{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "karrio",
    "name": "Karrio",
    "vendor": "Karrio, Inc.",
    "vendorUrl": "https://www.karrio.io",
    "kind": "http-api",
    "category": "shipping",
    "summary": "Karrio is an open-source multi-carrier shipping server from Karrio, Inc. Its REST API quotes rates, buys labels, tracks parcels and books pickups through the owner's own carrier accounts, self-hosted with Docker or run by Karrio as a paid platform.",
    "url": "https://www.anchorterminal.com/tools/karrio",
    "markdownUrl": "https://www.anchorterminal.com/tools/karrio.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/karrio.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/karrio.json",
    "repo": "https://github.com/karrioapi/karrio",
    "license": "LGPL-3.0 for the server, SDK and modules. Code under `ee/` is under the Karrio Enterprise licence and needs a subscription for production use. The MCP package in `packages/mcp` is Apache-2.0",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "pypi",
        "name": "karrio"
      },
      {
        "registry": "pypi",
        "name": "karrio-server"
      },
      {
        "registry": "oci",
        "name": "karrio/server"
      }
    ],
    "auth": "api-key",
    "authNotes": "A private API key from the instance's dashboard, sent as the HTTP Basic username with no password or as `Authorization: Token key_...`. Keys carry a label and are bound to test or live mode, and the docs say a private key can perform any request without restriction. A JWT pair is also issued by `POST /api/token` for an email and password. On a self-hosted instance the owner creates the first account, so no approval from Karrio is involved. The managed platform is reached through a demo booking.",
    "pricing": "freemium",
    "pricingNotes": "Free when self-hosted under LGPL-3.0, with carrier postage billed by the owner's own carrier accounts. The platform page says the managed Scale platform starts at $499 a month with pay-as-you-go pricing and a commercial licence for embedding starts at $50,000 a year, with no unit prices published. An agent can start on a self-hosted instance in test mode with no contract. The managed platform has no self-serve signup, only a demo booking (checked 2026-10-08).",
    "priceSummary": "$499 / mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the repository, the OpenAPI file, the docs or the platform page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 799,
      "npmWeekly": null,
      "pypiWeekly": 338,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.karrio.io/docs",
    "openapi": "https://raw.githubusercontent.com/karrioapi/karrio/main/schemas/openapi.yml",
    "capabilities": [
      "shipping.rates",
      "shipping.labels",
      "shipping.tracking",
      "shipping.returns"
    ],
    "tags": [
      "open-source",
      "self-hosted",
      "api-key",
      "openapi",
      "graphql",
      "webhooks",
      "sandbox",
      "docker",
      "python",
      "mcp"
    ],
    "lastRelease": "2026-06-23",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 48.7,
      "grade": "D",
      "agentReady": false,
      "rank": 617,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 8,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 57,
        "maintenance": 29,
        "payments": 40,
        "reliability": 76,
        "schema": 68,
        "security": 44,
        "transparency": 56
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 76,
          "points": 15.2,
          "reason": "Read with the local-software lines, since the graded surface is the open-source server its owner hosts. The managed platform has no status page we could find, and its hosts didn't answer on 8 October 2026. Docker images on Docker Hub and PyPI packages at 2026.1.32, with Python 3.11 or later stated for `karrio`, though `karrio-server` still declares 3.7 or later (18 of 20). A public tests workflow runs SDK type checks, SDK tests and server tests on PostgreSQL, and the last five runs on main, all on 23 June 2026, passed (25). GitHub Issues is switched off, so bug reports go to Discussions. Reports from July and August 2026 on FedEx dimensions and a GraphQL crash had no reply, and a June report that migration 0093 deleted tracker history was fixed in 2026.1.32 (10 of 25). Versions are calendar-based, not semver, and the breaking rename of the `purchased` status shipped in 2026.1.20 with a banner in the changelog (8 of 15). Releases are past 1.0 and numbered for production use (15)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 68,
          "points": 11.05,
          "reason": "`schemas/openapi.yml` is OpenAPI 3.0.3 at version 2026.1.32, with 65 paths, and the docs site renders a reference from it. GraphQL schemas sit beside it (25). No llms.txt on www.karrio.io or docs.karrio.io, both 404 (0). The spec carries about 1,200 description lines and the guides cover authentication, pagination, shipments, trackers and webhooks, with little on when not to use a call, such as the stored `/v1/shipments` against the pass-through `/v1/proxy/shipping` (12 of 20). Units, statuses and label types are enums and required fields are marked, but carrier `options` and connection `credentials` are open objects whose keys differ by carrier (10 of 15). The guides have cURL and JavaScript examples and the spec has an `ErrorResponse` schema, while the error guide is a table of HTTP statuses only (9 of 15). Versions are dated and `CHANGELOG.md` is current, but the changelog page on the website stops at 2024.12.6 (12 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 57,
