Cloud, hosting & identity · wired today
Drive Heroku with governed agents
Infrastructure state changes under you; agents need to read it live. The Heroku connector is one of 205 executable connectors and gives agents 4 read-only tools, with the credential held in the vault and every call receipted.
What agents can run against Heroku
| Tool | What it does |
|---|---|
list_apps | List the Heroku apps this API key can see |
get_app | Get one Heroku app by name or UUID, with its region, stack, owner and maintenance state |
list_dynos | List the running dynos for one Heroku app, with size, state and current release version |
list_releases | List the releases (deploy and config history) for one Heroku app |
Every tool above is read-only. Write surfaces ship only after live testing, and always behind approval gates.
What the Heroku connector needs
You provide API key from your Heroku account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.
Where to get it: Heroku's own API documentation ↗ covers creating and scoping the credential.
How proven is this?
This connector was blind shape-proven against the real Heroku API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.
Heroku integration FAQ
What can Quox agents do with Heroku?
Agents can run 4 read-only tools against Heroku: list apps, get app, list dynos, list releases. Every call is receipted in the evidence trail.
What does the Heroku integration need?
You provide API key from your Heroku account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.
Do agents see my Heroku credentials?
No. Credentials live encrypted in the Quox vault and are resolved server-side at call time. Agents invoke tools; they never receive the underlying secret.
How proven is the Heroku connector?
This connector was blind shape-proven against the real Heroku API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.