{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "easypost",
    "name": "EasyPost",
    "vendor": "Simpler Postage, Inc. (d/b/a EasyPost)",
    "vendorUrl": "https://www.easypost.com",
    "kind": "http-api",
    "category": "shipping",
    "summary": "EasyPost is a multi-carrier shipping API from Simpler Postage, Inc. Its REST API quotes carrier rates, buys labels, verifies addresses, tracks parcels and files refunds and insurance claims, with a hosted read-only MCP server in early release.",
    "url": "https://www.anchorterminal.com/tools/easypost",
    "markdownUrl": "https://www.anchorterminal.com/tools/easypost.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/easypost.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/easypost.json",
    "repo": "https://github.com/EasyPost/easypost-node",
    "license": "Proprietary service under the EasyPost Master Customer Agreement. The official client libraries on GitHub are MIT, with the Go library under ISC",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.easypost.com/v2",
    "packages": [
      {
        "registry": "npm",
        "name": "@easypost/api"
      },
      {
        "registry": "pypi",
        "name": "easypost"
      },
      {
        "registry": "go",
        "name": "github.com/EasyPost/easypost-go/v5"
      }
    ],
    "auth": "api-key",
    "authNotes": "A self-serve API key, sent as the HTTP Basic username with an empty password. The docs say a wallet and a ship-from address must be set up before keys can be seen or generated. Test and production keys exist, both with full account access, and they can be created, disabled, enabled and deleted through /api_keys or the dashboard. The hosted MCP server takes a production key as a Bearer token. No OAuth, partner review or sales approval is needed for the core API.",
    "pricing": "freemium",
    "pricingNotes": "Free for up to 3,000 labels on wallet carriers, with postage charged separately and a per-label fee after that which the pricing page doesn't state. Bringing your own carrier accounts costs $20 a month plus a per-label fee. Tracking is listed at $0.01 to $0.03 a shipment and insurance at 1 per cent of value, minimum $1.00. Test keys cost nothing, so an agent can build without a contract. Forge, GlobalShip and Luma are priced by sales (checked 2026-10-07).",
    "priceSummary": "$0.02 / call",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the pricing page or the legal centre (checked 2026-10-07).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 149,
      "npmWeekly": 99736,
      "pypiWeekly": 41831,
      "asOf": "2026-10-07"
    },
    "docsUrl": "https://docs.easypost.com",
    "llmsTxt": "https://docs.easypost.com/llms.txt",
    "capabilities": [
      "shipping.rates",
      "shipping.labels",
      "shipping.tracking",
      "shipping.address-validation",
      "shipping.returns"
    ],
    "tags": [
      "hosted",
      "closed-source",
      "api-key",
      "llms-txt",
      "mcp",
      "webhooks",
      "sandbox",
      "free-tier",
      "python",
      "typescript",
      "go",
      "java",
      "php",
      "ruby",
      "dotnet",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-09-28",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 54.3,
      "grade": "C",
      "agentReady": false,
      "rank": 531,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 63,
        "maintenance": 85,
        "payments": 22,
        "reliability": 53,
        "schema": 55,
        "security": 47,
        "transparency": 70
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 53,
          "points": 10.6,
          "reason": "Read with the hosted lines and scored on the REST API at api.easypost.com/v2, the surface an agent would use to rate, buy and track. The hosted MCP server only reads and is an early release. www.easypoststatus.com on Statuspage lists 44 components with incident history (20). In the 90 days to 7 October 2026 it shows seven incidents. A connectivity fault at the hosting provider on 23 July affected all operations from 07:57 to about 12:21 Pacific time, and two carrier-side incidents were marked major (UPS accounts supplied by EasyPost on 22 July for 3 h 29 min, USPS Ship on 20 September for 5 h 24 min). Two short API degradations lasted 10 and 14 minutes. One core outage and two upstream majors (7 of 30). The rate-limiting guide gives five requests a second on index endpoints and a 60-account cap on rating, but the load-based limiter on buying and rating has no published number (8 of 15). The guide describes 429 handling with retry and backoff and a code sample. No Retry-After header and no idempotency keys were found, and the sample retries only GET and DELETE (8 of 15). The Master Customer Agreement supplies the service as is and as available, and the support addendum sets response targets only (0). The v2 API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 55,
          "points": 8.94,
          "reason": "No OpenAPI or similar spec was found in the docs, llms.txt, the page index or the 56 public repositories of the EasyPost GitHub organisation. A Postman workspace is listed, which we didn't read (0 of 25). llms.txt, a Markdown copy of almost every page and doc-index.json with audience and usage notes for each page (10). Each object has a property table with a type and description, and the index says when each page applies. Endpoint pages are mostly examples, with little on when not to use a call (12 of 20). Types and allowed values are given in prose tables, such as the ten tracker statuses, with no schema to validate against, and the Markdown copies omit some parameter lists that the HTML pages render (8 of 15). Every endpoint has examples in cURL and seven SDK languages, plus an error object and 13 general error codes. The full error code list is on a part of the page the Markdown copy omits (13 of 15). The path carries v2 and the releases page has dated notes almost every week. No written versioning policy was found, and some calls sit under /beta (12 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 63,
          "points": 10.24,
