Skip to content
HeyCrustDocs

Search documentation

Search by topic or tool name
Browse documentation
Guides

Credentials and identifiers

Select the credential accepted by the exact HeyCrust interface.

On this page

What you need

Access to the intended app’s Developers settings and authorization to store or rotate credentials.

Steps

  1. Identify the interface in the table below before copying a credential.
  2. Store private credentials only in server environment/secret storage. Copy the app’s HeyCrust UUID from its page; verify the numeric Shopify ID/client ID separately.
  3. For an affiliate API integration, create a labeled app-scoped key with the least required scopes in Affiliate Developers. Save the one-time value privately.
  4. For an affiliate-key rotation, update the integration and verify its new credential before revoking an old key where supported. Workspace Regenerate immediately invalidates the previous workspace key; coordinate its consumers before using it. Revocation prevents subsequent use.
  5. Test a harmless read using the intended scope. Keep credentials out of query strings, commits, logs and screenshots.

Expected result

The interface accepts the intended credential and sees only its permitted app/tools. An authentication success does not imply permission for every operation.

Credential map

CredentialWhere it belongs
crst_ workspace keyBackend identify/events and broad owner MCP
crstpx_ app browser tokenEmbedded browser snippet and /api/track; analytics-grade, not a private backend key
hcak_ app-scoped keyPublic affiliate REST; partner-quality MCP with all required read scopes
hcaip_ production / hcait_ testSigned affiliate install claims for that app and mode
hcar_ referral link tokenPublic referral URL, not an API credential
Shopify app client secretSigned Shopify token/webhook verification; private and app-specific

Identifier map

Use HeyCrust UUID appId for backend events, identify and filters. Use digits-only numericAppId for the install claim. Shopify listing api_key is the Shopify client ID, not that numeric ID. GA4 property/stream IDs are numeric; a G-... measurement ID is a separate listing-setting value.

See API authentication and MCP connection.

Troubleshooting

401 commonly means wrong credential class or revoked key; 403 can mean a missing scope/app grant. A scoped hcak_ key cannot operate owner Flow/setup tools. An install key cannot substitute for REST/MCP credentials.