{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "remote",
    "name": "Remote",
    "vendor": "Remote Technology, Inc.",
    "vendorUrl": "https://remote.com",
    "kind": "http-api",
    "category": "hr",
    "summary": "Remote is a global employment platform covering employer of record, payroll, contractors and HR records. Its REST API, hosted MCP server and CLI let an agent read and update employments, time off, timesheets, expenses, onboarding and documents.",
    "url": "https://www.anchorterminal.com/tools/remote",
    "markdownUrl": "https://www.anchorterminal.com/tools/remote.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/remote.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/remote.json",
    "repo": "https://github.com/remoteoss/remote-for-ai",
    "license": "Proprietary service under Remote's terms of use. The remote-for-ai plugin and the Remote CLI repository on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://gateway.remote.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@remoteoss/remote-flows"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve for an existing Remote customer. A company admin or owner generates a Customer API token under Company Settings, Integrations and APIs, choosing read only, full access or custom scopes, after accepting the Remote API Terms of Use. Tokens are prefixed `ra_live_` or `ra_test_`. Partners building for many companies use OAuth 2.0, with credentials and scopes set up by Remote's partnerships team. The MCP server and the CLI sign in through a browser with OAuth 2.0 and PKCE, and MCP clients register dynamically. Scopes follow `resource:read` and `resource:write`.",
    "pricing": "paid",
    "pricingNotes": "No separate API charge was found. Access comes with a Remote account, priced per person a month, from $29 per employee for Payroll or per contractor for Contractor Management to $699 per employee for employer of record. Each plan's button books a demo, and no free production plan was found. A seeded sandbox company and API token are issued after an email verification and last 14 days, with no card (https://remote.com/pricing, https://developer.remote.com/docs/sandbox-quickstart, checked 2026-10-08).",
    "priceSummary": "$29 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 1775,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.remote.com",
    "llmsTxt": "https://developer.remote.com/llms.txt",
    "openapi": "https://gateway.remote.com/v1/docs/openapi.json",
    "capabilities": [
      "hr.employees",
      "hr.time-off",
      "hr.onboarding",
      "hr.org",
      "hr.documents"
    ],
    "tags": [
      "hosted",
      "official",
      "mcp",
      "closed-source",
      "oauth",
      "openapi",
      "llms-txt",
      "webhooks",
      "sandbox",
      "scim",
      "cli",
      "status-page",
      "soc2",
      "sales-led"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 70.7,
      "grade": "BB",
      "agentReady": true,
      "rank": 142,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 57,
        "maintenance": 72,
        "payments": 35,
        "reliability": 96,
        "schema": 78,
        "security": 74,
        "transparency": 68
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 96,
          "points": 19.2,
          "reason": "Graded on the hosted REST API at gateway.remote.com, with the MCP server at mcp.remote.com. status.remote.com on Better Stack has Website, Platform and API components with uptime figures (20). The incident history for August to October 2026 lists one incident, the website down on 19 August, and none on the API or Platform components (30). Limits are published as 300 requests a minute per company for customer tokens and 1,000 a minute per client ID for partners (15). Every response carries `x-ratelimit-count`, `x-ratelimit-remaining` and `x-ratelimit-reset`, and the spec's 429 schema points to `Retry-After`. There is no idempotency key, and retry guidance for writes is in the vendor's CLI skill notes, not the API docs (11). The terms of use warrant 99.5 per cent monthly uptime with a credit at Remote's discretion (10). The API is at /v1 with no beta label, and the MCP docs carry none (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "An OpenAPI 3.0 document answers at gateway.remote.com/v1/docs/openapi.json with 303 operations and 116 webhook events. We found it by trying the path, and no docs page we read links it (25). llms.txt and a Markdown copy of each page (10). Operation descriptions average about 940 characters, list the token types and scopes accepted, and deprecated operations name their replacement. Few say when not to use an endpoint (16). 301 enums and required fields throughout, but country-specific bodies are JSON Schemas fetched at run time, and some filters with fixed values are plain strings (10). 1,450 examples, with 422, 401 and 404 declared on most operations and 429 on 142. Error bodies come in several shapes (12). The path is versioned at /v1 and the spec's version is 0.1.0. The REST changelog the docs point to redirects to a ReadMe dashboard login, so no public changelog was read (5)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 57,
