{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "rootly-mcp",
    "name": "Rootly MCP Server",
    "vendor": "Rootly Inc.",
    "vendorUrl": "https://rootly.com",
    "kind": "mcp",
    "category": "observability",
    "summary": "Rootly's MCP server for its incident management and on-call platform. Agents list, search and update incidents, alerts, schedules and escalation policies through a hosted endpoint at mcp.rootly.com with OAuth or an API key, or run the Apache-2.0 package themselves.",
    "url": "https://www.anchorterminal.com/tools/rootly-mcp",
    "markdownUrl": "https://www.anchorterminal.com/tools/rootly-mcp.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/rootly-mcp.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/rootly-mcp.json",
    "repo": "https://github.com/rootlyhq/rootly-mcp-server",
    "license": "Apache-2.0 for the server. The hosted service runs under Rootly's Terms of Use",
    "transports": [
      "streamable-http",
      "sse",
      "stdio"
    ],
    "remoteUrl": "https://mcp.rootly.com/mcp",
    "packages": [
      {
        "registry": "pypi",
        "name": "rootly-mcp-server"
      }
    ],
    "auth": "mixed",
    "authNotes": "The hosted server takes an OAuth 2 login or a Rootly API key as a bearer token. OAuth clients can register themselves (RFC 7591), public clients must use PKCE with S256, access tokens last one hour and refresh tokens rotate. The MCP resource metadata advertises a single `all` scope. API keys are created by a person under Organisation Settings and are global with a chosen role, team-wide or personal. A local server reads `ROOTLY_API_TOKEN`.",
    "pricing": "paid",
    "pricingNotes": "No separate charge for MCP. It is included in the Essentials plan at $20 per product per user a month, where incident response and on-call are separate products, and in Enterprise, which is by quote. No free tier. Self-serve sign-up starts a trial of about two weeks, and whether it needs a card wasn't established (https://rootly.com/pricing, checked 2026-10-09).",
    "priceSummary": "$20 / seat-mo",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the repository, the MCP docs or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 218,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.rootly.com/integrations/mcp-server",
    "mcpTools": {
      "url": "https://mcp.rootly.com/mcp",
      "checkedAt": "2026-10-09T21:40:55.523633877Z",
      "status": "auth",
      "note": "asks for credentials before listing its tools",
      "changedAt": "2026-10-09T21:40:55.523633877Z"
    },
    "llmsTxt": "https://rootly.com/llms.txt",
    "openapi": "https://rootly.com/swagger/v1/swagger.json",
    "registryName": "com.rootly/mcp-server",
    "capabilities": [
      "observability.incidents",
      "work.oncall"
    ],
    "tags": [
      "official",
      "hosted",
      "open-source",
      "mcp",
      "oauth",
      "api-key",
      "incidents",
      "on-call",
      "python",
      "code-mode",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-10-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 59.7,
      "grade": "C",
      "agentReady": false,
      "rank": 541,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 77,
        "maintenance": 81,
        "payments": 20,
        "reliability": 48,
        "schema": 78,
        "security": 65,
        "transparency": 80
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 48,
          "points": 9.6,
          "reason": "Scored as a hosted MCP server, the path the docs recommend. status.rootly.com is linked from the site and llms.txt, but it answered our reader with a bot check, so its components (15) and incident history (5) were unread. The REST API behind the tools allows 3,000 read calls and 3,000 write calls a minute per API key, and 50 alert creations a minute. No separate limit for mcp.rootly.com was found (12). A 429 returns a JSON error with `X-RateLimit-Limit`, `X-RateLimit-Remaining`, `X-RateLimit-Used` and `X-RateLimit-Reset` headers. No `Retry-After`, backoff guidance or idempotency keys were found (8). The pricing table lists \"99.99 % Reliability\" for on-call, and no SLA document was found (0). The hosted `/mcp` and `/sse` endpoints carry no beta label. The README calls Code Mode experimental while the docs recommend it (8)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Read from the source at v2.3.21. Curated tools declare typed pydantic inputs and the rest are generated from Rootly's OpenAPI 3.0.1 description, 565 operations in the bundled copy, which the API docs also link for download (25). rootly.com/llms.txt and Markdown twins of the docs pages (10). Curated tools such as `list_incidents` say when to use them and when to prefer `search_incidents`. Generated tools carry the API's short summaries, for example \"List alerts\" (11). Sort orders use enums and generated tools keep the API's `include` enums, but severity, status and ID lists are free strings, with IDs passed comma-separated (9). The README and docs give worked calls for five tools and a troubleshooting section. The error types the server returns aren't documented (8). Semantic versioning with a dated Keep a