{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "amazon-sns",
    "name": "Amazon SNS",
    "vendor": "Amazon Web Services",
    "vendorUrl": "https://aws.amazon.com/sns/",
    "kind": "http-api",
    "category": "notifications",
    "summary": "Amazon SNS is AWS's publish and subscribe messaging service. A message published to a topic, or directly to a device or phone number, goes out as mobile push, SMS, plain-text email, HTTPS calls or to SQS queues and Lambda functions.",
    "url": "https://www.anchorterminal.com/tools/amazon-sns",
    "markdownUrl": "https://www.anchorterminal.com/tools/amazon-sns.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/amazon-sns.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/amazon-sns.json",
    "repo": "https://github.com/aws/api-models-aws",
    "license": "Proprietary service under the AWS Customer Agreement. The AWS SDKs and the AWS Labs MCP server are Apache-2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://sns.us-east-1.amazonaws.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@aws-sdk/client-sns"
      },
      {
        "registry": "pypi",
        "name": "boto3"
      },
      {
        "registry": "pypi",
        "name": "awslabs.amazon-sns-sqs-mcp-server"
      }
    ],
    "auth": "mixed",
    "authNotes": "Requests are signed with AWS Signature Version 4 using IAM credentials, long-lived access keys or temporary credentials from AWS STS. IAM identity policies and topic resource policies use the `sns` action prefix with topic ARNs and condition keys. Access is self-serve with an AWS account. SMS starts in a sandbox per account, and leaving it or raising the $1 monthly spend quota needs an AWS Support case. Mobile push needs a platform application holding credentials from Apple, Google or another push service.",
    "pricing": "usage",
    "pricingNotes": "Pay per request and per notification with no minimum. On standard topics in US East (N. Virginia), API requests cost $0.50 per million after 1,000,000 free each month, mobile push $0.50 per million after 1,000,000 free, email $2.00 per 100,000 after 1,000 free, and HTTP deliveries $0.60 per million after 100,000 free. Deliveries to SQS and Lambda are free. SMS is billed by AWS End User Messaging. New AWS customers get up to $200 in Free Tier credits, and AWS says most can sign up without a payment method (https://aws.amazon.com/sns/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
    "priceSummary": "$0.0005 / 1k req",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer guide index, the API model or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 6505984,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.aws.amazon.com/sns/latest/dg/welcome.html",
    "llmsTxt": "https://docs.aws.amazon.com/sns/latest/dg/llms.txt",
    "capabilities": [
      "notify.push",
      "notify.multichannel",
      "messaging.sms"
    ],
    "tags": [
      "hosted",
      "llms-txt",
      "typescript",
      "python",
      "push",
      "sms",
      "mcp",
      "enterprise"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 72.8,
      "grade": "BB",
      "agentReady": true,
      "rank": 86,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 65,
        "maintenance": 75,
        "payments": 35,
        "reliability": 75,
        "schema": 83,
        "security": 89,
        "transparency": 83
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 75,
          "points": 15,
          "reason": "AWS Health Dashboard with per-service, per-Region history (20). AWS's dashboard history file, read on 8 October, lists Amazon Simple Notification Service in the Middle East (UAE) me-central-1 and Middle East (Bahrain) me-south-1 multi-service events, open since 1 and 2 March 2026 at disruption status. On 15 September 2026, inside the 90-day window, AWS said it can't restore resources and data hosted only in me-south-1 or the mec1-az2 zone. None of the other eleven events since 10 July names the service. One major event, read as the Amazon SES and AWS End User Messaging dossiers read it (10). The quotas page gives published messages a second per account by Region (30,000 in US East (N. Virginia), 9,000 in two Regions, 1,500 in eight, 300 elsewhere) and a fixed rate for each other action (15). `ThrottlingException` is documented with a note that the AWS SDKs retry it, and the SDK reference describes exponential backoff with jitter. FIFO topics deduplicate on `MessageDeduplicationId` for five minutes, but `Publish` to a standard topic takes no idempotency token and the API model marks no error as retryable (10 of 15). The Amazon Messaging SLA commits 99.9 per cent monthly uptime per Region for SNS and SQS (10). Generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 83,
          "points": 13.49,