          "points": 9.26,
          "reason": "The MCP tool list needs a signed-in Remote account, so its size wasn't read. The docs say a client sees only the tools its role allows. REST lists take `page_size` up to 100, with no field selection (12). 42 operations take `page` and `page_size`, with filters such as `status`, `email` and `employment_id`, and `sort_by` on eight (16). A missing scope returns 403 naming every scope that would work, and 422 bodies carry field errors, but the body shape differs between endpoints (15). No idempotency key. Employments accept an `external_id` for deduplication, and approve or decline transitions refuse a second call per the vendor's skill notes. MCP annotations weren't read (8). No general server SDK in any language. The Remote Flows SDK is a React package, and the CLI has binaries for two platforms (6)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 74,
          "points": 12.95,
          "reason": "Customer tokens are named, scoped from a catalogue of 78 scopes, revocable and sent only in the `Authorization` header. The MCP server uses OAuth 2.0 with PKCE (S256) and dynamic client registration, with six `mcp:` scopes split into read and write (30). Customer tokens have a read-only preset, MCP write tools are limited to employee self-service and a time-off request still goes to a manager. A partner request that omits `scope` receives `all:write` (16). The remote-for-ai plugin's skills tell agents to treat MCP responses, webhook payloads and free-text fields as untrusted input. The API docs themselves carry no such guidance (10). The token list shows name, status, creator and date, and the MCP page says writes follow the product's audit flows. No log of API calls for the operator was found (5). ISO 27001, SOC 2 Type 2 and CSA STAR Level 1, a penetration test summary on request at trust.remote.com, and a security contact address. No security.txt and no bug bounty found (13)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "No x402, MPP or L402 (0). Per-person monthly prices are public, such as Payroll at $29 per employee and EOR at $699, with no API charge found. We scored it between plan-only and per-unit, as for Deel (15). A seeded sandbox company and token are issued after an email verification, with no card, for 14 days. No free production plan was found on the pricing page (15). A person submits the sandbox form or signs in through a browser. MCP clients can self-register for OAuth, but a person still signs in (5)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 72,
          "points": 6.3,
          "reason": "The newest dated release is Remote Flows SDK v1.60.0 on 8 October 2026. The REST API has no readable public changelog (30). The SDK shipped 12 tagged versions between 7 September and 8 October 2026, and the CLI shipped v0.1.2, v0.1.3 and v0.2.0 between 8 July and 28 September (20). Closed service. The docs give api-support@remote.com, and the changelog link for the REST API redirects to a login (6). The SDK and CLI are current, but there is no server SDK and the MCP server isn't in the official MCP registry (8). The SDK repository has CI, nightly end-to-end tests and Renovate. The CLI's source isn't public (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 68,
          "points": 5.95,
          "note": "editorial 51, provenance 85",
          "reason": "Editorial half only. Closed service under terms of use last updated 3 August 2026, with a section on AI clients and the MCP server. The plugin and CLI repositories are MIT. The Remote Flows SDK repository has no licence file (15). The privacy policy and a Data Processing Addendum with eleven schedules agree on roles, deletion or return at termination and no training of language models on personal data. Retention periods are in a policy available only on request (20). The spec and docs date individual deprecations, such as the time-off balance endpoint (February 2025) and the `company.manage` scope. No policy with notice periods or removal dates was found (8). AWS is named as host. The sub-processor list is for signed-in customers or on request at the Trust Centre, with 14 days to object to changes (8)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP tool list needs a signed-in Remote account, so its size wasn't read. The docs say a client sees only the tools its role allows. REST lists take `page_size` up to 100, with no field selection (12). 42 operations take `page` and `page_size`, with filters such as `status`, `email` and `employment_id`, and `sort_by` on eight (16). A missing scope returns 403 naming every scope that would work, and 422 bodies carry field errors, but the body shape differs between endpoints (15). No idempotency key. Employments accept an `external_id` for deduplication, and approve or decline transitions refuse a second call per the vendor's skill notes. MCP annotations weren't read (8). No general server SDK in any language. The Remote Flows SDK is a React package, and the CLI has binaries for two platforms (6).",
