{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "paperclip",
    "name": "Paperclip",
    "vendor": "Paperclip Labs, Inc.",
    "vendorUrl": "https://paperclip.ing",
    "kind": "harness",
    "category": "agent-harnesses",
    "summary": "Paperclip is an open-source, self-hosted server and web interface that organises AI agents into a company with an org chart, tasks, budgets and approvals. It drives Claude Code, Codex, OpenClaw and other harnesses through adapters.",
    "url": "https://www.anchorterminal.com/tools/paperclip",
    "markdownUrl": "https://www.anchorterminal.com/tools/paperclip.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paperclip.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paperclip.json",
    "repo": "https://github.com/paperclipai/paperclip",
    "license": "MIT",
    "transports": [],
    "packages": [
      {
        "registry": "npm",
        "name": "paperclipai"
      },
      {
        "registry": "npm",
        "name": "@paperclipai/mcp-server"
      },
      {
        "registry": "oci",
        "name": "ghcr.io/paperclipai/paperclip"
      }
    ],
    "auth": "mixed",
    "authNotes": "No Paperclip account. The default `local_trusted` mode needs no login on loopback. Authenticated mode uses browser sessions for people, board API keys for scripts, and agent API keys or short-lived run JWTs as bearer tokens.",
    "pricing": "free",
    "pricingNotes": "Free and MIT, self-hosted, with nothing to buy. The owner pays each harness's model provider or subscription. Paperclip Cloud is a waitlist with no published price.",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the site or the server source (checked 2026-10-08). The only mention in the repository is a link to a third-party skill in a planning note.",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 98666,
      "npmWeekly": 59684,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.paperclip.ing",
    "llmsTxt": "https://paperclip.ing/llms.txt",
    "capabilities": [
      "agent.multi-agent",
      "agent.mcp-client"
    ],
    "tags": [
      "open-source",
      "self-hosted",
      "local",
      "free",
      "no-card",
      "llms-txt",
      "docker",
      "mcp",
      "typescript"
    ],
    "lastRelease": "2026-10-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 59,
      "grade": "C",
      "agentReady": false,
      "rank": 390,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 12,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 70,
        "maintenance": 78,
        "payments": 60,
        "reliability": 66,
        "schema": 81,
        "security": 64,
        "transparency": 65
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 66,
          "points": 13.2,
          "reason": "Read as local software. Official npm package `paperclipai` (Node.js 24.11 or newer) and a Docker image on GHCR (20). 2,429 test files and 20 workflows. The Actions page for master on 8 October 2026 showed recent runs passing, with two failed Runner Full-Stack E2E runs (681 and 682) before two that passed (22). 2,849 open issues, 125 labelled bug, 1,599 opened before 8 July, and 78 closed in the last 30 days against 686 opened (6). Calendar versions in semver syntax, with a Breaking Changes section and an upgrade guide in release notes, but breaking changes arrive in ordinary releases and 2026.916.0 carried five (10). No 1.0. The npm `latest` tag is called the stable channel and follows a beta soak of at least three days, while the roadmap says the product is still moving quickly, so half credit (8)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 81,
          "points": 13.16,
          "reason": "The running server publishes OpenAPI at `/api/openapi.json` and validates requests with Zod, and the MCP server's tools take Zod schemas. No copy of the spec is published on the docs site, and paperclip.ing/openapi.json describes only the website (22). llms.txt at paperclip.ing, and docs pages answer as Markdown at `.md` (10). An API reference page per resource and task guides, but the MCP tool descriptions are one line each, such as List agents in a company (13). Typed inputs throughout, apart from the `paperclipApiRequest` tool, which takes any path under `/api` and a JSON body (12). cURL, JavaScript and Python examples and a status-code table, with one `{error}` shape and an occasional `details` field (12). A changelog page for every stable release and release notes in the repository, but the API path carries no version (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 70,