          "reason": "List calls take `page_size` up to 100 with a default of 20 on most endpoints. No field selection was found, and a shipment response nests addresses, parcel, rates and tracker (12 of 25). Cursor pagination by `before_id` and `after_id`, date ranges and a `has_more` flag, with support that varies by endpoint (16 of 20). Errors carry a machine-readable `code`, a message and per-field entries with an occasional suggestion. The `errors` array arrives as objects or as strings, so a client has to handle both (15 of 20). No idempotency keys were found. Trackers are deduplicated by tracking code and carrier for three months, but `reference` on a shipment isn't unique and nothing guards a repeated buy. The MCP tools only read, though we couldn't list them without a key to see annotations (5 of 20). One-call buy creates and purchases in one request, addresses and parcels can be nested or reused by id, and official SDKs cover seven languages (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 47,
          "points": 8.23,
          "reason": "API keys go in the HTTP Basic username over TLS 1.2. Keys can be created, disabled, enabled and deleted through the API or the dashboard, and the docs say a key allows full account access. Plain revocable keys, with no secret in a query string (20 of 30). Test keys buy no postage, child users hold separate keys, and the MCP server has read tools only and omits carrier credentials, wallet balances and payment methods. The REST API has no read-only or scoped key and no confirmation step before a purchase (8 of 20). Responses carry addresses and carrier tracking text. The MCP guide advises connecting only to trusted clients and servers, and no injection guidance was found (4 of 15). Events and their payloads can be retrieved and each shipment lists its fees, but no audit log of API calls or key use was found in the reviewed documentation (5 of 15). A Responsible Disclosure Policy with a safe-harbour commitment and the contact security-abuse@easypost.com, HMAC-signed webhooks, and a SOC 2 Type 2 report referred to in the data processing addendum. No security.txt and no bug bounty were found, and trust.easypost.com refused our reader (10 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 22,
          "points": 2.75,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). The API Addendum publishes unit fees without a login ($0.02 for each extra tracker, US address verification or rating call, $0.06 for an international verification, $0.03 a SmartRate call), and the pricing page lists tracking at $0.01 to $0.03 a shipment and insurance at 1 per cent. The per-label fee after 3,000 free labels isn't stated, and Forge, GlobalShip and Luma are priced by sales (12 of 20). Up to 3,000 labels carry no EasyPost fee and test keys cost nothing, but postage is always paid, and the docs say a wallet must be set up before keys are issued. Whether that needs a card wasn't established (10 of 20). A person signs up in a browser. Keys can be created by API only with an existing production key (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 85,
          "points": 7.44,
          "reason": "The releases page has an entry dated 28 September 2026, nine days before the check, and easypost-go 5.10.1 was tagged on 29 September (30). Ten dated release notes between 12 July and 28 September 2026 (20). A closed service with public release notes, support@easypost.com, a help centre, a dedicated ai@easypost.com address for the MCP server and a published four-hour response target on the Base support tier. We didn't read GitHub issues or test response times (11 of 15). Seven official SDKs, all pushed between 24 September and 3 October 2026, though the Java, Python, Ruby and Node stable releases date from 25 June (15). The Python library's CI lints and runs tests on Python 3.9 to 3.13, and the Node library has a 9.0.0 release candidate that moves to TypeScript and fetch (9 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 70,
          "points": 6.13,
          "note": "editorial 53, provenance 87",
          "reason": "The service is closed, under a Master Customer Agreement (version 6.1, effective 25 August 2026) and seven addenda in a legal centre that keeps every past version. The SDKs are MIT or ISC (15). The privacy policy (18 August 2025) gives no retention period. The agreement points to a Data Retention Policy in the help centre, which refused our reader, and it grants EasyPost a licence to use customer data to improve its services and develop new products during and after the term. A data processing addendum with EU and UK standard clauses is public (15 of 30). The agreement says EasyPost will use reasonable efforts to notify customers before API changes that aren't backwards compatible, with no notice period, and allows termination with a refund within 15 days if functionality is materially reduced. No deprecation policy with dates was found (6 of 20). Annex D of the addendum lists 12 subprocessors with purpose and country, all in the USA, and customers have 10 days to object to a new one (17 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-07",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "List calls take `page_size` up to 100 with a default of 20 on most endpoints. No field selection was found, and a shipment response nests addresses, parcel, rates and tracker (12 of 25). Cursor pagination by `before_id` and `after_id`, date ranges and a `has_more` flag, with support that varies by endpoint (16 of 20). Errors carry a machine-readable `code`, a message and per-field entries with an occasional suggestion. The `errors` array arrives as objects or as strings, so a client has to handle both (15 of 20). No idempotency keys were found. Trackers are deduplicated by tracking code and carrier for three months, but `reference` on a shipment isn't unique and nothing guards a repeated buy. The MCP tools only read, though we couldn't list them without a key to see annotations (5 of 20). One-call buy creates and purchases in one request, addresses and parcels can be nested or reused by id, and official SDKs cover seven languages (15).",
