{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "monday",
    "name": "monday.com",
    "vendor": "monday.com Ltd.",
    "vendorUrl": "https://monday.com",
    "kind": "http-api",
    "category": "project-management",
    "summary": "monday.com is a hosted work management platform built on boards, items and columns. Agents reach it through a GraphQL API at api.monday.com/v2 and an official hosted MCP server, using personal API tokens or OAuth.",
    "url": "https://www.anchorterminal.com/tools/monday",
    "markdownUrl": "https://www.anchorterminal.com/tools/monday.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/monday.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/monday.json",
    "repo": "https://github.com/mondaycom/mcp",
    "license": "Proprietary service under monday.com's Terms of Service and Developer Terms. The MCP server, agent toolkit and API SDK on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.monday.com/v2",
    "packages": [
      {
        "registry": "npm",
        "name": "@mondaydotcomorg/api"
      },
      {
        "registry": "npm",
        "name": "@mondaydotcomorg/monday-api-mcp"
      },
      {
        "registry": "npm",
        "name": "@mondaydotcomorg/agent-toolkit"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. A signed-in admin or member copies a personal API token from the developer centre and sends it in the `Authorization` header. The token has no scopes and mirrors the user's permissions, and each user has one, which can be regenerated. OAuth apps choose from 21 scopes such as `boards:read` and `updates:write`. The legacy OAuth flow issues tokens that don't expire, and the newer OAuth 2.1 flow adds PKCE, expiring access tokens, refresh tokens and revocation. The hosted MCP server takes OAuth with dynamic client registration or a personal token as a Bearer header. A publicly distributed MCP client must register through a review form first. A documented agent signup API returns an account and token with no browser step.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with up to 2 seats and 3 boards, no card needed per the pricing page, plus a free developer sandbox account with up to 10 seats and 1,000 items per product, so an agent can start without a contract. Paid plans are per seat. The pricing page served our reader in pounds, at £8 (Basic), £11 (Standard) and £17 (Pro) a seat a month billed annually for 10 seats, with Enterprise through sales. The API has no per-call price. Daily calls are capped by plan (1,000, 10,000 on Pro, 25,000 on Enterprise) and the page says more can be bought, with no price shown (checked 2026-10-08).",
    "priceSummary": "Freemium",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the MCP docs, the agent skill files or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 64,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 176164,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.monday.com/api-reference/docs/basics",
    "llmsTxt": "https://developer.monday.com/api-reference/llms.txt",
    "registryName": "com.monday/monday.com",
    "capabilities": [
      "tasks.create",
      "tasks.update",
      "projects.manage",
      "tasks.comments",
      "projects.reporting",
      "work.docs",
      "forms.create"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "graphql",
      "closed-source",
      "free-tier",
      "oauth",
      "llms-txt",
      "webhooks",
      "idempotency",
      "javascript",
      "typescript",
      "status-page",
      "soc2",
      "agent-signup"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 76.4,
      "grade": "BB",
      "agentReady": true,
      "rank": 32,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 82,
        "maintenance": 85,
        "payments": 50,
        "reliability": 79,
        "schema": 88,
        "security": 70,
        "transparency": 80
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 79,
          "points": 15.8,
          "reason": "Graded on the GraphQL API and the hosted MCP server. Statuspage at status.monday.com with components by region, an API component among them, and incident history (20). In the 90 days to 8 October 2026 it lists a critical platform connectivity incident of 2 hours 8 minutes on 5 September, a major platform latency incident of 2 hours 57 minutes on 13 July, a major automations incident of 32 minutes in the EU on 17 September and three minor ones. None names the API component, and we read the record as one outage plus one long slowdown (10). Daily, per-minute, concurrency, complexity and IP limits are published with numbers per plan (15). 429 carries `Retry-After`, rate limit errors carry `retry_in_seconds`, every response has `RateLimit` headers, and mutations accept an `Idempotency-Key` header (15). A 99.9 per cent uptime SLA is published for the Enterprise plan (10). The API is generally available and the hosted MCP docs carry no beta label, though the tools reference says some newer tools run against a preview API schema (9)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 88,
          "points": 14.3,
