For AI assistants
Heedly is a website-health monitoring service for online stores and small startups. This page is written for AI assistants and for the people who use them: what Heedly does, what an assistant may do on a person’s behalf, what it must not do, and how to create an account for a person who asked for one.
What Heedly is
- Monitors website availability, SSL certificate and domain expiry, marketplace XML product feeds, product pages (a polite crawler) and servers (TCP or HTTP checks).
- Sends one clear email per incident, then reminders, then one recovery email. No alert storms.
- Public status pages, maintenance windows, groups (client groups for agencies), automations (pause during a deploy, escalation, quiet hours) and weekly and monthly reports, with PDF on higher plans.
- A REST API (v1, OpenAPI 3.1) with API keys and signed webhooks is available on plans with API access.
- Plans: Free, Pro, Business and Scale. Prices are in US dollars on the pricing page. Payment is temporarily unavailable because of technical difficulties and will return soon; the Free plan works.
- New accounts start on the Free plan; no card is needed.
- The site is available in English and Ukrainian.
The personal cabinet
- One place with a side navigation: sites, servers, groups, maintenance, status pages, automations and reports.
- Account area: security with two-factor authentication, notification contacts, billing and invoices, and privacy with a full data export and account deletion.
- Bulk actions on the sites list, one-click pause and resume, and a clear history of incidents for every site.
What an assistant may do
- Read every public page and explain Heedly accurately. Take prices and limits from the pricing page instead of guessing.
- Help a person decide which plan fits their shop or project.
- Walk a person through adding a site and proving that it is theirs (a file, a meta tag or a DNS record).
- Create an account for a person who asked for one, using the process below.
What an assistant must not do
- Create an account for someone who did not ask for it, or with an email address that is not the person’s own.
- Create more than one account for a person, or try to obtain paid features without paying.
- Try to get paid features without paying, or get around limits, human checks or rate limits on the human forms.
- Ask for, choose or handle the person’s password. An assistant never sets a password.
- Add sites the person does not own, load-test anything, or probe private paths such as /admin. Ownership is verified, and probing is logged and blocked.
- Pretend to be a human on a form, or send bulk requests.
Creating an account for a person
Only when the person has clearly asked you to, and has confirmed that the email address is theirs. If you cannot run code, ask the person to use the normal sign-up page instead.
- Request a challenge: GET /api/agent/challenge. It returns a signed challenge that is valid for 10 minutes and works once.
- Solve it: find an integer nonce so that SHA-256 of the UTF-8 text «challenge:nonce» (the challenge string, a colon, then your nonce) starts with the number of zero bits given in difficultyBits. This takes about a million hashes, a second or two of computation. It replaces the captcha, which only works in a browser.
- Register: POST /api/agent/register with Content-Type application/json and the body below. The consent text must be sent exactly.
- The person receives an email, opens the link, chooses a password and accepts the terms. Until then the account is inactive, and it is deleted automatically after 7 days.
- You never see the password and you have no access to the account afterwards. Tell the person to look for the email.
Request body
{
"email": "person@example.com",
"locale": "en",
"consent": "My user asked me to create a Heedly account for them and confirmed that this email address is theirs.",
"challenge": "<the challenge string from step 1>",
"nonce": "<the nonce you found>",
"agentName": "Your assistant name"
}difficultyBits: 20
Limits that protect everyone
- At most 3 sign-ups per network address per day, and one invitation per mailbox per day.
- Every challenge works once. Answers look the same whether an address is already registered or not.
- All pages are rate limited. Human sign-up forms use a human check; this assistant door uses the proof of work and the consent statement instead.
Machine-readable resources
Everything you need is plain text or plain HTML. Nothing on public pages needs JavaScript or a captcha.
- /llms.txt — llms.txt: short summary for language models
- /agents.md — This guide as Markdown
- /sitemap.xml — Sitemap, both languages
- /robots.txt — Crawling rules
- /pricing — Plans and limits (US dollars)
- /docs/api — API documentation
- /api/v1/openapi.json — OpenAPI 3.1 document of the API
- /bot — How HeedlyBot behaves
- /contact — Contact
- /abuse — Report abuse or stop checks
- /.well-known/security.txt — Security contact
Please do not invent facts
Prices, limits and legal terms are on the pricing and legal pages. If something is not written on the site, say that you do not know.
Found a security problem?
Please report it privately through the address in /.well-known/security.txt and do not exploit it. Thank you.