          "maintenance": "The releases page has an entry dated 28 September 2026, nine days before the check, and easypost-go 5.10.1 was tagged on 29 September (30). Ten dated release notes between 12 July and 28 September 2026 (20). A closed service with public release notes, support@easypost.com, a help centre, a dedicated ai@easypost.com address for the MCP server and a published four-hour response target on the Base support tier. We didn't read GitHub issues or test response times (11 of 15). Seven official SDKs, all pushed between 24 September and 3 October 2026, though the Java, Python, Ruby and Node stable releases date from 25 June (15). The Python library's CI lints and runs tests on Python 3.9 to 3.13, and the Node library has a 9.0.0 release candidate that moves to TypeScript and fetch (9 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). The API Addendum publishes unit fees without a login ($0.02 for each extra tracker, US address verification or rating call, $0.06 for an international verification, $0.03 a SmartRate call), and the pricing page lists tracking at $0.01 to $0.03 a shipment and insurance at 1 per cent. The per-label fee after 3,000 free labels isn't stated, and Forge, GlobalShip and Luma are priced by sales (12 of 20). Up to 3,000 labels carry no EasyPost fee and test keys cost nothing, but postage is always paid, and the docs say a wallet must be set up before keys are issued. Whether that needs a card wasn't established (10 of 20). A person signs up in a browser. Keys can be created by API only with an existing production key (0).",
          "reliability": "Read with the hosted lines and scored on the REST API at api.easypost.com/v2, the surface an agent would use to rate, buy and track. The hosted MCP server only reads and is an early release. www.easypoststatus.com on Statuspage lists 44 components with incident history (20). In the 90 days to 7 October 2026 it shows seven incidents. A connectivity fault at the hosting provider on 23 July affected all operations from 07:57 to about 12:21 Pacific time, and two carrier-side incidents were marked major (UPS accounts supplied by EasyPost on 22 July for 3 h 29 min, USPS Ship on 20 September for 5 h 24 min). Two short API degradations lasted 10 and 14 minutes. One core outage and two upstream majors (7 of 30). The rate-limiting guide gives five requests a second on index endpoints and a 60-account cap on rating, but the load-based limiter on buying and rating has no published number (8 of 15). The guide describes 429 handling with retry and backoff and a code sample. No Retry-After header and no idempotency keys were found, and the sample retries only GET and DELETE (8 of 15). The Master Customer Agreement supplies the service as is and as available, and the support addendum sets response targets only (0). The v2 API is generally available (10).",
          "schema": "No OpenAPI or similar spec was found in the docs, llms.txt, the page index or the 56 public repositories of the EasyPost GitHub organisation. A Postman workspace is listed, which we didn't read (0 of 25). llms.txt, a Markdown copy of almost every page and doc-index.json with audience and usage notes for each page (10). Each object has a property table with a type and description, and the index says when each page applies. Endpoint pages are mostly examples, with little on when not to use a call (12 of 20). Types and allowed values are given in prose tables, such as the ten tracker statuses, with no schema to validate against, and the Markdown copies omit some parameter lists that the HTML pages render (8 of 15). Every endpoint has examples in cURL and seven SDK languages, plus an error object and 13 general error codes. The full error code list is on a part of the page the Markdown copy omits (13 of 15). The path carries v2 and the releases page has dated notes almost every week. No written versioning policy was found, and some calls sit under /beta (12 of 15).",
          "security": "API keys go in the HTTP Basic username over TLS 1.2. Keys can be created, disabled, enabled and deleted through the API or the dashboard, and the docs say a key allows full account access. Plain revocable keys, with no secret in a query string (20 of 30). Test keys buy no postage, child users hold separate keys, and the MCP server has read tools only and omits carrier credentials, wallet balances and payment methods. The REST API has no read-only or scoped key and no confirmation step before a purchase (8 of 20). Responses carry addresses and carrier tracking text. The MCP guide advises connecting only to trusted clients and servers, and no injection guidance was found (4 of 15). Events and their payloads can be retrieved and each shipment lists its fees, but no audit log of API calls or key use was found in the reviewed documentation (5 of 15). A Responsible Disclosure Policy with a safe-harbour commitment and the contact security-abuse@easypost.com, HMAC-signed webhooks, and a SOC 2 Type 2 report referred to in the data processing addendum. No security.txt and no bug bounty were found, and trust.easypost.com refused our reader (10 of 20).",
          "transparency": "The service is closed, under a Master Customer Agreement (version 6.1, effective 25 August 2026) and seven addenda in a legal centre that keeps every past version. The SDKs are MIT or ISC (15). The privacy policy (18 August 2025) gives no retention period. The agreement points to a Data Retention Policy in the help centre, which refused our reader, and it grants EasyPost a licence to use customer data to improve its services and develop new products during and after the term. A data processing addendum with EU and UK standard clauses is public (15 of 30). The agreement says EasyPost will use reasonable efforts to notify customers before API changes that aren't backwards compatible, with no notice period, and allows termination with a refund within 15 days if functionality is materially reduced. No deprecation policy with dates was found (6 of 20). Annex D of the addendum lists 12 subprocessors with purpose and country, all in the USA, and customers have 10 days to object to a new one (17 of 20)."
