{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "openproject",
    "name": "OpenProject",
    "vendor": "OpenProject GmbH",
    "vendorUrl": "https://www.openproject.org",
    "kind": "http-api",
    "category": "project-management",
    "summary": "OpenProject is open-source project management software for work packages, Gantt plans, boards and time tracking, sold as a cloud service and for self-hosting. Agents reach it through the APIv3 REST API, and paid plans add an MCP server.",
    "url": "https://www.anchorterminal.com/tools/openproject",
    "markdownUrl": "https://www.anchorterminal.com/tools/openproject.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openproject.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openproject.json",
    "repo": "https://github.com/opf/openproject",
    "license": "GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service",
    "transports": [
      "http"
    ],
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access is self-serve. A user creates a named personal API token in account settings and sends it as `Authorization: Bearer`, or as the Basic auth password with the user name `apikey`. The token carries that user's permissions, and no per-token scope or expiry was found. An administrator can register OAuth 2.0 applications for the authorisation code grant, PKCE or client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`). JWTs from a configured OIDC provider are also accepted. No app review or partner approval is described.",
    "pricing": "freemium",
    "pricingNotes": "The Community edition is free to self-host with the REST API included, and the cloud has a 14-day trial with no credit card, so an agent can start without a contract. Cloud plans are per user per month on a yearly term, Basic $7.25 (from 5 users, $8.50 on a monthly term), Professional $13.50 (from 25 users) and Premium $19.50 (from 100 users), with Corporate on request. Euro prices are 5.95, 10.95 and 15.95. API calls are not priced. The MCP server needs Professional or above. Community is not sold as a cloud plan (https://www.openproject.org/pricing/, checked 2026-10-08).",
    "priceSummary": "$7.25 / seat-mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 16352,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.openproject.org/docs/api/",
    "openapi": "https://www.openproject.org/docs/api/v3/spec.yml",
    "capabilities": [
      "tasks.create",
      "tasks.update",
      "projects.manage",
      "tasks.comments",
      "projects.reporting",
      "events.webhooks-send"
    ],
    "tags": [
      "official",
      "hosted",
      "self-hosted",
      "open-source",
      "rest",
      "openapi",
      "oauth",
      "mcp",
      "freemium",
      "free-trial",
      "webhooks",
      "status-page",
      "sla",
      "eu-hosting",
      "project-management"
    ],
    "lastRelease": "2026-10-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 57.4,
      "grade": "C",
      "agentReady": false,
      "rank": 550,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 11,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 70,
        "maintenance": 75,
        "payments": 30,
        "reliability": 52,
        "schema": 76,
        "security": 59,
        "transparency": 87
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 52,
          "points": 10.4,
          "reason": "Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. The same API ships in the free Community edition. Status page at status.openproject.com, run on UptimeRobot, with a 90-day uptime view and an update history (20). The page draws its figures by script from a path its robots.txt disallows, so we could not read the incident record. No readable history (5). No request limit for the API is published for the cloud. The only documented rule is an optional one for self-hosted installs, six requests per three seconds on form endpoints, off by default (3 of 15). No 429 or Retry-After guidance and no idempotency keys were found. Updates must send `lockVersion`, and a stale value is refused with 409 `UpdateConflict` (4 of 15). The service description commits to 99.9 per cent availability a year, with a credit of 5 per cent of the monthly fee for each hour beyond it (10). APIv3 is described as the stable API (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at `/api/v3/spec.json` and `/api/v3/spec.yml` (25). No llms.txt (the path returns 404). The docs are Markdown files in the public repository, not served to agents from the docs site (2 of 10). The reference explains HAL links, collections, filters, forms and each resource's permissions at length, with little on when not to use an endpoint (14 of 20). 204 component schemas and 95 enumerations, but write bodies are HAL objects with `_links`, filters travel as a JSON string in the query, and custom fields appear as `customFieldN`. Form endpoints return the allowed values for a given resource (10 of 15). The spec carries about 1,200 examples and lists 400, 403, 404, 406, 415 and 422 responses per operation, with stable error identifiers (14 of 15). The version sits in the path and release notes are dated and list API changes. No changelog for the API alone was found (11 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 70,