          "points": 11.38,
          "reason": "Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. The MCP server lists 44 tools with no toolsets or read-only subset found, offset by compact reads such as `paperclipInboxLite` and the heartbeat context (12). Budgets by company, agent and project with an automatic pause at 100 per cent, though the README says enforcement uses recorded spend and can lag work in flight (16). `onboard --yes`, CLI commands with `--json`, the REST API and routines started by cron, webhook or API (16). Atomic task checkout with a documented 409, `Idempotency-Key` on routine triggers, saved sessions and bounded recovery (17). One command starts a server with embedded PostgreSQL, but it needs Node.js 24.11 and each harness CLI installed and signed in on the host, and we found no client SDK beyond the TypeScript plugin SDK (9)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 64,
          "points": 11.2,
          "reason": "Harness reading of the framework checklist, as used for the other harnesses. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Anonymous usage telemetry is on by default and goes to telemetry.paperclip.ing. The README lists what is excluded and four opt-outs, and Sentry and OpenTelemetry stay off until configured. We found no first-run notice in the CLI source (18). Board approvals for hires and strategy, execution policies and per-action connection permissions, but `claude_local` defaults `dangerouslySkipPermissions` to true, `codex_local` defaults to bypassing approvals and the sandbox, local agents run on the host, sandbox providers are optional plugins and the default `local_trusted` mode has no login (10). A documented `low_trust_review` preset contains agents that read untrusted pull requests or tickets. It is opt-in (10). An activity log of mutating actions, run logs, cost events and audited board API keys (14). SECURITY.md with GitHub private reporting and twelve advisories published, two with CVEs. No security.txt, bug bounty or SOC 2 report found (12)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "No payment protocol (0). Read with the self-hosted rule. The software is free under MIT with nothing to buy (20). No card and no Paperclip account (20). One `npx` command installs and starts it with no signup (20). Paperclip Cloud is a waitlist with no published price, so there is no paid option to score."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "reason": "Version 2026.1005.0, dated 5 October 2026 in its notes and published on GitHub and npm on 6 October (30). Eleven stable releases since 20 July 2026 (20). 650 pull requests merged in the last 30 days, but 2,849 issues and 3,338 pull requests are open, 1,396 open issues have no comment, and 309 of the 472 still-open issues from the last two weeks have none (8). `paperclipai` and `@paperclipai/mcp-server` are both at 2026.1005.0 on npm. We did not check the MCP registry (12). CI on master, a lockfile refresh workflow and signed image attestations (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 65,
          "points": 5.69,
          "note": "editorial 73, provenance 56",
          "reason": "MIT (30). The privacy policy of 23 July 2026 separates self-hosted use from the hosted services and names Paperclip Labs, Inc., but keeps data as long as reasonably necessary, lists no subprocessors, and the 90-day telemetry retention appears only in source. The terms grant a broad licence over content sent to the services and allow model training on opt-in detailed telemetry (16). Release notes carry dated Breaking Changes sections and upgrade guides, with no written deprecation policy or notice period (10). The README discloses telemetry, what it excludes and four opt-outs, and the event contract is public in the repository, but it is on by default (17)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. The MCP server lists 44 tools with no toolsets or read-only subset found, offset by compact reads such as `paperclipInboxLite` and the heartbeat context (12). Budgets by company, agent and project with an automatic pause at 100 per cent, though the README says enforcement uses recorded spend and can lag work in flight (16). `onboard --yes`, CLI commands with `--json`, the REST API and routines started by cron, webhook or API (16). Atomic task checkout with a documented 409, `Idempotency-Key` on routine triggers, saved sessions and bounded recovery (17). One command starts a server with embedded PostgreSQL, but it needs Node.js 24.11 and each harness CLI installed and signed in on the host, and we found no client SDK beyond the TypeScript plugin SDK (9).",