        },
        "sources": [
          {
            "what": "home page",
            "url": "https://www.easypost.com/",
            "seen": "2026-10-07"
          },
          {
            "what": "pricing",
            "url": "https://www.easypost.com/pricing/",
            "seen": "2026-10-07"
          },
          {
            "what": "llms.txt and API basics",
            "url": "https://docs.easypost.com/llms.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "docs page index",
            "url": "https://docs.easypost.com/doc-index.json",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP guide, tools and security notes",
            "url": "https://docs.easypost.com/guides/mcp-guide",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP endpoint (401 without a key)",
            "url": "https://app-api.easypost.com/mcp",
            "seen": "2026-10-07"
          },
          {
            "what": "authentication",
            "url": "https://docs.easypost.com/markdown/docs/authentication.md",
            "seen": "2026-10-07"
          },
          {
            "what": "API keys",
            "url": "https://docs.easypost.com/markdown/docs/api-keys.md",
            "seen": "2026-10-07"
          },
          {
            "what": "rate limiting and backoff guide",
            "url": "https://docs.easypost.com/markdown/guides/rate-limiting-guide.md",
            "seen": "2026-10-07"
          },
          {
            "what": "errors reference",
            "url": "https://docs.easypost.com/markdown/docs/errors.md",
            "seen": "2026-10-07"
          },
          {
            "what": "errors guide and general error codes",
            "url": "https://docs.easypost.com/markdown/guides/errors-guide.md",
            "seen": "2026-10-07"
          },
          {
            "what": "pagination",
            "url": "https://docs.easypost.com/markdown/docs/pagination.md",
            "seen": "2026-10-07"
          },
          {
            "what": "shipments, buy and one-call buy",
            "url": "https://docs.easypost.com/markdown/docs/shipments.md",
            "seen": "2026-10-07"
          },
          {
            "what": "rates",
            "url": "https://docs.easypost.com/markdown/docs/shipments/rates.md",
            "seen": "2026-10-07"
          },
          {
            "what": "trackers, test codes and deduplication",
            "url": "https://docs.easypost.com/markdown/docs/trackers.md",
            "seen": "2026-10-07"
          },
          {
            "what": "addresses and verification",
            "url": "https://docs.easypost.com/markdown/docs/addresses.md",
            "seen": "2026-10-07"
          },
          {
            "what": "returns",
            "url": "https://docs.easypost.com/markdown/docs/shipments/returns.md",
            "seen": "2026-10-07"
          },
          {
            "what": "refunds",
            "url": "https://docs.easypost.com/markdown/docs/refunds.md",
            "seen": "2026-10-07"
          },
          {
            "what": "webhooks guide",
            "url": "https://docs.easypost.com/markdown/guides/webhooks-guide.md",
            "seen": "2026-10-07"
          },
          {
            "what": "getting started",
            "url": "https://docs.easypost.com/markdown/guides/getting-started.md",
            "seen": "2026-10-07"
          },
          {
            "what": "release notes",
            "url": "https://docs.easypost.com/releases",
            "seen": "2026-10-07"
          },
          {
            "what": "client libraries",
            "url": "https://docs.easypost.com/libraries",
            "seen": "2026-10-07"
          },
          {
            "what": "status page summary",
            "url": "https://www.easypoststatus.com/api/v2/summary.json",
            "seen": "2026-10-07"
          },
          {
            "what": "status incident history",
            "url": "https://www.easypoststatus.com/api/v2/incidents.json",
            "seen": "2026-10-07"
          },
          {