          "maintenance": "The newest dated release is Remote Flows SDK v1.60.0 on 8 October 2026. The REST API has no readable public changelog (30). The SDK shipped 12 tagged versions between 7 September and 8 October 2026, and the CLI shipped v0.1.2, v0.1.3 and v0.2.0 between 8 July and 28 September (20). Closed service. The docs give api-support@remote.com, and the changelog link for the REST API redirects to a login (6). The SDK and CLI are current, but there is no server SDK and the MCP server isn't in the official MCP registry (8). The SDK repository has CI, nightly end-to-end tests and Renovate. The CLI's source isn't public (8).",
          "payments": "No x402, MPP or L402 (0). Per-person monthly prices are public, such as Payroll at $29 per employee and EOR at $699, with no API charge found. We scored it between plan-only and per-unit, as for Deel (15). A seeded sandbox company and token are issued after an email verification, with no card, for 14 days. No free production plan was found on the pricing page (15). A person submits the sandbox form or signs in through a browser. MCP clients can self-register for OAuth, but a person still signs in (5).",
          "reliability": "Graded on the hosted REST API at gateway.remote.com, with the MCP server at mcp.remote.com. status.remote.com on Better Stack has Website, Platform and API components with uptime figures (20). The incident history for August to October 2026 lists one incident, the website down on 19 August, and none on the API or Platform components (30). Limits are published as 300 requests a minute per company for customer tokens and 1,000 a minute per client ID for partners (15). Every response carries `x-ratelimit-count`, `x-ratelimit-remaining` and `x-ratelimit-reset`, and the spec's 429 schema points to `Retry-After`. There is no idempotency key, and retry guidance for writes is in the vendor's CLI skill notes, not the API docs (11). The terms of use warrant 99.5 per cent monthly uptime with a credit at Remote's discretion (10). The API is at /v1 with no beta label, and the MCP docs carry none (10).",
          "schema": "An OpenAPI 3.0 document answers at gateway.remote.com/v1/docs/openapi.json with 303 operations and 116 webhook events. We found it by trying the path, and no docs page we read links it (25). llms.txt and a Markdown copy of each page (10). Operation descriptions average about 940 characters, list the token types and scopes accepted, and deprecated operations name their replacement. Few say when not to use an endpoint (16). 301 enums and required fields throughout, but country-specific bodies are JSON Schemas fetched at run time, and some filters with fixed values are plain strings (10). 1,450 examples, with 422, 401 and 404 declared on most operations and 429 on 142. Error bodies come in several shapes (12). The path is versioned at /v1 and the spec's version is 0.1.0. The REST changelog the docs point to redirects to a ReadMe dashboard login, so no public changelog was read (5).",
          "security": "Customer tokens are named, scoped from a catalogue of 78 scopes, revocable and sent only in the `Authorization` header. The MCP server uses OAuth 2.0 with PKCE (S256) and dynamic client registration, with six `mcp:` scopes split into read and write (30). Customer tokens have a read-only preset, MCP write tools are limited to employee self-service and a time-off request still goes to a manager. A partner request that omits `scope` receives `all:write` (16). The remote-for-ai plugin's skills tell agents to treat MCP responses, webhook payloads and free-text fields as untrusted input. The API docs themselves carry no such guidance (10). The token list shows name, status, creator and date, and the MCP page says writes follow the product's audit flows. No log of API calls for the operator was found (5). ISO 27001, SOC 2 Type 2 and CSA STAR Level 1, a penetration test summary on request at trust.remote.com, and a security contact address. No security.txt and no bug bounty found (13).",
          "transparency": "Editorial half only. Closed service under terms of use last updated 3 August 2026, with a section on AI clients and the MCP server. The plugin and CLI repositories are MIT. The Remote Flows SDK repository has no licence file (15). The privacy policy and a Data Processing Addendum with eleven schedules agree on roles, deletion or return at termination and no training of language models on personal data. Retention periods are in a policy available only on request (20). The spec and docs date individual deprecations, such as the time-off balance endpoint (February 2025) and the `company.manage` scope. No policy with notice periods or removal dates was found (8). AWS is named as host. The sub-processor list is for signed-in customers or on request at the Trust Centre, with 14 days to object to changes (8)."