          "maintenance": "Version 2026.1005.0, dated 5 October 2026 in its notes and published on GitHub and npm on 6 October (30). Eleven stable releases since 20 July 2026 (20). 650 pull requests merged in the last 30 days, but 2,849 issues and 3,338 pull requests are open, 1,396 open issues have no comment, and 309 of the 472 still-open issues from the last two weeks have none (8). `paperclipai` and `@paperclipai/mcp-server` are both at 2026.1005.0 on npm. We did not check the MCP registry (12). CI on master, a lockfile refresh workflow and signed image attestations (8).",
          "payments": "No payment protocol (0). Read with the self-hosted rule. The software is free under MIT with nothing to buy (20). No card and no Paperclip account (20). One `npx` command installs and starts it with no signup (20). Paperclip Cloud is a waitlist with no published price, so there is no paid option to score.",
          "reliability": "Read as local software. Official npm package `paperclipai` (Node.js 24.11 or newer) and a Docker image on GHCR (20). 2,429 test files and 20 workflows. The Actions page for master on 8 October 2026 showed recent runs passing, with two failed Runner Full-Stack E2E runs (681 and 682) before two that passed (22). 2,849 open issues, 125 labelled bug, 1,599 opened before 8 July, and 78 closed in the last 30 days against 686 opened (6). Calendar versions in semver syntax, with a Breaking Changes section and an upgrade guide in release notes, but breaking changes arrive in ordinary releases and 2026.916.0 carried five (10). No 1.0. The npm `latest` tag is called the stable channel and follows a beta soak of at least three days, while the roadmap says the product is still moving quickly, so half credit (8).",
          "schema": "The running server publishes OpenAPI at `/api/openapi.json` and validates requests with Zod, and the MCP server's tools take Zod schemas. No copy of the spec is published on the docs site, and paperclip.ing/openapi.json describes only the website (22). llms.txt at paperclip.ing, and docs pages answer as Markdown at `.md` (10). An API reference page per resource and task guides, but the MCP tool descriptions are one line each, such as List agents in a company (13). Typed inputs throughout, apart from the `paperclipApiRequest` tool, which takes any path under `/api` and a JSON body (12). cURL, JavaScript and Python examples and a status-code table, with one `{error}` shape and an occasional `details` field (12). A changelog page for every stable release and release notes in the repository, but the API path carries no version (12).",
          "security": "Harness reading of the framework checklist, as used for the other harnesses. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Anonymous usage telemetry is on by default and goes to telemetry.paperclip.ing. The README lists what is excluded and four opt-outs, and Sentry and OpenTelemetry stay off until configured. We found no first-run notice in the CLI source (18). Board approvals for hires and strategy, execution policies and per-action connection permissions, but `claude_local` defaults `dangerouslySkipPermissions` to true, `codex_local` defaults to bypassing approvals and the sandbox, local agents run on the host, sandbox providers are optional plugins and the default `local_trusted` mode has no login (10). A documented `low_trust_review` preset contains agents that read untrusted pull requests or tickets. It is opt-in (10). An activity log of mutating actions, run logs, cost events and audited board API keys (14). SECURITY.md with GitHub private reporting and twelve advisories published, two with CVEs. No security.txt, bug bounty or SOC 2 report found (12).",
          "transparency": "MIT (30). The privacy policy of 23 July 2026 separates self-hosted use from the hosted services and names Paperclip Labs, Inc., but keeps data as long as reasonably necessary, lists no subprocessors, and the 90-day telemetry retention appears only in source. The terms grant a broad licence over content sent to the services and allow model training on opt-in detailed telemetry (16). Release notes carry dated Breaking Changes sections and upgrade guides, with no written deprecation policy or notice period (10). The README discloses telemetry, what it excludes and four opt-outs, and the event contract is public in the repository, but it is on by default (17)."
