Publishing the SDK and the apps

The code of the npm packages and of the Zapier, Make and n8n apps is in the repository, ready. Publishing them to the directories is a step for Hela's publisher, once; the companies using them then need only their own Hela API key, created in Administration → Developers, and their own accounts at the partners.

What companies bring

At What the company supplies itself
Zapier, Make, n8n, Power Automate, MCP Its Hela API key (wanted scopes + webhooks:manage, events:read), its company id, the API address if self-hosted
Stripe, Mollie, PayPal, Square, SumUp, mobile money, Odoo, Yousign, Clockify, Toggl, Shopify, WooCommerce, GoCardless, Ponto, Plaid, WhatsApp, Slack, Twilio… Its own credentials at the partner, entered in Integrations
Google, Microsoft, Dropbox, QuickBooks, Xero, Yuki, Exact, Pennylane, DocuSign, Sage, Zoho, Apple Nothing: the company clicks Continue with…; whoever runs the server registered Hela once with the provider (Keys and environment variables)

npm: @hela/sdk and @hela/mcp

  1. An npm account and a hela organisation (npmjs.com → Add organization), or another prefix to carry into the package.json files.
  2. Both packages live in the pnpm workspace (packages/sdk, packages/mcp) and point at their TypeScript sources. To publish a compiled build: add a tsconfig.build.json with outDir: dist, replace main/types/exports with dist/…, and files with ["dist", "bin", "README.md"].
  3. npm login, then from each folder: pnpm publish --access public. @hela/mcp's bin starts the server through tsx; a dist build makes that unnecessary.
  4. A version follows the API's (3.0.x); an OpenAPI schema change deserves an SDK version.

Zapier

  1. A Zapier developer account and the CLI: npm i -g zapier-platform-cli, zapier login.
  2. In integrations/zapier: npm install, zapier register "Hela" (once; creates .zapierapprc), zapier push. The app is then private: share an invite link (zapier users:add) or publish.
  3. Directory publication (zapier promote, then Developer Platform → Publish): Zapier requires a description, a 256×256 logo, a privacy policy, three test Zaps and a review — two to six weeks. Custom authentication by API key is accepted; the default API address (https://api.hela.co/v1) must answer publicly.
  4. Each company then connects with its key and its company id; no Hela secret is in the app.

Make

  1. A Make account with Custom apps access (Developer Hub).
  2. Create a new app: name hela, then paste the base, connections, webhooks and modules sections of integrations/make/app.json into the matching tabs (the editor expects one block per tab). A square logo for the app.
  3. Test a scenario with your key. Publishing to the directory: Make → Publish → Submit for review (description, privacy policy, a few weeks' review). Meanwhile Share gives a private install link.

n8n

  1. An npm account (the community installs from npm).
  2. In integrations/n8n-nodes-hela: npm install, npm run build (compiles dist/), npm publish --access public. The package.json carries the n8n-community-node-package keyword and the n8n section listing the node, the trigger and the credentials.
  3. Users install from Settings → Community nodes with the package name. For n8n's verified list, submit the repository through the Community node verification form (code review, MIT licence required — which it is).
  4. Version: 3.0.x; a new operation is a minor version.

Power Automate

The custom connector is built from the OpenAPI schema without publication (Power Automate). A certified connector goes through Microsoft's Independent Publisher Connectors programme (public GitHub repository, review); allow four to eight weeks.

MCP server

Beyond npm, two directories list MCP servers: the MCP Registry (registry.modelcontextprotocol.io, a server.json in the repository) and Claude Desktop's list (Anthropic Connectors Directory, a form). Neither is needed for a company to use npx @hela/mcp.

What to keep in mind

  • The keys the apps use are the companies'; Hela holds no secret in any app, and nothing to rotate when a key changes.
  • Directories re-review apps on every version: keep the changelog (What's new) and test against /openapi.json before pushing.

¿Algo incorrecto o ausente? Escríbanos.