          "reason": "The full GraphQL schema is public as SDL and JSON, with a copy per API version, and the MCP tools are typed with Zod schemas in the open-source toolkit (25). llms.txt files at monday.com and developer.monday.com/api-reference, with a Markdown copy of each docs page (10). The tools reference has a page per tool for 64 tools and the schema carries descriptions. Some tool descriptions in the source are one line, such as \"Delete an item\", and the vendor's agent skill file names 2024-10 as the latest stable version and gives a Free daily limit of 200, both at odds with the docs (14). GraphQL inputs are typed with enums and required flags, but column values are passed as a JSON string whose shape depends on the column type (10). Curl and GraphQL examples throughout, and an error page that lists codes by status with sample bodies (14). Dated quarterly versions with release notes that separate breaking changes, plus a changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "The MCP reference lists 64 tools (5 of 25). The local server adds a read-only flag, tool modes and a three-tool dynamic mode, a custom OAuth app can cap the hosted connection by scope, and GraphQL field selection sizes every API response, so 16 overall. Cursor pagination up to 500 items a page, rule-based filters through `query_params`, and lookup by column value (20). Errors carry a code, a status code, a `request_id` and `retry_in_seconds` where it applies, though application errors arrive with HTTP 200 (18). `Idempotency-Key` on mutations with a 30-minute replay window, and readOnlyHint, destructiveHint and idempotentHint on the tools in the source (20). Few required arguments, but an agent must read a board's columns before writing values, and the only official API SDK is for JavaScript and TypeScript (8)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 70,
          "points": 12.25,
          "reason": "OAuth 2.1 with PKCE, expiring access tokens, refresh tokens and revocation, 21 scopes, and dynamic client registration on the MCP server. Personal tokens are unscoped and carry every permission their user has, and legacy OAuth tokens don't expire (26). A custom OAuth app can limit the MCP connection to scopes such as `boards:read`, admins can limit MCP to chosen workspaces, and the local server has `--read-only`. No server-side confirmation for deletes was found (14). The MCP security page places prompt-injection defence on the client, and the vendor's agent skill file tells agents to treat board content as data (8). Board activity logs are available through the API. The audit log API is limited to Enterprise admins, and the MCP security page says self-service export of detailed MCP or API audit logs isn't available (7). SOC 2 Type II and ISO 27001:2022 among ten listed attestations, and a vulnerability report form. No security.txt or bug bounty was found (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 50,
          "points": 6.25,
          "reason": "No x402, MPP or L402 found (0). Plan prices are public per seat, with daily API call allowances per plan and no per-call price. Extra calls can be bought, with no price shown (10). A Free plan and a free developer sandbox account, with no card needed per the pricing page (20). A documented signup API at signup-logic.monday.com returns an account and an API token after a captcha written for agents, with no browser step. We requested a challenge and it answered, and we didn't create an account (20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 85,
          "points": 7.44,
          "reason": "@mondaydotcomorg/agent-toolkit 5.72.0 was published on 7 October 2026, @mondaydotcomorg/api 14.1.0 on 6 October, and API version 2026-10 became current on 1 October per the version table (30). 44 toolkit releases on npm between 10 July and 7 October 2026 (20). A public changelog, release notes and a developer community forum. We couldn't read the GitHub issue tracker or reply times, so this line is scored conservatively (12). Listed in the official MCP registry as com.monday/monday.com, though the entry is version 0.0.1 from 23 October 2025 and still lists the SSE remote, and the API SDK is current (15). The MCP repository runs lint, build and tests on pull requests and has 78 test files. Git tags stop at v0.0.163 on 14 April 2026 while npm releases continue (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "note": "editorial 73, provenance 86",
          "reason": "Closed service with published Terms of Service (5 May 2026) and Developer Terms. The MCP server, toolkit and API SDK are MIT (15). Privacy policy updated 1 October 2026, a DPA dated 20 December 2023 with deletion or return of data after termination, and an AI trust centre that rules out model training on customer input and output. Retention is stated as for as long as reasonably needed, with no period given (20). API versions are deprecated with at least six months' notice and listed with dates. SSE on the hosted MCP server is called deprecated and unsupported with no date given (18). Sub-processor list updated 24 June 2026 with hosting regions, and US, EU and APAC account regions (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP reference lists 64 tools (5 of 25). The local server adds a read-only flag, tool modes and a three-tool dynamic mode, a custom OAuth app can cap the hosted connection by scope, and GraphQL field selection sizes every API response, so 16 overall. Cursor pagination up to 500 items a page, rule-based filters through `query_params`, and lookup by column value (20). Errors carry a code, a status code, a `request_id` and `retry_in_seconds` where it applies, though application errors arrive with HTTP 200 (18). `Idempotency-Key` on mutations with a 30-minute replay window, and readOnlyHint, destructiveHint and idempotentHint on the tools in the source (20). Few required arguments, but an agent must read a board's columns before writing values, and the only official API SDK is for JavaScript and TypeScript (8).",