            "what": "legal centre, Master Customer Agreement",
            "url": "https://legal.easypost.com/#mca",
            "seen": "2026-10-07"
          },
          {
            "what": "API Addendum, fees",
            "url": "https://legal.easypost.com/#api",
            "seen": "2026-10-07"
          },
          {
            "what": "privacy policy and Responsible Disclosure Policy",
            "url": "https://legal.easypost.com/#privacy-policy",
            "seen": "2026-10-07"
          },
          {
            "what": "Data Protection Addendum and subprocessor annex",
            "url": "https://legal.easypost.com/#dpa",
            "seen": "2026-10-07"
          },
          {
            "what": "Support Services Addendum",
            "url": "https://legal.easypost.com/#base-support",
            "seen": "2026-10-07"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.easypost.com/.well-known/security.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "vendor repositories",
            "url": "https://api.github.com/orgs/EasyPost/repos?per_page=100\u0026sort=pushed",
            "seen": "2026-10-07"
          },
          {
            "what": "Node library, changelog and tags",
            "url": "https://github.com/EasyPost/easypost-node",
            "seen": "2026-10-07"
          },
          {
            "what": "Python library, changelog, tags and CI",
            "url": "https://github.com/EasyPost/easypost-python",
            "seen": "2026-10-07"
          },
          {
            "what": "Go library tags",
            "url": "https://github.com/EasyPost/easypost-go",
            "seen": "2026-10-07"
          },
          {
            "what": "npm package",
            "url": "https://registry.npmjs.org/@easypost/api/latest",
            "seen": "2026-10-07"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@easypost/api",
            "seen": "2026-10-07"
          },
          {
            "what": "PyPI package",
            "url": "https://pypi.org/pypi/easypost/json",
            "seen": "2026-10-07"
          },
          {
            "what": "PyPI recent downloads",
            "url": "https://pypistats.org/api/packages/easypost/recent",
            "seen": "2026-10-07"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=easypost",
            "seen": "2026-10-07"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/easypost.com",
            "seen": "2026-10-07"
          }
        ],
        "openQuestions": [
          "unchecked: trust.easypost.com and www.easypost.com/security answered 403 to our reader, so certifications beyond the SOC 2 Type 2 report named in the data processing addendum are unconfirmed.",
          "unchecked: the Data Retention Policy at support.easypost.com, which answered 403, so retention periods for shipment data are unknown.",
          "unchecked: the MCP server's tool schemas and annotations. tools/list answers 401 without a production key, so the 11 tools are taken from the guide.",
          "unchecked: the Postman workspace at www.postman.com/easypost-api, which may hold a machine-readable collection.",
          "unchecked: GitHub issues and response times on the SDK repositories.",
          "www.easypost.com/pricing answered a Cloudflare block to curl and loaded through WebFetch. Prices here come from that one read and from the API Addendum.",
          "The per-label fee after 3,000 free labels, and whether the 3,000 are counted by month or year, aren't stated on the pricing page.",
          "Whether setting up the wallet needed for API keys requires a card or a deposit wasn't established. We didn't sign up.",
          "The rate-limiting guide gives five requests a second on index endpoints as an example. Limits on buying and rating are load-based with no number.",
          "The 23 July 2026 outage has its Statuspage impact field left at none, although the updates say all operations were affected. We scored it as a major outage.",
          "No date was found for the MCP server's launch. It isn't in the release notes we read."