        },
        "sources": [
          {
            "what": "docs index (llms.txt)",
            "url": "https://developer.remote.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "getting started",
            "url": "https://developer.remote.com/docs/getting-started-with-remote.md",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://developer.remote.com/docs/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "obtaining and revoking a customer token",
            "url": "https://developer.remote.com/docs/authorization-for-customers.md",
            "seen": "2026-10-08"
          },
          {
            "what": "scopes",
            "url": "https://developer.remote.com/docs/scopes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limit policy for customers",
            "url": "https://developer.remote.com/docs/rate-limit.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limit policy for partners",
            "url": "https://developer.remote.com/docs/rate-limit-for-partner.md",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox quickstart",
            "url": "https://developer.remote.com/docs/sandbox-quickstart.md",
            "seen": "2026-10-08"
          },
          {
            "what": "first API call and pagination",
            "url": "https://developer.remote.com/docs/your-first-api-call.md",
            "seen": "2026-10-08"
          },
          {
            "what": "environments",
            "url": "https://developer.remote.com/docs/environment-setup.md",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog locations",
            "url": "https://developer.remote.com/docs/changelogs.md",
            "seen": "2026-10-08"
          },
          {
            "what": "REST changelog link, redirects to a ReadMe login",
            "url": "https://developer.remote.com/update/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI 3.0 document",
            "url": "https://gateway.remote.com/v1/docs/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP introduction",
            "url": "https://developer.remote.com/docs/introduction-to-remote-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP quick start",
            "url": "https://developer.remote.com/docs/quick-start-guide-2.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server, unauthenticated initialize (401)",
            "url": "https://mcp.remote.com/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected resource metadata and scopes",
            "url": "https://mcp.remote.com/.well-known/oauth-protected-resource/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth authorisation server metadata",
            "url": "https://mcp.remote.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "Remote CLI introduction",
            "url": "https://developer.remote.com/docs/introduction-to-the-remote-cli.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Remote CLI repository, releases and skill notes",
            "url": "https://github.com/remoteoss/remote-cli",
            "seen": "2026-10-08"
          },
          {
            "what": "remote-for-ai plugin and skills",
            "url": "https://github.com/remoteoss/remote-for-ai",
            "seen": "2026-10-08"
          },
          {
            "what": "Remote Flows SDK repository and tags",
            "url": "https://github.com/remoteoss/remote-flows",
            "seen": "2026-10-08"
          },
          {
            "what": "Remote Flows SDK on npm",
            "url": "https://registry.npmjs.org/@remoteoss/remote-flows/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "webhook verification",
            "url": "https://developer.remote.com/docs/verifying-webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.remote.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status incident history",
            "url": "https://status.remote.com/incidents",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://remote.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of use, with API, AI and availability sections",
            "url": "https://remote.com/policy/terms-of-use",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://remote.com/policy/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Addendum",
            "url": "https://remote.com/policy/data-protection",
            "seen": "2026-10-08"
          },
          {
            "what": "security and compliance page",
            "url": "https://remote.com/why-remote/security-compliance",
            "seen": "2026-10-08"
          },
          {
            "what": "Trust Centre",
            "url": "https://trust.remote.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "API, CLI, MCP and sandbox page",
            "url": "https://remote.com/remote-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://remote.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=remote.com",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for remote.com",
            "url": "https://rdap.org/domain/remote.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the REST API changelog. https://developer.remote.com/update/changelog redirects to a ReadMe dashboard login, and /changelog returns 404",