          "maintenance": "@mondaydotcomorg/agent-toolkit 5.72.0 was published on 7 October 2026, @mondaydotcomorg/api 14.1.0 on 6 October, and API version 2026-10 became current on 1 October per the version table (30). 44 toolkit releases on npm between 10 July and 7 October 2026 (20). A public changelog, release notes and a developer community forum. We couldn't read the GitHub issue tracker or reply times, so this line is scored conservatively (12). Listed in the official MCP registry as com.monday/monday.com, though the entry is version 0.0.1 from 23 October 2025 and still lists the SSE remote, and the API SDK is current (15). The MCP repository runs lint, build and tests on pull requests and has 78 test files. Git tags stop at v0.0.163 on 14 April 2026 while npm releases continue (8).",
          "payments": "No x402, MPP or L402 found (0). Plan prices are public per seat, with daily API call allowances per plan and no per-call price. Extra calls can be bought, with no price shown (10). A Free plan and a free developer sandbox account, with no card needed per the pricing page (20). A documented signup API at signup-logic.monday.com returns an account and an API token after a captcha written for agents, with no browser step. We requested a challenge and it answered, and we didn't create an account (20).",
          "reliability": "Graded on the GraphQL API and the hosted MCP server. Statuspage at status.monday.com with components by region, an API component among them, and incident history (20). In the 90 days to 8 October 2026 it lists a critical platform connectivity incident of 2 hours 8 minutes on 5 September, a major platform latency incident of 2 hours 57 minutes on 13 July, a major automations incident of 32 minutes in the EU on 17 September and three minor ones. None names the API component, and we read the record as one outage plus one long slowdown (10). Daily, per-minute, concurrency, complexity and IP limits are published with numbers per plan (15). 429 carries `Retry-After`, rate limit errors carry `retry_in_seconds`, every response has `RateLimit` headers, and mutations accept an `Idempotency-Key` header (15). A 99.9 per cent uptime SLA is published for the Enterprise plan (10). The API is generally available and the hosted MCP docs carry no beta label, though the tools reference says some newer tools run against a preview API schema (9).",
          "schema": "The full GraphQL schema is public as SDL and JSON, with a copy per API version, and the MCP tools are typed with Zod schemas in the open-source toolkit (25). llms.txt files at monday.com and developer.monday.com/api-reference, with a Markdown copy of each docs page (10). The tools reference has a page per tool for 64 tools and the schema carries descriptions. Some tool descriptions in the source are one line, such as \"Delete an item\", and the vendor's agent skill file names 2024-10 as the latest stable version and gives a Free daily limit of 200, both at odds with the docs (14). GraphQL inputs are typed with enums and required flags, but column values are passed as a JSON string whose shape depends on the column type (10). Curl and GraphQL examples throughout, and an error page that lists codes by status with sample bodies (14). Dated quarterly versions with release notes that separate breaking changes, plus a changelog (15).",
          "security": "OAuth 2.1 with PKCE, expiring access tokens, refresh tokens and revocation, 21 scopes, and dynamic client registration on the MCP server. Personal tokens are unscoped and carry every permission their user has, and legacy OAuth tokens don't expire (26). A custom OAuth app can limit the MCP connection to scopes such as `boards:read`, admins can limit MCP to chosen workspaces, and the local server has `--read-only`. No server-side confirmation for deletes was found (14). The MCP security page places prompt-injection defence on the client, and the vendor's agent skill file tells agents to treat board content as data (8). Board activity logs are available through the API. The audit log API is limited to Enterprise admins, and the MCP security page says self-service export of detailed MCP or API audit logs isn't available (7). SOC 2 Type II and ISO 27001:2022 among ten listed attestations, and a vulnerability report form. No security.txt or bug bounty was found (15).",
          "transparency": "Closed service with published Terms of Service (5 May 2026) and Developer Terms. The MCP server, toolkit and API SDK are MIT (15). Privacy policy updated 1 October 2026, a DPA dated 20 December 2023 with deletion or return of data after termination, and an AI trust centre that rules out model training on customer input and output. Retention is stated as for as long as reasonably needed, with no period given (20). API versions are deprecated with at least six months' notice and listed with dates. SSE on the hosted MCP server is called deprecated and unsupported with no date given (18). Sub-processor list updated 24 June 2026 with hosting regions, and US, EU and APAC account regions (20)."