          "points": 9.26,
          "reason": "List calls take `limit` from 1 to 100 with `offset`. No field selection was found, and a shipment response nests addresses, parcels, rates and documents. The MCP server in source has 12 compact tools but isn't published (13 of 25). Offset pagination with `count`, `next` and `previous`, and filters on carrier, status, dates, keyword and metadata (17 of 20). Errors come back as an `errors` array with a code, message and details, and carrier messages pass through. The published guide lists HTTP statuses, not codes (12 of 20). No idempotency keys were found in the server or the spec. A cancel on an already cancelled shipment returns 202, and the MCP tools in source carry `readOnlyHint` and `destructiveHint` (8 of 20). A shipment created with a `service` buys the label in one call and addresses can be nested. The Python SDK is current, while the npm client `karrio` is at 2023.1.0 (7 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 44,
          "points": 7.7,
          "reason": "Private API keys with a label, bound to test or live mode, sent as the Basic username or in the `Authorization` header. The docs say a private key can perform any request without restriction. Short-lived resource tokens for document links can travel in a `?token=` query string, which we didn't count against the score because they expire in five minutes by default and open one resource (20 of 30). Test-mode keys keep building away from live carriers. Team permissions are in the paid `ee/` code, and the MCP guide asks the agent to confirm with the user before `create_shipment` (7 of 20). Responses carry carrier tracking text and addresses, and no injection guidance was found (3 of 15). API logs, tracing records and events are stored and readable in the open-source edition, and audit logging is listed as an enterprise feature (10 of 15). `SECURITY.md` gives an email address only. No security.txt, bug bounty or certification was found, and GitHub lists no published advisories although 2026.1.32 fixed MD5 password storage (4 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). Self-hosting is free, and the platform page gives starting prices only, $499 a month for the managed Scale platform with pay-as-you-go usage and $50,000 a year for a commercial licence, with no unit price (10 of 20). The open-source edition needs no card or account (20). Install is scriptable with Docker Compose and `POST /api/token` issues a JWT for an email and password, but carrier accounts and the API key are set up by a person, so half (10 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 29,
          "points": 2.54,
          "reason": "The newest release, 2026.1.32, is dated 23 June 2026, 107 days before the check, and nothing has landed on main since (10 of 30). No release between 10 July and 8 October 2026 (0 of 20). Of the 15 newest Discussions threads, 10 showed no maintainer reply, and fix pull requests opened between 23 September and 2 October 2026 each had one or two comments and were unmerged, among 83 open pull requests (8 of 25). No entry in the official MCP registry and no MCP package on npm. The PyPI packages match the last release and the npm client is at 2023.1.0 (5 of 15). CI passed on the last commit and the changelog records pinning axios away from compromised versions, while dependency pull requests from April and June 2026 remain open (6 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 56,
          "points": 4.9,
          "note": "editorial 59, provenance 53",
          "reason": "The server, SDK and modules are LGPL-3.0, an OSI licence. `ee/` is under a proprietary licence in the same repository, and the PyPI metadata for `karrio` leaves the licence field empty (26 of 30). On a self-hosted instance the data stays with the owner. The privacy policy (8 April 2025) covers the website and associated services, excludes customer data, gives no retention periods and names 12 service providers. No data processing addendum was found (14 of 30). Breaking changes are flagged in the changelog and the spec says a new dated version marks an incompatible change. No deprecation policy with notice periods was found (7 of 20). Sentry and PostHog reporting are documented and stay off unless the operator sets their keys. The Compose files pull images through a Scarf gateway and the README carries a Scarf pixel, neither described in the docs we read (12 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "List calls take `limit` from 1 to 100 with `offset`. No field selection was found, and a shipment response nests addresses, parcels, rates and documents. The MCP server in source has 12 compact tools but isn't published (13 of 25). Offset pagination with `count`, `next` and `previous`, and filters on carrier, status, dates, keyword and metadata (17 of 20). Errors come back as an `errors` array with a code, message and details, and carrier messages pass through. The published guide lists HTTP statuses, not codes (12 of 20). No idempotency keys were found in the server or the spec. A cancel on an already cancelled shipment returns 202, and the MCP tools in source carry `readOnlyHint` and `destructiveHint` (8 of 20). A shipment created with a `service` buys the label in one call and addresses can be nested. The Python SDK is current, while the npm client `karrio` is at 2023.1.0 (7 of 15).",
