v3/mcp.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/heap-vs-statsig.json, and with the fewest tokens: https://www.anchorterminal.com/compare/heap-vs-statsig.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"heap\", \"b\": \"statsig\"}`. From a terminal: `anchor compare heap statsig`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/heap.json and https://www.anchorterminal.com/api/v1/tools/statsig.json\n\n## Other comparisons with Heap or Statsig\n\n- [Amplitude vs Statsig](https://www.anchorterminal.com/compare/amplitude-vs-statsig.md)\n- [Mixpanel vs Statsig](https://www.anchorterminal.com/compare/mixpanel-vs-statsig.md)\n- [Pendo vs Statsig](https://www.anchorterminal.com/compare/pendo-vs-statsig.md)\n- [PostHog vs Statsig](https://www.anchorterminal.com/compare/posthog-vs-statsig.md)\n- [Amplitude vs Heap](https://www.anchorterminal.com/compare/amplitude-vs-heap.md)\n- [GrowthBook vs Heap](https://www.anchorterminal.com/compare/growthbook-vs-heap.md)\n- [Heap vs Mixpanel](https://www.anchorterminal.com/compare/heap-vs-mixpanel.md)\n- [Heap vs Pendo](https://www.anchorterminal.com/compare/heap-vs-pendo.md)\n- [Heap vs PostHog](https://www.anchorterminal.com/compare/heap-vs-posthog.md)\n- [GrowthBook vs Statsig](https://www.anchorterminal.com/compare/growthbook-vs-statsig.md)\n- [LaunchDarkly vs Statsig](https://www.anchorterminal.com/compare/launchdarkly-vs-statsig.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Heap vs Statsig",
        "url": ""
      }
    ],
    "description": "Statsig scores 72.3 (BB) on agent readiness against Heap's 53 (D), and leads in every scored category. Both do analytics events. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Heap D 53",
      "Statsig BB 72.3",
      "scores"
    ],
    "h1": "Heap vs Statsig",
    "image": "https://www.anchorterminal.com/assets/og/compare-heap-vs-statsig.png",
    "path": "/compare/heap-vs-statsig",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Heap vs Statsig for AI agents, D 53 vs BB 72.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/heap-vs-statsig"
  },
  "tokens": {
    "markdown": 2050,
    "slim": 730
  },
  "version": 1
}
