{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "sendblue",
    "name": "Sendblue",
    "vendor": "Round One, Inc.",
    "vendorUrl": "https://www.sendblue.com",
    "kind": "http-api",
    "category": "messaging",
    "summary": "Sendblue is a hosted API from Round One, Inc. for sending and receiving iMessage, RCS, SMS and MMS from dedicated or shared phone numbers. Agents use a REST API, TypeScript and Python SDKs, a CLI and an MCP server.",
    "url": "https://www.anchorterminal.com/tools/sendblue",
    "markdownUrl": "https://www.anchorterminal.com/tools/sendblue.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sendblue.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sendblue.json",
    "repo": "https://github.com/sendblue-api/sendblue-ts",
    "license": "Proprietary service under Round One, Inc.'s terms of service. The TypeScript and Python SDKs and the MCP server are Apache-2.0, and the CLI is MIT",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://api.sendblue.com",
    "packages": [
      {
        "registry": "npm",
        "name": "sendblue"
      },
      {
        "registry": "pypi",
        "name": "sendblue"
      },
      {
        "registry": "npm",
        "name": "sendblue-api-mcp"
      },
      {
        "registry": "npm",
        "name": "@sendblue/cli"
      }
    ],
    "auth": "api-key",
    "authNotes": "Every request carries the account's key pair in the `sb-api-key-id` and `sb-api-secret-key` headers, and requests from a browser are refused. The keys come from the dashboard or from `sendblue show-keys` after the CLI creates the account, which needs a person to text a one-time code or enter an email code. `POST /v3/auth/tokens` mints a temporary bearer token, account-wide or limited to named phone numbers, valid for 900 seconds by default and revocable. The MCP server reads `SENDBLUE_API_API_KEY` and `SENDBLUE_API_API_SECRET` from the environment. Agency subaccounts with their own keys need approval from support.",
    "pricing": "freemium",
    "pricingNotes": "Flat price per line with no per-message fee. The Free Sandbox is $0 with no card, on a shared number with up to 10 verified contacts. The AI Agent plan is $100 a month per dedicated line and is inbound-first. Proactive outbound messaging is on the Enterprise or Blue Ocean plan, priced through sales. The terms add 3 per cent for card payments and $60 per line to port a number out (https://www.sendblue.com/pricing, checked 2026-10-08).",
    "priceSummary": "$100 / mo",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, either `llms.txt`, the pricing page or the terms (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 18,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 249505,
      "pypiWeekly": 39912,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.sendblue.com",
    "llmsTxt": "https://docs.sendblue.com/llms.txt",
    "capabilities": [
      "messaging.sms",
      "messaging.mms",
      "messaging.rcs",
      "messaging.inbound",
      "messaging.verify"
    ],
    "tags": [
      "hosted",
      "imessage",
      "sms",
      "rcs",
      "mcp",
      "cli",
      "llms-txt",
      "typescript",
      "python",
      "webhooks",
      "no-card",
      "status-page"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 61.7,
      "grade": "C",
      "agentReady": false,
      "rank": 358,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 9,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 76,
        "maintenance": 72,
        "payments": 40,
        "reliability": 71,
        "schema": 66,
        "security": 46,
        "transparency": 58
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 71,
          "points": 14.2,
          "reason": "Read with the hosted lines. status.sendblue.com is an UptimeRobot page with five monitors and 90 days of daily ratios (20). No incident is written up there. The API ingestion health monitor shows 95.349 per cent for 16 July 2026 (about 67 minutes, and we can't tell whether it was one outage), 98.770 per cent for 24 July, and API root 98.192 per cent for 7 October, so between minor incidents and one major (15 of 30). Rate limits are published with numbers per plan and per line (15). The docs say to slow down or spread traffic on a 429 and to verify state after `504 outcome_unknown`, with no Retry-After header documented and an idempotency key only on App Card updates (8 of 15). The API page shows a 99.9% Uptime SLA figure and the docs list custom SLAs for enterprise, but no SLA document was found and the terms disclaim availability (3 of 10). The REST API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 66,