          "maintenance": "The newest release, 2026.1.32, is dated 23 June 2026, 107 days before the check, and nothing has landed on main since (10 of 30). No release between 10 July and 8 October 2026 (0 of 20). Of the 15 newest Discussions threads, 10 showed no maintainer reply, and fix pull requests opened between 23 September and 2 October 2026 each had one or two comments and were unmerged, among 83 open pull requests (8 of 25). No entry in the official MCP registry and no MCP package on npm. The PyPI packages match the last release and the npm client is at 2023.1.0 (5 of 15). CI passed on the last commit and the changelog records pinning axios away from compromised versions, while dependency pull requests from April and June 2026 remain open (6 of 10).",
          "payments": "Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). Self-hosting is free, and the platform page gives starting prices only, $499 a month for the managed Scale platform with pay-as-you-go usage and $50,000 a year for a commercial licence, with no unit price (10 of 20). The open-source edition needs no card or account (20). Install is scriptable with Docker Compose and `POST /api/token` issues a JWT for an email and password, but carrier accounts and the API key are set up by a person, so half (10 of 20).",
          "reliability": "Read with the local-software lines, since the graded surface is the open-source server its owner hosts. The managed platform has no status page we could find, and its hosts didn't answer on 8 October 2026. Docker images on Docker Hub and PyPI packages at 2026.1.32, with Python 3.11 or later stated for `karrio`, though `karrio-server` still declares 3.7 or later (18 of 20). A public tests workflow runs SDK type checks, SDK tests and server tests on PostgreSQL, and the last five runs on main, all on 23 June 2026, passed (25). GitHub Issues is switched off, so bug reports go to Discussions. Reports from July and August 2026 on FedEx dimensions and a GraphQL crash had no reply, and a June report that migration 0093 deleted tracker history was fixed in 2026.1.32 (10 of 25). Versions are calendar-based, not semver, and the breaking rename of the `purchased` status shipped in 2026.1.20 with a banner in the changelog (8 of 15). Releases are past 1.0 and numbered for production use (15).",
          "schema": "`schemas/openapi.yml` is OpenAPI 3.0.3 at version 2026.1.32, with 65 paths, and the docs site renders a reference from it. GraphQL schemas sit beside it (25). No llms.txt on www.karrio.io or docs.karrio.io, both 404 (0). The spec carries about 1,200 description lines and the guides cover authentication, pagination, shipments, trackers and webhooks, with little on when not to use a call, such as the stored `/v1/shipments` against the pass-through `/v1/proxy/shipping` (12 of 20). Units, statuses and label types are enums and required fields are marked, but carrier `options` and connection `credentials` are open objects whose keys differ by carrier (10 of 15). The guides have cURL and JavaScript examples and the spec has an `ErrorResponse` schema, while the error guide is a table of HTTP statuses only (9 of 15). Versions are dated and `CHANGELOG.md` is current, but the changelog page on the website stops at 2024.12.6 (12 of 15).",
          "security": "Private API keys with a label, bound to test or live mode, sent as the Basic username or in the `Authorization` header. The docs say a private key can perform any request without restriction. Short-lived resource tokens for document links can travel in a `?token=` query string, which we didn't count against the score because they expire in five minutes by default and open one resource (20 of 30). Test-mode keys keep building away from live carriers. Team permissions are in the paid `ee/` code, and the MCP guide asks the agent to confirm with the user before `create_shipment` (7 of 20). Responses carry carrier tracking text and addresses, and no injection guidance was found (3 of 15). API logs, tracing records and events are stored and readable in the open-source edition, and audit logging is listed as an enterprise feature (10 of 15). `SECURITY.md` gives an email address only. No security.txt, bug bounty or certification was found, and GitHub lists no published advisories although 2026.1.32 fixed MD5 password storage (4 of 20).",
          "transparency": "The server, SDK and modules are LGPL-3.0, an OSI licence. `ee/` is under a proprietary licence in the same repository, and the PyPI metadata for `karrio` leaves the licence field empty (26 of 30). On a self-hosted instance the data stays with the owner. The privacy policy (8 April 2025) covers the website and associated services, excludes customer data, gives no retention periods and names 12 service providers. No data processing addendum was found (14 of 30). Breaking changes are flagged in the changelog and the spec says a new dated version marks an incompatible change. No deprecation policy with notice periods was found (7 of 20). Sentry and PostHog reporting are documented and stay off unless the operator sets their keys. The Compose files pull images through a Scarf gateway and the README carries a Scarf pixel, neither described in the docs we read (12 of 20)."