Changelog file. The docs page still names two tools in camelCase and links the old Rootly-AI-Labs repository (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "The default endpoint lists about 218 tools per the README, which the checklist scores at 5. A slim profile (77 names in the source, about 70 per the README), a Code Mode endpoint with five meta-tools and an exact allowlist for servers the owner runs add back 10 (15). List tools page with bounded sizes, strip alert and incident lists to summary fields and clamp out-of-range counts, reporting each change under `argument_adjustments` (18). Tool errors return `error_type` and a message, with hints for plan-gated 404s, the pagination cap and replaced alert routing tools (16). Every tool sets `readOnlyHint`, `destructiveHint` and `openWorldHint` since 2.3.19, and writes set `idempotentHint`. `create_incident` has no idempotency key (15). Curated tools have no required parameters beyond record references and accept common aliases such as `limit`. Rootly lists REST SDKs for Go, Python and other languages (13)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 65,
          "points": 11.38,
          "reason": "OAuth 2 with dynamic client registration, PKCE with S256, one-hour access tokens, rotating refresh tokens, a revocation endpoint and `:read` and `:write` scopes per resource. The MCP server's resource metadata advertises a single `all` scope since 2.3.13, so MCP logins aren't narrowed by scope. API keys are global with a chosen role, team or personal, sent in the `Authorization` header (26). Delete operations are off by default and API key, user, role and webhook endpoints are excluded. Write tools are on by default for hosted connections, the documented read-only switch applies to servers the owner runs, and no confirmation step was found (11). Incident text, alert payloads and meeting transcripts are untrusted content, and no injection guidance was found (3). `list_audits` reads Rootly's audit log, which the pricing page lists under Enterprise (9). security.txt valid to 1 September 2027, a disclosure policy with safe harbour and response times, no paid bounty, SOC 2 Type II stated with the report on request, and dependency advisories recorded in the changelog (16)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402, MPP or L402 (0). Plan prices are public. Essentials is $20 per product per user a month, with MCP and API access included, and Enterprise is by quote. No per-call price (10). No free tier. Self-serve sign-up starts a trial of about two weeks per the pricing page. The sign-up page answered with a bot check, so whether a card is needed wasn't established, and the line takes half marks (10). A person signs up in a browser and either logs in through OAuth or creates an API key (0). The package is free to run but needs a Rootly account, so the self-hosted rule doesn't apply."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 81,
          "points": 7.09,
          "reason": "v2.3.21 was tagged on 5 October 2026, four days before this check (30). Six dated releases between 23 July and 5 October 2026 (20). The commit log shows pull requests merged through 6 October and a fix credited to an outside contributor. We couldn't read the issue tracker, because api.github.com didn't answer (12). The official MCP registry lists `com.rootly/mcp-server` under Rootly's own domain namespace, but the entry is 2.2.4 from 18 February 2026 and names only the SSE endpoint (10). CI runs lint, two type checkers and tests on Python 3.12 and 3.13, with a lockfile check, Dependabot and a dependency review workflow (9)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "note": "editorial 65, provenance 95",
          "reason": "The server is Apache-2.0 and the hosted service runs under Rootly's Terms of Use of July 2026 (27). A privacy policy of October 2026, a subprocessor list and AI data pages are public, and retention is stated only in general terms. The README says hosted telemetry records tool arguments, responses, timing and errors through AgentCat with redaction hooks. AgentCat isn't on the subprocessor list and the MCP docs page doesn't mention telemetry (15). No deprecation policy was found. camelCase tool names stay callable as hidden aliases with no removal date, and the terms say notice of changes isn't always practical (8). The subprocessor list names about 30 processors with purpose, data and location, nearly all in the United States (15)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The default endpoint lists about 218 tools per the README, which the checklist scores at 5. A slim profile (77 names in the source, about 70 per the README), a Code Mode endpoint with five meta-tools and an exact allowlist for servers the owner runs add back 10 (15). List tools page with bounded sizes, strip alert and incident lists to summary fields and clamp out-of-range counts, reporting each change under `argument_adjustments` (18). Tool errors return `error_type` and a message, with hints for plan-gated 404s, the pagination cap and replaced alert routing tools (16). Every tool sets `readOnlyHint`, `destructiveHint` and `openWorldHint` since 2.3.19, and writes set `idempotentHint`. `create_incident` has no idempotency key (15). Curated tools have no required parameters beyond record references and accept common aliases such as `limit`. Rootly lists REST SDKs for Go, Python and other languages (13).",