          "unchecked: the MCP tool list, its size and its annotations. The server returns 401 without a signed-in Remote account",
          "unchecked: the Remote API Terms of Use at remote.com/api-terms-of-use. The page draws a PDF by script, and the file it loads is named as terms of service updated May 2024",
          "unchecked: the Customer Terms of Service, Local Terms and Order Form Terms tabs were not read in full",
          "unchecked: the sub-processor list, which is at employ.remote.com/dashboard/processors for signed-in customers",
          "unchecked: GitHub stars and open issues. The GitHub API refused us for its rate limit",
          "unchecked: whether 429 responses carry `Retry-After`. The spec's schema says so and the rate limit page lists only the three `x-ratelimit` headers",
          "unchecked: whether the sandbox request form asks for anything beyond an email address. We did not submit it",
          "The OpenAPI document was found by trying gateway.remote.com/v1/docs/openapi.json. No docs page we read links it",
          "The lead names Remote Technology, Inc. The terms of use are an agreement with Remote Europe Holding B.V., and the privacy policy calls Remote Technology, Inc. the group's holding company",
          "The terms of use list 'automate' among things a user will not do to the Platform, in the same document that sets rules for AI clients and the MCP server. Recorded as a fact",
          "The security page states 99.999 per cent uptime, the terms warrant 99.5 per cent, and the status page shows 99.993 per cent for the API component"
        ]
      },
      "negative": 0,
      "verdict": "The REST API has 303 operations in a public OpenAPI document, 78 OAuth scopes split into read and write, a sandbox issued by email with no card, and a hosted MCP server using OAuth with PKCE. The REST changelog link redirects to a login page, and writes have no idempotency key.",
      "bestFor": "A company that employs people through Remote (EOR, payroll, contractors or its HRIS) and wants an agent to read employments, file and review time off, track onboarding, and read payslips and documents.",
      "strengths": [
        "OpenAPI 3.0 document with 303 operations and 116 webhook events, plus llms.txt and a Markdown copy of every docs page",
        "78 scopes in `resource:action` form, with a read-only preset for customer tokens and a 403 body that names the scopes that would have worked",
        "Seeded sandbox company and `ra_test_` token issued after an email verification, available for 14 days, with no card",
        "Hosted MCP server with OAuth 2.0, PKCE and dynamic client registration. Its writes are employee self-service and follow the product's approval flow",
        "Terms warrant 99.5 per cent monthly uptime, and status.remote.com lists no API or platform incident from August to October 2026"
      ],
      "weaknesses": [
        "The REST API changelog link in the docs redirects to a ReadMe dashboard login, so no public dated record of API changes was read",
        "No idempotency key on writes. The vendor's own skill notes list creates for employments, time off, expenses and webhooks as unsafe to retry",
        "A partner authorisation request that omits `scope` is issued `all:write`, per the scopes page",
        "No general server SDK. The Remote Flows SDK is React, and the CLI ships as binaries for macOS on Apple Silicon and Linux x86_64 only",
        "The sub-processor list sits behind a customer login, and remote.com has no security.txt"
      ],
      "agentNotes": [
        "Match the token prefix to the host. `ra_test_` works only on https://gateway.remote-sandbox.com and `ra_live_` only on https://gateway.remote.com",
        "Stay under 300 requests a minute per company for customer tokens, shared by every token, and read `x-ratelimit-remaining` and `x-ratelimit-reset` (milliseconds)",
        "Check for an existing record before retrying a create, or set `external_id` on employments and treat a 422 for a duplicate as success",
        "Fetch the country form schema (`GET /v1/countries/{country_code}/{form}`) before writing employment data. Country codes are three-letter ISO",
        "Use the REST API for unattended work. The MCP server needs a browser sign-in and its write tools cover employee self-service only"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 70.7
        }
      ],
      "editorialScores": {
        "ergonomics": 57,
        "maintenance": 72,
        "payments": 35,
        "reliability": 96,
        "schema": 78,
        "security": 74,
        "transparency": 51
      },
      "provenanceScore": 85
    },
    "connect": {
      "install": "curl -fsSL https://raw.githubusercontent.com/remoteoss/remote-cli/main/install.sh | sh",
      "http": "curl https://gateway.remote-sandbox.com/v1/employments \\\n  -H \"Authorization: Bearer $REMOTE_API_TOKEN\"",
      "claudeCode": "claude mcp add --scope user --transport http remote-com-mcp https://mcp.remote.com/mcp",
      "config": {
        "mcpServers": {
          "remote-com-mcp": {
            "type": "http",