          "points": 10.73,
          "reason": "We graded the REST API. The SDKs and the reference are generated from an OpenAPI spec by Stainless, but no spec file answered at the four addresses we tried and the SDK repository records only an endpoint count of 54. The published MCP package has JSON Schema inputs on its 18 tools (12 of 25). `llms.txt` and a Markdown twin of every docs page at `/index.md` (10). The reference and `llms.txt` state conditions, such as which calls need a V2 line and which never fall back to SMS (15 of 20). Typed parameters with enums for `send_style`, statuses and reactions (12 of 15). Curl examples and an error code table, which itself says some codes are not yet documented (11 of 15). Paths mix `/api`, `/api/v2`, `/v3` and `/accounts`, there is no API changelog in the docs, and the SDK changelog mostly records regenerated clients (6 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "Message lists take `limit` from 1 to 100, and the MCP server adds a `jq_filter` on every tool, a read-only filter and a three-tool dynamic mode (20 of 25). `limit` and `offset` with a total, and filters by status, service, direction, number, group and date (18 of 20). Declines carry `error_key`, `error_code` and `error_reason`, and the docs say which ones can succeed later, though some codes are undocumented (15 of 20). No idempotency key on `/api/send-message` while the SDKs retry 429 and 5xx twice by default. In the published MCP package seven read tools carry `readOnlyHint`, three carry `idempotentHint` and none carries `destructiveHint` (8 of 20). A send needs three fields, and there are official TypeScript and Python SDKs (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 46,
          "points": 8.05,
          "reason": "One key pair per account in two headers, never in the URL, plus temporary bearer tokens that can be limited to named phone numbers, expire after 900 seconds by default and can be revoked. Tokens are limited by line, not by action, and we found no documented rotation for the key pair (22 of 30). No read-only key. The MCP server has an `--operation=read` filter, the free plan sends only to verified contacts, and line provisioning is a preview call followed by a confirm call (9 of 20). Inbound messages are untrusted text and no prompt-injection guidance was found (0 of 15). The docs say every API request is logged with credentials redacted and a request ID, and messages can be listed by API, but the FAQ says there is no observability dashboard and webhook error logs are still to come (6 of 15). Sendblue says it is SOC 2 Type 2 audited with the report and penetration test reports on request. No security.txt, disclosure policy or bug bounty was found (9 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Plan prices are public, $0 and $100 a month per line with no per-message fee, while the outbound plan is priced through sales (10 of 20). The free plan needs no card (20). The CLI creates an account and API keys with no browser, but a person has to text a one-time code from a phone or supply an email code, so half (10 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 72,
          "points": 6.3,
          "reason": "`sendblue` 3.19.1 on npm and 1.31.1 on PyPI on 7 October 2026 (30). Eight npm releases between 22 September and 7 October alone (20). No API changelog in the docs, support by email, and we couldn't read the GitHub issue trackers (6 of 15). Official TypeScript and Python SDKs are current, but `sendblue-api-mcp`, the MCP package the docs install, is still 2.0.1 from 5 August 2025 and no Sendblue messaging server is in the official MCP registry (10 of 15). The SDK repository has CI and release workflows, and the published MCP package pins the SDK at `^2.0.1` (6 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 58,
          "points": 5.08,
          "note": "editorial 29, provenance 86",