        },
        "sources": [
          {
            "what": "repository at tag v2026.1.32 (README, licences, changelog, OpenAPI file, settings, MCP package, CI workflows)",
            "url": "https://github.com/karrioapi/karrio",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://github.com/karrioapi/karrio/blob/main/CHANGELOG.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI 3.0.3 file",
            "url": "https://raw.githubusercontent.com/karrioapi/karrio/main/schemas/openapi.yml",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP package source",
            "url": "https://github.com/karrioapi/karrio/tree/main/packages/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP guide",
            "url": "https://www.karrio.io/docs/developing/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry lookup for the MCP package, 404",
            "url": "https://registry.npmjs.org/@karrio%2fmcp",
            "seen": "2026-10-08"
          },
          {
            "what": "platform page with prices",
            "url": "https://www.karrio.io/platform",
            "seen": "2026-10-08"
          },
          {
            "what": "home page",
            "url": "https://www.karrio.io",
            "seen": "2026-10-08"
          },
          {
            "what": "Customer Terms and Conditions",
            "url": "https://www.karrio.io/terms-of-service",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.karrio.io/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "older terms referenced by the enterprise licence",
            "url": "https://docs.karrio.io/product/resources/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "dashboard host, 503 with a paused deployment",
            "url": "https://app.karrio.io",
            "seen": "2026-10-08"
          },
          {
            "what": "Discussions",
            "url": "https://github.com/orgs/karrioapi/discussions",
            "seen": "2026-10-08"
          },
          {
            "what": "GitHub API for stars, open pull requests and test runs",
            "url": "https://api.github.com/repos/karrioapi/karrio",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI package",
            "url": "https://pypi.org/pypi/karrio/json",
            "seen": "2026-10-08"
          },
          {
            "what": "Docker Hub image",
            "url": "https://hub.docker.com/r/karrio/server",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search, no result",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=karrio",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record for karrio.io",
            "url": "https://rdap.identitydigital.services/rdap/domain/karrio.io",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: whether the managed platform is still operating. `api.karrio.io` didn't resolve and `app.karrio.io` and `platform.karrio.io` returned Vercel's paused-deployment error on 8 October 2026, which may be temporary",
          "unchecked: the community carrier submodule, which we didn't fetch, so the connector count of 30 covers `modules/connectors` only",
          "unchecked: reply times in Discord, and the sponsorship prices for Insiders, since polar.sh/karrioapi returned 404",
          "Whether releases have moved to a private or Insiders repository since June 2026 wasn't established",
          "No address validation endpoint was found in the OpenAPI file, so `shipping.address-validation` is left out. Returns rest on the `is_return` and `return_shipment` fields in the spec, which we didn't exercise",
          "The lead said REST API and SDKs with a cloud option. The cloud option couldn't be reached, and the listing grades the self-hosted server"
        ]
      },
      "negative": -7,
      "negativeNotes": [
        "12 March to 23 June 2026. Versions 2026.1.22 to 2026.1.31 applied an MD5 `PASSWORD_HASHERS` override outside the test runner, so production instances stored MD5 password hashes. Fixed in 2026.1.32 and described in the changelog, with no published advisory, so 4 of a possible 15 (https://github.com/karrioapi/karrio/blob/main/CHANGELOG.md).",
        "8 October 2026. The README and the MCP guide tell users to run `npx karrio-mcp` and `npx -y @karrio/mcp`, and the npm registry answers 404 for both. The examples' API host `api.karrio.io` didn't resolve the same day. 3 for a claim the listing can't meet (https://registry.npmjs.org/@karrio%2fmcp, https://www.karrio.io/docs/developing/mcp-server)."