        },
        "sources": [
          {
            "what": "monday.com llms.txt",
            "url": "https://monday.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API docs llms.txt index",
            "url": "https://developer.monday.com/api-reference/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API basics",
            "url": "https://developer.monday.com/api-reference/docs/basics.md",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://developer.monday.com/api-reference/docs/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://developer.monday.com/api-reference/docs/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "idempotency",
            "url": "https://developer.monday.com/api-reference/docs/idempotency.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error handling",
            "url": "https://developer.monday.com/api-reference/docs/error-handling.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API versioning",
            "url": "https://developer.monday.com/api-reference/docs/api-versioning.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://developer.monday.com/api-reference/docs/release-notes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API changelog",
            "url": "https://developer.monday.com/api-reference/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "GraphQL schema (SDL)",
            "url": "https://api.monday.com/v2/get_schema?format=sdl",
            "seen": "2026-10-08"
          },
          {
            "what": "Platform MCP overview",
            "url": "https://developer.monday.com/api-reference/docs/mondaycom-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP integration guide",
            "url": "https://developer.monday.com/api-reference/docs/integrate-with-monday-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tools reference",
            "url": "https://developer.monday.com/api-reference/docs/platform-mcp-tools.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP security overview",
            "url": "https://developer.monday.com/api-reference/docs/monday-mcp-security-overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP with an API token",
            "url": "https://developer.monday.com/api-reference/docs/mcp-api-token.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP with a custom OAuth app",
            "url": "https://developer.monday.com/api-reference/docs/control-mcp-access-with-oauth-app.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP dynamic client registration",
            "url": "https://developer.monday.com/api-reference/docs/mcp-dynamic-client-registration.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP authorisation server metadata",
            "url": "https://mcp.monday.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server card",
            "url": "https://monday.com/.well-known/mcp.json",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth and scopes",
            "url": "https://developer.monday.com/apps/docs/oauth.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth 2.1 migration",
            "url": "https://developer.monday.com/apps/docs/migrating-to-the-new-oauth-flow.md",
            "seen": "2026-10-08"
          },
          {
            "what": "audit logs API",
            "url": "https://developer.monday.com/api-reference/reference/audit-logs.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://developer.monday.com/api-reference/reference/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "developer sandbox account",
            "url": "https://developer.monday.com/api-reference/docs/developer-sandbox.md",
            "seen": "2026-10-08"
          },
          {
            "what": "agent skill file for the API and MCP",
            "url": "https://monday.com/.well-known/agent-skills/general-monday-gql-api-usage/SKILL.md",
            "seen": "2026-10-08"
          },
          {
            "what": "agent signup skill file",
            "url": "https://monday.com/.well-known/agent-skills/signup-for-agents/SKILL.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server and agent toolkit repository",
            "url": "https://github.com/mondaycom/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "API SDK repository",
            "url": "https://github.com/mondaycom/monday-graphql-api",
            "seen": "2026-10-08"
          },
          {
            "what": "agent toolkit on npm",
            "url": "https://registry.npmjs.org/@mondaydotcomorg/agent-toolkit",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server on npm",
            "url": "https://registry.npmjs.org/@mondaydotcomorg/monday-api-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "API SDK on npm",
            "url": "https://registry.npmjs.org/@mondaydotcomorg/api",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=monday\u0026limit=50",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.monday.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://monday.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://monday.com/trustcenter",
            "seen": "2026-10-08"
          },
          {
            "what": "AI trust centre",
            "url": "https://monday.com/w/ai-trust-center",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://monday.com/l/legal/tos/",
            "seen": "2026-10-08"
          },
          {
            "what": "service level agreement for the Enterprise plan",