          "maintenance": "v2.3.21 was tagged on 5 October 2026, four days before this check (30). Six dated releases between 23 July and 5 October 2026 (20). The commit log shows pull requests merged through 6 October and a fix credited to an outside contributor. We couldn't read the issue tracker, because api.github.com didn't answer (12). The official MCP registry lists `com.rootly/mcp-server` under Rootly's own domain namespace, but the entry is 2.2.4 from 18 February 2026 and names only the SSE endpoint (10). CI runs lint, two type checkers and tests on Python 3.12 and 3.13, with a lockfile check, Dependabot and a dependency review workflow (9).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public. Essentials is $20 per product per user a month, with MCP and API access included, and Enterprise is by quote. No per-call price (10). No free tier. Self-serve sign-up starts a trial of about two weeks per the pricing page. The sign-up page answered with a bot check, so whether a card is needed wasn't established, and the line takes half marks (10). A person signs up in a browser and either logs in through OAuth or creates an API key (0). The package is free to run but needs a Rootly account, so the self-hosted rule doesn't apply.",
          "reliability": "Scored as a hosted MCP server, the path the docs recommend. status.rootly.com is linked from the site and llms.txt, but it answered our reader with a bot check, so its components (15) and incident history (5) were unread. The REST API behind the tools allows 3,000 read calls and 3,000 write calls a minute per API key, and 50 alert creations a minute. No separate limit for mcp.rootly.com was found (12). A 429 returns a JSON error with `X-RateLimit-Limit`, `X-RateLimit-Remaining`, `X-RateLimit-Used` and `X-RateLimit-Reset` headers. No `Retry-After`, backoff guidance or idempotency keys were found (8). The pricing table lists \"99.99 % Reliability\" for on-call, and no SLA document was found (0). The hosted `/mcp` and `/sse` endpoints carry no beta label. The README calls Code Mode experimental while the docs recommend it (8).",
          "schema": "Read from the source at v2.3.21. Curated tools declare typed pydantic inputs and the rest are generated from Rootly's OpenAPI 3.0.1 description, 565 operations in the bundled copy, which the API docs also link for download (25). rootly.com/llms.txt and Markdown twins of the docs pages (10). Curated tools such as `list_incidents` say when to use them and when to prefer `search_incidents`. Generated tools carry the API's short summaries, for example \"List alerts\" (11). Sort orders use enums and generated tools keep the API's `include` enums, but severity, status and ID lists are free strings, with IDs passed comma-separated (9). The README and docs give worked calls for five tools and a troubleshooting section. The error types the server returns aren't documented (8). Semantic versioning with a dated Keep a Changelog file. The docs page still names two tools in camelCase and links the old Rootly-AI-Labs repository (15).",
          "security": "OAuth 2 with dynamic client registration, PKCE with S256, one-hour access tokens, rotating refresh tokens, a revocation endpoint and `:read` and `:write` scopes per resource. The MCP server's resource metadata advertises a single `all` scope since 2.3.13, so MCP logins aren't narrowed by scope. API keys are global with a chosen role, team or personal, sent in the `Authorization` header (26). Delete operations are off by default and API key, user, role and webhook endpoints are excluded. Write tools are on by default for hosted connections, the documented read-only switch applies to servers the owner runs, and no confirmation step was found (11). Incident text, alert payloads and meeting transcripts are untrusted content, and no injection guidance was found (3). `list_audits` reads Rootly's audit log, which the pricing page lists under Enterprise (9). security.txt valid to 1 September 2027, a disclosure policy with safe harbour and response times, no paid bounty, SOC 2 Type II stated with the report on request, and dependency advisories recorded in the changelog (16).",
          "transparency": "The server is Apache-2.0 and the hosted service runs under Rootly's Terms of Use of July 2026 (27). A privacy policy of October 2026, a subprocessor list and AI data pages are public, and retention is stated only in general terms. The README says hosted telemetry records tool arguments, responses, timing and errors through AgentCat with redaction hooks. AgentCat isn't on the subprocessor list and the MCP docs page doesn't mention telemetry (15). No deprecation policy was found. camelCase tool names stay callable as hidden aliases with no removal date, and the terms say notice of changes isn't always practical (8). The subprocessor list names about 30 processors with purpose, data and location, nearly all in the United States (15)."