      ],
      "verdict": "A current OpenAPI 3.0.3 contract with 65 paths, a free LGPL-3.0 server and 30 carrier connectors suit a team that hosts it. The last release was 23 June 2026, the `@karrio/mcp` package the docs install is absent from npm, and `api.karrio.io` didn't resolve on 8 October 2026.",
      "bestFor": "A team that wants to host its own multi-carrier API with its own carrier contracts and can maintain a Django and PostgreSQL stack.",
      "strengths": [
        "OpenAPI 3.0.3 contract in the repository at version 2026.1.32, with 65 paths covering rates, shipments, trackers, pickups, manifests, orders, documents and webhooks",
        "The core server and SDK are LGPL-3.0 and run on the owner's infrastructure with Docker Compose, with no fee to Karrio",
        "30 carrier connectors in `modules/connectors`, among them UPS, FedEx, USPS, DHL Express, Canada Post, DPD and Australia Post, used with the owner's own carrier accounts",
        "API keys are bound to test or live mode, and test mode runs rates, labels, trackers and pickups against carrier sandboxes",
        "Default throttles are in the settings file with numbers (600 requests a minute per user, 300 for carrier calls) and can be changed by environment variable"
      ],
      "weaknesses": [
        "No release since 2026.1.32 on 23 June 2026, 107 days before this check, and fix pull requests opened in September 2026 were still open",
        "Neither `@karrio/mcp` nor `karrio-mcp` exists on npm, though the README and the MCP guide give `npx` commands for them",
        "`api.karrio.io` didn't resolve and `app.karrio.io` answered 503 with a paused deployment on 8 October 2026, and the managed platform starts with a demo booking",
        "Versions 2026.1.22 to 2026.1.31 stored passwords as MD5 hashes in production, fixed in 2026.1.32 with a changelog line and no published advisory",
        "No idempotency keys were found, and a private API key can perform any request. Team permissions and audit logging sit in the paid `ee/` code"
      ],
      "agentNotes": [
        "Run your own instance with Docker Compose and call it at `http://localhost:5002`. Don't rely on `api.karrio.io`, which didn't resolve on 8 October 2026",
        "Don't run `npx karrio-mcp` or `npx -y @karrio/mcp`. Neither name is published on npm, so build the server from `packages/mcp` in the repository",
        "Change the default `admin@example.com` and `demo` login before the instance is reachable, and upgrade to 2026.1.32 or later so passwords aren't stored as MD5",
        "Don't blind-retry `POST /v1/shipments` with a `service` set or `POST /v1/shipments/{id}/purchase`. Fetch the shipment and check its status first, since no idempotency key exists",
        "Use a test-mode API key while building. Send it as the HTTP Basic username or as `Authorization: Token key_...`"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 48.7
        }
      ],
      "editorialScores": {
        "ergonomics": 57,
        "maintenance": 29,
        "payments": 40,
        "reliability": 76,
        "schema": 68,
        "security": 44,
        "transparency": 59
      },
      "provenanceScore": 53
    },
    "connect": {
      "install": "git clone --depth 1 https://github.com/karrioapi/karrio\ncd karrio\ngit submodule update --init community\ncd docker\ndocker compose up",
      "http": "curl http://localhost:5002/v1/shipments \\\n  -u key_xxxxxx:"
    },
    "letme": {
      "capability": "https://letme.dev/shipping.rates",
      "tool": "https://letme.dev/karrio"
    },
    "notable": [
      "The repository's default branch and newest tag are both at 2026.1.32, dated 23 June 2026, with 33 dated 2026 entries in `CHANGELOG.md` before it (https://github.com/karrioapi/karrio/blob/main/CHANGELOG.md)",
      "The README configures the MCP server with `npx karrio-mcp` and the MCP guide with `npx -y @karrio/mcp`. The npm registry answered 404 for both names on 8 October 2026 (https://registry.npmjs.org/@karrio%2fmcp)",
      "`packages/mcp` holds 12 tools in source, each with `readOnlyHint` and `destructiveHint` annotations, over stdio or Streamable HTTP (https://github.com/karrioapi/karrio/tree/main/packages/mcp)",
      "`api.karrio.io`, the base URL in the docs' examples, didn't resolve in DNS on 8 October 2026, and `app.karrio.io` returned 503 with Vercel's `DEPLOYMENT_PAUSED` error (https://app.karrio.io)",
      "The platform page says self-hosting is free, the managed Scale platform starts at $499 a month with pay-as-you-go pricing, and a commercial licence for embedding starts at $50,000 a year (https://www.karrio.io/platform)",
      "The 2026.1.32 changelog says the MD5 `PASSWORD_HASHERS` override is now scoped to the test runner so production no longer stores MD5 password hashes. The override arrived in a commit of 12 March 2026 (https://github.com/karrioapi/karrio/blob/main/CHANGELOG.md)",
      "GitHub Issues is switched off and questions go to Discussions, where 10 of the 15 newest threads showed no maintainer reply on 8 October 2026 (https://github.com/orgs/karrioapi/discussions)",