        },
        "sources": [
          {
            "what": "repository README (product, quickstart, telemetry, roadmap)",
            "url": "https://github.com/paperclipai/paperclip",
            "seen": "2026-10-08"
          },
          {
            "what": "GitHub releases (dates of stable versions)",
            "url": "https://github.com/paperclipai/paperclip/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package and dist-tags",
            "url": "https://registry.npmjs.org/paperclipai/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/paperclipai",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories",
            "url": "https://github.com/paperclipai/paperclip/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "GHSA-x8hx-rhr2-9rf7 (DNS rebinding)",
            "url": "https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7",
            "seen": "2026-10-08"
          },
          {
            "what": "GHSA-gqqj-85qm-8qhf (inherited Gmail connector)",
            "url": "https://github.com/paperclipai/paperclip/security/advisories/GHSA-gqqj-85qm-8qhf",
            "seen": "2026-10-08"
          },
          {
            "what": "hostname guard in current source",
            "url": "https://github.com/paperclipai/paperclip/blob/master/server/src/app.ts",
            "seen": "2026-10-08"
          },
          {
            "what": "claude_local adapter defaults",
            "url": "https://github.com/paperclipai/paperclip/blob/master/docs/adapters/claude-local.md",
            "seen": "2026-10-08"
          },
          {
            "what": "codex_local default constant",
            "url": "https://github.com/paperclipai/paperclip/blob/master/packages/adapters/codex-local/src/index.ts",
            "seen": "2026-10-08"
          },
          {
            "what": "agent permission defaults",
            "url": "https://github.com/paperclipai/paperclip/blob/master/doc/agent-permission-defaults.md",
            "seen": "2026-10-08"
          },
          {
            "what": "low-trust presets",
            "url": "https://github.com/paperclipai/paperclip/blob/master/doc/LOW-TRUST-PRESETS.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release process and version scheme",
            "url": "https://github.com/paperclipai/paperclip/blob/master/doc/RELEASING.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes 2026.916.0 (breaking changes)",
            "url": "https://github.com/paperclipai/paperclip/blob/master/releases/v2026.916.0.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server README and tool definitions",
            "url": "https://github.com/paperclipai/paperclip/tree/master/packages/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "telemetry contract and retention",
            "url": "https://github.com/paperclipai/paperclip/tree/master/packages/shared/src/telemetry",
            "seen": "2026-10-08"
          },
          {
            "what": "SECURITY.md",
            "url": "https://github.com/paperclipai/paperclip/blob/master/SECURITY.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Actions runs on master",
            "url": "https://github.com/paperclipai/paperclip/actions?query=branch%3Amaster",
            "seen": "2026-10-08"
          },
          {
            "what": "issue and pull request counts (search API)",
            "url": "https://api.github.com/search/issues?q=repo:paperclipai/paperclip+is:issue+is:open",
            "seen": "2026-10-08"
          },
          {
            "what": "API overview (auth, errors, OpenAPI)",
            "url": "https://docs.paperclip.ing/reference/api/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "approvals guide",
            "url": "https://docs.paperclip.ing/guides/day-to-day/approvals/",
            "seen": "2026-10-08"
          },
          {
            "what": "custom MCP servers",
            "url": "https://docs.paperclip.ing/connectors/custom-mcp-servers/",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://paperclip.ing/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://paperclip.ing/changelog/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://paperclip.ing/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://paperclip.ing/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud waitlist",
            "url": "https://paperclip.ing/waitlist/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://paperclip.ing/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for paperclip.ing",
            "url": "https://pubapi.registry.google/rdap/domain/paperclip.ing",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the GitHub API rate limit stopped us reading ten of the twelve advisories in full, so their severity and fixed versions come from the advisory list",