            "url": "https://mcp.remote.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/hr.employees",
      "tool": "https://letme.dev/remote"
    },
    "notable": [
      "The MCP server at https://mcp.remote.com/mcp returns 401 to an unauthenticated `initialize` and points to OAuth metadata listing six scopes, `mcp:employer:read`, `mcp:employer:write`, `mcp:employee:read`, `mcp:employee:write` and two for Remote admins (https://mcp.remote.com/.well-known/oauth-protected-resource/mcp)",
      "MCP write tools are employee self-service today (time off requests, personal details, career goals and notes), and a time off request made through MCP still goes to a manager for approval (https://developer.remote.com/docs/introduction-to-remote-mcp)",
      "Customer tokens are limited to 300 requests a minute per company across all tokens, and partner clients to 1,000 a minute per client ID (https://developer.remote.com/docs/rate-limit, https://developer.remote.com/docs/rate-limit-for-partner)",
      "A partner authorisation request that leaves out `scope` is issued `all:write`, and the older `company.manage` scope is deprecated (https://developer.remote.com/docs/scopes)",
      "The docs send readers to https://developer.remote.com/update/changelog for the REST API changelog, and on 8 October 2026 that address redirected to a ReadMe dashboard login (https://developer.remote.com/docs/changelogs)",
      "The terms of use, updated 3 August 2026, define AI clients and AI integration endpoints, name the Remote MCP server, and bar using them to gather data for model training or to exceed published rate limits (https://remote.com/policy/terms-of-use)",
      "The terms warrant 99.5 per cent monthly uptime for the platform, with a credit at Remote's discretion (https://remote.com/policy/terms-of-use)",
      "The remote-for-ai plugin sets up the MCP server and ships eight skills for Claude Code, Cursor, Codex and Gemini CLI (https://github.com/remoteoss/remote-for-ai)"
    ],
    "area": "business",
    "details": [
      {
        "label": "API",
        "value": "REST at https://gateway.remote.com/v1, JSON only. 303 operations (156 GET, 85 POST, 38 PUT, 16 PATCH, 8 DELETE) and 116 webhook events in the OpenAPI 3.0 document, with SCIM 2.0 users and groups at /v1/scim/v2"
      },
      {
        "label": "HR coverage",
        "value": "Employments (list, create, update, invite), personal details, departments, managers and company structure, custom fields, time off (types, leave policies, balances, create, approve, decline, cancel), timesheets, expenses, onboarding and pre-onboarding documents, offboarding and resignations, contract amendments, payslips and documents"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://mcp.remote.com/mcp over streamable HTTP, sandbox at https://mcp.remote-sandbox.com/mcp. OAuth 2.0 with PKCE and dynamic client registration. Read tools across employments, contracts, payroll, time off, organisation structure, timesheets and invoices. Write tools for employee self-service. Tested with Claude Desktop, claude.ai, Claude Code and Cursor"
      },
      {
        "label": "Credentials",
        "value": "Customer API token (`ra_live_` or `ra_test_`), partner OAuth 2.0 (authorisation code, client credentials, refresh token), or browser sign-in for MCP and the CLI. All Bearer, in the `Authorization` header"
      },
      {
        "label": "Scopes",
        "value": "78 in the spec, such as employment:read, timeoff:write and expense:write. Write implies read. Seven category scopes, plus all:read and all:write. Existing tokens can't be widened"
      },
      {
        "label": "Rate limits",
        "value": "300 requests a minute per company for customer tokens, 1,000 a minute per client ID for partners. `x-ratelimit-count`, `x-ratelimit-remaining` and `x-ratelimit-reset` (milliseconds) on every authenticated response, 429 on excess"
      },
      {
        "label": "Retries",
        "value": "No idempotency key. `external_id` on employments for deduplication. The vendor's CLI skill notes mark approve, decline, cancel, PATCH and PUT as safe to retry and creates as unsafe"
      },
      {
        "label": "Errors",
        "value": "403 for a missing scope names every scope that would satisfy the endpoint. 422 carries field errors. Body shapes differ between endpoints (`message`, `errors` as a list or keyed by field, or `code` with `message`)"
      },
      {
        "label": "Pagination",
        "value": "`page` and `page_size` (default 20, maximum 100) with `current_page`, `total_count` and `total_pages` in the response. Filters such as `status`, `email` and `employment_id`, and `sort_by` with `order` on some lists"
      },
      {
        "label": "Sandbox",
        "value": "https://gateway.remote-sandbox.com, isolated from production. A seeded demo company and `ra_test_` token arrive after an email verification and last 14 days. 21 sandbox-only operations approve or bypass steps a Remote admin would handle"
      },
      {
        "label": "Webhooks",
        "value": "116 events in the spec. Each callback gets a `signing_key`, and deliveries are signed in `X-Remote-Signature`. The CLI lists delivery history and replays events"
