Credentials and identifiers
Select the credential accepted by the exact HeyCrust interface.
On this page
What you need
Access to the intended app’s Developers settings and authorization to store or rotate credentials.
Steps
- Identify the interface in the table below before copying a credential.
- Store private credentials only in server environment/secret storage. Copy the app’s HeyCrust UUID from its page; verify the numeric Shopify ID/client ID separately.
- For an affiliate API integration, create a labeled app-scoped key with the least required scopes in Affiliate Developers. Save the one-time value privately.
- For an affiliate-key rotation, update the integration and verify its new credential before revoking an old key where supported. Workspace Regenerate immediately invalidates the previous workspace key; coordinate its consumers before using it. Revocation prevents subsequent use.
- Test a harmless read using the intended scope. Keep credentials out of query strings, commits, logs and screenshots.
Expected result
The interface accepts the intended credential and sees only its permitted app/tools. An authentication success does not imply permission for every operation.
Credential map
| Credential | Where it belongs |
|---|---|
crst_ workspace key | Backend identify/events and broad owner MCP |
crstpx_ app browser token | Embedded browser snippet and /api/track; analytics-grade, not a private backend key |
hcak_ app-scoped key | Public affiliate REST; partner-quality MCP with all required read scopes |
hcaip_ production / hcait_ test | Signed affiliate install claims for that app and mode |
hcar_ referral link token | Public referral URL, not an API credential |
| Shopify app client secret | Signed Shopify token/webhook verification; private and app-specific |
Identifier map
Use HeyCrust UUID appId for backend events, identify and filters. Use digits-only numericAppId for the install claim. Shopify listing api_key is the Shopify client ID, not that numeric ID. GA4 property/stream IDs are numeric; a G-... measurement ID is a separate listing-setting value.
See API authentication and MCP connection.
Troubleshooting
401 commonly means wrong credential class or revoked key; 403 can mean a missing scope/app grant. A scoped hcak_ key cannot operate owner Flow/setup tools. An install key cannot substitute for REST/MCP credentials.