          "reason": "No OpenAPI, but the Smithy model is published in aws/api-models-aws, 42 operations under API version 2010-03-31 (25). llms.txt for the developer guide and the API reference, with a Markdown twin of every page (10). The API reference explains each action and the guide says when to pick FIFO over standard topics. Few actions say when not to use them (12 of 20). 65 required members are marked, but the model has only 4 enumerated types and 11 length, pattern or range constraints. Topic, subscription and endpoint settings are string-to-string maps, and delivery policies, filter policies and per-channel messages are JSON inside strings (8 of 15). The `Publish` reference page carries three request and response examples and lists 15 errors with HTTP status codes, and the guide has SDK and CLI examples. The model itself carries no examples (13 of 15). Versioned API and a dated document history, last entry 30 April 2026 (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 65,
          "points": 10.56,
          "reason": "Graded on the SNS API through the AWS CLI and SDKs. AWS Labs also publishes a local MCP server for SNS and SQS, which belongs to our AWS MCP servers listing. `Publish` returns only a `MessageId`. Eight list actions page with `NextToken`, and only `ListSMSSandboxPhoneNumbers` takes `MaxResults` (14 of 25). No server-side filter on the list actions beyond `ListSubscriptionsByTopic` and listing endpoints by platform application (10 of 20). 34 typed errors with HTTP status codes, plus a page of mobile push errors with causes (16 of 20). `CreateTopic` and `CreatePlatformEndpoint` are documented as idempotent, `PublishBatch` answers per entry ID, and FIFO topics deduplicate for five minutes. `Publish` to a standard topic has no idempotency token, so a retried send can go out twice (12 of 20). `Publish` requires only `Message` and one target, and SDKs exist in every major language, but every call needs SigV4 and responses are XML outside the SDKs (13 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 89,
          "points": 15.58,
          "reason": "IAM with identity policies and topic resource policies per action and ARN, service condition keys, temporary credentials and rotation. No secret travels in a URL (30). `AmazonSNSReadOnlyAccess` is an AWS managed policy, and a policy can allow `sns:Publish` on one topic only. Email addresses have to confirm a subscription before receiving anything. No confirmation step for sends, which IAM leaves to the caller (16 of 20). API responses carry no third-party content. SNS signs the messages it posts to HTTPS endpoints and the guide tells receivers to verify the signature (10). CloudTrail logs control-plane calls as management events and `Publish` and `PublishBatch` on topics and platform endpoints as optional data events. Publishes to a phone number are not logged by CloudTrail. Delivery status can go to CloudWatch Logs (15). In scope for SOC 1, 2 and 3 (page updated 11 August 2026), with a vulnerability disclosure programme on HackerOne. aws.amazon.com's security.txt expired on 24 September 2026, and we found no paid bug bounty. Read as the Amazon SES re-check read the same evidence (18 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "No x402, MPP or L402 (0). Per-request and per-notification prices published without login, with a price feed the pricing page loads (20). Standard topics carry a monthly free allowance of 1,000,000 API requests, 1,000,000 mobile push notifications, 100,000 HTTP notifications and 1,000 emails. The Free Tier FAQ says most new customers don't need a payment method, though AWS may still ask for one, so 15 of 20. A person signs up for the AWS account, and SMS production access needs a support case, so no autonomous route (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "reason": "The SNS model last changed on 17 September 2026, and the JavaScript SDK client shipped 3.1147.0 on 6 October (30). That model change, a documentation update, is the only SNS change in aws/api-models-aws since 10 July, and the guide's document history has no entry after 30 April 2026. The SDK client had 63 versions in the same period, published with the whole SDK, so half (10 of 20). Closed service with a dated document history and AWS re:Post. Direct support is a paid plan (10 of 15). Official SDKs released on most working days (15). The JavaScript client needs Node 20 or later and is published from the SDK's release pipeline (10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "note": "editorial 71, provenance 95",