          "points": 11.38,
          "reason": "Graded on the REST API. Collections take `pageSize` and `offset`, and eight collection endpoints, work packages among them, take `select` to trim fields. HAL responses embed related resources in full by default (14 of 25). Filters with operators, `sortBy`, grouping and saved queries (20). Errors carry an `errorIdentifier` URN and a message, and validation failures arrive as `MultipleErrors` with one entry per property (18 of 20). No idempotency keys. `lockVersion` stops lost updates, form endpoints validate a change without saving it, and each tool of the paid MCP server sets read-only, destructive and idempotent hints (12 of 20). No official SDK was found. The docs list community clients for JavaScript and Go that the vendor says it does not vet. Creating a work package needs a subject and links to a project and type (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 59,
          "points": 10.33,
          "reason": "OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`) and none finer. Personal API tokens are named, can be several and can be deleted, and carry their user's full permissions. No expiry or per-token scope was found. Tokens travel in the Authorization header only (22 of 30). Reach is limited by project roles and permissions, so a dedicated user with a read-only role is the least-privilege route, and administrators can switch off single MCP tools. No confirmation step for deletes (12 of 20). Work package text and comments are untrusted content, and no prompt-injection guidance was found in the API or MCP docs (2 of 15). Every change to a work package is journalled with its author, and application logs record sign-ins and credential changes. No per-token API log for a cloud customer was found (8 of 15). A signed security.txt valid to 31 December 2026, a disclosure policy with a 21-day target for critical fixes, advisories and CVEs published on GitHub, signed container images with SBOMs, and a YesWeHack bounty paid for by the European Commission. No SOC 2 or ISO 27001 certificate for the vendor was found (15 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices are public per user per month, Basic at $7.25, Professional at $13.50 and Premium at $19.50 on a yearly term, Corporate on request. API calls are not priced (10). The cloud trial runs 14 days and the signup page says no credit card is needed. The Community edition is free to self-host, API included (20). A person fills in a web form with a domain and an email address to get an instance, and creates the token in account settings (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "reason": "Version 17.9.1 was released on 1 October 2026 (30). Seven releases in the last 90 days, 17.7.0 on 5 August through 17.9.1 (20). OpenProject tracks bugs on community.openproject.org, which we did not sample, so responsiveness is scored on the release record and the advisory handling alone, with fixes published alongside each advisory (15 of 25). No official SDK and no MCP registry entry were found (0 of 15). The repository runs test, CodeQL, Brakeman, dependency review and npm audit workflows, and its default branch had commits on 8 October 2026 (10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 87,
          "points": 7.61,
          "note": "editorial 79, provenance 95",
          "reason": "The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. The cloud runs under the Terms of Service of 6 August 2026 (28 of 30). The privacy policy of 30 July 2026 covers the cloud and names OpenProject GmbH as processor. An instance is deleted six months after the contract ends, web logs within 90 days, and the terms give 21 days' notice to export data. The data processing agreement follows the EU standard clauses and was last updated on 28 March 2024 (25 of 30). No deprecation policy with dates was found. The docs say the vendor strives to keep APIv3 backward compatible in stable releases, and 14 operations are marked deprecated with no removal date (7 of 20). The sub-processor list of 18 May 2026 names four companies for the openproject.com shard (AWS among them) and three for the EU shard (Scaleway among them), with addresses and transfer safeguards (19 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the REST API. Collections take `pageSize` and `offset`, and eight collection endpoints, work packages among them, take `select` to trim fields. HAL responses embed related resources in full by default (14 of 25). Filters with operators, `sortBy`, grouping and saved queries (20). Errors carry an `errorIdentifier` URN and a message, and validation failures arrive as `MultipleErrors` with one entry per property (18 of 20). No idempotency keys. `lockVersion` stops lost updates, form endpoints validate a change without saving it, and each tool of the paid MCP server sets read-only, destructive and idempotent hints (12 of 20). No official SDK was found. The docs list community clients for JavaScript and Go that the vendor says it does not vet. Creating a work package needs a subject and links to a project and type (6 of 15).",