          "unchecked: whether Paperclip is in the official MCP registry",
          "unchecked: reply times on issues. The counts come from the GitHub search API",
          "GHSA-x8hx-rhr2-9rf7 and GHSA-gqqj-85qm-8qhf name no patched version. We read the first as fixed from the current source and found no change of default for the second",
          "We found no first-run telemetry notice in the CLI source, and did not install or run the software",
          "No price, date or terms for Paperclip Cloud beyond the waitlist page",
          "The licence file in the repository names Paperclip AI and the terms name Paperclip Labs, Inc.",
          "The scout gave 6 October 2026 for the latest release. The release notes and the site say 5 October, and GitHub and npm published it on 6 October",
          "Judgement call. The listing is in agent harnesses, but Paperclip drives other harnesses and does not run the model loop for most adapters, so `agent.harness` is left out of its capabilities"
        ]
      },
      "negative": -10,
      "negativeNotes": [
        "2026-04-10 to 2026-04-16. Ten advisories published in a week, four of them critical, among them GHSA-68qg-g8mg-6pr7 (CVE-2026-41679, 10.0, unauthenticated remote code execution through an import authorisation bypass) and two cross-tenant agent key flaws rated 9.9. All ten list 2026.416.0 as the fix. Fixed and published, a little under six months old, -5. https://github.com/paperclipai/paperclip/security/advisories",
        "2026-07-22. GHSA-x8hx-rhr2-9rf7 (9.6), drive-by remote code execution against the default `local_trusted` mode through DNS rebinding. The advisory names no patched version. The current source applies the hostname guard to `local_trusted` private deployments, so we read it as fixed without a documented version, -3. https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7",
        "2026-04-16. GHSA-gqqj-85qm-8qhf (8.7), a `codex_local` agent inherited a Gmail connector from the owner's ChatGPT account and sent real email. The advisory names no patched version, and `codex_local` still defaults to bypassing approvals and the sandbox, -2. https://github.com/paperclipai/paperclip/security/advisories/GHSA-gqqj-85qm-8qhf"
      ],
      "verdict": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.",
      "bestFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
      "strengths": [
        "One deployment runs agents on Claude Code, Codex, Cursor, Gemini CLI, OpenCode, Pi, Hermes, Grok Build, Kimi Code and OpenClaw through adapters, under one org chart",
        "Board approvals gate agent hires and the CEO agent's strategy, and connection actions can be set to Allowed, Ask first or Off",
        "Budgets by company, agent and project pause an agent at 100 per cent of recorded spend",
        "The running server publishes its REST surface as OpenAPI at `/api/openapi.json`, and the docs site answers every page as Markdown at `.md`",
        "Eleven stable releases between 20 July and 5 October 2026, each with dated notes and an upgrade guide"
      ],
      "weaknesses": [
        "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host",
        "Twelve published security advisories since April 2026, five critical, including CVE-2026-41679 (unauthenticated remote code execution, fixed in 2026.416.0)",
        "Anonymous usage telemetry is on by default and goes to telemetry.paperclip.ing until an opt-out is set",
        "2,849 open issues on 8 October 2026, 1,396 of them with no comment, and 78 closed in 30 days against 686 opened",
        "Calendar versions with no 1.0, and release 2026.916.0 carried five breaking changes"
      ],
      "agentNotes": [
        "Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default",
        "Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider",
        "Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there",
        "Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin",
        "Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 59
        }
      ],
      "editorialScores": {
        "ergonomics": 70,
        "maintenance": 78,
        "payments": 60,
        "reliability": 66,
        "schema": 81,
        "security": 64,
        "transparency": 73
      },
      "provenanceScore": 56
    },
    "connect": {
      "install": "npx paperclipai@latest onboard --yes   # Node.js 24.11 or newer",
      "http": "curl http://localhost:3100/api/health",
      "headless": {
        "command": "npx paperclipai issue create --title \"$TASK\" --json",
        "env": {
          "PAPERCLIP_API_KEY": "\u003cboard or agent key\u003e",
          "PAPERCLIP_TELEMETRY_DISABLED": "1"
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/agent.multi-agent",
      "tool": "https://letme.dev/paperclip"
    },
    "notable": [
