{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "optimizely",
    "name": "Optimizely Experimentation",
    "vendor": "Optimizely",
    "vendorUrl": "https://www.optimizely.com",
    "kind": "http-api",
    "category": "product-analytics",
    "summary": "Optimizely Experimentation is a hosted platform for A/B tests, feature flags and personalisation, covering Web Experimentation and Feature Experimentation. Agents reach it through a hosted MCP server with seven tools and through REST APIs.",
    "url": "https://www.anchorterminal.com/tools/optimizely",
    "markdownUrl": "https://www.anchorterminal.com/tools/optimizely.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/optimizely.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/optimizely.json",
    "repo": "https://github.com/optimizely/javascript-sdk",
    "license": "Proprietary hosted service under Optimizely's Online Software Subscription Agreement and its API, SDK and MCP terms. The Feature Experimentation SDKs on GitHub are Apache 2.0",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://exp.mcp.opal.optimizely.com/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@optimizely/optimizely-sdk"
      },
      {
        "registry": "pypi",
        "name": "optimizely-sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "Sales-led. Access needs a subscription. The MCP server uses OAuth 2.0 through Opti ID with PKCE and dynamic client registration, and needs an account with Opal enabled and linked to a Feature Experimentation or Web Experimentation instance. The REST APIs take a personal access token, created under Profile then API Access, in the `Authorization: Bearer` header, or OAuth 2.0 for a registered application. Tokens and MCP sessions act with the user's role.",
    "pricing": "paid",
    "pricingNotes": "No price is published. The plans page says every plan is individually packaged and leads to a demo request. No free plan, trial or sandbox was found, so an agent cannot start without a contract. MCP use does not consume Opal credits (https://www.optimizely.com/plans/, checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the v2 Swagger spec or the plans page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 7,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 460480,
      "pypiWeekly": 85924,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.optimizely.com/experimentation-strategy/docs/optimizely-experimentation-mcp-server-overview",
    "llmsTxt": "https://docs.optimizely.com/llms.txt",
    "openapi": "https://api.optimizely.com/v2/swagger.json",
    "capabilities": [
      "analytics.experiments",
      "analytics.flags",
      "analytics.query"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "closed-source",
      "sales-led",
      "enterprise",
      "webhooks",
      "status-page",
      "sla",
      "soc2",
      "iso27001",
      "bug-bounty"
    ],
    "lastRelease": "2026-09-18",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 62.6,
      "grade": "B",
      "agentReady": false,
      "rank": 330,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 68,
        "maintenance": 78,
        "payments": 0,
        "reliability": 73,
        "schema": 74,
        "security": 66,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 73,
          "points": 14.6,
          "reason": "Graded on the hosted service with the hosted lines. Statuspage at status.optimizely.com with 174 components, among them Optimizely REST API, Results API and Events API for Feature Experimentation and Web Experimentation (20). No incident was filed against an Experimentation component between 10 July and 8 October 2026. On 23 July 2026 sign-in through Optimizely Identity failed with 429 errors for about 3 hours 15 minutes because of a disruption at Okta, marked major, and on 17 September 2026 a 3-minute minor incident sent users to the wrong SSO page. Both affect the OAuth sign-in the MCP server depends on (20 of 30). The Feature Experimentation API is limited to 2 requests a second and 120 a minute, the Optimizely API to 100 a minute and the results endpoints to 20 a minute. No limit was found for the MCP server (13 of 15). No 429 response, `Retry-After` header, backoff guidance or idempotency key was found in the v2 spec or the pages read (0 of 15). The Service Level Agreement V 2024-05 gives credits from 10 per cent once downtime passes 43 minutes in a month, capped at 50 per cent (10). The REST APIs are versioned and the MCP pages carry no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "Public Swagger 2.0 spec for the Optimizely API with 65 paths and 93 operations. The spec for the Feature Experimentation API at `/flags/v1` answers 401 without a token, though its reference pages carry the same structured definitions. We could not read the MCP tool schemas, which need a sign-in (20 of 25). llms.txt with 11,441 lines and a Markdown copy of every docs page (10). All 93 operations have a description. The MCP overview gives each of the seven tools one line of purpose and no guidance on when not to use it (12 of 20). 111 enums and 193 required lists in the v2 spec. The MCP server puts queries and writes behind two general tools, `exp_execute_query` and `exp_manage_entity_lifecycle`, with schemas and templates fetched by two more (10 of 15). 274 examples in the v2 spec, with 401 on 77 operations, 403 on 73, 404 on 59 and 400 on 41, and no 429 (11 of 15). Versions are in the path (`/v2`, `/flags/v1`) and each product has dated release notes with an RSS feed. No changelog for the APIs alone was found (11 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 68,
