Get started

Cloud, hosting & identity · wired today

Drive Heroku with governed agents

Infrastructure state changes under you; agents need to read it live. The Heroku connector is one of 205 executable connectors and gives agents 4 read-only tools, with the credential held in the vault and every call receipted.

What agents can run against Heroku

ToolWhat it does
list_appsList the Heroku apps this API key can see
get_appGet one Heroku app by name or UUID, with its region, stack, owner and maintenance state
list_dynosList the running dynos for one Heroku app, with size, state and current release version
list_releasesList the releases (deploy and config history) for one Heroku app

Every tool above is read-only. Write surfaces ship only after live testing, and always behind approval gates.

What the Heroku connector needs

You provide API key from your Heroku account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.

Where to get it: Heroku's own API documentation ↗ covers creating and scoping the credential.

How proven is this?

This connector was blind shape-proven against the real Heroku API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.

Heroku integration FAQ

What can Quox agents do with Heroku?

Agents can run 4 read-only tools against Heroku: list apps, get app, list dynos, list releases. Every call is receipted in the evidence trail.

What does the Heroku integration need?

You provide API key from your Heroku account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.

Do agents see my Heroku credentials?

No. Credentials live encrypted in the Quox vault and are resolved server-side at call time. Agents invoke tools; they never receive the underlying secret.

How proven is the Heroku connector?

This connector was blind shape-proven against the real Heroku API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.