          "maintenance": "Version 17.9.1 was released on 1 October 2026 (30). Seven releases in the last 90 days, 17.7.0 on 5 August through 17.9.1 (20). OpenProject tracks bugs on community.openproject.org, which we did not sample, so responsiveness is scored on the release record and the advisory handling alone, with fixes published alongside each advisory (15 of 25). No official SDK and no MCP registry entry were found (0 of 15). The repository runs test, CodeQL, Brakeman, dependency review and npm audit workflows, and its default branch had commits on 8 October 2026 (10).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public per user per month, Basic at $7.25, Professional at $13.50 and Premium at $19.50 on a yearly term, Corporate on request. API calls are not priced (10). The cloud trial runs 14 days and the signup page says no credit card is needed. The Community edition is free to self-host, API included (20). A person fills in a web form with a domain and an email address to get an instance, and creates the token in account settings (0).",
          "reliability": "Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. The same API ships in the free Community edition. Status page at status.openproject.com, run on UptimeRobot, with a 90-day uptime view and an update history (20). The page draws its figures by script from a path its robots.txt disallows, so we could not read the incident record. No readable history (5). No request limit for the API is published for the cloud. The only documented rule is an optional one for self-hosted installs, six requests per three seconds on form endpoints, off by default (3 of 15). No 429 or Retry-After guidance and no idempotency keys were found. Updates must send `lockVersion`, and a stale value is refused with 409 `UpdateConflict` (4 of 15). The service description commits to 99.9 per cent availability a year, with a credit of 5 per cent of the monthly fee for each hour beyond it (10). APIv3 is described as the stable API (10).",
          "schema": "A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at `/api/v3/spec.json` and `/api/v3/spec.yml` (25). No llms.txt (the path returns 404). The docs are Markdown files in the public repository, not served to agents from the docs site (2 of 10). The reference explains HAL links, collections, filters, forms and each resource's permissions at length, with little on when not to use an endpoint (14 of 20). 204 component schemas and 95 enumerations, but write bodies are HAL objects with `_links`, filters travel as a JSON string in the query, and custom fields appear as `customFieldN`. Form endpoints return the allowed values for a given resource (10 of 15). The spec carries about 1,200 examples and lists 400, 403, 404, 406, 415 and 422 responses per operation, with stable error identifiers (14 of 15). The version sits in the path and release notes are dated and list API changes. No changelog for the API alone was found (11 of 15).",
          "security": "OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`) and none finer. Personal API tokens are named, can be several and can be deleted, and carry their user's full permissions. No expiry or per-token scope was found. Tokens travel in the Authorization header only (22 of 30). Reach is limited by project roles and permissions, so a dedicated user with a read-only role is the least-privilege route, and administrators can switch off single MCP tools. No confirmation step for deletes (12 of 20). Work package text and comments are untrusted content, and no prompt-injection guidance was found in the API or MCP docs (2 of 15). Every change to a work package is journalled with its author, and application logs record sign-ins and credential changes. No per-token API log for a cloud customer was found (8 of 15). A signed security.txt valid to 31 December 2026, a disclosure policy with a 21-day target for critical fixes, advisories and CVEs published on GitHub, signed container images with SBOMs, and a YesWeHack bounty paid for by the European Commission. No SOC 2 or ISO 27001 certificate for the vendor was found (15 of 20).",
          "transparency": "The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. The cloud runs under the Terms of Service of 6 August 2026 (28 of 30). The privacy policy of 30 July 2026 covers the cloud and names OpenProject GmbH as processor. An instance is deleted six months after the contract ends, web logs within 90 days, and the terms give 21 days' notice to export data. The data processing agreement follows the EU standard clauses and was last updated on 28 March 2024 (25 of 30). No deprecation policy with dates was found. The docs say the vendor strives to keep APIv3 backward compatible in stable releases, and 14 operations are marked deprecated with no removal date (7 of 20). The sub-processor list of 18 May 2026 names four companies for the openproject.com shard (AWS among them) and three for the EU shard (Scaleway among them), with addresses and transfer safeguards (19 of 20)."