          "points": 11.05,
          "reason": "The MCP server lists seven tools, which is 25 on the checklist. We took 2 off because the tool definitions were unread and their size is unknown (23 of 25). `per_page` up to 100 and `page` on the v2 lists, `page_token`, `sort` and `query` on the flags list, and time windows on results (17 of 20). The Optimizely API returns `code`, `message` and a `uuid`, and the Feature Experimentation API returns a problem detail object. MCP error results were unread (13 of 20). No idempotency keys were found and the tool annotations were unread. The docs say the agent confirms project, environment and details before a change, which is client behaviour, and entities are archived through the lifecycle tool (5 of 20). The MCP server needs only a URL. The official SDKs in eleven languages evaluate flags and log events and do not cover the management APIs (10 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 66,
          "points": 11.55,
          "reason": "The MCP server uses OAuth 2.0 with PKCE (S256), dynamic client registration and a revocation endpoint, with one scope, `mcp:tools`. REST personal access tokens are revocable, named and sent in a header, and administrators can revoke any collaborator's token. The REST OAuth flow has the single scope `all`, described as full access to the account (22 of 30). Sessions and tokens carry the user's role, Feature Experimentation has granular roles for flags, environments and audiences, and change approvals have routed flag changes to reviewers since 6 August 2026. No read-only mode for the MCP server was found, and confirmation before a write is left to the client (13 of 20). No guidance on prompt injection was found, though tools return names, descriptions and hypotheses that people wrote (3 of 15). Change history for projects and flags is in the application, at `/v2/changes` and in webhooks (12 of 15). ISO 27001, ISO 27017, ISO 27018, SOC 2 Type 2 and PCI DSS are stated for Web and Feature Experimentation, with annual penetration tests and a bug bounty programme reachable at securityeng@optimizely.com. No security.txt and no public programme link (16 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 0,
          "points": 0,
          "reason": "No x402, MPP or L402 (0). No price is published. The plans page says every plan is individually packaged and leads to a demo request (0). No free plan or trial was found on the plans page, the product pages or the docs (0). Access needs a subscription and a browser sign-in through Opti ID (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "reason": "`@optimizely/optimizely-sdk` 6.6.1 was tagged on 18 September 2026, and the newest product release notes are dated 3 September 2026 for Feature Experimentation and September 2026 for Web Experimentation (30). Feature Experimentation notes on 22 July, 6 August and 3 September 2026, plus SDK releases 6.6.0 and 6.6.1 (20). Closed service with public release notes, an RSS feed and a support centre. We did not read how quickly questions are answered (9 of 15). Official SDKs are current in eleven languages. The MCP server is not in the official MCP registry, where a search for optimizely returns nothing (12 of 15). The JavaScript SDK repository has six CI workflow files and 8 commits since 10 July 2026 (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 63, provenance 86",
          "reason": "Closed hosted service under a published Online Software Subscription Agreement and API, SDK and MCP terms. The SDKs are open source under Apache 2.0 (17 of 30). The privacy notice of 1 July 2026 says it does not cover customer data and points to the subscription agreement and the Data Processing Agreement (V 2026-01), which agree. Event data is kept 18 months, and customer data may be deleted 30 days after a subscription ends. How the MCP server and Opal handle prompts for Experimentation is not stated on the MCP pages (22 of 30). The API, SDK and MCP terms let Optimizely revise, suspend or cancel any API or MCP at any time under its documentation and policies. An SDK compatibility matrix exists. No deprecation policy with a notice period was found for the APIs (6 of 20). The sub-processor list, updated 14 September 2026, names providers by product with hosting locations. Web and Feature Experimentation list Amazon Web Services in the United States and Google Cloud in the United States and Europe (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP server lists seven tools, which is 25 on the checklist. We took 2 off because the tool definitions were unread and their size is unknown (23 of 25). `per_page` up to 100 and `page` on the v2 lists, `page_token`, `sort` and `query` on the flags list, and time windows on results (17 of 20). The Optimizely API returns `code`, `message` and a `uuid`, and the Feature Experimentation API returns a problem detail object. MCP error results were unread (13 of 20). No idempotency keys were found and the tool annotations were unread. The docs say the agent confirms project, environment and details before a change, which is client behaviour, and entities are archived through the lifecycle tool (5 of 20). The MCP server needs only a URL. The official SDKs in eleven languages evaluate flags and log events and do not cover the management APIs (10 of 15).",