      "The Compose files pull images through `karrio.docker.scarf.sh`, a Scarf gateway, and Sentry and PostHog reporting run only when the operator sets `SENTRY_DSN` or `POSTHOG_KEY` (https://github.com/karrioapi/karrio/blob/main/docker/docker-compose.yml)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Graded surface",
        "value": "The open-source server its owner hosts, REST under `/v1` with a GraphQL API beside it. The managed platform wasn't reachable for grading on 8 October 2026"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.0.3, version 2026.1.32, 65 paths. Shipments, rates, trackers, pickups, manifests, orders, addresses, parcels, products, documents, webhooks, carrier connections, batches, plus `/v1/proxy/*` calls that pass straight to a carrier without storing a record"
      },
      {
        "label": "Carriers",
        "value": "30 connectors in `modules/connectors`, among them UPS, FedEx, USPS, DHL Express, DHL Parcel DE, Canada Post, Purolator, DPD, GLS, La Poste, Chronopost, Australia Post and Sendle. More sit in a community submodule we didn't count. The owner supplies the carrier accounts"
      },
      {
        "label": "Credentials",
        "value": "Private API keys (`key_...`) with a label, bound to test or live mode, sent as the HTTP Basic username or `Authorization: Token`. JWT pairs from `POST /api/token` with email and password. Short-lived resource tokens from `POST /api/tokens` for document links, five minutes by default and one hour at most"
      },
      {
        "label": "Getting access",
        "value": "Self-hosted, `docker compose up` in `docker/`, API on port 5002 and dashboard on 3002, default login `admin@example.com` with password `demo`. The managed platform is by demo booking"
      },
      {
        "label": "Test mode",
        "value": "Keys are bound to test or live mode, and JWT requests choose with the `x-test-mode` header. Test mode calls the carriers' sandbox hosts with the owner's sandbox credentials"
      },
      {
        "label": "Rate limits",
        "value": "Defaults in `settings/base.py`. 60 a minute anonymous, 600 a minute per user, 300 a minute on carrier requests, each set by environment variable (`ANON_RATE_LIMIT`, `USER_RATE_LIMIT`, `CARRIER_REQUEST_RATE_LIMIT`)"
      },
      {
        "label": "Pagination",
        "value": "`limit` from 1 to 100 and `offset`, with `count`, `next` and `previous` in the response. Shipment lists filter by carrier, status, dates, keyword, metadata key and value, `is_return` and more"
      },
      {
        "label": "MCP server",
        "value": "`packages/mcp` in the repository, Apache-2.0, version 1.0.0, 12 tools and two carrier resources, stdio or Streamable HTTP on port 3100. Not on npm on 8 October 2026 and not in the official MCP registry"
      },
      {
        "label": "Packages",
        "value": "PyPI `karrio` 2026.1.32 (Python 3.11 or later), `karrio-server` 2026.1.32 and `karrio-cli`, all uploaded 23 June 2026. Docker Hub `karrio/server`, about 27,000 pulls. The npm client `karrio` is at 2023.1.0"
      },
      {
        "label": "Licence",
        "value": "LGPL-3.0 for the server, SDK and modules. `ee/` (multi-tenancy, workflows, audit logging, SSO) under the Karrio Enterprise licence, which needs a subscription for production use. MCP package Apache-2.0"
      },
      {
        "label": "Support",
        "value": "GitHub Discussions and Discord for the open-source edition. The platform page lists email and Slack support for Scale customers and an SLA for enterprise and commercial licence customers"
      }
    ],
    "unitPrices": [
      {
        "item": "Open-source edition, self-hosted",
        "unit": "month",
        "usd": 0,
        "note": "LGPL-3.0, you pay for your own hosting and carrier postage"
      },
      {
        "item": "Scale managed platform, starting price",
        "unit": "month",
        "usd": 499,
        "note": "plus pay-as-you-go usage with no published unit price, by demo booking"
      }
    ],
    "provenance": {
      "legalEntity": "Karrio, Inc.",
      "domain": "karrio.io",
      "domainRegistered": "2022-01-20",
      "endpointOnVendorDomain": false,
      "terms": "https://www.karrio.io/terms-of-service",
      "privacy": "https://www.karrio.io/privacy-policy",
      "statusPage": "",
      "changelog": "https://github.com/karrioapi/karrio/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Customer Terms and Conditions (last modified 8 April 2025) name Karrio, Inc., a Delaware corporation at 760 Chemin Marie-Le Ber, Verdun, Quebec, Canada, and govern the hosted platform. The self-hosted open-source edition is governed by LGPL-3.0, and `LICENSE_EE` points `ee/` users to the subscription terms at docs.karrio.io/product/resources/terms, an older copy dated 19 April 2022.",
        "The privacy policy (last modified 8 April 2025) covers karrio.io and associated services and excludes customer data processed on a customer's behalf. No data processing addendum was found.",
        "The graded surface is an instance on the owner's own host, so the endpoint isn't on the vendor's domain. `api.karrio.io` didn't resolve and `app.karrio.io` returned 503 on 8 October 2026.",
        "No status page was found. `status.karrio.io` didn't resolve and the site links none.",