        },
        "sources": [
          {
            "what": "MCP server repository at v2.3.21 (README, source, tests, CI workflows, server.json), read from a shallow clone",
            "url": "https://github.com/rootlyhq/rootly-mcp-server",
            "seen": "2026-10-09"
          },
          {
            "what": "changelog, 2.1.0 to 2.3.21",
            "url": "https://github.com/rootlyhq/rootly-mcp-server/blob/main/CHANGELOG.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server docs (Markdown twin)",
            "url": "https://docs.rootly.com/integrations/mcp-server",
            "seen": "2026-10-09"
          },
          {
            "what": "API overview with rate limits and key types (Markdown twin)",
            "url": "https://docs.rootly.com/api-reference/overview",
            "seen": "2026-10-09"
          },
          {
            "what": "OAuth 2.0 and OpenID Connect docs (Markdown twin)",
            "url": "https://docs.rootly.com/api-reference/oauth2",
            "seen": "2026-10-09"
          },
          {
            "what": "subprocessor list",
            "url": "https://docs.rootly.com/configuration/subprocessors",
            "seen": "2026-10-09"
          },
          {
            "what": "AI data privacy page",
            "url": "https://docs.rootly.com/ai/data-privacy-for-ai",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://rootly.com/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "Terms of Use, July 2026",
            "url": "https://rootly.com/legal/terms",
            "seen": "2026-10-09"
          },
          {
            "what": "Privacy Policy, October 2026",
            "url": "https://rootly.com/legal/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "security page",
            "url": "https://rootly.com/security",
            "seen": "2026-10-09"
          },
          {
            "what": "vulnerability disclosure policy, May 2026",
            "url": "https://rootly.com/legal/vulnerability-disclosure-policy",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://rootly.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "llms.txt",
            "url": "https://rootly.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "trust centre",
            "url": "https://security.rootly.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "official MCP registry search for rootly",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=rootly",
            "seen": "2026-10-09"
          },
          {
            "what": "one unauthenticated `initialize` to the hosted endpoint, answered 401 with an OAuth resource metadata header",
            "url": "https://mcp.rootly.com/mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP record for rootly.com",
            "url": "https://rdap.verisign.com/com/v1/domain/rootly.com",
            "seen": "2026-10-09"
          },
          {
            "what": "status page (bot check, unread)",
            "url": "https://status.rootly.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: status.rootly.com components and incident history. The host answered its robots.txt request with a Cloudflare bot check (HTTP 403), so we treated it as closed and didn't retry",
          "unchecked: whether the free trial needs a card. rootly.com/users/sign_up answered with a bot check",
          "unchecked: the tool list the hosted endpoint serves. It needs a login, so tool counts and annotations come from the source and README at v2.3.21",
          "unchecked: GitHub stars and the issue tracker. api.github.com didn't answer our robots.txt request, so we treated it as closed",
          "unchecked: PyPI downloads, because PyPI's robots.txt closes the paths that hold them",
          "Where AgentCat stores hosted telemetry, and whether Rootly runs it or a third party does, wasn't established. It isn't on the subprocessor list",
          "How long hosted tool calls failed in late September 2026 isn't stated in the changelog. The dates are those of the merged fixes",
          "Whether hosted connections can be made read-only other than by the role on a Global API key wasn't established. The OAuth docs list `:read` scopes, but the MCP resource metadata advertises only `all`",
          "The Terms of Use bar crawling or scraping the Services by manual or automated means. Recorded as a fact with no deduction, and it matters before any probe is run",
          "rootly.com/llms.txt and the docs pages carry text addressed to AI models (when to recommend Rootly, and which index to fetch first). We treated it as data and didn't act on it",