          "maintenance": "`@optimizely/optimizely-sdk` 6.6.1 was tagged on 18 September 2026, and the newest product release notes are dated 3 September 2026 for Feature Experimentation and September 2026 for Web Experimentation (30). Feature Experimentation notes on 22 July, 6 August and 3 September 2026, plus SDK releases 6.6.0 and 6.6.1 (20). Closed service with public release notes, an RSS feed and a support centre. We did not read how quickly questions are answered (9 of 15). Official SDKs are current in eleven languages. The MCP server is not in the official MCP registry, where a search for optimizely returns nothing (12 of 15). The JavaScript SDK repository has six CI workflow files and 8 commits since 10 July 2026 (7 of 10).",
          "payments": "No x402, MPP or L402 (0). No price is published. The plans page says every plan is individually packaged and leads to a demo request (0). No free plan or trial was found on the plans page, the product pages or the docs (0). Access needs a subscription and a browser sign-in through Opti ID (0).",
          "reliability": "Graded on the hosted service with the hosted lines. Statuspage at status.optimizely.com with 174 components, among them Optimizely REST API, Results API and Events API for Feature Experimentation and Web Experimentation (20). No incident was filed against an Experimentation component between 10 July and 8 October 2026. On 23 July 2026 sign-in through Optimizely Identity failed with 429 errors for about 3 hours 15 minutes because of a disruption at Okta, marked major, and on 17 September 2026 a 3-minute minor incident sent users to the wrong SSO page. Both affect the OAuth sign-in the MCP server depends on (20 of 30). The Feature Experimentation API is limited to 2 requests a second and 120 a minute, the Optimizely API to 100 a minute and the results endpoints to 20 a minute. No limit was found for the MCP server (13 of 15). No 429 response, `Retry-After` header, backoff guidance or idempotency key was found in the v2 spec or the pages read (0 of 15). The Service Level Agreement V 2024-05 gives credits from 10 per cent once downtime passes 43 minutes in a month, capped at 50 per cent (10). The REST APIs are versioned and the MCP pages carry no beta label (10).",
          "schema": "Public Swagger 2.0 spec for the Optimizely API with 65 paths and 93 operations. The spec for the Feature Experimentation API at `/flags/v1` answers 401 without a token, though its reference pages carry the same structured definitions. We could not read the MCP tool schemas, which need a sign-in (20 of 25). llms.txt with 11,441 lines and a Markdown copy of every docs page (10). All 93 operations have a description. The MCP overview gives each of the seven tools one line of purpose and no guidance on when not to use it (12 of 20). 111 enums and 193 required lists in the v2 spec. The MCP server puts queries and writes behind two general tools, `exp_execute_query` and `exp_manage_entity_lifecycle`, with schemas and templates fetched by two more (10 of 15). 274 examples in the v2 spec, with 401 on 77 operations, 403 on 73, 404 on 59 and 400 on 41, and no 429 (11 of 15). Versions are in the path (`/v2`, `/flags/v1`) and each product has dated release notes with an RSS feed. No changelog for the APIs alone was found (11 of 15).",
          "security": "The MCP server uses OAuth 2.0 with PKCE (S256), dynamic client registration and a revocation endpoint, with one scope, `mcp:tools`. REST personal access tokens are revocable, named and sent in a header, and administrators can revoke any collaborator's token. The REST OAuth flow has the single scope `all`, described as full access to the account (22 of 30). Sessions and tokens carry the user's role, Feature Experimentation has granular roles for flags, environments and audiences, and change approvals have routed flag changes to reviewers since 6 August 2026. No read-only mode for the MCP server was found, and confirmation before a write is left to the client (13 of 20). No guidance on prompt injection was found, though tools return names, descriptions and hypotheses that people wrote (3 of 15). Change history for projects and flags is in the application, at `/v2/changes` and in webhooks (12 of 15). ISO 27001, ISO 27017, ISO 27018, SOC 2 Type 2 and PCI DSS are stated for Web and Feature Experimentation, with annual penetration tests and a bug bounty programme reachable at securityeng@optimizely.com. No security.txt and no public programme link (16 of 20).",
          "transparency": "Closed hosted service under a published Online Software Subscription Agreement and API, SDK and MCP terms. The SDKs are open source under Apache 2.0 (17 of 30). The privacy notice of 1 July 2026 says it does not cover customer data and points to the subscription agreement and the Data Processing Agreement (V 2026-01), which agree. Event data is kept 18 months, and customer data may be deleted 30 days after a subscription ends. How the MCP server and Opal handle prompts for Experimentation is not stated on the MCP pages (22 of 30). The API, SDK and MCP terms let Optimizely revise, suspend or cancel any API or MCP at any time under its documentation and policies. An SDK compatibility matrix exists. No deprecation policy with a notice period was found for the APIs (6 of 20). The sub-processor list, updated 14 September 2026, names providers by product with hosting locations. Web and Feature Experimentation list Amazon Web Services in the United States and Google Cloud in the United States and Europe (18 of 20)."