        ]
      },
      "negative": 0,
      "verdict": "Docs written for agents (llms.txt, a Markdown copy of each page, a JSON page index), seven official SDKs and free test keys make the REST API easy to start on. No OpenAPI spec or idempotency keys were found, every key has full account access, and the status page shows a connectivity outage on 23 July 2026 that affected all operations.",
      "bestFor": "An agent that quotes rates across carriers, buys a label, verifies an address, follows tracking by webhook and requests a refund from one merchant account, mainly on US carriers.",
      "strengths": [
        "llms.txt, a Markdown copy of almost every docs page and a JSON page index with a note on when to read each page",
        "Test API keys run the rate, buy, track and webhook flow at no cost, with no postage bought and no carrier contacted",
        "Seven official SDKs (C#, Go, Java, Node, PHP, Python, Ruby), with Go 5.10.1 on 29 September 2026 and PHP 8.8.3 on 8 September",
        "Dated release notes almost every week, 10 entries between 12 July and 28 September 2026",
        "The data processing addendum names 12 subprocessors with purpose and country, and the legal centre keeps every past version of each agreement"
      ],
      "weaknesses": [
        "No OpenAPI spec was found in the docs or in the EasyPost GitHub organisation. The reference is prose and tables, with a Postman workspace",
        "No idempotency keys were found, and `reference` on a shipment isn't unique, so a retried buy can purchase a second label",
        "API keys allow full account access. Test and production modes and child users are the only separation, with no read-only or scoped key",
        "An outage on 23 July 2026 at the hosting provider affected all operations for about four and a half hours. Two carrier-side incidents were marked major in the same 90 days",
        "The Master Customer Agreement supplies the service as is, with no uptime commitment, and the per-label fee after 3,000 free labels isn't on the pricing page"
      ],
      "agentNotes": [
        "Use a test API key while building. It buys no postage and contacts no carrier, and test tracking codes simulate each tracking status",
        "Don't blind-retry `POST /shipments/:id/buy` after a timeout. Retrieve the shipment first and check for `postage_label`, since no idempotency key exists",
        "Send the API key as the HTTP Basic username with an empty password on the REST API, and as a Bearer token on the MCP server",
        "Handle `errors` as either an array of objects or an array of strings. The docs say both shapes occur",
        "Pass a scoped `carrier_accounts` list when rating. Only the first 60 accounts are rated and the call doesn't fail when more are enabled"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 54.3
        }
      ],
      "editorialScores": {
        "ergonomics": 63,
        "maintenance": 85,
        "payments": 22,
        "reliability": 53,
        "schema": 55,
        "security": 47,
        "transparency": 53
      },
      "provenanceScore": 87
    },
    "connect": {
      "install": "npm install @easypost/api",
      "http": "curl -u \"$EASYPOST_API_KEY\": https://api.easypost.com/v2/shipments",
      "claudeCode": "claude mcp add --scope project --transport http easypost \\\n  https://app-api.easypost.com/mcp \\\n  --header 'Authorization: Bearer ${EASYPOST_API_KEY}'",
      "config": {
        "mcpServers": {
          "easypost": {
            "headers": {
              "Authorization": "Bearer ${EASYPOST_API_KEY}"
            },
            "type": "http",
            "url": "https://app-api.easypost.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/shipping.rates",
      "tool": "https://letme.dev/easypost"
    },
    "notable": [
      "The docs are published for agents. llms.txt, a Markdown copy of almost every page under /markdown, and doc-index.json with a note on when each page is the right one to read (https://docs.easypost.com/llms.txt)",
      "EasyPost MCP is a hosted server at https://app-api.easypost.com/mcp with 11 tools that only read. The guide calls it an early release and says it needs a production API key (https://docs.easypost.com/guides/mcp-guide)",
      "No vendor entry was found in the official MCP registry. The two EasyPost entries there, io.github.pipeworx-io/easypost and io.usefulapi/easypost, are third-party (https://registry.modelcontextprotocol.io/v0/servers?search=easypost)",
      "The pricing page lists the Suite as free for up to 3,000 labels on wallet carriers, postage not included, and $20 a month plus a per-label fee for customers who bring their own carrier accounts (https://www.easypost.com/pricing/)",
      "The API Addendum publishes overage fees, $0.02 for each extra tracker, US address verification or rating call and $0.06 for an international address verification (https://legal.easypost.com/#api)",
      "Trackers are deduplicated. The same tracking code and carrier from the same user within three months returns the original tracker (https://docs.easypost.com/docs/trackers)",
      "A return label is a shipment created with `is_return` set to true, which swaps the two addresses (https://docs.easypost.com/docs/shipments/returns)",
      "The status page records an outage on 23 July 2026, a connectivity fault at the hosting provider that affected all operations from 07:57 to about 12:21 Pacific time (https://www.easypoststatus.com/history)"
    ],
    "area": "business",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.easypost.com/v2 over TLS 1.2, JSON. Shipments, rates, addresses, trackers, refunds, insurance, claims, pickups, batches, orders, customs, scan forms, reports, webhooks, events, users, API keys and billing. Some newer calls sit under /beta, such as POST /beta/rates"
      },
      {
        "label": "Credentials",
