# Credentials and identifiers

Select the credential accepted by the exact HeyCrust interface.

## What you need

Access to the intended app’s Developers settings and authorization to store or rotate credentials.

## Steps

1. Identify the interface in the table below before copying a credential.
2. Store private credentials only in server environment/secret storage. Copy the app’s HeyCrust UUID from its page; verify the numeric Shopify ID/client ID separately.
3. For an affiliate API integration, create a labeled app-scoped key with the least required scopes in Affiliate Developers. Save the one-time value privately.
4. For an affiliate-key rotation, update the integration and verify its new credential before revoking an old key where supported. Workspace **Regenerate** immediately invalidates the previous workspace key; coordinate its consumers before using it. Revocation prevents subsequent use.
5. Test a harmless read using the intended scope. Keep credentials out of query strings, commits, logs and screenshots.

## Expected result

The interface accepts the intended credential and sees only its permitted app/tools. An authentication success does not imply permission for every operation.

## Credential map

| Credential | Where it belongs |
| --- | --- |
| `crst_` workspace key | Backend identify/events and broad owner MCP |
| `crstpx_` app browser token | Embedded browser snippet and `/api/track`; analytics-grade, not a private backend key |
| `hcak_` app-scoped key | Public affiliate REST; partner-quality MCP with all required read scopes |
| `hcaip_` production / `hcait_` test | Signed affiliate install claims for that app and mode |
| `hcar_` referral link token | Public referral URL, not an API credential |
| Shopify app client secret | Signed Shopify token/webhook verification; private and app-specific |

## Identifier map

Use HeyCrust UUID `appId` for backend events, identify and filters. Use digits-only `numericAppId` for the install claim. Shopify listing `api_key` is the Shopify client ID, not that numeric ID. GA4 property/stream IDs are numeric; a `G-...` measurement ID is a separate listing-setting value.

See [API authentication](/docs/api) and [MCP connection](/docs/mcp/connect).

## Troubleshooting

401 commonly means wrong credential class or revoked key; 403 can mean a missing scope/app grant. A scoped `hcak_` key cannot operate owner Flow/setup tools. An install key cannot substitute for REST/MCP credentials.