        },
        "sources": [
          {
            "what": "docs hub",
            "url": "https://docs.optimizely.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt, 11,441 lines",
            "url": "https://docs.optimizely.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "APIs, SDKs and MCPs index",
            "url": "https://docs.optimizely.com/optimizely-one/apis-sdks-and-mcps",
            "seen": "2026-10-08"
          },
          {
            "what": "Experimentation MCP server overview and tool list",
            "url": "https://docs.optimizely.com/experimentation-strategy/docs/optimizely-experimentation-mcp-server-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server install guide",
            "url": "https://docs.optimizely.com/experimentation-strategy/docs/install-optimizely-experimentation-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server quickstart",
            "url": "https://docs.optimizely.com/experimentation-strategy/docs/optimizely-experimentation-mcp-server-quickstart",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server example prompts",
            "url": "https://docs.optimizely.com/experimentation-strategy/docs/optimizely-experimentation-mcp-server-example-prompts",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP endpoint, 401 with resource metadata",
            "url": "https://exp.mcp.opal.optimizely.com/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth protected resource metadata",
            "url": "https://exp.mcp.opal.optimizely.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth server metadata",
            "url": "https://exp.mcp.opal.optimizely.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "Feature Experimentation APIs overview and rate limits",
            "url": "https://docs.optimizely.com/feature-experimentation/api",
            "seen": "2026-10-08"
          },
          {
            "what": "personal access tokens for the REST APIs",
            "url": "https://docs.optimizely.com/feature-experimentation/api/pQfa-generate-tokens-and-use-the-rest-apis",
            "seen": "2026-10-08"
          },
          {
            "what": "Web Experimentation REST API get started",
            "url": "https://docs.optimizely.com/web-experimentation/api/get-started",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth 2.0 for the REST API",
            "url": "https://docs.optimizely.com/web-experimentation/docs/oauth-20",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger 2.0 spec for the Optimizely API",
            "url": "https://api.optimizely.com/v2/swagger.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Feature Experimentation API spec, 401 without a token",
            "url": "https://api.optimizely.com/flags/v1/swagger.json",
            "seen": "2026-10-08"
          },
          {
            "what": "List Flags reference",
            "url": "https://docs.optimizely.com/feature-experimentation/api/list-flags",
            "seen": "2026-10-08"
          },
          {
            "what": "List Experiments reference",
            "url": "https://docs.optimizely.com/web-experimentation/api/list-experiments",
            "seen": "2026-10-08"
          },
          {
            "what": "change history",
            "url": "https://docs.optimizely.com/feature-experimentation/docs/history",
            "seen": "2026-10-08"
          },
          {
            "what": "data retention policy",
            "url": "https://docs.optimizely.com/experimentation-strategy/docs/data-retention-policy-and-faqs",
            "seen": "2026-10-08"
          },
          {
            "what": "2026 Feature Experimentation release notes",
            "url": "https://docs.optimizely.com/feature-experimentation/release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "2026 Web Experimentation release notes",
            "url": "https://docs.optimizely.com/web-experimentation/release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "plans page",
            "url": "https://www.optimizely.com/plans/",
            "seen": "2026-10-08"
          },
          {
            "what": "Online Software Subscription Agreement 2025-11",
            "url": "https://www.optimizely.com/legal/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "API, SDK and MCP terms page",
            "url": "https://www.optimizely.com/legal/api-sdk-mcp-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "API, SDK and MCP terms, version 2026-08, PDF",
            "url": "https://uxwamy.files.cmp.optimizely.com/download/bb998ee0a23c11f18c58be3fca7a7297",
            "seen": "2026-10-08"
          },
          {
            "what": "Service Level Agreement V 2024-05, PDF",
            "url": "https://uxwamy.files.cmp.optimizely.com/download/9615c632b35f11f19d4f926135d8b1a8",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice V 2026-07",
            "url": "https://www.optimizely.com/legal/privacy-notice/",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Agreement page",
            "url": "https://www.optimizely.com/trust-center/data-processing-agreement/",
