{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "outline",
    "name": "Outline",
    "vendor": "General Outline, Inc.",
    "vendorUrl": "https://www.getoutline.com",
    "kind": "http-api",
    "category": "productivity",
    "summary": "Outline is a team wiki and knowledge base from General Outline, available hosted or self-hosted. Agents reach it through an RPC-style HTTP API with a public OpenAPI description, or an MCP server built into each workspace.",
    "url": "https://www.anchorterminal.com/tools/outline",
    "markdownUrl": "https://www.anchorterminal.com/tools/outline.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/outline.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/outline.json",
    "repo": "https://github.com/outline/outline",
    "license": "Source available under BSL 1.1, which bars running it as a document service for third parties and converts each release to Apache 2.0 on its change date (2030-09-09 for 1.10.1). The OpenAPI description is BSD-3-Clause. The hosted service is under the vendor's terms",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://app.getoutline.com/api",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Self-serve. A workspace member creates an API key under Settings, API \u0026 Apps, and sends it as a Bearer token. Keys start with `ol_api_`, are shown once, can carry an expiry and scopes, and can be revoked by their creator or an admin. An unscoped key has all of its owner's access. OAuth 2.0 uses the authorisation code grant with PKCE (S256), refresh tokens, a revocation endpoint and dynamic client registration at `/oauth/register`, with no app review. Scopes are `read` and `write`, namespaced forms such as `documents:read`, and single methods or wildcards such as `documents.info` and `documents.*`. The MCP server takes OAuth by default or an API key. The user guide also allows the key in the request payload as `token`.",
    "pricing": "paid",
    "pricingNotes": "Outline Cloud is priced by team size a month, $10 for 1 to 10 members, $79 for 11 to 100 and $249 for 101 to 200, with larger teams by quote and annual billing available (https://www.getoutline.com/pricing). The API, webhooks and audit log are on every tier, and API calls are not charged. A new workspace gets 30 days free and turns read-only until a payment method is added, so an agent's owner can start without a contract. The self-hosted price table is drawn in the browser and was not read.",
    "priceSummary": "$10 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API documentation, the OpenAPI description or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 19,
    "popularity": {
      "githubStars": 40842,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.getoutline.com/developers",
    "llmsTxt": "https://www.getoutline.com/llms.txt",
    "openapi": "https://www.getoutline.com/openapi.json",
    "capabilities": [
      "work.docs",
      "knowledge.search"
    ],
    "tags": [
      "official",
      "hosted",
      "self-hosted",
      "source-available",
      "paid",
      "free-trial",
      "api-key",
      "oauth",
      "mcp",
      "openapi",
      "llms-txt",
      "webhooks",
      "status-page"
    ],
    "lastRelease": "2026-09-09",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 60.3,
      "grade": "C",
      "agentReady": false,
      "rank": 408,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 62,
        "maintenance": 83,
        "payments": 30,
        "reliability": 67,
        "schema": 76,
        "security": 71,
        "transparency": 69
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 67,
          "points": 13.4,
          "reason": "Graded on the hosted Outline Cloud API with the hosted lines. Status page at status.getoutline.com on Oh Dear with three monitors, Application, Website and Collaboration (20). The history page read No incident history available on 8 October 2026, the seven-day view was clean and the RSS feed was empty, with no uptime figures, so we could not tell a clean record from an unused page and gave 20 of 30. The API documentation says write methods are limited more tightly than reads and gives no numbers. The numbers are in the public source (1,000 requests a minute by default, 25 or 100 a minute on document methods, 1,000 an hour on MCP), which is not a statement about the hosted service (5). Every operation documents 429 with `Retry-After` and three `RateLimit-*` headers, and `documents.update` takes `lastRevision` for a 409 on a stale write. No idempotency keys (12). No SLA found (0). The API and MCP server are generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "Public OpenAPI 3.0 description at www.getoutline.com/openapi.json and in outline/openapi, 154 operations, and MCP tools typed with zod schemas (25). llms.txt on the vendor site, and changelog and integration pages served as Markdown with a `.md` suffix (10). All 154 operations have a summary and a description. Most are one or two sentences and few say when not to use a method (13). 51 schemas, 60 enums, `maxLength` and `format` constraints and 123 required lists. Scopes on `apiKeys.create` are free strings and request bodies do not close off extra properties (12). 153 example values, a curl and a JavaScript sample in the introduction only, and shared 400, 401, 403, 404 and 429 responses (10). The description is versioned 0.1.0 with no version in the path and no API changelog. The outline/openapi commit log and 19 fields marked deprecated are the record (6)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 62,