          "reason": "Closed service with clear terms from Round One, Inc., and Apache-2.0 SDKs (15 of 30). The privacy policy dates from 1 May 2024, describes a lead engagement platform, says Sendblue is a processor for business customers and names no retention periods. The docs say inbound media links expire after 30 days. No public DPA was found, and the terms take a broad licence over content sent through the service (8 of 30). No deprecation policy. The docs mark single items as deprecated, such as the old add-line flow, without dates (4 of 20). No sub-processor list or data locations. The docs name Twilio and Agora for calling only (2 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Message lists take `limit` from 1 to 100, and the MCP server adds a `jq_filter` on every tool, a read-only filter and a three-tool dynamic mode (20 of 25). `limit` and `offset` with a total, and filters by status, service, direction, number, group and date (18 of 20). Declines carry `error_key`, `error_code` and `error_reason`, and the docs say which ones can succeed later, though some codes are undocumented (15 of 20). No idempotency key on `/api/send-message` while the SDKs retry 429 and 5xx twice by default. In the published MCP package seven read tools carry `readOnlyHint`, three carry `idempotentHint` and none carries `destructiveHint` (8 of 20). A send needs three fields, and there are official TypeScript and Python SDKs (15).",
          "maintenance": "`sendblue` 3.19.1 on npm and 1.31.1 on PyPI on 7 October 2026 (30). Eight npm releases between 22 September and 7 October alone (20). No API changelog in the docs, support by email, and we couldn't read the GitHub issue trackers (6 of 15). Official TypeScript and Python SDKs are current, but `sendblue-api-mcp`, the MCP package the docs install, is still 2.0.1 from 5 August 2025 and no Sendblue messaging server is in the official MCP registry (10 of 15). The SDK repository has CI and release workflows, and the published MCP package pins the SDK at `^2.0.1` (6 of 10).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public, $0 and $100 a month per line with no per-message fee, while the outbound plan is priced through sales (10 of 20). The free plan needs no card (20). The CLI creates an account and API keys with no browser, but a person has to text a one-time code from a phone or supply an email code, so half (10 of 20).",
          "reliability": "Read with the hosted lines. status.sendblue.com is an UptimeRobot page with five monitors and 90 days of daily ratios (20). No incident is written up there. The API ingestion health monitor shows 95.349 per cent for 16 July 2026 (about 67 minutes, and we can't tell whether it was one outage), 98.770 per cent for 24 July, and API root 98.192 per cent for 7 October, so between minor incidents and one major (15 of 30). Rate limits are published with numbers per plan and per line (15). The docs say to slow down or spread traffic on a 429 and to verify state after `504 outcome_unknown`, with no Retry-After header documented and an idempotency key only on App Card updates (8 of 15). The API page shows a 99.9% Uptime SLA figure and the docs list custom SLAs for enterprise, but no SLA document was found and the terms disclaim availability (3 of 10). The REST API is generally available (10).",
          "schema": "We graded the REST API. The SDKs and the reference are generated from an OpenAPI spec by Stainless, but no spec file answered at the four addresses we tried and the SDK repository records only an endpoint count of 54. The published MCP package has JSON Schema inputs on its 18 tools (12 of 25). `llms.txt` and a Markdown twin of every docs page at `/index.md` (10). The reference and `llms.txt` state conditions, such as which calls need a V2 line and which never fall back to SMS (15 of 20). Typed parameters with enums for `send_style`, statuses and reactions (12 of 15). Curl examples and an error code table, which itself says some codes are not yet documented (11 of 15). Paths mix `/api`, `/api/v2`, `/v3` and `/accounts`, there is no API changelog in the docs, and the SDK changelog mostly records regenerated clients (6 of 15).",
          "security": "One key pair per account in two headers, never in the URL, plus temporary bearer tokens that can be limited to named phone numbers, expire after 900 seconds by default and can be revoked. Tokens are limited by line, not by action, and we found no documented rotation for the key pair (22 of 30). No read-only key. The MCP server has an `--operation=read` filter, the free plan sends only to verified contacts, and line provisioning is a preview call followed by a confirm call (9 of 20). Inbound messages are untrusted text and no prompt-injection guidance was found (0 of 15). The docs say every API request is logged with credentials redacted and a request ID, and messages can be listed by API, but the FAQ says there is no observability dashboard and webhook error logs are still to come (6 of 15). Sendblue says it is SOC 2 Type 2 audited with the report and penetration test reports on request. No security.txt, disclosure policy or bug bounty was found (9 of 20).",