      "`claude_local` defaults `dangerouslySkipPermissions` to true, and `codex_local` defaults to bypassing approvals and the sandbox (https://github.com/paperclipai/paperclip/blob/master/docs/adapters/claude-local.md)",
      "Telemetry is enabled by default, with four documented ways to turn it off (https://github.com/paperclipai/paperclip#telemetry)",
      "Twelve security advisories published, five critical, most fixed in 2026.416.0 (https://github.com/paperclipai/paperclip/security/advisories)",
      "Stable releases promote a beta that has soaked for at least three days, and canaries publish on every push to master (https://github.com/paperclipai/paperclip/blob/master/doc/RELEASING.md)",
      "The running server publishes an OpenAPI document at `/api/openapi.json` (https://docs.paperclip.ing/reference/api/overview)",
      "First public version 0.1.0 is dated 15 January 2026 on the changelog, and the GitHub repository dates from 2 March 2026 (https://paperclip.ing/changelog/v0.1.0/)"
    ],
    "area": "frameworks",
    "details": [
      {
        "label": "Interfaces",
        "value": "Web UI and REST API on `http://localhost:3100`, the `paperclipai` CLI with `--json`, a stdio MCP server (`@paperclipai/mcp-server`, 44 tools) and an experimental OAuth MCP endpoint at `/mcp/paperclip`, off by default"
      },
      {
        "label": "Adapters",
        "value": "Claude Code, Codex, Cursor and Cursor Cloud, Gemini CLI, OpenCode, Pi, Hermes and Hermes Gateway, Grok Build, Kimi Code, OpenClaw gateway, plus custom processes, HTTP endpoints and external adapter packages"
      },
      {
        "label": "Approvals",
        "value": "Board approval for agent hires, CEO strategy and budget overrides. Execution policies with review and approval stages. Connection actions Allowed, Ask first or Off"
      },
      {
        "label": "Sandbox",
        "value": "None by default. Local adapters run the harness on the host, and `claude_local` and `codex_local` skip the harness's own prompts by default. Sandbox provider plugins for E2B, Cloudflare, Daytona, Modal, Novita and Kubernetes"
      },
      {
        "label": "Network",
        "value": "No egress controls found for local runs. Loopback bind by default, with a hostname guard on private deployments"
      },
      {
        "label": "MCP client",
        "value": "Connectors catalogue and custom MCP servers over HTTP with OAuth, a key or no credentials, reached by agents through a tool gateway"
      },
      {
        "label": "Models",
        "value": "Whatever each harness runs. Model keys or subscriptions belong to the owner"
      },
      {
        "label": "Headless",
        "value": "`npx paperclipai@latest onboard --yes`, CLI commands with `--json`, and routines started by cron, webhook or API with `Idempotency-Key`"
      },
      {
        "label": "Telemetry",
        "value": "On by default, anonymous per the README. `PAPERCLIP_TELEMETRY_DISABLED=1`, `DO_NOT_TRACK=1`, `CI=true` or `telemetry.enabled: false`. Sentry and OpenTelemetry are opt-in"
      },
      {
        "label": "Releases in 90 days",
        "value": "11 stable (2026.720.0 to 2026.1005.0), with canary builds on every push to master"
      },
      {
        "label": "Storage",
        "value": "Embedded PostgreSQL and local files by default, or the owner's PostgreSQL and S3-compatible storage"
      },
      {
        "label": "Hosted option",
        "value": "Paperclip Cloud is a waitlist with no published price (https://paperclip.ing/waitlist/)"
      }
    ],
    "provenance": {
      "legalEntity": "Paperclip Labs, Inc.",
      "domain": "paperclip.ing",
      "domainRegistered": "2026-03-02",
      "endpointOnVendorDomain": null,
      "terms": "https://paperclip.ing/terms/",
      "privacy": "https://paperclip.ing/privacy/",
      "statusPage": "",
      "changelog": "https://paperclip.ing/changelog/",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms (effective 1 April 2026, updated 23 July 2026) and the privacy policy (effective 23 July 2026) name Paperclip Labs, Inc. and Delaware law. The licence file in the repository reads Copyright (c) 2025 Paperclip AI.",
        "RDAP at the .ing registry gives a registration date of 2026-03-02 for paperclip.ing, with Cloudflare as registrar. The GitHub repository was created the same day.",
        "paperclip.ing/.well-known/security.txt and docs.paperclip.ing/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md sends reports to GitHub private advisories.",
        "The software is self-hosted, so there is no vendor endpoint or status page to check. status.paperclip.ing did not answer.",
        "The privacy policy says it governs the hosted services, and that a self-hosted deployment processes data on the owner's infrastructure."