            "seen": "2026-10-08"
          },
          {
            "what": "third-party sub-processors",
            "url": "https://www.optimizely.com/legal/sub-processors/third-party/",
            "seen": "2026-10-08"
          },
          {
            "what": "security measures",
            "url": "https://www.optimizely.com/trust-center/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "compliance and certifications",
            "url": "https://www.optimizely.com/trust-center/compliance/",
            "seen": "2026-10-08"
          },
          {
            "what": "status page incidents",
            "url": "https://status.optimizely.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status page components",
            "url": "https://status.optimizely.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry, no result",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=optimizely",
            "seen": "2026-10-08"
          },
          {
            "what": "JavaScript SDK repository, tags and CI",
            "url": "https://github.com/optimizely/javascript-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "@optimizely/optimizely-sdk weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@optimizely/optimizely-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "optimizely-sdk on PyPI, recent downloads",
            "url": "https://pypistats.org/api/packages/optimizely-sdk/recent",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt, 404",
            "url": "https://www.optimizely.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for optimizely.com",
            "url": "https://rdap.verisign.com/com/v1/domain/optimizely.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The lead was right that the docs hub lists REST APIs and an MCP server. The hub is at docs.optimizely.com, and docs.developers.optimizely.com redirects there",
          "The API, SDK and MCP terms (clause 1.11) forbid a licensee from disseminating performance information about any API, SDK or MCP, including uptime, response time and benchmarks. This matters for any probe results we publish and wants a decision before probes run",
          "provenance.terms points at the Online Software Subscription Agreement, which is an HTML page. The API, SDK and MCP terms are part of it and are published only as a PDF",
          "provenance.privacy points at the privacy notice, which says it does not apply to customer data. Customer data is governed by the Data Processing Agreement, published as a PDF",
          "unchecked: the live `tools/list` response of the MCP server, its input schemas and annotations, which need a sign-in. Tool names and purposes come from the docs overview",
          "unchecked: the spec for the Feature Experimentation API at `/flags/v1`, which answers 401 without a token. Its operations were read from the reference pages",
          "unchecked: whether the REST APIs return 429 with `Retry-After`. The v2 spec documents no 429 and we did not search every docs page",
          "unchecked: GitHub stars and issue response times. We read the JavaScript SDK repository by clone only",
          "unchecked: the bug bounty programme's platform and scope. The security page names a programme and an email address without a link",
          "No free plan or trial was found on the plans page, the experimentation and feature management product pages or the docs index. An older free feature flagging page returns 404",
          "The 23 July 2026 identity incident was caused by Okta and was not filed against an Experimentation component. We counted it as minor for this listing because existing tokens were not shown to be affected",
          "Capabilities leave out events and funnels. The Events API and the SDKs log events, but the management surface an agent uses has no funnel or retention query"
        ]
      },
      "negative": 0,
      "verdict": "Optimizely Experimentation suits agents working for an existing customer that manage flags and experiments and read results. The hosted MCP server has seven tools behind OAuth and carries the user's permissions, and the main REST API has a public Swagger spec. No price, free plan or trial is published, and no 429 or idempotency guidance was found.",
      "bestFor": "An agent working for an existing Optimizely customer that lists and creates flags, experiments and audiences, reads experiment results and writes SDK integration code.",
      "strengths": [
        "Hosted MCP server with seven tools for querying, managing and implementing flags and experiments, released on 29 April 2026",
        "MCP sign-in is OAuth 2.0 with PKCE and dynamic client registration, and the server sees only what the user's account can see",
        "Public Swagger 2.0 spec for the Optimizely API with 93 operations, each with a description, plus llms.txt and a Markdown copy of every docs page",
        "Rate limits are published with numbers, 120 requests a minute on the Feature Experimentation API and 100 a minute on the Optimizely API",