          "points": 10.07,
          "reason": "`documents.search` returns a context snippet and ranking with each hit, and list methods take `limit`. No field selection, and hits embed the document object. The MCP server has 19 tools, registered according to the token's scopes (13). `limit` and `offset` paging with `nextPath`, `sort` and `direction`, and structured `filters` on document lists and search (17). Errors return `ok`, `error`, `message` and `status` with codes such as `validation_error` and `rate_limit_exceeded` (14). No idempotency keys. `documents.create` accepts a client-chosen `id`, `documents.update` rejects stale writes with 409 through `lastRevision`, and all 19 MCP tools carry `readOnlyHint` and `idempotentHint`. None carries `destructiveHint` (11). Few required parameters and sensible defaults. No official client libraries (7)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 71,
          "points": 12.43,
          "reason": "OAuth 2.0 with PKCE (S256), refresh tokens, revocation and dynamic client registration, and API keys that are shown once, revocable, optionally expiring and scoped down to single methods (30). The user guide allows the key in the request payload as `token`. The source also reads `token` from the query string, which the documentation does not mention, so no deduction. A `read` scope, per-method scopes, MCP tools filtered by scope, a workspace switch for MCP, and deletes that go to the trash for 30 days unless `permanent` is set. No confirmation step for writes or deletes (15). Documents and comments are text written by other users. No prompt-injection guidance was found. WebMCP leaves destructive actions out (3). Audit log with actor, IP address and authentication type, kept one year, on every cloud tier and through `events.list` (14). A disclosure policy through GitHub advisories with 26 advisories published and patched in public, and CodeQL in CI. No security.txt, bug bounty, SOC 2 or ISO 27001 found (9). The 2026 scope-bypass advisories are counted under incidents."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Prices are public as plans by team size, $10, $79 and $249 a month, with nothing per call (10). A new workspace is free for 30 days and becomes read-only until a payment method is added, so no card is needed to start (20). A person creates the workspace and the first key or OAuth approval in a browser. `apiKeys.create` and `/oauth/register` exist but need a signed-in user first (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "v1.10.1 was released on 9 September 2026, 29 days before the check, and the main branch had 200 commits since 5 September (30). Five tagged releases since 11 July 2026, and seven dated changelog entries in the same period (20). The 30 newest open issues and pull requests on 8 October 2026 show the maintainer opening and answering items daily, with 83 open in total on a repository of 40,842 stars (22). No vendor entry in the official MCP registry, where a search returned community servers only, and no official client libraries. The OpenAPI description was updated on 7 October 2026 (3). CI, CodeQL and Dependabot are configured in the repository (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 69,
          "points": 6.04,
          "note": "editorial 58, provenance 79",
          "reason": "The source is public under BSL 1.1, which is not an OSI licence and bars running a competing document service, with each release converting to Apache 2.0 after its change date. The OpenAPI description is BSD-3-Clause. Between closed and open source (22). A privacy policy, a DPA and a security page exist. The policy is undated and states no retention periods, the DPA points to a Data Security and Retention clause that the policy does not contain, and the terms of service cover the website only. Backups are kept at least three months and audit logs one year (14). Deprecated parameters are marked in the OpenAPI description, 19 of them, with no dates and no deprecation policy (5). The DPA lists 13 sub-processors with purpose and country, and the security page places servers in the US on AWS. No change log for the list (17)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`documents.search` returns a context snippet and ranking with each hit, and list methods take `limit`. No field selection, and hits embed the document object. The MCP server has 19 tools, registered according to the token's scopes (13). `limit` and `offset` paging with `nextPath`, `sort` and `direction`, and structured `filters` on document lists and search (17). Errors return `ok`, `error`, `message` and `status` with codes such as `validation_error` and `rate_limit_exceeded` (14). No idempotency keys. `documents.create` accepts a client-chosen `id`, `documents.update` rejects stale writes with 409 through `lastRevision`, and all 19 MCP tools carry `readOnlyHint` and `idempotentHint`. None carries `destructiveHint` (11). Few required parameters and sensible defaults. No official client libraries (7).",