          "transparency": "Closed service with clear terms from Round One, Inc., and Apache-2.0 SDKs (15 of 30). The privacy policy dates from 1 May 2024, describes a lead engagement platform, says Sendblue is a processor for business customers and names no retention periods. The docs say inbound media links expire after 30 days. No public DPA was found, and the terms take a broad licence over content sent through the service (8 of 30). No deprecation policy. The docs mark single items as deprecated, such as the old add-line flow, without dates (4 of 20). No sub-processor list or data locations. The docs name Twilio and Agora for calling only (2 of 20)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://docs.sendblue.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "site llms.txt",
            "url": "https://www.sendblue.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.sendblue.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "API product page, uptime and SOC 2 claims",
            "url": "https://www.sendblue.com/api",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits and queues",
            "url": "https://docs.sendblue.com/limits/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security and compliance",
            "url": "https://docs.sendblue.com/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "credentials",
            "url": "https://docs.sendblue.com/getting-started/credentials/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server docs",
            "url": "https://docs.sendblue.com/mcp/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "temporary tokens reference",
            "url": "https://docs.sendblue.com/api/resources/auth/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "send-message reference",
            "url": "https://docs.sendblue.com/api/resources/messages/methods/send/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "sending messages, statuses and error codes",
            "url": "https://docs.sendblue.com/getting-started/sending-messages/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "messages list and pagination",
            "url": "https://docs.sendblue.com/api-v2/messages/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://docs.sendblue.com/getting-started/webhooks/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Verify",
            "url": "https://docs.sendblue.com/api-v2/verify/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ",
            "url": "https://docs.sendblue.com/faq/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "docs sitemap",
            "url": "https://docs.sendblue.com/sitemap-0.xml",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.sendblue.com",
            "seen": "2026-10-08"
          },
          {
            "what": "status page monitor feed, 90 days of daily ratios",
            "url": "https://status.sendblue.com/api/getMonitorList/qLPAQMdXQL",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.sendblue.com/terms-of-service",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.sendblue.com/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript SDK and MCP source, cloned",
            "url": "https://github.com/sendblue-api/sendblue-ts",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK on npm",
            "url": "https://registry.npmjs.org/sendblue",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP package on npm, tarball unpacked",
            "url": "https://registry.npmjs.org/sendblue-api-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "second MCP package name on npm",
            "url": "https://registry.npmjs.org/sendblue-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI on npm",
            "url": "https://registry.npmjs.org/@sendblue/cli",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/pypi/sendblue/json",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=sendblue",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt, 404",
            "url": "https://www.sendblue.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/sendblue.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: GitHub stars and open issues for sendblue-api/sendblue-ts, because the GitHub API refused us for its rate limit",
          "unchecked: whether CI passes on the SDK's default branch, which a clone doesn't show",
          "unchecked: the SOC 2 Type 2 report and penetration test reports, which Sendblue supplies on request",
          "No public OpenAPI file was found at `/openapi.json`, `/openapi.yaml`, `/openapi.yml` on docs.sendblue.com or `/openapi.json` on api.sendblue.com",