        "Change history is readable through the REST API, and change approvals route flag changes to reviewers since 6 August 2026"
      ],
      "weaknesses": [
        "No price is published. The plans page says every plan is individually packaged and leads to a demo request",
        "No free plan or trial was found, and the MCP server needs an account with Opal enabled",
        "No 429 response, `Retry-After` header or idempotency key was found in the spec or the pages read",
        "The REST OAuth flow has one scope, `all`, described as full access to the account",
        "The spec for the Feature Experimentation API at `/flags/v1` answers 401 without a token, and the MCP server is not in the official MCP registry"
      ],
      "agentNotes": [
        "Connect to https://exp.mcp.opal.optimizely.com/mcp and complete OAuth in a browser. The session is time-limited, so expect to sign in again",
        "Call `exp_get_schemas` before `exp_execute_query`, and `exp_get_entity_templates` before `exp_manage_entity_lifecycle`, to learn the fields each entity needs",
        "Confirm the project and environment with the user before any create or update. Changes go to live Optimizely data",
        "Use the Visual Editor for Web Experimentation variation code. The MCP server does not write custom HTML, CSS or JavaScript",
        "Over REST, stay under 2 requests a second on `/flags/v1`, 100 a minute on `/v2` and 20 a minute on the results endpoints"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 62.6
        }
      ],
      "editorialScores": {
        "ergonomics": 68,
        "maintenance": 78,
        "payments": 0,
        "reliability": 73,
        "schema": 74,
        "security": 66,
        "transparency": 63
      },
      "provenanceScore": 86
    },
    "connect": {
      "http": "curl -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\" \"https://api.optimizely.com/v2/projects\"",
      "claudeCode": "claude mcp add --transport http optimizely-exp https://exp.mcp.opal.optimizely.com/mcp",
      "config": {
        "mcpServers": {
          "optimizely-exp": {
            "type": "http",
            "url": "https://exp.mcp.opal.optimizely.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/analytics.experiments",
      "tool": "https://letme.dev/optimizely"
    },
    "notable": [
      "The Experimentation MCP server is hosted at https://exp.mcp.opal.optimizely.com/mcp and lists seven tools, among them `exp_execute_query`, `exp_summarize_test_result` and `exp_manage_entity_lifecycle` (https://docs.optimizely.com/experimentation-strategy/docs/optimizely-experimentation-mcp-server-overview)",
      "The server needs an Opti ID account and an Optimizely account with Opal enabled, and its use does not consume Opal credits (https://docs.optimizely.com/experimentation-strategy/docs/install-optimizely-experimentation-mcp-server)",
      "The OAuth metadata lists PKCE with S256, a registration endpoint, a revocation endpoint and the scope `mcp:tools` (https://exp.mcp.opal.optimizely.com/.well-known/oauth-authorization-server)",
      "The Feature Experimentation API is limited to 2 requests a second and 120 a minute, the Optimizely API to 100 a minute, and the two results endpoints to 20 a minute (https://docs.optimizely.com/feature-experimentation/api)",
      "The Swagger 2.0 spec for the Optimizely API is public with 65 paths and 93 operations (https://api.optimizely.com/v2/swagger.json)",
      "The API, SDK and MCP terms, version 2026-08, forbid disseminating performance information about any API, SDK or MCP, including uptime, response time and benchmarks, in clause 1.11 (https://www.optimizely.com/legal/api-sdk-mcp-terms/)",
      "Event data is kept for 18 months from the first event of an experiment (https://docs.optimizely.com/experimentation-strategy/docs/data-retention-policy-and-faqs)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "The hosted Experimentation MCP server and the REST APIs behind it. The Optimizely API at `https://api.optimizely.com/v2` and the Feature Experimentation API at `https://api.optimizely.com/flags/v1`"
      },
      {
        "label": "MCP server",
        "value": "Streamable HTTP, hosted by Optimizely. 7 tools. `exp_get_schemas`, `exp_execute_query`, `exp_summarize_test_result`, `exp_program_reporting_top_experiments`, `exp_search_fx_sdk_docs`, `exp_manage_entity_lifecycle` and `exp_get_entity_templates`"
      },
      {
        "label": "REST APIs",
        "value": "Optimizely API v2 with 93 operations across projects, experiments, campaigns, audiences, events, pages, attributes, environments, changes, webhooks and results. Feature Experimentation API for flags, rules, rulesets, variations, variables, reports, holdouts and custom fields"
      },
      {
        "label": "Credentials",
        "value": "MCP uses OAuth 2.0 through Opti ID with PKCE (S256), dynamic client registration and a revocation endpoint. REST takes a personal access token as a bearer header, or OAuth 2.0 for a registered application with the single scope `all`"
      },
      {
        "label": "Access",