          "maintenance": "v1.10.1 was released on 9 September 2026, 29 days before the check, and the main branch had 200 commits since 5 September (30). Five tagged releases since 11 July 2026, and seven dated changelog entries in the same period (20). The 30 newest open issues and pull requests on 8 October 2026 show the maintainer opening and answering items daily, with 83 open in total on a repository of 40,842 stars (22). No vendor entry in the official MCP registry, where a search returned community servers only, and no official client libraries. The OpenAPI description was updated on 7 October 2026 (3). CI, CodeQL and Dependabot are configured in the repository (8).",
          "payments": "No x402, MPP or L402 (0). Prices are public as plans by team size, $10, $79 and $249 a month, with nothing per call (10). A new workspace is free for 30 days and becomes read-only until a payment method is added, so no card is needed to start (20). A person creates the workspace and the first key or OAuth approval in a browser. `apiKeys.create` and `/oauth/register` exist but need a signed-in user first (0).",
          "reliability": "Graded on the hosted Outline Cloud API with the hosted lines. Status page at status.getoutline.com on Oh Dear with three monitors, Application, Website and Collaboration (20). The history page read No incident history available on 8 October 2026, the seven-day view was clean and the RSS feed was empty, with no uptime figures, so we could not tell a clean record from an unused page and gave 20 of 30. The API documentation says write methods are limited more tightly than reads and gives no numbers. The numbers are in the public source (1,000 requests a minute by default, 25 or 100 a minute on document methods, 1,000 an hour on MCP), which is not a statement about the hosted service (5). Every operation documents 429 with `Retry-After` and three `RateLimit-*` headers, and `documents.update` takes `lastRevision` for a 409 on a stale write. No idempotency keys (12). No SLA found (0). The API and MCP server are generally available (10).",
          "schema": "Public OpenAPI 3.0 description at www.getoutline.com/openapi.json and in outline/openapi, 154 operations, and MCP tools typed with zod schemas (25). llms.txt on the vendor site, and changelog and integration pages served as Markdown with a `.md` suffix (10). All 154 operations have a summary and a description. Most are one or two sentences and few say when not to use a method (13). 51 schemas, 60 enums, `maxLength` and `format` constraints and 123 required lists. Scopes on `apiKeys.create` are free strings and request bodies do not close off extra properties (12). 153 example values, a curl and a JavaScript sample in the introduction only, and shared 400, 401, 403, 404 and 429 responses (10). The description is versioned 0.1.0 with no version in the path and no API changelog. The outline/openapi commit log and 19 fields marked deprecated are the record (6).",
          "security": "OAuth 2.0 with PKCE (S256), refresh tokens, revocation and dynamic client registration, and API keys that are shown once, revocable, optionally expiring and scoped down to single methods (30). The user guide allows the key in the request payload as `token`. The source also reads `token` from the query string, which the documentation does not mention, so no deduction. A `read` scope, per-method scopes, MCP tools filtered by scope, a workspace switch for MCP, and deletes that go to the trash for 30 days unless `permanent` is set. No confirmation step for writes or deletes (15). Documents and comments are text written by other users. No prompt-injection guidance was found. WebMCP leaves destructive actions out (3). Audit log with actor, IP address and authentication type, kept one year, on every cloud tier and through `events.list` (14). A disclosure policy through GitHub advisories with 26 advisories published and patched in public, and CodeQL in CI. No security.txt, bug bounty, SOC 2 or ISO 27001 found (9). The 2026 scope-bypass advisories are counted under incidents.",
          "transparency": "The source is public under BSL 1.1, which is not an OSI licence and bars running a competing document service, with each release converting to Apache 2.0 after its change date. The OpenAPI description is BSD-3-Clause. Between closed and open source (22). A privacy policy, a DPA and a security page exist. The policy is undated and states no retention periods, the DPA points to a Data Security and Retention clause that the policy does not contain, and the terms of service cover the website only. Backups are kept at least three months and audit logs one year (14). Deprecated parameters are marked in the OpenAPI description, 19 of them, with no dates and no deprecation policy (5). The DPA lists 13 sub-processors with purpose and country, and the security page places servers in the US on AWS. No change log for the list (17)."