          "reason": "Closed service under the AWS Customer Agreement and section 11 of the Service Terms, with Apache-2.0 SDKs (20 of 30). The guide says SNS stores messages with disk encryption by default, with optional server-side encryption under AWS KMS keys, and the retry page gives how long an undelivered message is kept (up to 23 days for AWS endpoints, 6 hours for push, SMS and email). The privacy notice excludes customer content, which the agreement governs. We found no statement on retention of subscription data or delivery logs (18 of 30). Message data protection was closed to new customers on 30 April 2026 with a notice dated 31 March 2026, 30 days ahead. No general deprecation policy found (15 of 20). The sub-processor page, last updated 28 July 2026, names AMCS LLC and AMCS SG Private Limited as sellers of SNS and promises 30 days' notice of new ones. The carriers and push services that messages pass through are not listed (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the SNS API through the AWS CLI and SDKs. AWS Labs also publishes a local MCP server for SNS and SQS, which belongs to our AWS MCP servers listing. `Publish` returns only a `MessageId`. Eight list actions page with `NextToken`, and only `ListSMSSandboxPhoneNumbers` takes `MaxResults` (14 of 25). No server-side filter on the list actions beyond `ListSubscriptionsByTopic` and listing endpoints by platform application (10 of 20). 34 typed errors with HTTP status codes, plus a page of mobile push errors with causes (16 of 20). `CreateTopic` and `CreatePlatformEndpoint` are documented as idempotent, `PublishBatch` answers per entry ID, and FIFO topics deduplicate for five minutes. `Publish` to a standard topic has no idempotency token, so a retried send can go out twice (12 of 20). `Publish` requires only `Message` and one target, and SDKs exist in every major language, but every call needs SigV4 and responses are XML outside the SDKs (13 of 15).",
          "maintenance": "The SNS model last changed on 17 September 2026, and the JavaScript SDK client shipped 3.1147.0 on 6 October (30). That model change, a documentation update, is the only SNS change in aws/api-models-aws since 10 July, and the guide's document history has no entry after 30 April 2026. The SDK client had 63 versions in the same period, published with the whole SDK, so half (10 of 20). Closed service with a dated document history and AWS re:Post. Direct support is a paid plan (10 of 15). Official SDKs released on most working days (15). The JavaScript client needs Node 20 or later and is published from the SDK's release pipeline (10).",
          "payments": "No x402, MPP or L402 (0). Per-request and per-notification prices published without login, with a price feed the pricing page loads (20). Standard topics carry a monthly free allowance of 1,000,000 API requests, 1,000,000 mobile push notifications, 100,000 HTTP notifications and 1,000 emails. The Free Tier FAQ says most new customers don't need a payment method, though AWS may still ask for one, so 15 of 20. A person signs up for the AWS account, and SMS production access needs a support case, so no autonomous route (0).",
          "reliability": "AWS Health Dashboard with per-service, per-Region history (20). AWS's dashboard history file, read on 8 October, lists Amazon Simple Notification Service in the Middle East (UAE) me-central-1 and Middle East (Bahrain) me-south-1 multi-service events, open since 1 and 2 March 2026 at disruption status. On 15 September 2026, inside the 90-day window, AWS said it can't restore resources and data hosted only in me-south-1 or the mec1-az2 zone. None of the other eleven events since 10 July names the service. One major event, read as the Amazon SES and AWS End User Messaging dossiers read it (10). The quotas page gives published messages a second per account by Region (30,000 in US East (N. Virginia), 9,000 in two Regions, 1,500 in eight, 300 elsewhere) and a fixed rate for each other action (15). `ThrottlingException` is documented with a note that the AWS SDKs retry it, and the SDK reference describes exponential backoff with jitter. FIFO topics deduplicate on `MessageDeduplicationId` for five minutes, but `Publish` to a standard topic takes no idempotency token and the API model marks no error as retryable (10 of 15). The Amazon Messaging SLA commits 99.9 per cent monthly uptime per Region for SNS and SQS (10). Generally available (10).",
          "schema": "No OpenAPI, but the Smithy model is published in aws/api-models-aws, 42 operations under API version 2010-03-31 (25). llms.txt for the developer guide and the API reference, with a Markdown twin of every page (10). The API reference explains each action and the guide says when to pick FIFO over standard topics. Few actions say when not to use them (12 of 20). 65 required members are marked, but the model has only 4 enumerated types and 11 length, pattern or range constraints. Topic, subscription and endpoint settings are string-to-string maps, and delivery policies, filter policies and per-channel messages are JSON inside strings (8 of 15). The `Publish` reference page carries three request and response examples and lists 15 errors with HTTP status codes, and the guide has SDK and CLI examples. The model itself carries no examples (13 of 15). Versioned API and a dated document history, last entry 30 April 2026 (15).",