        "value": "The MCP server and tokens act with the user's role. Administrators can create and revoke tokens for any collaborator. Feature Experimentation has granular roles for flags, environments and audiences"
      },
      {
        "label": "Rate limits",
        "value": "Feature Experimentation API 2 requests a second and 120 a minute. Optimizely API 100 a minute. Get Campaign results and Get Experiment results 20 a minute. No limit was found for the MCP server"
      },
      {
        "label": "Errors",
        "value": "Optimizely API errors carry `code`, `message`, `messages` and `uuid`. The Feature Experimentation API returns `ProblemDetail` with `type`, `title`, `status`, `detail` and `uuid`. The v2 spec documents 401, 403, 404 and 400 and no 429"
      },
      {
        "label": "Pagination",
        "value": "`per_page` (default 25, maximum 100) and `page` on 19 parameters in the v2 spec. `page_token`, `page_window`, `sort` and `query` on the flags list"
      },
      {
        "label": "Pricing",
        "value": "Not published. The plans page says every plan is individually packaged and leads to a demo request. The subscription agreement charges overage at twice the unit price"
      },
      {
        "label": "SDKs",
        "value": "Feature Experimentation SDKs for JavaScript, React, Python, Java, Go, Ruby, PHP, C#, Swift, Android and Flutter, Apache 2.0. `@optimizely/optimizely-sdk` 6.6.1 was tagged on 18 September 2026. They evaluate flags and log events and do not cover the management APIs"
      },
      {
        "label": "Audit",
        "value": "Change history for each project and flag in the application, through `/v2/changes` and through webhooks. Change approvals for flag changes since 6 August 2026"
      },
      {
        "label": "Certifications",
        "value": "ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, SOC 2 Type 2 and PCI DSS v4.0.1 for Web and Feature Experimentation per the compliance page. A bug bounty programme is stated, with reports to securityeng@optimizely.com. No security.txt"
      },
      {
        "label": "Status",
        "value": "https://status.optimizely.com on Statuspage, 174 components. Feature Experimentation and Web Experimentation groups include Optimizely REST API, Results API, Events API and Event Export"
      },
      {
        "label": "SLA",
        "value": "Service Level Agreement V 2024-05. Credits start at 10 per cent once downtime passes 43 minutes in a 720-hour month and are capped at 50 per cent of the monthly fee"
      },
      {
        "label": "Data",
        "value": "Sub-processor list updated 14 September 2026 names Amazon Web Services (United States), Google Cloud (United States, Europe), Cloudflare, Datadog and Okta for Web and Feature Experimentation. Event data is kept 18 months"
      }
    ],
    "provenance": {
      "legalEntity": "Optimizely North America Inc.",
      "domain": "optimizely.com",
      "domainRegistered": "2010-01-11",
      "endpointOnVendorDomain": true,
      "terms": "https://www.optimizely.com/legal/terms/",
      "privacy": "https://www.optimizely.com/legal/privacy-notice/",
      "statusPage": "https://status.optimizely.com",
      "changelog": "https://docs.optimizely.com/feature-experimentation/release-notes",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Online Software Subscription Agreement 2025-11, published 10 November 2025, names Optimizely North America Inc as the contracting entity for customers in the USA, Canada, Mexico, Australia, New Zealand, APJ and the rest of the world, Optimizely AB for the Nordics, UK, Ireland, EU, UAE and Saudi Arabia, and Optimizely GmbH for DACH.",
        "The API, SDK and MCP terms, version 2026-08 published 26 August 2026, are a PDF linked from https://www.optimizely.com/legal/api-sdk-mcp-terms/ and form part of the subscription agreement.",
        "The privacy notice, V 2026-07 published 1 July 2026, says it does not apply to customer data, which Optimizely processes under the subscription agreement and the Data Processing Agreement (V 2026-01).",
        "The MCP server answers at exp.mcp.opal.optimizely.com and the REST APIs at api.optimizely.com.",
        "www.optimizely.com/.well-known/security.txt and www.optimizely.com/security.txt both return 404.",
        "RDAP for optimizely.com gives a registration date of 2010-01-11."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Optimizely North America Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "optimizely.com, registered 2010-01-11 (16 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "exp.mcp.opal.optimizely.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.optimizely.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.optimizely.com/legal/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 6973,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "If the Dispute is not resolved through Mediation within sixty days, then, upon the election of either Party, the Dispute shall be submitted to an applicable court in the Jurisdiction (“Venue”) and subject to the Governing Law below."