        "www.karrio.io/.well-known/security.txt returns 404. `SECURITY.md` in the repository sends reports to hello@karrio.io.",
        "The changelog page on www.karrio.io stops at 2024.12.6. `CHANGELOG.md` in the repository is current to 2026.1.32.",
        "RDAP for karrio.io gives a registration date of 2022-01-20."
      ],
      "score": 53,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Karrio, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "karrio.io, registered 2022-01-20 (4 years)",
          "points": 7,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on karrio.io",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.karrio.io/terms-of-service",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-04-08",
          "words": 5676,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Modified: 08 April 2025",
              "says": "Last updated 2025-04-08"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement is governed by and construed in accordance with the internal laws of the State of California without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the State of California.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "event will either party’s aggregate liability arising out of or related to this"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Notwithstanding anything to the contrary in this Agreement, Karrio may temporarily suspend Customer’s and any Authorized User’s access to any portion or all of the Services if: (i) Karrio reasonably determines that (A) there is a threat or attack on any of the Karrio IP;"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer shall not use the Services for any purposes beyond the scope of the access granted in this Agreement."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(vi) access or use any Karrio IP for purposes of competitive analysis of Karrio or the Services, the development, provision, or use of a competing software service or product, or any other purpose that is to Karrio’s detriment or commercial disadvantage",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Karrio may name the customer and use its name, logo and trademarks in its customer list, press releases, blog posts, advertisements and website.",
              "quote": "Karrio may identify Customer as a user of the Services and may use Customer’s name, logo, and other trademarks in Karrio’s customer list, press releases, blog posts, advertisements, and website"
            },
            {
              "date": "2026-10-08",
              "text": "Karrio may make aggregated data compiled from customer data available to third parties, including its other customers.",
              "quote": "Customer agrees that Karrio may (i) make Aggregated Data available to third parties including its other customers in compliance with applicable law, and (ii) use Aggregated Data to the extent and in the manner permitted under applicable law."
            },
            {
              "date": "2026-10-08",
              "text": "Storing payment cardholder information through the service needs Karrio's prior written approval.",
              "quote": "Customer may not store any payment cardholder information using the Services without Karrio’s prior written approval."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.karrio.io/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-04-08",
          "words": 7526,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last modified: 08 April 2025",
              "says": "Last updated 2025-04-08"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect personal information in connection with your visits to and use of the Service."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will usually store the personal information we collect about you for no longer than necessary for the purposes set out in Annex 1 and Annex 2, in accordance with our legal obligations and legitimate business interests."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "California - Your California Privacy Rights: If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Note we do not sell your personal information within the meaning of Chapter 603A.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "In these instances, and if you have provided consent, you have the right to withdraw your consent."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you believe that we might have collected information from a child under 13, please contact us at privacy@karrio.io.",
              "says": "privacy@karrio.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "The personal information we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third party service providers have operations."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice does not cover customer data that Karrio processes on a customer's behalf, and it refers readers to that customer's own privacy notice.",
              "quote": "This Privacy Notice does not apply to such processing and we recommend you read the Privacy Notice of the respective customer, if their processing concerns your personal information."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/karrio.json"
  }
}