        },
        "sources": [
          {
            "what": "API reference",
            "url": "https://www.getoutline.com/developers",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI description, 154 operations",
            "url": "https://www.getoutline.com/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI repository and commit log",
            "url": "https://github.com/outline/openapi",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://www.getoutline.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "user guide, API keys and scopes",
            "url": "https://docs.getoutline.com/s/guide/doc/api-1rEIXDfLF6",
            "seen": "2026-10-08"
          },
          {
            "what": "user guide, MCP setup",
            "url": "https://docs.getoutline.com/s/guide/doc/mcp-6j9jtENNKL",
            "seen": "2026-10-08"
          },
          {
            "what": "user guide, audit log",
            "url": "https://docs.getoutline.com/s/guide/doc/audit-log-cEpf9ayBaQ",
            "seen": "2026-10-08"
          },
          {
            "what": "user guide, security",
            "url": "https://docs.getoutline.com/s/guide/doc/security-DlJBglbImQ",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tool definitions in the source",
            "url": "https://github.com/outline/outline/tree/main/server/mcp/tools",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limiter strategies in the source",
            "url": "https://github.com/outline/outline/blob/main/server/utils/RateLimiter.ts",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth authorisation server metadata",
            "url": "https://app.getoutline.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected resource metadata",
            "url": "https://app.getoutline.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog, MCP launch",
            "url": "https://www.getoutline.com/changelog/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog, MCP improvements",
            "url": "https://www.getoutline.com/changelog/mcp-improvements",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog, WebMCP support",
            "url": "https://www.getoutline.com/changelog/webmcp-support",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog feed",
            "url": "https://www.getoutline.com/rss.xml",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.getoutline.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.getoutline.com",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://status.getoutline.com/status-page/outline-status/history?secret=",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.getoutline.com/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.getoutline.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing agreement and sub-processors",
            "url": "https://docs.getoutline.com/s/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://www.getoutline.com/integrations/webhooks",
            "seen": "2026-10-08"
          },
          {
            "what": "licence",
            "url": "https://github.com/outline/outline/blob/main/LICENSE",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy",
            "url": "https://github.com/outline/outline/blob/main/docs/SECURITY.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories",
            "url": "https://github.com/outline/outline/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "releases",
            "url": "https://github.com/outline/outline/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "repository metadata and open issues",
            "url": "https://api.github.com/repos/outline/outline",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt, 404",
            "url": "https://www.getoutline.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=outline",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for getoutline.com",
            "url": "https://rdap.verisign.com/com/v1/domain/getoutline.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the On-Premises price table on the pricing page is drawn in the browser, so self-hosted editions and prices were not read",
          "unchecked: the rate limits applied on the hosted service. The numbers quoted come from the public source and its defaults",
          "unchecked: the MCP tool list as served by a live workspace, which needs a signed-in session. The 19 tools were counted on the main branch",
          "The status history page shows no incidents at all and no uptime figures. Whether that is a clean record or an unused page could not be established",
          "The only terms document found reads as website terms, yet the DPA treats the Terms of Service as the customer agreement. `provenance.terms` points at it for want of another",
          "The lead called Outline open source. The repository is under BSL 1.1, which its own text says is not an open source licence",
          "Whether the hosted service runs the tagged release or the main branch was not established. The pricing page calls it always up to date",
          "No bug bounty, SOC 2 or ISO 27001 statement was found on the pages read. One may exist under a confidentiality agreement"
        ]
      },
      "negative": -5,
      "negativeNotes": [
        "2026-05-07 and 2026-06-15. CVE-2026-43886 (GHSA-7732-6qrg-wjf4, high) let an OAuth client request `read *` and receive wildcard access, fixed in 1.7.0. CVE-2026-54573 (GHSA-5x79-rj4g-qrh8, high) let a scoped API key or token reach other methods by adding a URL fragment, fixed in 1.8.0. Both defeat the scopes an agent's owner relies on. Fixed and published, so 2 points (https://github.com/outline/outline/security/advisories/GHSA-7732-6qrg-wjf4, https://github.com/outline/outline/security/advisories/GHSA-5x79-rj4g-qrh8).",
        "2026-06-06 and 2026-07-27. Two MCP advisories, `list_documents` returning metadata of private documents on an exact slug match (GHSA-pp65-6cc2-4mx9, medium) and viewers publishing into restricted collections through MCP (GHSA-c43v-wwv4-9mcc, medium), both fixed in 1.8.0. Fixed and published, 1 point (https://github.com/outline/outline/security/advisories/GHSA-pp65-6cc2-4mx9, https://github.com/outline/outline/security/advisories/GHSA-c43v-wwv4-9mcc).",
        "2025-11-16 to 2026-07-30. Eighteen further advisories in twelve months, among them a critical rate-limit bypass allowing brute force of the email login code (CVE-2026-33640, fixed in 1.6.0) and cross-workspace access to private documents through share creation (CVE-2026-41649, fixed in 1.7.0). All fixed and published by the vendor, so 2 points (https://github.com/outline/outline/security/advisories)."