          "Whether the 67 minutes missing from the API ingestion monitor on 16 July 2026 were one outage. The status page has no written incident for it",
          "The pricing page says the free plan has no outbound messaging and no webhooks, while the docs say free accounts can message verified contacts. We didn't test which holds",
          "Whether the 99.9% Uptime SLA figure on the API page is backed by a contract term. No SLA document was found",
          "Which countries' numbers Sendblue can assign and reach. The docs describe E.164 numbers and area codes without a coverage list",
          "Whether the account key pair can be rotated or more than one pair issued",
          "The lead's interface line reads REST API (v2). The API has no single version, with paths under `/api`, `/api/v2`, `/v3` and `/accounts`"
        ]
      },
      "negative": 0,
      "verdict": "Sendblue sends iMessage with RCS and SMS fallback at a flat $100 a line each month, and its CLI creates a free account and API keys from a terminal once a person texts a code. Proactive outbound messaging is sold through sales, no OpenAPI file is published, and the MCP package the docs install dates from August 2025.",
      "bestFor": "An agent that answers people over iMessage on a US number, where blue-bubble threads, typing indicators and reactions matter and the person texts first.",
      "strengths": [
        "One request to `/api/send-message` sends iMessage and can fall back to RCS or SMS, with no per-message fee on any plan",
        "The CLI creates a free account, a shared line and API keys from a terminal, with no card, once a person texts a one-time code",
        "Temporary bearer tokens from `/v3/auth/tokens` can be limited to named phone numbers, expire after 900 seconds by default and can be revoked",
        "Every docs page has a Markdown twin at `/index.md`, and `llms.txt` summarises each page with its limits and conditions",
        "Rate limits are published with numbers for each plan, and declined sends return an `error_key` an agent can branch on"
      ],
      "weaknesses": [
        "Proactive outbound messaging needs the Blue Ocean plan, which has no public price. The $100 AI Agent plan is inbound-first",
        "No OpenAPI file was found at any public address, although the SDKs and the reference are generated from one",
        "The docs install `sendblue-api-mcp`, last published on 5 August 2025 with 18 tools. The API now has 54 configured endpoints",
        "`/api/send-message` takes no idempotency key, and the SDKs retry 429 and 5xx responses twice by default",
        "No public DPA, sub-processor list, retention period, deprecation policy or security.txt was found"
      ],
      "agentNotes": [
        "Send `from_number` on every request. Read the account's numbers from `GET /api/lines` first, because a send without it fails",
        "On the free plan a recipient must text the Sendblue number once before any message to them is accepted",
        "Before a contact's first reply keep messages under 300 characters with no links, media, phone numbers or email addresses, and stop at six",
        "Branch on `error_key` in an HTTP 400 decline and don't retry it. Only HTTP 429 clears by waiting",
        "Set `maxRetries: 0` on sends where a duplicate matters, and treat `504 outcome_unknown` on group changes as possibly applied",
        "Mint a token at `/v3/auth/tokens` limited to one phone number for a sub-agent, and keep the account key pair out of its context"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 61.7
        }
      ],
      "editorialScores": {
        "ergonomics": 76,
        "maintenance": 72,
        "payments": 40,
        "reliability": 71,
        "schema": 66,
        "security": 46,
        "transparency": 29
      },
      "provenanceScore": 86
    },
    "connect": {
      "install": "npm install sendblue",
      "http": "curl -X POST https://api.sendblue.com/api/send-message \\\n  -H \"sb-api-key-id: $SENDBLUE_API_KEY_ID\" -H \"sb-api-secret-key: $SENDBLUE_API_KEY_SECRET\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"number\":\"+19998887777\",\"from_number\":\"+18887776666\",\"content\":\"Hello from Sendblue!\"}'",
      "claudeCode": "claude mcp add sendblue_api --env SENDBLUE_API_API_KEY=your-api-key --env SENDBLUE_API_API_SECRET=your-api-secret -- npx -y sendblue-api-mcp --client=claude-code --tools=all",
      "config": {
        "mcpServers": {
          "sendblue_api": {
            "args": [
              "-y",
              "sendblue-api-mcp",