          "security": "IAM with identity policies and topic resource policies per action and ARN, service condition keys, temporary credentials and rotation. No secret travels in a URL (30). `AmazonSNSReadOnlyAccess` is an AWS managed policy, and a policy can allow `sns:Publish` on one topic only. Email addresses have to confirm a subscription before receiving anything. No confirmation step for sends, which IAM leaves to the caller (16 of 20). API responses carry no third-party content. SNS signs the messages it posts to HTTPS endpoints and the guide tells receivers to verify the signature (10). CloudTrail logs control-plane calls as management events and `Publish` and `PublishBatch` on topics and platform endpoints as optional data events. Publishes to a phone number are not logged by CloudTrail. Delivery status can go to CloudWatch Logs (15). In scope for SOC 1, 2 and 3 (page updated 11 August 2026), with a vulnerability disclosure programme on HackerOne. aws.amazon.com's security.txt expired on 24 September 2026, and we found no paid bug bounty. Read as the Amazon SES re-check read the same evidence (18 of 20).",
          "transparency": "Closed service under the AWS Customer Agreement and section 11 of the Service Terms, with Apache-2.0 SDKs (20 of 30). The guide says SNS stores messages with disk encryption by default, with optional server-side encryption under AWS KMS keys, and the retry page gives how long an undelivered message is kept (up to 23 days for AWS endpoints, 6 hours for push, SMS and email). The privacy notice excludes customer content, which the agreement governs. We found no statement on retention of subscription data or delivery logs (18 of 30). Message data protection was closed to new customers on 30 April 2026 with a notice dated 31 March 2026, 30 days ahead. No general deprecation policy found (15 of 20). The sub-processor page, last updated 28 July 2026, names AMCS LLC and AMCS SG Private Limited as sellers of SNS and promises 30 days' notice of new ones. The carriers and push services that messages pass through are not listed (18 of 20)."
        },
        "sources": [
          {
            "what": "developer guide index (llms.txt)",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference index (llms.txt)",
            "url": "https://docs.aws.amazon.com/sns/latest/api/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "what is Amazon SNS",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/welcome.md",
            "seen": "2026-10-08"
          },
          {
            "what": "application-to-person messaging",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-user-notifications.md",
            "seen": "2026-10-08"
          },
          {
            "what": "endpoints and quotas",
            "url": "https://docs.aws.amazon.com/general/latest/gr/sns.html",
            "seen": "2026-10-08"
          },
          {
            "what": "document history",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-release-notes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "message data protection availability change",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-message-data-protection-availability-change.md",
            "seen": "2026-10-08"
          },
          {
            "what": "message delivery retries",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-message-delivery-retries.md",
            "seen": "2026-10-08"
          },
          {
            "what": "FIFO message deduplication",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/fifo-message-dedup.md",
            "seen": "2026-10-08"
          },
          {
            "what": "message batching",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-batch-api-actions.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SMS sandbox",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-sms-sandbox.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SMS spending quota",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/channels-sms-awssupport-spend-threshold.md",
            "seen": "2026-10-08"
          },
          {
            "what": "mobile text messaging and AWS End User Messaging",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-mobile-phone-number-as-subscriber.md",
            "seen": "2026-10-08"
          },
          {
            "what": "email subscriptions",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-email-notifications.md",
            "seen": "2026-10-08"
          },
          {
            "what": "mobile push platforms",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-mobile-application-as-subscriber.md",
            "seen": "2026-10-08"
          },
          {
            "what": "mobile push Regions",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-mobile-push-supported-regions.md",
            "seen": "2026-10-08"
          },
          {
            "what": "CloudTrail logging",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/logging-using-cloudtrail.md",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS managed policies",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/security-iam-awsmanpol.md",