      ],
      "verdict": "API keys and OAuth tokens can be limited to single endpoints, all 154 operations document a 429 response with Retry-After, and the workspace MCP server registers tools by granted scope. Two scope-bypass flaws were published and fixed in May and June 2026, rate limits carry no published numbers, and there are no official client libraries.",
      "bestFor": "Teams that keep their wiki in Outline and want an agent to search, read, write and comment on Markdown documents, on the hosted service or a self-hosted copy with the same API.",
      "strengths": [
        "Public OpenAPI 3.0 description with 154 operations, each with a summary and description, plus llms.txt on the vendor site",
        "API keys take an expiry and scopes down to one endpoint such as `documents.info`, and OAuth supports PKCE and dynamic client registration",
        "Every operation documents 429 with `Retry-After` and three `RateLimit-*` response headers",
        "Each workspace has an MCP server with 19 tools, registered according to the token's scopes, with read-only and idempotent hints on all of them",
        "Audit log kept for one year on every cloud tier and readable through `events.list` with `auditLog` set"
      ],
      "weaknesses": [
        "No rate limit numbers in the API documentation. The limits we found are in the source code, not stated for the hosted service",
        "Two flaws that let a restricted key or token exceed its scopes were published in May and June 2026, both fixed (GHSA-7732-6qrg-wjf4, GHSA-5x79-rj4g-qrh8)",
        "No official client libraries. The vendor points to the OpenAPI description for generating clients",
        "No idempotency keys, and no MCP tool carries a destructive hint or a confirmation step",
        "The published terms of service read as website terms, and the privacy policy states no retention periods",
        "No security.txt, bug bounty or SOC 2 or ISO 27001 report was found on the vendor's pages"
      ],
      "agentNotes": [
        "Send every call as POST with a JSON body to `https://app.getoutline.com/api/\u003cmethod\u003e`, for example `documents.search`, with a Bearer key in the header",
        "Ask for a key scoped to the methods the task needs, such as `documents.info documents.search`. An unscoped key has all of its owner's access",
        "Pass `lastRevision` on `documents.update` so a stale write is rejected with 409, and use `editMode` `patch` with `findText` to change one passage",
        "Wait for the seconds in `Retry-After` on a 429. Write methods have tighter limits than reads",
        "Leave `permanent` unset on `documents.delete`. The default moves the document to the trash, where it can be restored for 30 days"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 60.3
        }
      ],
      "editorialScores": {
        "ergonomics": 62,
        "maintenance": 83,
        "payments": 30,
        "reliability": 67,
        "schema": 76,
        "security": 71,
        "transparency": 58
      },
      "provenanceScore": 79
    },
    "connect": {
      "http": "curl https://app.getoutline.com/api/documents.info -X POST -H 'authorization: Bearer MY_API_KEY' -H 'content-type: application/json' -H 'accept: application/json' -d '{\"id\": \"outline-api-NTpezNwhUP\"}'",
      "claudeCode": "claude mcp add --transport http outline https://\u003cyoursubdomain\u003e.getoutline.com/mcp",
      "config": {
        "mcpServers": {
          "outline": {
            "url": "https://\u003cyoursubdomain\u003e.getoutline.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/work.docs",
      "tool": "https://letme.dev/outline"
    },
    "notable": [
      "The API is RPC style. Every one of 154 operations is a POST to `https://app.getoutline.com/api/\u003cmethod\u003e`, and the vendor says its own application runs on the same API (https://www.getoutline.com/openapi.json)",
      "Each workspace has had a built-in MCP server since 18 February 2026, at https://\u003csubdomain\u003e.getoutline.com/mcp over Streamable HTTP, switched on or off by an admin under Settings, Workspace, AI (https://docs.getoutline.com/s/guide/doc/mcp-6j9jtENNKL)",
      "The MCP source registers 19 tools and filters them by the token's scopes. All carry `readOnlyHint` and `idempotentHint`, and none carries `destructiveHint` (https://github.com/outline/outline/tree/main/server/mcp/tools)",
      "The repository is under BSL 1.1, which its own text says is not an open source licence, while the vendor's security page calls the product open-source at its core (https://github.com/outline/outline/blob/main/LICENSE)",
      "Twenty-two advisories were published on the repository between 16 November 2025 and 30 July 2026, one critical and eight high, all with a patched version named (https://github.com/outline/outline/security/advisories)",