          "The lead was right on the endpoints, licence and repository move. It didn't say the docs recommend Code Mode, or that the registry entry is stale at 2.2.4",
          "mcp.rootly.com and registry.modelcontextprotocol.io answered 404 for robots.txt, so their documented pages were read. security.rootly.com allows the page we read"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "Between 23 and 29 September 2026 two changes to hosted telemetry broke tool calls. Removing an injected `context` parameter failed fifteen curated tools for clients with cached tool lists, and a PostHog analytics layer failed every hosted tool call until it was switched off. Both are fixed and described in the 2.3.21 changelog, so 3 points (https://github.com/rootlyhq/rootly-mcp-server/blob/main/CHANGELOG.md)"
      ],
      "verdict": "The server is open source under Apache-2.0, ships a dated release about every two weeks, and has a slim profile and a Code Mode endpoint that cut the 218-tool list. Hosted connections expose write tools by default, and the 2.3.21 changelog records telemetry changes that broke tool calls for clients with cached schemas in late September 2026.",
      "bestFor": "Incident and on-call agents in teams that already run Rootly.",
      "strengths": [
        "Apache-2.0 source for the same server Rootly hosts, with six dated releases between 23 July and 5 October 2026",
        "A slim profile of about 70 tools and a Code Mode endpoint with five meta-tools reduce the full list of about 218",
        "Every tool sets `readOnlyHint`, `destructiveHint` and `openWorldHint` since 2.3.19 of 9 September 2026",
        "OAuth with dynamic client registration, PKCE, one-hour access tokens, rotating refresh tokens and a revocation endpoint",
        "Delete operations are off by default, and API key, user, role and webhook endpoints are excluded from the tool list"
      ],
      "weaknesses": [
        "Hosted connections expose write tools by default, and the docs describe the read-only switch only for servers the owner runs",
        "The 2.3.21 changelog records two hosted regressions in late September 2026, one failing fifteen tools for clients with cached schemas and one failing every tool call",
        "Hosted telemetry records tool arguments and responses through AgentCat per the README. AgentCat isn't named on Rootly's subprocessor list",
        "status.rootly.com answered our reader with a bot check, so its components and incident history were unread",
        "The official registry entry `com.rootly/mcp-server` is still 2.2.4 from 18 February 2026 and lists only the SSE endpoint",
        "Rootly's Terms of Use bar crawling or scraping the Services by manual or automated means. This matters before any probe is run"
      ],
      "agentNotes": [
        "Connect to `https://mcp.rootly.com/mcp-codemode` or add `?tool_profile=slim` to `/mcp`. The default endpoint loads about 218 tool definitions",
        "Connect Code Mode in place of the classic endpoint, not beside it. The docs say models skip `execute` when both are present",
        "Use a Global API key for `get_oncall_handoff_summary` and `get_oncall_shift_metrics`. Team and personal keys return partial results",
        "Refetch the tool list after a server release. Curated tools reject undeclared arguments, which failed calls from cached schemas in September 2026",
        "Treat a 404 from a generated tool as a possible plan limit or missing parent record, and read the hint in the response"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 59.7
        }
      ],
      "editorialScores": {
        "ergonomics": 77,
        "maintenance": 81,
        "payments": 20,
        "reliability": 48,
        "schema": 78,
        "security": 65,
        "transparency": 65
      },
      "provenanceScore": 95
    },
    "connect": {
      "install": "uvx --from rootly-mcp-server rootly-mcp-server",
      "claudeCode": "claude mcp add --transport http rootly https://mcp.rootly.com/mcp",
      "config": {
        "mcpServers": {
          "rootly": {
            "url": "https://mcp.rootly.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/observability.incidents",
      "tool": "https://letme.dev/rootly-mcp"
    },
    "notable": [
      "Hosted endpoints are `https://mcp.rootly.com/mcp` (streamable HTTP), `/sse` and `/mcp-codemode`, and the docs recommend Code Mode, which exposes `list_tools`, `tool_search`, `get_schema`, `tags` and `execute` in place of about 200 tool schemas (https://docs.rootly.com/integrations/mcp-server)",
      "The README puts the default tool list at about 218 and the slim profile at about 70, selected with `?tool_profile=slim` or the `X-Rootly-Tool-Profile` header (https://github.com/rootlyhq/rootly-mcp-server)",