            "url": "https://monday.com/l/legal/monday-com-service-level-agreement-for-enterprise-plan/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://monday.com/l/privacy/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing addendum",
            "url": "https://monday.com/l/privacy/dpa/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://monday.com/l/privacy/sub-processors-subsidiaries-support/",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for monday.com",
            "url": "https://rdap.verisign.com/com/v1/domain/monday.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: US dollar prices. monday.com/pricing served our reader in pounds, so `unitPrices` is left empty",
          "unchecked: GitHub stars, open issues and reply times for mondaycom/mcp. The GitHub API refused us for its rate limit",
          "unchecked: the hosted MCP server's live tool list, input schemas and annotations, which need a signed-in account. The count of 64 comes from the published tools reference, and annotations were read in the open-source toolkit",
          "unchecked: which plan and limits an account created through the agent signup API receives. We requested a captcha challenge, which answered, and didn't create an account",
          "unchecked: whether Free plan signup in a browser asks for a card. The pricing page says no card is needed",
          "The agent skill file gives a Free plan daily limit of 200 calls, while the rate limits page and the pricing page give 1,000 for Free, Basic and Standard. We used the docs' figure",
          "The docs call SSE on the hosted MCP server deprecated and unsupported, while the MCP registry entry and the agent skill file still list https://mcp.monday.com/sse, which answered our request with a 302. No removal date was found",
          "The status incident of 5 September 2026 is titled as planned maintenance for 5 August but its updates describe connectivity issues across the platform, and it is marked critical",
          "No bug bounty, security.txt, retention period for account content or price for extra API calls was found in the reviewed pages"
        ]
      },
      "negative": 0,
      "verdict": "The GraphQL API publishes its full schema, accepts an `Idempotency-Key` header on mutations and reports limits in `RateLimit` headers, and a documented signup API lets an agent create its own account and token. Personal tokens carry every permission their user has, daily calls stop at 1,000 below Pro, and the status page shows two long platform incidents since July 2026.",
      "bestFor": "Teams that already run projects on monday.com boards and want an agent to create items, change status, post updates and read board summaries through MCP or GraphQL.",
      "strengths": [
        "Full GraphQL schema is public as SDL and JSON at api.monday.com/v2/get_schema, with a copy for each dated API version",
        "Mutations accept an `Idempotency-Key` header, with responses cached for 30 minutes and replays marked `Idempotency-Replayed: true`",
        "A documented signup API at signup-logic.monday.com creates an account and returns an API token after an agent captcha, with no browser step",
        "Hosted MCP server at https://mcp.monday.com/mcp with OAuth, PKCE and dynamic client registration, and 64 tools in the published reference",
        "Quarterly dated API versions, each stable for at least six months, with deprecations announced at least six months ahead"
      ],
      "weaknesses": [
        "Personal API tokens have no scopes. Each carries every permission its user has in the app",
        "1,000 API calls a day on Free, Basic and Standard, shared with MCP tool calls, against 10,000 on Pro and 25,000 on Enterprise",
        "status.monday.com lists a critical platform incident of 2 hours 8 minutes on 5 September 2026 and a major latency incident of 2 hours 57 minutes on 13 July 2026",
        "The MCP security page says self-service export of detailed MCP or API audit logs isn't available, and the audit log API is limited to Enterprise admins",
        "Column values travel as a JSON string whose shape depends on the column type, and the only official API SDK is for JavaScript and TypeScript"
      ],
      "agentNotes": [
        "Send an `API-Version` header such as 2026-10 on every call. Without it the API uses whichever version is current",
        "Read the board's columns first (`get_board_info` or `boards { columns }`), then write column values as a JSON string keyed by column ID",
        "Reuse one `Idempotency-Key` per mutation when retrying after a timeout or 5xx. After a 429, wait for `Retry-After` or `retry_in_seconds`",
        "Page items with `items_page` and `next_items_page`, at most 500 a page. Cursors expire after 60 minutes",
        "For a narrower grant than a personal token, connect MCP through a custom OAuth app with only scopes such as `boards:read`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 76.4
        }
      ],
      "editorialScores": {
        "ergonomics": 82,
        "maintenance": 85,
        "payments": 50,
        "reliability": 79,
        "schema": 88,
        "security": 70,
        "transparency": 73
      },
      "provenanceScore": 86
    },
    "connect": {
      "install": "npx @mondaydotcomorg/monday-api-mcp@latest",
      "http": "curl -X POST https://api.monday.com/v2 \\\n  -H \"Authorization: YOUR_API_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"query\": \"query { me { id name } }\"}'",
      "config": {
        "mcpServers": {
          "monday-mcp": {
            "url": "https://mcp.monday.com/mcp"
          }
        }
      },