      "CVE-2026-43886 let an OAuth client add the wildcard scope to a read-only request, fixed in 1.7.0, and CVE-2026-54573 let a scoped key reach other methods through a URL fragment, fixed in 1.8.0 (https://github.com/outline/outline/security/advisories/GHSA-7732-6qrg-wjf4, https://github.com/outline/outline/security/advisories/GHSA-5x79-rj4g-qrh8)",
      "WebMCP support, added on 9 September 2026, registers command bar actions as in-page tools for browser agents and leaves out deletes (https://www.getoutline.com/changelog/webmcp-support)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "The hosted Outline Cloud API at https://app.getoutline.com/api, with the built-in MCP server described alongside it. The same API and MCP server ship in the self-hosted editions"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.0, 154 operations in 26 groups, all POST with JSON bodies. Documents (30 operations), collections (19), users (12), comments (9), groups (9), templates (7), plus shares, revisions, attachments, events and webhook subscriptions"
      },
      {
        "label": "Documents",
        "value": "Bodies are Markdown up to 1,536,000 characters. `documents.update` takes `editMode` with `findText` for patch edits and `lastRevision` for a 409 on a stale write. `documents.delete` moves to the trash for 30 days unless `permanent` is set"
      },
      {
        "label": "Search",
        "value": "`documents.search` returns a context snippet and ranking per hit with structured `filters`, `documents.search_titles` matches titles only, and `documents.answerQuestion` answers from documents where the workspace has AI answers on"
      },
      {
        "label": "MCP server",
        "value": "https://\u003csubdomain\u003e.getoutline.com/mcp, Streamable HTTP only, 19 tools (documents, collections, comments, templates, attachments, users and a `fetch` tool), OAuth or API key, off or on per workspace. The source limits it to 1,000 requests an hour"
      },
      {
        "label": "Credentials",
        "value": "API keys with optional expiry and scopes, or OAuth 2.0 with PKCE, refresh tokens, revocation and dynamic client registration. Scopes are `read`, `write`, namespaced such as `documents:read`, or single methods and wildcards"
      },
      {
        "label": "Rate limits",
        "value": "No numbers in the API documentation. A 429 carries `Retry-After`, `RateLimit-Limit`, `RateLimit-Remaining` and `RateLimit-Reset`. The source defaults to 1,000 requests a minute overall, with document methods at 25 or 100 a minute and some at 10 or 100 an hour"
      },
      {
        "label": "Errors",
        "value": "JSON with `ok`, `error`, `message` and `status`, for example `validation_error` at 400 and `rate_limit_exceeded` at 429. 401 and 429 are documented on every operation, 403 on 151"
      },
      {
        "label": "Paging",
        "value": "`limit` and `offset` with `sort` and `direction` on list methods, and a `nextPath` in each response. No field selection"
      },
      {
        "label": "Webhooks",
        "value": "Workspace webhooks post JSON for document, collection, comment, user, group and share events, signed where a secret is set, and are managed through four `webhookSubscriptions` methods. Repeatedly failing webhooks are disabled"
      },
      {
        "label": "Client libraries",
        "value": "None official. The vendor publishes the OpenAPI description in outline/openapi for generating clients"
      },
      {
        "label": "Audit",
        "value": "Audit log with actor, IP address and authentication type, kept for one year, in Settings and through `events.list` with `auditLog`"
      },
      {
        "label": "Status",
        "value": "status.getoutline.com on Oh Dear with three monitors (Application, Website, Collaboration). The history page showed no incidents on 8 October 2026 and gives no uptime figures"
      },
      {
        "label": "Data",
        "value": "Servers in the US on AWS, AES-256 at rest, daily backups kept at least three months, per the vendor's security page. The DPA lists 13 sub-processors with countries, OpenAI among them for generative AI"
      },
      {
        "label": "Releases",
        "value": "v1.10.1 on 9 September 2026 and five tagged releases since 11 July 2026. The hosted changelog has 172 dated entries, the newest on 9 September 2026"
      }
    ],
    "unitPrices": [
      {
        "item": "Cloud, 1 to 10 members",
        "unit": "month",
        "usd": 10,
        "note": "billed monthly, annual billing available"
      },
      {
        "item": "Cloud, 11 to 100 members",
        "unit": "month",
        "usd": 79,
        "note": "billed monthly, annual billing available"
      },
      {
        "item": "Cloud, 101 to 200 members",
        "unit": "month",
        "usd": 249,
        "note": "billed monthly, annual billing available"
      }
    ],
    "provenance": {
      "legalEntity": "General Outline, Inc.",
      "domain": "getoutline.com",
      "domainRegistered": "2017-11-08",