      },
      {
        "label": "Clients",
        "value": "Remote CLI `remotecli` v0.2.0 (28 September 2026), binaries for macOS on Apple Silicon and Linux x86_64, source not public. Remote Flows SDK @remoteoss/remote-flows 1.60.0 (8 October 2026), a React package for embedded flows. remote-for-ai plugin with eight skills"
      },
      {
        "label": "Certifications",
        "value": "ISO 27001, SOC 2 Type 2 and CSA STAR Level 1 per remote.com and trust.remote.com. Hosted on AWS"
      },
      {
        "label": "Status",
        "value": "status.remote.com on Better Stack, with Website, Platform and API components and uptime figures"
      }
    ],
    "unitPrices": [
      {
        "item": "Payroll",
        "unit": "seat-month",
        "usd": 29,
        "note": "per employee"
      },
      {
        "item": "Contractor Management",
        "unit": "seat-month",
        "usd": 29,
        "note": "per contractor"
      },
      {
        "item": "Contractor Management Plus",
        "unit": "seat-month",
        "usd": 99,
        "note": "per contractor"
      },
      {
        "item": "PEO",
        "unit": "seat-month",
        "usd": 99,
        "note": "from, per employee, United States"
      },
      {
        "item": "Contractor of Record",
        "unit": "seat-month",
        "usd": 325,
        "note": "from, per contractor"
      },
      {
        "item": "Employer of Record",
        "unit": "seat-month",
        "usd": 699,
        "note": "per employee"
      }
    ],
    "provenance": {
      "legalEntity": "Remote Europe Holding B.V.",
      "domain": "remote.com",
      "domainRegistered": "1992-06-24",
      "endpointOnVendorDomain": true,
      "terms": "https://remote.com/policy/terms-of-use",
      "privacy": "https://remote.com/policy/privacy-policy",
      "statusPage": "https://status.remote.com",
      "changelog": "https://developer.remote.com/docs/changelogs",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms of use (last updated 3 August 2026) are an agreement with Remote Europe Holding B.V., Kraijenhoffstraat 137A, 1018 RG Amsterdam. The privacy policy names Remote Technology, Inc. as the group's holding company, and the site's copyright line and the MIT licences on GitHub carry that name.",
        "The terms of use cover the platform and products, with sections on use through the API and on AI clients and the MCP server. The docs also name a Remote API Terms of Use at remote.com/api-terms-of-use, which draws a PDF by script and was not read.",
        "The privacy policy (last updated 3 August 2026) covers remote.com, employ.remote.com, the mobile app and the services where Remote is the controller. Customer data processed on a client's behalf falls under the Data Processing Addendum at remote.com/policy/data-protection.",
        "The API answers on gateway.remote.com and the MCP server on mcp.remote.com. The sandbox uses a second domain, remote-sandbox.com. OAuth for MCP is issued by api.employ.remote.com.",
        "https://remote.com/.well-known/security.txt returns 404. The security page gives a contact email address.",
        "The changelog link is the docs page that lists where each component's changelog lives. The REST API changelog it names redirected to a ReadMe dashboard login on 8 October 2026.",
        "RDAP for remote.com gives a registration date of 1992-06-24."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Remote Europe Holding B.V.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "remote.com, registered 1992-06-24 (34 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "gateway.remote.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.remote.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://remote.com/policy/terms-of-use",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-03",
          "words": 11857,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated August 3, 2026",
              "says": "Last updated 2026-08-03"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The formation, interpretation, and performance of these Terms and any disputes arising out of it shall be governed by the laws of England and Wales.",
              "says": "The law of England and Wales"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "To the extent permitted by law, Our aggregate liability for Your use of the Platform is limited to the Service Fees actually paid by You to Us for the Service being used, for the one month period prior to the first event or occurrence giving rise to such liability.",
              "says": "Capped at the fees paid in the 1 month before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Because We value great relationships and transparency, the provision of Our Product is subject to a compliance check (KYC), following which We may suspend or cancel Your account, should We deem the check not satisfactory."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "In connection with Your use of the Platform, Product and any Remote content, You will not, and will not permit any third party to:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "We warrant that the Platform shall have an uptime of not less than 99.5% per month (resulting in a downtime of not more than 0.5% per month) (Service Availability).",