            "seen": "2026-10-08"
          },
          {
            "what": "IAM support",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/security_iam_service-with-iam.md",
            "seen": "2026-10-08"
          },
          {
            "what": "data encryption",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-data-encryption.md",
            "seen": "2026-10-08"
          },
          {
            "what": "message signature verification",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-verify-signature-of-message.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Publish reference",
            "url": "https://docs.aws.amazon.com/sns/latest/api/API_Publish.md",
            "seen": "2026-10-08"
          },
          {
            "what": "common errors",
            "url": "https://docs.aws.amazon.com/sns/latest/api/CommonErrors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS CLI publish example",
            "url": "https://docs.aws.amazon.com/sns/latest/dg/example_sns_Publish_section.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK retry behaviour",
            "url": "https://docs.aws.amazon.com/sdkref/latest/guide/feature-retry-behavior.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Smithy model for sns (cloned)",
            "url": "https://github.com/aws/api-models-aws",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Labs SNS and SQS MCP server (cloned)",
            "url": "https://github.com/awslabs/mcp/tree/main/src/amazon-sns-sqs-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://aws.amazon.com/sns/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "price feed the pricing page loads",
            "url": "https://b0.p.awsstatic.com/pricing/2.0/meteredUnitMaps/sns/USD/current/sns.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Amazon Messaging SLA",
            "url": "https://aws.amazon.com/messaging/sla/",
            "seen": "2026-10-08"
          },
          {
            "what": "health dashboard history file",
            "url": "https://history-events-us-east-1-prod.s3.amazonaws.com/historyevents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "health dashboard current events",
            "url": "https://health.aws.amazon.com/public/currentevents",
            "seen": "2026-10-08"
          },
          {
            "what": "Free Tier FAQ",
            "url": "https://aws.amazon.com/free/free-tier-faqs/",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Service Terms, section 11",
            "url": "https://aws.amazon.com/service-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "AWS Customer Agreement",
            "url": "https://aws.amazon.com/agreement/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://aws.amazon.com/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://aws.amazon.com/compliance/sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "SOC services in scope",
            "url": "https://aws.amazon.com/compliance/services-in-scope/SOC/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://aws.amazon.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "vulnerability reporting",
            "url": "https://aws.amazon.com/security/vulnerability-reporting/",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package and weekly downloads",
            "url": "https://registry.npmjs.org/@aws-sdk/client-sns",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server package",
            "url": "https://pypi.org/pypi/awslabs.amazon-sns-sqs-mcp-server/json",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for amazonaws.com",
            "url": "https://rdap.verisign.com/com/v1/domain/amazonaws.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: SMS prices and registration rules. SMS sent through SNS is billed by AWS End User Messaging, which has its own listing, and we did not re-read its price pages for this one.",
          "unchecked: which subscription protocols FIFO topics support, and the archive retention period for FIFO topics. We read the FIFO overview and deduplication pages only.",
          "unchecked: the SNS condition keys in the service authorisation reference, which the guide links to.",
          "unchecked: the tool list of the AWS Labs SNS and SQS MCP server at run time. We read its source and README and did not run it.",
          "unchecked: PyPI weekly downloads. `boto3` covers every AWS service, so no SNS figure exists there.",
          "No retention period for subscription data or delivery status logs was found in the pages read.",
          "The lead called the interface a REST API. The model declares the AWS Query protocol, form-encoded requests with XML responses, signed with SigV4.",
          "The category fits only in part. SNS sends push, SMS and email but has no user preferences, digests, templates or in-app channel, and much of its use is application-to-application fan-out."