        },
        "sources": [
          {
            "what": "API introduction (authentication, HAL, methods)",
            "url": "https://www.openproject.org/docs/api/introduction/",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI 3.1 document, as served by the community instance",
            "url": "https://community.openproject.org/api/v3/spec.yml",
            "seen": "2026-10-08"
          },
          {
            "what": "repository, cloned (API docs, release notes, MCP tool code, configuration docs, workflows)",
            "url": "https://github.com/opf/openproject",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server docs",
            "url": "https://www.openproject.org/docs/system-admin-guide/integrations/mcp-server/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page and its price table script",
            "url": "https://www.openproject.org/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "cloud trial signup page",
            "url": "https://start.openproject.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.openproject.com",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Service",
            "url": "https://www.openproject.org/legal/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "service description (availability, credits, support levels)",
            "url": "https://www.openproject.org/legal/description-of-services/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.openproject.org/legal/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing agreement",
            "url": "https://www.openproject.org/legal/data-processing-agreement/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://www.openproject.org/legal/data-processing-agreement/sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "statement on security",
            "url": "https://www.openproject.org/docs/security-and-privacy/statement-on-security/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.openproject.org/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories, nine pages read",
            "url": "https://github.com/opf/openproject/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://www.openproject.org/docs/release-notes/",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record for openproject.org",
            "url": "https://rdap.org/domain/openproject.org",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the incident record. status.openproject.com draws its uptime figures and update history by script from `/api/`, which its robots.txt disallows, so Reliability is scored without a readable history",
          "unchecked: issue responsiveness. Bugs are tracked on community.openproject.org, which we did not sample",
          "unchecked: the official MCP registry and the live tool list of the MCP server. The tool list was read from the docs and the repository",
          "Whether OpenProject Enterprise cloud applies any request limit to APIv3, and what it returns when one is hit",
          "When the cloud received the fixes in the advisories published in 2026. The advisories give self-hosted version numbers only",
          "Whether API tokens can expire. No expiry setting was found in the access token docs",
          "Which certifications OpenProject GmbH holds. The security page mentions regular external audits without naming a standard",
          "The lead described the product correctly. It did not mention the MCP server, which is an Enterprise add-on, or that the Community edition is not sold as a cloud plan"
        ]
      },
      "negative": -5,
      "negativeNotes": [
        "2026-06-08. 13 advisories rated critical were published against opf/openproject between January and June 2026, among them cache store poisoning leading to remote code execution (GHSA-qj96-f42f-6336, fixed in 17.3.3 and 17.4.1), SQL injection in the timestamps function (GHSA-98vw-2r87-fx2r) and a pre-authentication remote code execution in the Docker image through a default secret key (GHSA-r85r-gjq2-f83r, 13 May 2026). OpenProject published them itself, and its policy is to publish each advisory with the fixing release, so the deduction is reduced, -3 (https://github.com/opf/openproject/security/advisories).",
        "2026-09-30. 83 advisories in all were published in the twelve months to 8 October 2026, several of them missing permission checks in APIv3 that exposed private work package data across projects. Several credit the YesWeHack bounty sponsored by the European Commission. The advisories give self-hosted version numbers and do not say when the cloud was patched. Fixed and published, -2 (https://github.com/opf/openproject/security/advisories)."
      ],
      "verdict": "OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.",
      "bestFor": "Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.",
      "strengths": [
        "OpenAPI 3.1 document with 234 paths and 320 operations, public on the docs site and served by every instance at `/api/v3/spec.json`",
        "Errors carry a stable `errorIdentifier` URN, and validation failures list one entry per property",
        "The Community edition is GPL-3.0 and free to self-host with the REST API included, and the cloud trial needs no credit card",
        "Seven releases between 5 August and 1 October 2026, with security fixes published as GitHub advisories and CVEs",
        "The service description commits to 99.9 per cent yearly availability with service credits, and an EU shard keeps all sub-processors in the EU"
      ],
      "weaknesses": [
        "83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection",
        "No request limit, 429 behaviour or Retry-After guidance is published for the cloud API",
        "Personal API tokens act with their user's full permissions, and OAuth has one scope per API with no read-only form",
        "No official SDK. The client libraries the docs list are community projects the vendor says it does not vet",
        "The MCP server is an Enterprise add-on for the Professional plan and above, which starts at 25 users"
      ],
      "agentNotes": [
        "Send the API token as `Authorization: Bearer \u003ctoken\u003e`, or as the Basic auth password with the user name `apikey`",