      "Write tools are on by default for hosted and local servers, delete operations are off, and API key, user, role and webhook endpoints are excluded (https://github.com/rootlyhq/rootly-mcp-server)",
      "The 2.3.21 changelog of 5 October 2026 records that telemetry changes failed fifteen tools for clients with cached schemas and, separately, every hosted tool call, both since fixed (https://github.com/rootlyhq/rootly-mcp-server/blob/main/CHANGELOG.md)",
      "The README says hosted telemetry records tool arguments, responses, timing, errors and identity through AgentCat, with redaction hooks and an optional Sentry export (https://github.com/rootlyhq/rootly-mcp-server)",
      "The official MCP registry entry `com.rootly/mcp-server` is 2.2.4 from 18 February 2026 and lists only the SSE endpoint (https://registry.modelcontextprotocol.io/v0/servers?search=rootly)",
      "The repository moved from Rootly-AI-Labs to rootlyhq, and the docs page still links the old address (https://docs.rootly.com/integrations/mcp-server)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Endpoints",
        "value": "`https://mcp.rootly.com/mcp` (streamable HTTP), `https://mcp.rootly.com/sse` and `https://mcp.rootly.com/mcp-codemode`. An unauthenticated `initialize` answers 401 with an OAuth resource metadata header"
      },
      {
        "label": "Tools",
        "value": "About 218 on the default endpoint and about 70 on the slim profile per the README at v2.3.21. Curated tools cover incidents, on-call, alerts and audits, and the rest are generated from Rootly's OpenAPI description"
      },
      {
        "label": "Code Mode",
        "value": "Five meta-tools (`list_tools`, `tool_search`, `get_schema`, `tags`, `execute`). The model writes a short async Python block that chains tool calls on the server. The README calls it experimental and the docs recommend it"
      },
      {
        "label": "Writes",
        "value": "Create and update tools are on by default. `ROOTLY_MCP_ENABLE_WRITE_TOOLS=false` or `--no-enable-write-tools` makes a server the owner runs read-only. Deletes are off by default"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2 with dynamic client registration, PKCE, one-hour tokens and rotating refresh tokens, or a bearer API key (global with a role, team, or personal)"
      },
      {
        "label": "Rate limits",
        "value": "REST API limits of 3,000 reads and 3,000 writes a minute per API key and 50 alert creations a minute, with X-RateLimit headers. No limit specific to the MCP endpoint was found"
      },
      {
        "label": "Annotations",
        "value": "`readOnlyHint`, `destructiveHint` and `openWorldHint` on every tool since 2.3.19, with `idempotentHint` on writes"
      },
      {
        "label": "Telemetry",
        "value": "Hosted deployments send tool-call telemetry to AgentCat, with credential scrubbing and an optional Sentry export. PostHog analytics is opt-in and off wherever AgentCat is active"
      },
      {
        "label": "Local server",
        "value": "Python 3.12 or later, run with `uvx --from rootly-mcp-server rootly-mcp-server` and `ROOTLY_API_TOKEN`. A Dockerfile is in the repository"
      },
      {
        "label": "Releases",
        "value": "v2.3.21 on 5 October 2026. Six dated releases between 23 July and 5 October 2026, under semantic versioning"
      },
      {
        "label": "Security programme",
        "value": "security.txt valid to 1 September 2027, a disclosure policy with safe harbour that names the MCP server in scope, no paid bounty, and SOC 2 Type II stated on the pricing page"
      },
      {
        "label": "Subprocessors",
        "value": "About 30 listed with purpose, data and location, nearly all in the United States, with AWS as primary hosting. AgentCat isn't on the list"
      }
    ],
    "unitPrices": [
      {
        "item": "Essentials plan, incident response",
        "unit": "seat-month",
        "usd": 20,
        "note": "MCP, API and status pages included"
      },
      {
        "item": "Essentials plan, on-call",
        "unit": "seat-month",
        "usd": 20,
        "note": "added to incident response, $40 for both"
      }
    ],
    "provenance": {
      "legalEntity": "Rootly Inc.",
      "domain": "rootly.com",
      "domainRegistered": "2006-05-27",
      "endpointOnVendorDomain": true,
      "terms": "https://rootly.com/legal/terms",
      "privacy": "https://rootly.com/legal/privacy",
      "statusPage": "https://status.rootly.com",