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…(or series of connected events) arising in any twelve-month period is absolutely limited, and will not exceed the annual Subscription Fees paid by Customer for the applicable Software Service associated with the damages for that twelve month period.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If Customer fails or refuses to pay Fees, Optimizely may, in addition to all other available remedies, suspend Customer's Use of the applicable Software Service under section 3.2.3 below until payment is made."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer may not withhold, reduce or set-off Fees owed."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "…the Agreement: (i) the Order Form (and each subsequent Order), (ii) the Product Supplement, (iii) the Service Level Agreement , (iv) the Support Policy , (v) the Data Processing Agreement , and (vi) this Online SSA."
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(iv) use, or otherwise utilize, the Software Service, or any Documentation or Optimizely Material to build, and/or assist any Third-Party in building or supporting, software products that compete with Optimizely;",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Subscriptions renew automatically for successive twelve month periods, and Optimizely may raise the subscription fee for each renewal on 120 days' written notice.",
              "quote": "For each Extended Subscription Term, Optimizely may increase the Subscription Fee."
            },
            {
              "date": "2026-10-08",
              "text": "Cancelling a renewal requires written notice at least 90 days before the end of the subscription term.",
              "quote": "A Party may cancel its Subscription for the next Extended Subscription Term by written notice to the other Party at least ninety (90) days prior to the end of the Subscription Term."
            },
            {
              "date": "2026-10-08",
              "text": "Use above the agreed volume is charged at twice the unit price, accruing from the date the overage first occurs and invoiced monthly in arrears.",
              "quote": "Overage Fees be calculated against the applicable Usage Volumes and will be two times (2x) Usage Volume unit price."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.optimizely.com/legal/privacy-notice/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 13005,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Optimizely may collect various types of personal information about you when conducting its business, including (but not limited to):"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Optimizely will only process and retain your personal information for as long as it is required:",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "transfer it to recipients like other entities of the Optimizely Group, third-party service providers, Optimizely partners and others."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Given that Optimizely websites and online services are not directed to Minors, and in accordance with the disclosure requirements of the applicable state privacy laws, Optimizely does not sell the personal information of any Minors.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "To learn more about how you may revoke consent, please refer to Your Control of Your Personal Information, How Can You Exercise Your Rights of Control, and Contact Us sections below."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you would like to find out the Optimizely Group entity that is responsible for the business relationship with you or your employer, please contact us at privacy@optimizely.com",
              "says": "privacy@optimizely.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Data Privacy Framework (collectively, the “Data Privacy Frameworks” or “DPFs”) as set forth by the U.S.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "Advertising Partners: We may share certain personal information (including information collected through cookies) with our advertising service providers and vendors in order to advertise our Services to you."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The notice covers only data Optimizely controls and does not apply to customer data it processes on a customer's instruction under the subscription agreement and data processing agreement.",
              "quote": "As such, this Privacy Notice does not apply to the processing of Customer Data (including personal information), and we recommend you read the privacy notice of the respective client if their processing concerns your personal information."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/optimizely.json",
    "live": {
      "slug": "optimizely",
      "probe": {
        "target": "https://exp.mcp.opal.optimizely.com/mcp",
        "method": "get",
        "lastAt": "2026-10-08T21:12:17.737693254Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 147,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 146,
        "p95ms24h": 196,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.optimizely.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:06:19.531982091Z"
      },
      "updatedAt": "2026-10-08T21:12:17.737693254Z"
    }
  }
}