      "headless": {
        "mcpServers": {
          "monday-mcp": {
            "headers": {
              "Authorization": "Bearer YOUR_API_TOKEN"
            },
            "url": "https://mcp.monday.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/tasks.create",
      "tool": "https://letme.dev/monday"
    },
    "notable": [
      "The GraphQL schema is served without a login as SDL and JSON, per API version (https://api.monday.com/v2/get_schema?format=sdl)",
      "The hosted MCP server at https://mcp.monday.com/mcp speaks streamable HTTP only. The docs call SSE deprecated and unsupported, while the MCP registry entry still lists https://mcp.monday.com/sse (https://developer.monday.com/api-reference/docs/integrate-with-monday-mcp)",
      "The tools reference lists 64 MCP tools in 15 groups, among them boards and items, docs, dashboards, forms, automations, agents and sprints (https://developer.monday.com/api-reference/docs/platform-mcp-tools)",
      "An agent signup API returns an account and an API token after a 30-second captcha written for agents, limited to 15 account creations a minute per IP (https://monday.com/.well-known/agent-skills/signup-for-agents/SKILL.md)",
      "Daily call limits are 1,000 on Free, Basic and Standard, 10,000 on Pro and 25,000 on Enterprise, and MCP tool calls count towards them (https://developer.monday.com/api-reference/docs/rate-limits)",
      "Mutations take an `Idempotency-Key` header with a 30-minute replay window and a 409 for a concurrent duplicate (https://developer.monday.com/api-reference/docs/idempotency)",
      "API versions are released each quarter, at least three run in parallel, and each deprecation is announced at least six months ahead (https://developer.monday.com/api-reference/docs/api-versioning)",
      "status.monday.com lists six incidents between 13 July and 17 September 2026, one marked critical and two major, none naming the API component (https://status.monday.com/history)",
      "The open-source MCP server and agent toolkit are MIT, and @mondaydotcomorg/agent-toolkit had 44 npm releases between 10 July and 7 October 2026 (https://github.com/mondaycom/mcp)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces graded",
        "value": "GraphQL platform API at https://api.monday.com/v2 and the official hosted MCP server at https://mcp.monday.com/mcp, which the vendor describes as a wrapper around that API"
      },
      {
        "label": "Free tier",
        "value": "Free plan, up to 2 seats and 3 boards, no card per the pricing page. Free developer sandbox account with up to 10 seats, 1,000 items per product and a 10M complexity budget, for development and testing only"
      },
      {
        "label": "Agent signup",
        "value": "POST to signup-logic.monday.com for a captcha challenge, verify it, then create the account. The response carries an API token. 15 account creations a minute per IP. A person is invited afterwards through the `invite_users` mutation"
      },
      {
        "label": "Rate limits",
        "value": "Daily calls 1,000 (Free, Basic, Standard), 10,000 (Pro), 25,000 (Enterprise), reset at midnight UTC. Per minute 1,000, 2,500 on Pro, 5,000 on Enterprise. Concurrency 40, 100, 250. 5M complexity points a query. 5,000 requests per 10 seconds per IP (vendor's figures)"
      },
      {
        "label": "Retries",
        "value": "429 with `Retry-After`, a `retry_in_seconds` field on rate limit errors, `RateLimit` and `RateLimit-Policy` headers on every response, and an `Idempotency-Key` header on mutations with a 30-minute replay window. A rate-limited request counts as 0.1 of a daily call"
      },
      {
        "label": "Auth and scopes",
        "value": "Personal API token (unscoped, one per user, regenerable) or OAuth. 21 OAuth scopes, among them boards:read, boards:write, updates:read, updates:write, docs:read, docs:write, users:read, webhooks:write and workspaces:write. OAuth 2.1 flow with PKCE, refresh tokens and revocation"
      },
      {
        "label": "Read and write",
        "value": "Boards, groups, columns, items and subitems, updates (comments) and replies, docs, workspaces and folders, dashboards and widgets, forms, users and teams, files, webhooks, activity logs"
      },
      {
        "label": "Search and paging",
        "value": "`items_page` with `query_params` rules and `items_page_by_column_values`, cursor paging through `next_items_page`, up to 500 items a page, cursors valid for 60 minutes. GraphQL field selection sizes each response"
      },
      {
        "label": "MCP server",
        "value": "Hosted, streamable HTTP, 64 tools in the published reference. OAuth with dynamic client registration or a personal token. A custom OAuth app can cap the connection to chosen scopes, and admins can limit MCP to chosen workspaces. Tool calls count towards the daily API limit"
      },
      {
        "label": "Local MCP server",
        "value": "@mondaydotcomorg/monday-api-mcp 3.3.1 (22 September 2026), Node.js 20 or later, MIT, with `--read-only`, `--mode` and `--enable-dynamic-api-tools` flags. Tools carry readOnlyHint, destructiveHint and idempotentHint annotations in the source"
      },
      {
        "label": "Change events",
        "value": "Board webhooks created by the `create_webhook` mutation, with a challenge to verify the URL and a documented retry policy. Some requests carry a JWT signed with the app's signing secret"
      },
      {
        "label": "Schema",