      "changelog": "https://github.com/rootlyhq/rootly-mcp-server/blob/main/CHANGELOG.md",
      "securityTxt": "valid",
      "checked": "2026-10-09",
      "notes": [
        "The Terms of Use (last updated July 2026) are a contract with ROOTLY INC., 1390 Market Street, San Francisco, and cover its websites, products, services and applications. The privacy policy (October 2026) writes the name as Rootly, Inc.",
        "The hosted MCP endpoint is mcp.rootly.com and the REST API is api.rootly.com, both on the vendor's domain.",
        "rootly.com/.well-known/security.txt names security@rootly.com and expires on 1 September 2027.",
        "status.rootly.com is linked from the site and llms.txt. It answered our reader with a bot check and was unread.",
        "RDAP for rootly.com gives a registration date of 2006-05-27.",
        "The subprocessor page refers to a U.S. Data Processing Addendum of September 2026, which we didn't find published."
      ],
      "score": 95,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Rootly Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "rootly.com, registered 2006-05-27 (20 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.rootly.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.rootly.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://rootly.com/legal/terms",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-07-01",
          "words": 5351,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: July 2026",
              "says": "Last updated 2026-07-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms are governed by and will be construed under the Federal Arbitration Act, applicable federal law, and the laws of the State of California, without regard to the conflicts of laws provisions thereof.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…(B) ANY SUBSTITUTE GOODS, SERVICES OR TECHNOLOGY, (C) ANY AMOUNT, IN THE AGGREGATE, IN EXCESS OF THE GREATER OF (I) ONE-HUNDRED ($100) DOLLARS OR (II) THE AMOUNTS PAID AND/OR PAYABLE BY YOU TO ROOTLY IN CONNECTION WITH THE SERVICES IN THE TWELVE (12) MONTH PERIOD PRECEDING THIS APPLICABLE CLAIM OR (D) ANY MATTER BEYON…",
              "says": "Capped at the greater of $100 and the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may suspend or discontinue any part of the Services, or we may introduce new features or impose limits on certain features or restrict access to parts or all of the Services."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We reserve the right to change the Terms at any time, but if we do, we will place a notice on our site located at https://rootly.com, send you an email, and/or notify you by some other means.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "IF YOU DO NOT AGREE TO ALL OF THE FOLLOWING, YOU MAY NOT USE OR ACCESS THE SERVICES IN ANY MANNER."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "\"crawls,\" \"scrapes,\" or \"spiders\" any page, data, or portion of or relating to the Services or Content (through use of manual or automated means);",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We'll try to give you notice when we make a material change to the Services that would adversely affect you, but this isn't always practical.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Rootly is also free to terminate (or suspend access to) your use of the Services or your account for any reason in our discretion, including your breach of these Terms."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "These Terms include information about future changes to these Terms, automatic renewals, limitations of liability, a class action waiver and resolution of disputes by arbitration instead of in court."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The terms forbid processes that run or are activated while the user is not logged into the Services.",
              "quote": "runs Maillist, Listserv, any form of auto-responder or \"spam\" on the Services, or any processes that run or are activated while you are not logged into the Services, or that otherwise interfere with the proper working of the Services"
            },
            {
              "date": "2026-10-08",
              "text": "Paid services renew automatically for the same term at the then-current non-promotional rate unless the customer opts out through the order form.",
              "quote": "Unless you opt out of auto-renewal, which can be done through your order form, any Paid Services you have signed up for will be automatically extended for successive renewal periods of the same duration as the subscription term originally selected, at the then-current non-promotional rate."