              "says": "Names 99.5% availability"
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Use any AI Client or AI Integration Endpoint (including the Remote MCP server) to extract, scrape, or replicate data from the Platform for the purpose of training any artificial intelligence model or building a competing product or service;",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Access or use the Platform to build, develop or assist in creating a competing product or service.",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "The exclusive jurisdiction and venue for actions related to the subject matter hereof shall be subject to arbitration or mediation in England and Wales, and You shall submit to the arbitration rules of such jurisdiction."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Total liability is limited to the service fees paid for the service in the one month before the first event giving rise to the claim.",
              "quote": "To the extent permitted by law, Our aggregate liability for Your use of the Platform is limited to the Service Fees actually paid by You to Us for the Service being used, for the one month period prior to the first event or occurrence giving rise to such liability."
            },
            {
              "date": "2026-10-08",
              "text": "Outputs and actions of AI agents on the account, including an AI client connected through the Remote MCP server or another AI integration endpoint, are treated as the customer's own actions.",
              "quote": "all Outputs generated and actions executed by AI Agents in connection with Your account are deemed to be actions taken by You and on Your behalf, regardless of whether the AI Agent is provided by Remote, by a Third Party Provider, or by an AI Client connected through an AI Integration Endpoint;"
            },
            {
              "date": "2026-10-08",
              "text": "The 99.5 per cent monthly uptime commitment does not apply to the AI integration endpoints, which are available on a reasonable-endeavours basis.",
              "quote": "The Service Availability commitment set out in the Terms of Use does not apply to the AI Integration Endpoints."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://remote.com/policy/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-03",
          "words": 10043,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: August 3, 2026",
              "says": "Last updated 2026-08-03"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We are committed to safeguarding personal data and apply appropriate technical and organisational measures to protect the personal data that we collect and process."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Application logs are shipped off site and kept for at least 30 days.",
              "says": "Names a period of 30 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Sharing data with third-party AI Service providers to power our AI features"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Opt-out to the sale of personal information (DO NOT SELL MY PERSONAL INFORMATION)",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to opt out of marketing communications we send you at any time."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "This Policy and all other data protection compliance requirements are overseen by Remote's Group Data Protection Officer (\"DPO\").",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In addition, under certain conditions, You may be able to initiate binding arbitration for complaints regarding Data Privacy Framework compliance.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Remote logs the inputs, outputs and requests made to its AI functions.",
              "quote": "When you use our AI features, we log inputs, outputs and requests made to the AI Services."
            },
            {
              "date": "2026-10-08",
              "text": "Remote states that it does not use personal data to train large language models and contractually requires its suppliers not to train their AI models on it.",
              "quote": "We do not use Personal Data to train large language models, and we contractually require our suppliers not to use Personal Data to train their AI models."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/remote.json",
    "live": {
      "slug": "remote",
      "probe": {
        "target": "https://gateway.remote.com",
        "method": "get",
        "lastAt": "2026-10-09T09:27:02.601987051Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 67,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 64,
        "p95ms24h": 86,
        "samples24h": 20,
        "samples30d": 20,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 20,
            "ok": 20
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.remote.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:58:28.834580334Z"
      },
      "updatedAt": "2026-10-09T09:27:02.601987051Z"
    }
  }
}
