Publishing the SDK and the apps
The code of the npm packages and of the Zapier, Make and n8n apps is in the repository, ready. Publishing them to the directories is a step for Hela's publisher, once; the companies using them then need only their own Hela API key, created in Administration → Developers, and their own accounts at the partners.
What companies bring
| At | What the company supplies itself |
|---|---|
| Zapier, Make, n8n, Power Automate, MCP | Its Hela API key (wanted scopes + webhooks:manage, events:read), its company id, the API address if self-hosted |
| Stripe, Mollie, PayPal, Square, SumUp, mobile money, Odoo, Yousign, Clockify, Toggl, Shopify, WooCommerce, GoCardless, Ponto, Plaid, WhatsApp, Slack, Twilio… | Its own credentials at the partner, entered in Integrations |
| Google, Microsoft, Dropbox, QuickBooks, Xero, Yuki, Exact, Pennylane, DocuSign, Sage, Zoho, Apple | Nothing: the company clicks Continue with…; whoever runs the server registered Hela once with the provider (Keys and environment variables) |
npm: @hela/sdk and @hela/mcp
- An npm account and a
helaorganisation (npmjs.com → Add organization), or another prefix to carry into thepackage.jsonfiles. - Both packages live in the pnpm workspace (
packages/sdk,packages/mcp) and point at their TypeScript sources. To publish a compiled build: add atsconfig.build.jsonwithoutDir: dist, replacemain/types/exportswithdist/…, andfileswith["dist", "bin", "README.md"]. npm login, then from each folder:pnpm publish --access public.@hela/mcp'sbinstarts the server throughtsx; adistbuild makes that unnecessary.- A version follows the API's (
3.0.x); an OpenAPI schema change deserves an SDK version.
Zapier
- A Zapier developer account and the CLI:
npm i -g zapier-platform-cli,zapier login. - In
integrations/zapier:npm install,zapier register "Hela"(once; creates.zapierapprc),zapier push. The app is then private: share an invite link (zapier users:add) or publish. - Directory publication (
zapier promote, then Developer Platform → Publish): Zapier requires a description, a 256×256 logo, a privacy policy, three test Zaps and a review — two to six weeks. Custom authentication by API key is accepted; the default API address (https://api.hela.co/v1) must answer publicly. - Each company then connects with its key and its company id; no Hela secret is in the app.
Make
- A Make account with Custom apps access (Developer Hub).
- Create a new app: name
hela, then paste thebase,connections,webhooksandmodulessections ofintegrations/make/app.jsoninto the matching tabs (the editor expects one block per tab). A square logo for the app. - Test a scenario with your key. Publishing to the directory: Make → Publish → Submit for review (description, privacy policy, a few weeks' review). Meanwhile Share gives a private install link.
n8n
- An npm account (the community installs from npm).
- In
integrations/n8n-nodes-hela:npm install,npm run build(compilesdist/),npm publish --access public. Thepackage.jsoncarries then8n-community-node-packagekeyword and then8nsection listing the node, the trigger and the credentials. - Users install from Settings → Community nodes with the package name. For n8n's verified list, submit the repository through the Community node verification form (code review, MIT licence required — which it is).
- Version:
3.0.x; a new operation is a minor version.
Power Automate
The custom connector is built from the OpenAPI schema without publication (Power Automate). A certified connector goes through Microsoft's Independent Publisher Connectors programme (public GitHub repository, review); allow four to eight weeks.
MCP server
Beyond npm, two directories list MCP servers: the MCP Registry (registry.modelcontextprotocol.io, a server.json in the repository) and Claude Desktop's list (Anthropic Connectors Directory, a form). Neither is needed for a company to use npx @hela/mcp.
What to keep in mind
- The keys the apps use are the companies'; Hela holds no secret in any app, and nothing to rotate when a key changes.
- Directories re-review apps on every version: keep the changelog (What's new) and test against
/openapi.jsonbefore pushing.