        "value": "API key as the HTTP Basic username with an empty password. Test and production keys. Keys can be created, disabled, enabled and deleted through /api_keys with a production key. Every key has full account access. Child users have their own keys"
      },
      {
        "label": "Getting access",
        "value": "Self-serve signup at app.easypost.com. The docs say a wallet and a ship-from address must be set up before API keys can be seen or generated"
      },
      {
        "label": "Test mode",
        "value": "A test key buys no postage and contacts no carrier. Test tracking codes return fixed statuses and fire webhooks. Negotiated rates appear only in production"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://app-api.easypost.com/mcp, Streamable HTTP, Bearer production API key, early release. 11 read-only tools (whoami, list_shipments, get_shipment, list_trackers, get_tracker, list_carrier_accounts, carrier_metadata, pickups, refunds, insurances, claims). Test keys aren't supported"
      },
      {
        "label": "Rate limits",
        "value": "A load-based limiter on buying and rating, with no number published, and a fixed limit on index endpoints, given as five requests a second. 429 on excess. At most 60 carrier accounts are rated in one request"
      },
      {
        "label": "Lists",
        "value": "`page_size` up to 100 (most endpoints default to 20), `before_id` and `after_id`, `start_datetime` and `end_datetime`, and a `has_more` flag. Support varies by endpoint"
      },
      {
        "label": "Errors",
        "value": "JSON `error` object with `code`, `message` and `errors` (field, message, suggestion). `errors` can be an array of objects or of strings. 13 general codes in the errors guide, such as PAYMENT_REQUIRED and MODE.UNAUTHORIZED"
      },
      {
        "label": "Webhooks",
        "value": "Up to 30 endpoints, `X-Hmac-Signature` from a `webhook_secret`, an `X-Easypost-Event-Type` header, up to three custom headers, a seven-second response window and six retries"
      },
      {
        "label": "Refunds",
        "value": "POST /refunds by carrier and tracking code. USPS labels within 30 days if never scanned, with at least 15 days of processing. UPS and FedEx within 90 days"
      },
      {
        "label": "Address verification",
        "value": "`verify`, `verify_strict` and `verify_carrier` (UPS or FedEx) on address creation. The docs say more than 240 countries and territories are covered, at levels that vary by country"
      },
      {
        "label": "Fees in the API Addendum",
        "value": "Each label bought includes one tracker call, one address verification call and three rating calls. Beyond that, $0.02 a tracker, $0.02 a US address verification, $0.06 an international one, $0.02 a rating call, $0.03 a SmartRate call, $0.15 a Pay-On-Delivery return label, and a 3 per cent surcharge on labels bought on the customer's own USPS rate card with PC Postage (version 4.2, effective 21 August 2026)"
      },
      {
        "label": "SDKs",
        "value": "easypost-csharp 7.10.0 (27 July 2026), easypost-go 5.10.1 (29 September), easypost-java 8.8.0 (25 June), @easypost/api 8.9.0 (25 June, with 9.0.0-rc.1 on 8 September), easypost-php 8.8.3 (8 September), easypost 10.7.0 on PyPI (25 June), easypost-ruby 7.7.0 (25 June). MIT, with Go under ISC"
      },
      {
        "label": "Status",
        "value": "www.easypoststatus.com on Statuspage, 44 components covering the API, webhooks, tracking, address verification, label purchases and each carrier, with incident history"
      },
      {
        "label": "Support",
        "value": "support@easypost.com and a help centre. The Support Services Addendum sets a four-hour response target on the Base tier and 30 minutes for a critical outage"
      }
    ],
    "unitPrices": [
      {
        "item": "Extra tracker call",
        "unit": "call",
        "usd": 0.02,
        "note": "one included with each label bought"
      },
      {
        "item": "Extra US address verification",
        "unit": "call",
        "usd": 0.02,
        "note": "one included with each label bought; $0.06 outside the US"
      },
      {
        "item": "Extra rating call",
        "unit": "call",
        "usd": 0.02,
        "note": "three included with each label bought"
      },
      {
        "item": "SmartRate call",
        "unit": "call",
        "usd": 0.03
      },
      {
        "item": "Bring your own carrier accounts",
        "unit": "month",
        "usd": 20,
        "note": "plus a per-label fee not stated on the pricing page"
      }
    ],
    "provenance": {
      "legalEntity": "Simpler Postage, Inc. (d/b/a EasyPost)",
      "domain": "easypost.com",
      "domainRegistered": "1998-01-18",
      "endpointOnVendorDomain": true,
      "terms": "https://legal.easypost.com/#mca",
      "privacy": "https://legal.easypost.com/#privacy-policy",
      "statusPage": "https://www.easypoststatus.com",
      "changelog": "https://docs.easypost.com/releases",
      "securityTxt": "none",
      "checked": "2026-10-07",
      "notes": [
        "The Master Customer Agreement (version 6.1, effective 25 August 2026) names Simpler Postage, Inc. (d/b/a EasyPost), 2600 N. Ashton Blvd., Suite 300A, Lehi, UT 84043.",
        "www.easypost.com/.well-known/security.txt and api.easypost.com/.well-known/security.txt return 404. The legal centre carries a Responsible Disclosure Policy with the contact security-abuse@easypost.com.",
        "The privacy policy and the Data Protection Addendum are both version 1.0, effective 18 August 2025. The addendum's Annex D lists 12 subprocessors, all in the USA.",
        "The MCP server is on app-api.easypost.com and the REST API on api.easypost.com. The status page is on a separate domain, easypoststatus.com.",
        "trust.easypost.com answered 403 to our reader, so certifications are taken only from the addendum, which refers to a SOC 2 Type 2 report."