        ]
      },
      "negative": 0,
      "verdict": "IAM and topic policies limit a credential to single actions and topics, a read-only managed policy exists, and CloudTrail can log each publish. Standard topics take no idempotency token, so a retried `Publish` can send twice. SNS has no user preferences, digests or in-app channel, email is plain text to confirmed subscribers, and SMS starts in a sandbox.",
      "bestFor": "Teams already on AWS that want cheap push, SMS and plain-text email alerts or fan-out to queues and functions under IAM and CloudTrail.",
      "strengths": [
        "IAM identity policies and topic resource policies per action and topic, temporary credentials, and an `AmazonSNSReadOnlyAccess` managed policy",
        "Published quotas of 30,000 published messages a second per account in US East (N. Virginia) and 300 in the smallest Regions",
        "First 1,000,000 API requests, 1,000,000 mobile push notifications and 1,000 emails each month are free on standard topics",
        "Smithy model published for all 42 operations, with llms.txt indexes and a Markdown twin of every guide and reference page",
        "99.9 per cent monthly uptime commitment per Region under the Amazon Messaging SLA, last updated 4 May 2022"
      ],
      "weaknesses": [
        "No idempotency token on `Publish` to a standard topic. Only FIFO topics deduplicate, over a five-minute window",
        "No user preferences, digests, templates or in-app channel. Email is plain text and each address has to confirm its subscription",
        "SMS starts in a sandbox with ten verified numbers and a $1 monthly spend quota, raised through an AWS Support case",
        "Topic, subscription and endpoint settings travel as string maps and JSON inside strings, and the model has only four enumerated types",
        "The AWS Health Dashboard lists the service in the UAE and Bahrain Region disruptions open since March 2026"
      ],
      "agentNotes": [
        "Sign requests with SigV4 for service `sns` at `sns.\u003cregion\u003e.amazonaws.com`, or call `aws sns publish --topic-arn \u003carn\u003e --message \u003ctext\u003e` from the AWS CLI",
        "Track `MessageId` yourself on standard topics, because a retried `Publish` sends again. Use a FIFO topic with `MessageDeduplicationId` when duplicates matter",
        "Send per-channel text by setting `MessageStructure` to `json` and passing a JSON string with a `default` key plus keys such as `APNS`, `GCM`, `email` and `sms`",
        "Check `GetSMSSandboxAccountStatus` and the monthly spend quota before texting. Sandbox sends reach only verified numbers",
        "Expect an email subscription to stay in `PendingConfirmation` until the recipient clicks the link, and keep each email subscription under 10 messages a second"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 72.8
        }
      ],
      "editorialScores": {
        "ergonomics": 65,
        "maintenance": 75,
        "payments": 35,
        "reliability": 75,
        "schema": 83,
        "security": 89,
        "transparency": 71
      },
      "provenanceScore": 95
    },
    "connect": {
      "config": {
        "mcpServers": {
          "awslabs.amazon-sns-sqs-mcp-server": {
            "args": [
              "awslabs.amazon-sns-sqs-mcp-server@latest"
            ],
            "command": "uvx",
            "env": {
              "AWS_PROFILE": "your-aws-profile",
              "AWS_REGION": "us-east-1"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/notify.push",
      "tool": "https://letme.dev/amazon-sns"
    },
    "sameCompany": [
      "aws-end-user-messaging",
      "amazon-s3"
    ],
    "notable": [
      "SMS sent through SNS goes out through AWS End User Messaging SMS, which also bills it. The Service Terms make SNS use subject to the End User Messaging terms as well (https://docs.aws.amazon.com/sns/latest/dg/sns-mobile-phone-number-as-subscriber.html)",
      "New SMS senders start in a sandbox with at most 10 verified destination numbers, and the account SMS spend quota defaults to $1.00 a month (https://docs.aws.amazon.com/sns/latest/dg/sns-sms-sandbox.html)",
      "Mobile push goes through six services, Amazon Device Messaging, Apple Push Notification Service, Baidu Cloud Push, Firebase Cloud Messaging, MPNS and WNS, in 25 Regions (https://docs.aws.amazon.com/sns/latest/dg/sns-mobile-application-as-subscriber.html)",
      "Email is plain text, each address has to confirm its subscription, and a subscription that passes 10 messages a second is suspended to pending confirmation (https://docs.aws.amazon.com/sns/latest/dg/sns-email-notifications.html)",
      "Message data protection closed to new customers on 30 April 2026, and AWS points to a Lambda and Amazon Bedrock Guardrails pattern as the replacement (https://docs.aws.amazon.com/sns/latest/dg/sns-message-data-protection-availability-change.html)",
      "AWS Labs publishes a local MCP server for SNS and SQS, `awslabs.amazon-sns-sqs-mcp-server` 2.1.1 of 8 September 2026. It changes only resources it created and tagged, and its tools for platform applications and SMS settings are switched off (https://github.com/awslabs/mcp/tree/main/src/amazon-sns-sqs-mcp-server)",
