# Heap (slim) > Heap is Contentsquare's product analytics service, which captures web and mobile interactions automatically. Its server-side HTTP API accepts custom events, identities, user and account properties, and user deletion requests. - Full: https://www.anchorterminal.com/tools/heap.md (~6,750 tokens) · this version ~1,630 tokens · JSON https://www.anchorterminal.com/tools/heap.json · canonical https://www.anchorterminal.com/tools/heap - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 53/100 · rank #488 of 629 · #7 in Product analytics & experimentation · not agent-ready · confidence low** Assessment: Heap's server-side API suits an agent that records events. Limits are published, bulk calls take 1,000 items and track accepts an idempotency key. The API returns no analytics, and ingest calls carry no secret beyond the environment ID. Heap's help centre lists a Heap MCP article, which a bot check stopped us reading, so the MCP server is ungraded. ## Facts - Kind: HTTP API · vendor: Contentsquare (Content Square, Inc.) · category: Product analytics & experimentation · legal entity: Content Square, Inc. · provenance 66/100 - Endpoint: `https://heapanalytics.com` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Contentsquare's master services agreement. The React Native bridge and the Node client on npm are MIT - Probe metrics: not measured yet (probes haven't run) - Surface graded: The server-side HTTP API at https://heapanalytics.com (EU projects at https://c.eu.heap-api.com). The Heap MCP server named in the help centre was not read - Endpoints: POST /api/track (single or bulk), POST /api/v1/identify, POST /api/add_user_properties, POST /api/add_account_properties, POST /api/public/v0/auth_token, POST /api/public/v0/user_deletion, GET /api/public/v0/deletion_status/:id - Credentials: Ingest calls send only `app_id` (the environment ID). User deletion uses HTTP Basic with app_id and an admin-generated API key to get a temporary Bearer token - Rate limits: Track and add user properties 30 requests per 30 seconds per identity per app_id. Bulk track 1,000 events a minute per identity and 15,000 a minute per app_id - Batch sizes: 1,000 events per bulk track request, 1,000 users per bulk property request, 10,000 users per deletion request - Idempotency: `idempotency_key` on track and bulk track. Property calls overwrite the previous value - Docs for agents: https://developers.heap.io/llms.txt and a .md copy of each page, with OpenAPI 3.1 fragments embedded in the track and identify pages. No single spec file found - SDKs: Client capture SDKs for web (heap.js 5.3.17, 6 October 2026), Android, iOS, React Native and Flutter. The Node client heap-api on npm is 1.0.1 and dates from 2016 - Plans: Free up to 10,000 sessions a month with six months of history. Growth by estimate after signup. Pro and Premier by quote. Heap Connect is an add-on for Pro and included in Premier - SLA: 99.5 per cent availability of the user interface on Pro and Enterprise plans, with service credits, per Contentsquare's support package - Status: status.heap.io on Statuspage with components for Data Collection, App, Heap Connect, Session Replay, integrations and alerts - Certifications: SOC 2 Type II, ISO 27001, 27017, 27018 and 27701 per trust.contentsquare.com. Bug bounty on YesWeHack by invitation after a valid report - Data location: AWS, with the customer choosing Europe (Ireland, with Frankfurt at rest) or the USA (Virginia). OpenAI is the LLM sub-processor for Sense Chat - Prices: Free free per month (plan) - Scores: Reliability 72, Performance pending, Schema & documentation 57, Agent ergonomics 49, Security & auth 41, Payments & pricing 25, Task success pending, Maintenance & community 63, Transparency & trust 64 · total over the 7 assessed categories - Why: Reliability, Graded on the server-side API with the hosted lines. · Schema & documentation, OpenAPI 3.1 fragments are embedded in the Markdown of the track and identify pages. · Agent ergonomics, Responses are an empty object, so context cost is small, but there is nothing to read back (15). · Security & auth, Track, identify and property calls carry no secret. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, heap.js 5.3.17 shipped on 6 October 2026, but that is the browser SDK. · Transparency & trust, Closed service with published terms, now Contentsquare's master services agreement (15). - Sources: 22, open questions: 6, both in the full twin - Capabilities: analytics.events - JSON: https://www.anchorterminal.com/api/v1/tools/heap.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/heap.svg` or a link to https://www.anchorterminal.com/tools/heap from a page on heap.io or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send EU projects to https://c.eu.heap-api.com instead of https://heapanalytics.com. The path stays the same 2. Pass one of `identity` or `user_id` on track, never both 3. Set `idempotency_key` on every track event so a retry doesn't duplicate it 4. Stay under 30 requests per 30 seconds per identity, or batch up to 1,000 events in one bulk call 5. For deletion, exchange the app_id and API key of the Main Production environment for a token first. Any other environment ID returns Unauthorized ## Connect ```bash curl -X POST \ -H "Content-Type: application/json" \ -d '{ "app_id": "11", "identity": "alice@example.com", "event": "Send Transactional Email", "properties": {"subject": "Welcome to My App!"} }' \ https://heapanalytics.com/api/track ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/heap ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Statsig | BB | 72.3 | analytics.events | https://www.anchorterminal.com/tools/statsig.min.md | | GrowthBook | BB | 70.1 | analytics.events | https://www.anchorterminal.com/tools/growthbook.min.md | | PostHog | B | 68.4 | analytics.events | https://www.anchorterminal.com/tools/posthog.min.md | | Amplitude | B | 66.2 | analytics.events | https://www.anchorterminal.com/tools/amplitude.min.md | | Mixpanel | B | 62 | analytics.events | https://www.anchorterminal.com/tools/mixpanel.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)