        "Read the resource first and send its current `lockVersion` with every PATCH. A stale value returns 409 `UpdateConflict`",
        "POST to the `/form` endpoint of a work package to learn writable fields and allowed values before creating or updating",
        "URL-encode `filters` as a JSON array, and add `pageSize`, `offset` and `select` to keep work package lists small",
        "Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 57.4
        }
      ],
      "editorialScores": {
        "ergonomics": 70,
        "maintenance": 75,
        "payments": 30,
        "reliability": 52,
        "schema": 76,
        "security": 59,
        "transparency": 79
      },
      "provenanceScore": 95
    },
    "connect": {
      "http": "curl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42"
    },
    "letme": {
      "capability": "https://letme.dev/tasks.create",
      "tool": "https://letme.dev/openproject"
    },
    "notable": [
      "APIv3 is a hypermedia REST API in HAL+JSON, documented in one OpenAPI 3.1 file with 234 paths and 320 operations, which each instance also serves at `/api/v3/spec.json` (https://www.openproject.org/docs/api/introduction/)",
      "The MCP server at `/mcp` is an Enterprise add-on for the Professional, Premium and Corporate plans. The docs list 23 tools and ten resources, and version 17.9 added time entry tools (https://www.openproject.org/docs/system-admin-guide/integrations/mcp-server/)",
      "83 security advisories were published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical. Several credit a YesWeHack bounty sponsored by the European Commission (https://github.com/opf/openproject/security/advisories)",
      "The service description commits to 99.9 per cent availability a year for the cloud, with a 5 per cent credit per hour beyond it (https://www.openproject.org/legal/description-of-services/)",
      "The cloud runs as two shards, openproject.com on AWS and openproject.eu on Scaleway, with every EU-shard sub-processor based in the EU (https://www.openproject.org/legal/data-processing-agreement/sub-processors/)",
      "No request limit for the API is published. The configuration docs describe one optional rule for self-hosted installs, six requests per three seconds on form endpoints (https://github.com/opf/openproject/blob/dev/docs/installation-and-operations/configuration/README.md)",
      "The security statement says OpenProject has no bug bounty programme of its own and targets a fix for critical and high findings within 21 days of confirmation (https://www.openproject.org/docs/security-and-privacy/statement-on-security/)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "APIv3 of OpenProject Enterprise cloud at `https://\u003cname\u003e.openproject.com/api/v3` (or an openproject.eu host on the EU shard). The same API ships in the free Community edition for self-hosting"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.1, 234 paths and 320 operations (178 GET, 80 POST, 32 PATCH, 30 DELETE). HAL+JSON responses. Covers work packages, projects, portfolios, time entries, memberships, queries, versions, wiki pages, notifications and more"
      },
      {
        "label": "Authentication",
        "value": "Personal API token as Bearer or as Basic auth with user name `apikey`. OAuth 2.0 authorisation code, PKCE and client credentials with scopes `api_v3`, `mcp`, `scim_v2` and `bcf_v2_1`. JWTs from a configured OIDC provider"
      },
      {
        "label": "MCP server",
        "value": "Enterprise add-on for Professional, Premium and Corporate, at `/mcp` on the instance. 23 tools per the docs, among them `search_work_packages`, `create_work_package`, `update_work_package`, `create_work_package_comment` and four time entry tools, plus ten resources. Tools can be switched off one by one"
      },
      {
        "label": "Rate limits",
        "value": "None published for the cloud API. Self-hosted installs can turn on a rule of six requests per three seconds on API form endpoints"
      },
      {
        "label": "Pagination and sizing",
        "value": "`pageSize` and `offset` on collections, with a maximum page size set by the administrator. `select` on eight collection endpoints. `filters` with operators and `sortBy`"
      },
      {
        "label": "Errors",
        "value": "`errorIdentifier` URNs such as `urn:openproject-org:api:v3:errors:MissingPermission`, with `MultipleErrors` grouping per-property validation failures. 409 `UpdateConflict` on a stale `lockVersion`"
      },
      {
        "label": "Webhooks",
        "value": "Set by an administrator, with a signature secret, per-project selection and events for projects, work packages, comments, time entries and attachments"
      },
      {
        "label": "SLA",
        "value": "99.9 per cent availability a calendar year excluding scheduled maintenance, with a credit of 5 per cent of the monthly fee per hour beyond it, claimed within 30 days"
      },
      {
        "label": "Security programme",
        "value": "Signed security.txt, disclosure policy, GitHub advisories with CVEs, a YesWeHack bounty sponsored by the European Commission, signed container images with SBOM and VEX documents"
      },
      {
        "label": "Status",
        "value": "status.openproject.com on UptimeRobot. Figures load by script from a path robots.txt disallows"
      },
      {
        "label": "Sub-processors",
        "value": "openproject.com shard, AWS, MessageBird, Postmark and mailbox.org. openproject.eu shard, Scaleway, rapidmail and mailbox.org. List updated 18 May 2026"
      },
      {
        "label": "Releases",
        "value": "17.9.1 on 1 October 2026, 17.9.0 and 17.8.1 on 30 September, 17.8.0 on 2 September, 17.7.x in August"
      }
    ],
    "unitPrices": [
      {
        "item": "Community (self-hosted)",
        "unit": "seat-month",
        "usd": 0,
        "note": "free, REST API included; not sold as a cloud plan"
      },
      {
        "item": "Basic (cloud)",
        "unit": "seat-month",
        "usd": 7.25,
        "note": "yearly term, from 5 users; $8.50 on a monthly term"
      },
      {
        "item": "Professional (cloud)",
        "unit": "seat-month",
        "usd": 13.5,
        "note": "yearly term, from 25 users; includes the MCP server"
      },
      {
        "item": "Premium (cloud)",