      "AWS's Health Dashboard lists Amazon SNS in the Middle East (UAE) me-central-1 and (Bahrain) me-south-1 disruptions open since March 2026. On 15 September 2026 AWS said it can't restore data hosted only in me-south-1 or the mec1-az2 zone (https://health.aws.amazon.com/health/status)"
    ],
    "area": "everyday",
    "details": [
      {
        "label": "API",
        "value": "Amazon SNS API version 2010-03-31, 42 operations, AWS Query protocol with XML responses, signed with SigV4. Reached through the AWS CLI (`aws sns`) and the AWS SDKs"
      },
      {
        "label": "Endpoint",
        "value": "`sns.\u003cregion\u003e.amazonaws.com`, with dual-stack `sns.\u003cregion\u003e.api.aws` and FIPS endpoints in US and Canada Regions. 36 Regions on the endpoints page, GovCloud included"
      },
      {
        "label": "Channels to people",
        "value": "Mobile push (APNs, FCM, ADM, Baidu, MPNS, WNS), SMS through AWS End User Messaging, and plain-text email to confirmed subscribers. No in-app channel"
      },
      {
        "label": "Other subscribers",
        "value": "Amazon SQS, AWS Lambda, HTTP and HTTPS endpoints, Amazon Data Firehose"
      },
      {
        "label": "Topics",
        "value": "Standard topics, up to 100,000 per account and 12,500,000 subscriptions each. FIFO topics, up to 1,000 per account and 100 subscriptions each, with ordering and five-minute deduplication"
      },
      {
        "label": "Rate limits",
        "value": "Published messages per account per second, 30,000 in US East (N. Virginia), 9,000 in US West (Oregon) and Europe (Ireland), 1,500 in eight Regions, 300 elsewhere on standard topics. `Subscribe` 100 a second. Email 10 a second per subscription, a hard limit. SMS 20 a second"
      },
      {
        "label": "Message size",
        "value": "256 KiB by default, up to 1 MiB with the topic's `MaximumMessageSize`. `PublishBatch` takes up to 10 messages"
      },
      {
        "label": "Retries",
        "value": "Push, SMS and email, 50 attempts over 6 hours. SQS and Lambda, 100,015 attempts over 23 days. Then the message is discarded unless the subscription has a dead-letter queue. HTTPS retry policy can be set, up to 3,600 seconds"
      },
      {
        "label": "Filtering",
        "value": "Subscription filter policies on message attributes or body, 200 per topic and 10,000 per account"
      },
      {
        "label": "SMS sandbox",
        "value": "Sends only to verified numbers (up to 10) with a $1.00 monthly spend quota until an AWS Support case is approved"
      },
      {
        "label": "Audit",
        "value": "CloudTrail management events for control-plane calls and optional data events for `Publish` and `PublishBatch` on topics and platform endpoints. Publishes to a phone number are not logged. Push delivery status to CloudWatch Logs"
      },
      {
        "label": "Agent tooling",
        "value": "AWS Labs local MCP server `awslabs.amazon-sns-sqs-mcp-server` 2.1.1, stdio, tools generated from the SDK. Resource creation is off unless `--allow-resource-creation` is passed. No hosted MCP server for the service"
      },
      {
        "label": "SLA",
        "value": "Amazon Messaging SLA, 99.9 per cent monthly uptime per Region for SNS and SQS, credits of 10, 25 or 100 per cent"
      },
      {
        "label": "Compliance",
        "value": "Amazon SNS is in scope for SOC 1, 2 and 3 (page updated 11 August 2026)"
      }
    ],
    "unitPrices": [
      {
        "item": "API requests, standard topics",
        "unit": "1k-requests",
        "usd": 0.0005,
        "note": "US East (N. Virginia), after 1,000,000 free a month. Each 64 KB of payload counts as one request"
      },
      {
        "item": "Publishes, FIFO topics",
        "unit": "1k-requests",
        "usd": 0.0003,
        "note": "US East (N. Virginia), plus $0.017 per GB of payload and $0.01 per million subscription messages"
      },
      {
        "item": "Mobile push notification",
        "unit": "message",
        "usd": 5e-7,
        "note": "$0.50 per million after 1,000,000 free a month"
      },
      {
        "item": "Email notification",
        "unit": "1k-emails",
        "usd": 0.02,
        "note": "$2.00 per 100,000 after 1,000 free a month"
      },
      {
        "item": "HTTP or HTTPS notification",
        "unit": "message",
        "usd": 6e-7,
        "note": "$0.60 per million after 100,000 free a month"
      }
    ],
    "provenance": {
      "legalEntity": "Amazon Web Services, Inc.",
      "domain": "amazonaws.com",
      "domainRegistered": "2005-08-18",
      "endpointOnVendorDomain": true,
      "terms": "https://aws.amazon.com/agreement/",
      "privacy": "https://aws.amazon.com/privacy/",
      "statusPage": "https://health.aws.amazon.com/health/status",
      "changelog": "https://docs.aws.amazon.com/sns/latest/dg/sns-release-notes.html",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The AWS Customer Agreement (last updated 14 August 2026) governs use of the service, with other AWS entities as contracting party by account country.",