      ],
      "score": 56,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Paperclip Labs, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "paperclip.ing, registered 2026-03-02 (under a year)",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://paperclip.ing/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-07-23",
          "words": 1654,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective Date: April 1, 2026 · Last updated: July 23, 2026",
              "says": "Last updated 2026-07-23"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These terms shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-laws principles.",
              "says": "The law of the State of Delaware"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, USE, GOODWILL, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR RELATING TO YOUR USE OF OR INABILITY TO USE THE SERVICES, REGARDLESS OF THE THEORY OF LIABILITY.",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "may suspend or terminate your access to the Services at any time, with or without cause, and with or without notice."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You may not assign these terms without our prior written consent."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "the right to collect, store, process, analyze, and use such data for any purpose related to the operation, improvement, development, and commercialization of the Services and related products, including the training and improvement of machine learning models and algorithms."
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "may suspend or terminate your access to the Services at any time, with or without cause, and with or without notice."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Any dispute arising out of or relating to these terms or the Services shall be resolved through binding arbitration administered in accordance with the rules of the American Arbitration Association, with the arbitration conducted in English."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Submitted Content is licensed to Paperclip Labs on a transferable, sublicensable basis for operating, improving and developing the Services and related products.",
              "quote": "you grant Paperclip Labs, Inc. a worldwide, non-exclusive, royalty-free, transferable, sublicensable license to use, reproduce, modify, distribute, display, and create derivative works from such Content for the purposes of operating, improving, and developing the Services and related products."
            },
            {
              "date": "2026-10-08",
              "text": "The content licence survives termination for Content already processed or incorporated into aggregated or anonymised datasets.",
              "quote": "This license survives termination of your use of the Services for Content already processed or incorporated into aggregated or anonymized datasets."
            },
            {
              "date": "2026-10-08",
              "text": "Disputes go to binding arbitration, and the prevailing party may recover reasonable attorneys' fees and costs.",
              "quote": "The prevailing party shall be entitled to recover reasonable attorneys’ fees and costs."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://paperclip.ing/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-07-23",
          "words": 1684,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective Date: July 23, 2026 · Last updated: July 23, 2026",
              "says": "Last updated 2026-07-23"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Detailed Telemetry (opt-in only): Where you explicitly enable detailed telemetry, we may collect full stack traces, agent run logs, configuration data, operational metadata, and other diagnostic information."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Connected Third-Party Account Data: When you connect a third-party account (see Section 4), we access data from that account strictly as needed to provide the features you have enabled and only within the scopes you authorize."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "not used or transferred for advertising, including personalized, retargeting, or interest-based advertising;"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "The right to access personal data we hold about you;"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions about this Privacy Policy, please contact us:"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Your data may be transferred to and processed in countries other than your country of residence, including the United States.",
              "says": "Data goes to the United States"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Data from connected third-party accounts is not sold, not used for advertising and not used to train generalised AI or machine learning models.",
              "quote": "We do not sell connected-account data, do not use it for advertising, and do not use it to train generalized AI/ML models."
            },
            {
              "date": "2026-10-08",
              "text": "Humans do not read connected-account data except with explicit consent, for security or legal compliance, or once the data is aggregated and anonymised.",
              "quote": "We do not allow humans to read your connected-account data except where you give explicit consent, where it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or where the data has been aggregated and anonymized."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/paperclip.json",
    "live": {
      "slug": "paperclip",
      "versions": [
        {
          "registry": "github",
          "name": "paperclipai/paperclip",
          "version": "v2026.1005.0",
          "released": "2026-10-06",
          "seenAt": "2026-10-08T16:24:44.149648743Z"
        },
        {
          "registry": "npm",
          "name": "@paperclipai/mcp-server",
          "version": "2026.1005.0",
          "seenAt": "2026-10-08T16:24:42.049344463Z"
        },
        {
          "registry": "npm",
          "name": "paperclipai",
          "version": "2026.1005.0",
          "seenAt": "2026-10-08T16:24:41.941235603Z"
        }
      ],
      "githubStars": 98744,
      "npmWeekly": 59684,
      "securityTxt": {
        "url": "https://paperclip.ing/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:39:09.089543926Z"
      },
      "updatedAt": "2026-10-08T16:24:44.149648743Z"
    }
  }
}