      ],
      "score": 87,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Simpler Postage, Inc. (d/b/a EasyPost)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "easypost.com, registered 1998-01-18 (28 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.easypost.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "www.easypoststatus.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://legal.easypost.com/#mca",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-25",
          "words": 97752,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective August 25th 2026",
              "says": "Last updated 2026-08-25"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement shall be governed by the laws of the State of Utah, exclusive of its rules governing conflicts of laws.",
              "says": "The law of the State of Utah"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "NOTWITHSTANDING ANYTHING ELSE IN THIS AGREEMENT, EASYPOST PROVIDES NO WARRANTY, INDEMNITY, SUPPORT FOR BETA FEATURES, AND ITS LIABILITY FOR BETA FEATURES WILL NOT EXCEED US$50.",
              "says": "Capped at US$50"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Termination of this Agreement will terminate all Order Form Terms then-in effect unless otherwise specified on the applicable Order Form."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Updated Master Terms will be effective upon the earlier of: (a) renewal, including auto renewal, of an Order Form (provided that the updated Master Terms were posted at least 30 days prior to such renewal) and (b) Customer entering into a new Order Form after such updated Master Terms have been posted.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "IF YOU DO NOT HAVE SUCH AUTHORITY, OR IF YOU DO NOT AGREE WITH THIS AGREEMENT, YOU MUST NOT ACCEPT THIS AGREEMENT AND MAY NOT USE ANY PRODUCT OR RECEIVE ANY PROFESSIONAL SERVICES."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Access for any competitive purposes (including to build an application or product that is competitive with the EasyPost Products and Services).",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Any dispute or claim arising out of or relating to this Agreement or breach thereof, shall be settled by confidential binding arbitration in Salt Lake City, Utah, under the Rules of Arbitration of the International Chamber of Commerce by one arbitrator appointed in accordance with said rules."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://legal.easypost.com/#privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-25",
          "words": 97752,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective August 25th 2026",
              "says": "Last updated 2026-08-25"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "(d/b/a EasyPost) (“Company”, “we”, “us” “our”) describes how we collect, use and disclose information about users of our website (www.easypost.com) and our mobile and desktop applications and platform, services, tools and features, including when interacting with us in the context of an application for employment or i…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain your information for as long as is reasonably necessary for the purposes specified in this Privacy Policy."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Customer’s use of Third-Party Offerings is subject to Customer’s agreement with the relevant provider governing Customer’s access to and receipt or use of such Third-Party Offerings (“Third-Party Provider Agreements”) and not this Agreement."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not “sell” or “share” personal information (as those terms are defined in applicable law), including sensitive personal information, nor have we done so in the preceding 12 months."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "not share with Company any Personal Data of any Data Subject who has exercised a right to opt-out that Customer has committed to honoring;"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Should you have any questions about our privacy practices or this Privacy Policy, please email us at privacy@easypost.com or contact us at Simpler Postage, Inc.",
              "says": "privacy@easypost.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "“EU Standard Contractual Clauses” means the contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council s…",
              "says": "Relies on standard contractual clauses"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/easypost.json",
    "live": {
      "slug": "easypost",
      "probe": {
        "target": "https://api.easypost.com/v2",
        "method": "get",
        "lastAt": "2026-10-08T19:52:49.942305454Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 614,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 620,
        "p95ms24h": 709,
        "samples24h": 50,
        "samples30d": 50,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 50,
            "ok": 50
          }
        ]
      },
      "vendorStatus": {
        "page": "https://www.easypoststatus.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:50:36.5258912Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "EasyPost/easypost-node",
          "version": "v8.9.0",
          "released": "2026-06-25",
          "seenAt": "2026-10-08T16:09:51.321427764Z"
        },
        {
          "registry": "npm",
          "name": "@easypost/api",
          "version": "8.9.0",
          "seenAt": "2026-10-08T16:09:46.909448157Z"
        },
        {
          "registry": "pypi",
          "name": "easypost",
          "version": "10.7.0",
          "released": "2026-06-25",
          "seenAt": "2026-10-08T16:09:51.109480743Z"
        }
      ],
      "githubStars": 149,
      "npmWeekly": 99736,
      "pypiWeekly": 43392,
      "securityTxt": {
        "url": "https://easypost.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:46.376321685Z"
      },
      "pages": [
        {
          "url": "https://docs.easypost.com/releases",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:18:43.380604863Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "bdf82a55e910"
        },
        {
          "url": "https://legal.easypost.com/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:24.366175945Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c3f1c1d70fd7"
        }
      ],
      "updatedAt": "2026-10-08T19:52:49.942305454Z"
    }
  }
}