            },
            {
              "date": "2026-10-08",
              "text": "A customer may opt out of the arbitration agreement by written notice postmarked within 30 days of first accepting the terms.",
              "quote": "You have the right to opt out of the provisions of this Section by sending written notice of your decision to opt out to the following address: 1390 Market Street. #2126 San Francisco, CA 94102 USA postmarked within thirty (30) days of first accepting these Terms."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://rootly.com/legal/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-10-01",
          "words": 5715,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: October 2026",
              "says": "Last updated 2026-10-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This chart details the categories of Personal Data that we collect and have collected over the past 12 months:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Generally, we retain Personal Data about you for as long as you have an open account with us, until you request deletion of your Personal Data (as described below), or as otherwise necessary to provide you with our Services.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may use analytics providers to analyze how you interact and engage with the Services, or third parties may help us provide you with customer support."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We will not sell your Personal Data, and have not done so over the last 12 months.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Please note that your right to deletion will be subject to certain requirements and exceptions in accordance with privacy laws that provide for such right, such as the CCPA (see the \"California Resident Rights\" section below) or the GDPR (please see the \"European Data Subject Rights\" section below)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have a disability, you may access this Privacy Policy in an alternative format by contacting privacy@rootly.com.",
              "says": "privacy@rootly.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "To learn more about the Data Privacy Framework (DPF) program, please visit https://www.dataprivacyframework.gov/.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Data sent to AI providers is used only for Rootly AI services and is neither stored nor used for training by those providers.",
              "quote": "Purpose of Sharing Data with AI Models: Data sent to AI providers is solely used for providing Rootly AI services and is neither stored nor used for training purposes by the AI providers."
            },
            {
              "date": "2026-10-08",
              "text": "Rootly AI does not use a customer's data, even anonymously, to improve results for other customers.",
              "quote": "Responsible Use: Rootly AI never uses your data (even if anonymously) to improve results for other customers."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/rootly-mcp.json",
    "live": {
      "slug": "rootly-mcp",
      "probe": {
        "target": "https://mcp.rootly.com/mcp",
        "method": "mcp-initialize",
        "lastAt": "2026-10-10T03:53:41.576109542Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 124,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 145,
        "p95ms24h": 639,
        "samples24h": 125,
        "samples30d": 125,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 40,
            "ok": 40
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.rootly.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-10T00:51:12.811638334Z"
      },
      "versions": [
        {
          "registry": "mcp-registry",
          "name": "com.rootly/mcp-server",
          "version": "2.2.4",
          "seenAt": "2026-10-10T03:11:32.438759038Z"
        },
        {
          "registry": "pypi",
          "name": "rootly-mcp-server",
          "version": "2.3.21",
          "released": "2026-10-05",
          "seenAt": "2026-10-09T17:17:28.762424921Z"
        }
      ],
      "githubStars": 45,
      "pypiWeekly": 857,
      "pages": [
        {
          "url": "https://raw.githubusercontent.com/rootlyhq/rootly-mcp-server/main/CHANGELOG.md",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:46:01.143243901Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "683318338330"
        },
        {
          "url": "https://rootly.com/pricing",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-09T18:44:45.953017148Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "82eeac0db50e"
        },
        {
          "url": "https://rootly.com/legal/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:44:41.908181684Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "54ed65019be2"
        },
        {
          "url": "https://rootly.com/legal/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:44:43.959085202Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "4d2b0a72745f"
        }
      ],
      "mcpTools": {
        "url": "https://mcp.rootly.com/mcp",
        "checkedAt": "2026-10-09T21:40:55.523633877Z",
        "status": "auth",
        "note": "asks for credentials before listing its tools",
        "changedAt": "2026-10-09T21:40:55.523633877Z"
      },
      "updatedAt": "2026-10-10T03:53:41.576109542Z"
    }
  }
}