      "endpointOnVendorDomain": true,
      "terms": "https://www.getoutline.com/terms",
      "privacy": "https://www.getoutline.com/privacy",
      "statusPage": "https://status.getoutline.com",
      "changelog": "https://www.getoutline.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The data processing agreement at docs.getoutline.com/s/dpa names General Outline, Inc., a Delaware corporation at 228 Park Ave S, PMB 377005, New York, and says it supplements the Terms of Service, which it calls the Agreement.",
        "The page at www.getoutline.com/terms is titled Terms of Service and is the only terms document found. Its clauses cover the website's materials and say nothing on the hosted service, payment or customer content.",
        "The privacy policy is undated, names General Outline, Inc. as operator of getoutline.com, and covers registered and signed-in users as well as visitors.",
        "The hosted API answers at https://app.getoutline.com/api and each workspace at \u003csubdomain\u003e.getoutline.com, both on the vendor's domain.",
        "www.getoutline.com/.well-known/security.txt and app.getoutline.com/.well-known/security.txt both return 404. Reports go through GitHub security advisories per docs/SECURITY.md in the repository.",
        "RDAP for getoutline.com gives a registration date of 2017-11-08."
      ],
      "score": 79,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "General Outline, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "getoutline.com, registered 2017-11-08 (8 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "app.getoutline.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 4 of the 7 things a reader expects",
          "points": 7.4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 2 of the 8 things a reader expects",
          "points": 5.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.getoutline.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.getoutline.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 712,
          "points": 7.4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "Except to the extent any applicable law provides otherwise, these terms and conditions are governed by and construed in accordance with the laws of San Francisco County, California and you irrevocably submit to the exclusive jurisdiction of the courts in that State.",
              "says": "The law of San Francisco County"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In no event shall Outline or its suppliers be liable for any damages (including, without limitation, damages for loss of data or profit, or due to business interruption) arising out of the use or inability to use the materials on Outline’s website, even if Outline or a Outline authorized representative has been notifi…"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": false
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Outline may revise these terms of service for its website at any time without notice.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "This is the grant of a license, not a transfer of title, and under this license you may not:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The terms cover materials on the Outline website and grant licences over them for personal, non-commercial viewing only.",
              "quote": "Permission is granted to temporarily download one copy of the materials (information or software) on Outline’s website for personal, non-commercial transitory viewing only."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.getoutline.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 1024,
          "points": 5.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "It is Outline’s policy to respect your privacy regarding any information we may collect while operating our websites."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Other than to its employees, contractors and affiliated organizations, as described above, Outline discloses potentially personally-identifying and personally-identifying information only in response to a subpoena, court order or other governmental request, or when Outline believes in good faith that disclosure is rea…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Outline reserves the right to publish a request sent to it, such as a support email.",
              "quote": "If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/outline.json",
    "live": {
      "slug": "outline",
      "probe": {
        "target": "https://app.getoutline.com/api",
        "method": "get",
        "lastAt": "2026-10-08T21:12:17.808760869Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 291,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 261,
        "p95ms24h": 291,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.getoutline.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:39:01.469357096Z"
      },
      "updatedAt": "2026-10-08T21:12:17.808760869Z"
    }
  }
}