        "unit": "seat-month",
        "usd": 19.5,
        "note": "yearly term, from 100 users"
      }
    ],
    "provenance": {
      "legalEntity": "OpenProject GmbH",
      "domain": "openproject.org",
      "domainRegistered": "2003-10-24",
      "endpointOnVendorDomain": true,
      "terms": "https://www.openproject.org/legal/terms-of-service/",
      "privacy": "https://www.openproject.org/legal/privacy/",
      "statusPage": "https://status.openproject.com",
      "changelog": "https://www.openproject.org/docs/release-notes/",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service (last updated 6 August 2026) name OpenProject GmbH, Krausenstrasse 9, 10117 Berlin, Germany, and cover both the cloud and the on-premises Enterprise edition. The German version takes precedence.",
        "The privacy policy (version 30 July 2026) has a section on OpenProject Enterprise Cloud, where OpenProject GmbH is processor and the customer controller. The data processing agreement at https://www.openproject.org/legal/data-processing-agreement/ is part of the terms.",
        "Cloud instances answer at \u003cname\u003e.openproject.com or, on the EU shard, an openproject.eu host. Both are the vendor's domains, apart from the openproject.org site that carries the docs and legal pages. Self-hosted instances answer on the owner's domain.",
        "www.openproject.org/.well-known/security.txt is PGP-signed, names security@openproject.com and expires on 31 December 2026.",
        "RDAP for openproject.org gives a registration date of 2003-10-24 and InterNetX GmbH as registrar."
      ],
      "score": 95,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "OpenProject GmbH",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "openproject.org, registered 2003-10-24 (22 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "openproject.org",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 3 of the 7 things a reader expects",
          "points": 6.6,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.openproject.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.openproject.org/legal/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-06",
          "words": 7259,
          "points": 6.6,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 2026-08-06",
              "says": "Last updated 2026-08-06"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": false
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "§ 5 Contractual Term and Termination of the Agreement"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": false
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Further details regarding the services that OpenProject will provide, in particular as regards the functional scope of the software or its technical and hours of availability, data portability, or applicable service levels, can be found in the service or selected rate plan description."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The contract term renews automatically for the originally selected period unless the customer terminates it.",
              "quote": "The contractual term shall be automatically extended by the originally selected period, unless the contract is terminated as follows:"
            },
            {
              "date": "2026-10-08",
              "text": "OpenProject may name the customer as a user of its products in reference lists and external communications, to an appropriate and customary extent.",
              "quote": "OpenProject may refer to the Customer’s use of OpenProject products pursuant to a contractual relationship with OpenProject and to an appropriate and customary extent in reference lists and in its external communications."
            },
            {
              "date": "2026-10-08",
              "text": "If the customer gives no deletion instructions by the end of the term, OpenProject asks it to back up its data on its own systems within 21 days.",
              "quote": "If the Customer fails to specify any corresponding provisions by the end of the contractual term, OpenProject will request the Customer to back up their data on their own systems within 21 days."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.openproject.org/legal/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 7432,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "In this process, we collect and process the following personal data:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Your data will be deleted no later than 90 days.",
              "says": "Names a period of 90 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Our service provider is based in the European Economic Area, does not use the texts translated for us for further training of its AI, does not store the texts beyond the translation process, and is bound to us by a data processing agreement regarding data protection and professional confidentiality."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "In some cases, your consent is the legal basis, pursuant to Article 6 (1) (a) and Article 7 GDPR, which you may revoke at any time with with effect for the future by sending an email to privacy@openproject.com."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "In some cases, your consent is the legal basis, pursuant to Article 6 (1) (a) and Article 7 GDPR, which you may revoke at any time with with effect for the future by sending an email to privacy@openproject.com.",
              "says": "privacy@openproject.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards, including the European Commission’s Standard Contractual Clauses where applicable, are in place.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "An Enterprise Cloud instance is deleted automatically six months after the contract expires.",
              "quote": "Your instance of the OpenProject Enterprise Cloud will be automatically deleted six months after the expiry of your contract."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/openproject.json",
    "live": {
      "slug": "openproject",
      "vendorStatus": {
        "page": "https://status.openproject.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:58:22.822468534Z"
      },
      "updatedAt": "2026-10-09T07:58:22.822468534Z"
    }
  }
}