        "value": "GraphQL SDL and JSON at https://api.monday.com/v2/get_schema, per version, about 578 KB, with 104 query fields and 196 mutations by our count. No OpenAPI description, because the API is GraphQL"
      },
      {
        "label": "Versioning",
        "value": "Dated quarterly versions (2026-10 became current on 1 October 2026 per the version table), release candidate, current and maintenance run in parallel, each stable for at least six months, selected by the `API-Version` header"
      },
      {
        "label": "SDKs",
        "value": "@mondaydotcomorg/api 14.1.0 for JavaScript and TypeScript (6 October 2026, MIT). @mondaydotcomorg/agent-toolkit 5.72.0 (7 October 2026) for MCP and OpenAI tool definitions. No official Python SDK was found"
      },
      {
        "label": "Audit",
        "value": "Board activity logs through the API. The audit log API is limited to account admins on the Enterprise plan. The MCP security page says self-service export of detailed MCP or API audit logs isn't available"
      },
      {
        "label": "Certifications",
        "value": "SOC 1 Type II, SOC 2 Type II, SOC 3, ISO/IEC 27001:2022, 27017, 27018, 27032 and 27701, CSA STAR and TX-RAMP per the trust centre. Vulnerability reports go through a form. No bug bounty or security.txt was found"
      },
      {
        "label": "SLA",
        "value": "99.9 per cent monthly uptime with service credits, Enterprise plan only (agreement last updated 20 December 2023)"
      },
      {
        "label": "Data regions",
        "value": "US, EU and APAC account regions. Sub-processor list updated 24 June 2026, with hosting on Amazon Web Services, Google Cloud and Microsoft Azure"
      },
      {
        "label": "Open source",
        "value": "No. The MCP server, the agent toolkit and the API SDK are public under MIT"
      }
    ],
    "provenance": {
      "legalEntity": "monday.com Ltd.",
      "domain": "monday.com",
      "domainRegistered": "1995-07-19",
      "endpointOnVendorDomain": true,
      "terms": "https://monday.com/l/legal/tos/",
      "privacy": "https://monday.com/l/privacy/privacy-policy/",
      "statusPage": "https://status.monday.com",
      "changelog": "https://developer.monday.com/api-reference/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service (last updated 5 May 2026) are between the customer and monday.com Ltd., 6 Yitzhak Sadeh St., Tel-Aviv 6777506, Israel. The privacy policy was last updated on 1 October 2026.",
        "The API answers at api.monday.com, the MCP server at mcp.monday.com and its authorisation server at auth.monday.com, all monday.com subdomains.",
        "monday.com/.well-known/security.txt, www.monday.com/.well-known/security.txt and monday.com/security.txt each return 404. The trust centre sends vulnerability reports to a form at monday.com/security/form.",
        "RDAP for monday.com gives a registration date of 1995-07-19.",
        "The Service Level Agreement for the Enterprise plan (last updated 20 December 2023) commits to 99.9 per cent monthly uptime for the core services. The DPA carries the same date."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "monday.com Ltd.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "monday.com, registered 1995-07-19 (31 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.monday.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 6,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.monday.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://monday.com/l/legal/tos/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-05-05",
          "words": 14113,
          "points": 6,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: May 05, 2026",
              "says": "Last updated 2026-05-05"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms and any action related thereto will be governed and interpreted by and under the laws of the State of Israel without giving effect to any conflicts of laws principles that require the application of the law of a different jurisdiction.",
              "says": "The law of the State of Israel"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "and (iii) IN NO EVENT SHALL THE TOTAL AGGREGATE LIABILITY OF monday.com, ITS AFFILIATES OR ITS THIRD PARTY SERVICE PROVIDERS, UNDER, OR OTHERWISE IN CONNECTION WITH, THESE TERMS (INCLUDING THE SITES, THE SERVICES AND THE THIRD PARTY SERVICES), EXCEED US $100.",
              "says": "Capped at US $100"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Any such access to the Services by such Third Party Agents is provided at monday.com’s sole discretion and may be suspended, limited, or terminated at any time, with or without notice."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "When we make material changes to these Terms, we’ll provide Customer with notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Services or by sending Customer an email.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You shall not submit to the Services any data that is protected under a special legislation and requires a unique treatment, including, without limitations, (i) categories of data enumerated in European Union Regulation 2016/679, Article 9(1) or any similar legislation or regulation in other jurisdiction;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "To the extent you purchased an eligible enterprise tier subscription, you will be entitled, in relation to the Services, to priority support and an uptime commitment by monday.com, in accordance with the Service Level Agreement, as may be updated from time to time."