        "Section 11 of the AWS Service Terms (last updated 1 October 2026) adds terms for Amazon SNS. It says AMCS LLC sells parts of the service in Japan and AMCS SG Private Limited in Singapore, and that fees apply even when delivery is blocked for reasons outside AWS's control (https://aws.amazon.com/service-terms/).",
        "The AWS Privacy Notice (last updated 18 May 2026) says it does not apply to content customers process with AWS services, which the agreement governs.",
        "https://aws.amazon.com/.well-known/security.txt carries Expires 2026-09-24T16:25:03Z, so it had expired on 8 October 2026.",
        "RDAP for amazonaws.com gives a registration date of 2005-08-18. The API answers at sns.\u003cregion\u003e.amazonaws.com, while product and legal pages sit on aws.amazon.com."
      ],
      "score": 95,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Amazon Web Services, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "amazonaws.com, registered 2005-08-18 (21 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "sns.us-east-1.amazonaws.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "health.aws.amazon.com/health/status",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://aws.amazon.com/agreement/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-14",
          "words": 10799,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: August 14, 2026",
              "says": "Last updated 2026-08-14"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The laws of the Province of Ontario, Canada and federal laws of Canada applicable therein",
              "says": "The law of the Province of Ontario"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…UNDER THIS AGREEMENT OF EITHER AWS OR YOU, AND ANY OF OUR RESPECTIVE AFFILIATES OR LICENSORS, WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO AWS UNDER THIS AGREEMENT FOR THE SERVICES THAT GAVE RISE TO THE LIABILITY DURING THE 12 MONTHS BEFORE THE LIABILITY AROSE;",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If you become aware of any violation of your obligations under this Agreement caused by an End User, you will immediately suspend access to Your Content and the Services by such End User."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We may change, discontinue or add Service Level Agreements, provided, however, that we will provide at least 90 days’ advance notice for adverse changes to any Service Level Agreement.",
              "says": "Gives 90 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "AWS log-in credentials and private keys generated by the Services are for your internal use only and you will not sell, transfer or sublicense them to any other entity or person, except that you may disclose your private key to your agents and subcontractors performing work on your behalf."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Service Level Agreements and Service Terms apply to certain Services."
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may terminate this Agreement for any reason by providing you at least 30 days’ advance notice."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Disputes will be resolved by binding arbitration, rather than in court, except that either party may elect to proceed in small claims court if your claims qualify."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "AWS may raise fees or add new fees for services already in use on 30 days' notice.",
              "quote": "We may increase or add new fees and charges for any existing Services you are using by giving you at least 30 days’ prior notice."
            },
            {
              "date": "2026-10-08",
              "text": "For 30 days after termination the customer may retrieve its content only if all amounts due are paid. This period does not apply when AWS terminates under Section 5.2(b).",
              "quote": "(ii) we will allow you to retrieve Your Content from the Services only if you have paid all amounts due under this Agreement."
            },
            {
              "date": "2026-10-08",
              "text": "The customer may not issue a press release or other public communication about the agreement or its use of AWS services.",
              "quote": "You will not issue any press release or make any other public communication with respect to this Agreement or your use of the Services or AWS Content."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://aws.amazon.com/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-05-18",
          "words": 8790,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: May 18, 2026",
              "says": "Last updated 2026-05-18"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”)."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.",
              "quote": "This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/amazon-sns.json",
    "live": {
      "slug": "amazon-sns",
      "probe": {
        "target": "https://sns.us-east-1.amazonaws.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:03.674891671Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 247,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 252,
        "p95ms24h": 316,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "updatedAt": "2026-10-08T21:12:03.674891671Z"
    }
  }
}