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(viii) use the Services or Sites for competitive purposes, including to develop or enhance a competing service or product;",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We reserve the right at any time to modify or discontinue, temporarily or permanently, your and/or Customer’s access to the API (or any part of it) with or without notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Any such access to the Services by such Third Party Agents is provided at monday.com’s sole discretion and may be suspended, limited, or terminated at any time, with or without notice."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "WHERE PERMITTED UNDER APPLICABLE LAW, YOU AND MONDAY.COM AGREE THAT EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER PARTY ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE ACTION."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Actions taken by third party AI agents, scripts or automated systems under an account are treated as authorised by the customer, including registration, account creation and upgrades.",
              "quote": "then such use and actions taken by any such Third Party Agents are deemed to be authorized by you and are made at your request and/or instruction, including but not limited to registration to the Services, creation of an Account and/or any Upgrades to the Services."
            },
            {
              "date": "2026-10-08",
              "text": "monday.com may use the customer's name and logo in marketing and public announcements, and the customer may revoke that right by contacting monday.com.",
              "quote": "Customer may revoke such right, at any time, by contacting [email protected]."
            },
            {
              "date": "2026-10-08",
              "text": "The customer must export its data before termination, and the read-only period afterwards may be ended by monday.com at any time, after which the data is deleted.",
              "quote": "It is Customer’s sole liability to export the Customer Data prior to such termination or expiration."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://monday.com/l/privacy/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-10-01",
          "words": 8239,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: October 01, 2026",
              "says": "Last updated 2026-10-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "(i) Customer Data: personal data that we collect, process and manage on behalf of our business customers (“Customers”), submitted to the monday.com cloud-based services, including our platforms, products, applications, APIs, tools, and any ancillary or supplementary monday.com products and services (including Upgrades…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Data Retention: We may retain your personal data for as long as it is reasonably needed to maintain and expand our relationship and provide you with our Services and offerings;"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Transfer of the Restricted personal data to third parties: (1) in accordance with this Privacy Policy, solely to the extent necessary to provide or improve the Integrated Google Services;"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Selecting “Do not sell or share my personal data” in the cookie banner, where available, or adjusting the preferences accessible through the “Cookie settings” link in the website footer;",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "…or the CCPA), such as (each to the extent applicable to you under the laws which apply to you) – the right to know/request access to (specific pieces of personal data collected;"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you believe that we might have any such data, please contact us at privacy@monday.com.",
              "says": "privacy@monday.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "monday.com Inc., our US subsidiary, complies with the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework as set forth by the US Department of Commerce, and where appropriate – primarily relies on such certification for accepting transfers of data from t…",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "Sale and Sharing under US Data Protection Laws: Under some US data protection laws, like the CCPA, our disclosure of certain internet activity and device information with third parties through cookies may be considered a “sale” or “sharing” of personal information for targeted advertising."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Content a user submits to private boards can still be accessed, copied and processed by the account administrators.",
              "quote": "Any content submitted by you to private boards may still be accessed, copied and processed by the Account Admin(s)."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/monday.json",
    "live": {
      "slug": "monday",
      "probe": {
        "target": "https://api.monday.com/v2",
        "method": "get",
        "lastAt": "2026-10-08T17:36:40.643440441Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 205,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 150,
        "p95ms24h": 273,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.monday.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:25:20.348396479Z"
      },
      "versions": [
        {
          "registry": "npm",
          "name": "@mondaydotcomorg/agent-toolkit",
          "version": "5.73.0",
          "seenAt": "2026-10-08T16:21:49.787128646Z"
        },
        {
          "registry": "npm",
          "name": "@mondaydotcomorg/api",
          "version": "14.1.0",
          "seenAt": "2026-10-08T16:21:47.55416646Z"
        },
        {
          "registry": "npm",
          "name": "@mondaydotcomorg/monday-api-mcp",
          "version": "3.3.1",
          "seenAt": "2026-10-08T16:21:48.399378593Z"
        }
      ],
      "githubStars": 427,
      "npmWeekly": 176164,
      "securityTxt": {
        "url": "https://monday.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:39:08.858683148Z"
      },
      "updatedAt": "2026-10-08T17:36:40.643440441Z"
    }
  }
}