              "--tools=all"
            ],
            "command": "npx",
            "env": {
              "SENDBLUE_API_API_KEY": "your-api-key",
              "SENDBLUE_API_API_SECRET": "your-api-secret"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/messaging.sms",
      "tool": "https://letme.dev/sendblue"
    },
    "notable": [
      "Three plans on the pricing page. Free Sandbox at $0 on a shared number with up to 10 verified contacts, AI Agent at $100 a month per dedicated line, and Enterprise at a custom price for outbound messaging (https://www.sendblue.com/pricing)",
      "The CLI flow `npx -y @sendblue/cli@latest sandbox init` creates the account and API keys after a person texts a one-time phrase to a Sendblue number, with no card and no browser (https://docs.sendblue.com/llms.txt)",
      "Both `llms.txt` files are written as instructions to an AI model. The one on www.sendblue.com opens by telling the model that the user clicked a copy button and wants help setting up. We record this as a fact and took no deduction (https://www.sendblue.com/llms.txt)",
      "The MCP package the docs install, `sendblue-api-mcp`, is at 2.0.1 from 5 August 2025 and depends on SDK `^2.0.1`. The repository's current MCP source is named `sendblue-mcp` at 3.19.1, and npm has that name at 2.1.0 from 9 December 2025 (https://registry.npmjs.org/sendblue-api-mcp/latest)",
      "Limits are per line. Blue Ocean allows 50 new contacts a day, 15 an hour and 10 messages a second. AI Agent allows 1,000 inbound contacts a day and 200 follow-ups a day after the 24-hour window (https://docs.sendblue.com/limits/)",
      "The SDKs default to `https://api.sendblue.co` and the reference examples use that host, while the docs name `https://api.sendblue.com` as the canonical base URL (https://github.com/sendblue-api/sendblue-ts/blob/main/src/client.ts)",
      "The status page is an UptimeRobot page with five monitors and no written incidents. The API ingestion monitor shows 95.349 per cent for 16 July 2026 (https://status.sendblue.com)",
      "The terms add a 3 per cent fee for card payments, a $60 fee per line to port a number out, and say fees are non-refundable (https://www.sendblue.com/terms-of-service)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Channels",
        "value": "iMessage, RCS, SMS and MMS, with group messages, tapback reactions, typing indicators, read receipts, carousels, App Cards and voice notes on iMessage. FaceTime audio and Twilio voice are separate add-ons. No WhatsApp"
      },
      {
        "label": "Fallback",
        "value": "Ordinary messages fall back from iMessage to RCS and then SMS at no extra charge. App Cards and inline replies never fall back"
      },
      {
        "label": "Sender registration",
        "value": "Sendblue says no A2P registration is needed. Each line is a phone number Sendblue assigns, shared on the free plan and dedicated on paid plans"
      },
      {
        "label": "Plans",
        "value": "Free Sandbox $0 (shared number, up to 10 verified contacts). AI Agent $100 a month per line (inbound-first). Enterprise or Blue Ocean for outbound, price on request"
      },
      {
        "label": "Rate limits",
        "value": "10 messages a second per line, HTTP 429 above that. Blue Ocean 50 new contacts a day and 15 an hour per line. AI Agent 1,000 inbound contacts a day and 200 follow-ups a day per line. Contacts API 100 requests per 10 seconds. Lookups 30 an hour and 100 a day per line"
      },
      {
        "label": "Before the first reply",
        "value": "At most six messages of up to 300 characters with no media, links, phone numbers or email addresses, until the contact replies. One `pre_reply_override` per contact per line per day"
      },
      {
        "label": "Inbound",
        "value": "Seven webhook types (receive, outbound, typing_indicator, call_log, line_blocked, line_assigned, contact_created), managed at `/api/account/webhooks`, three retries on 5xx, a shared secret sent in the `sb-signing-secret` header"
      },
      {
        "label": "Credentials",
        "value": "`sb-api-key-id` and `sb-api-secret-key` headers for the account. Temporary bearer tokens from `/v3/auth/tokens`, account-wide or limited to named phone numbers, 900 seconds by default, revocable"
      },
      {
        "label": "MCP server",
        "value": "`sendblue-api-mcp` on npm (stdio, 2.0.1, 5 August 2025), 18 tools, `--operation=read` and `--resource` filters and a `--tools=dynamic` mode with three meta-tools. Not in the official MCP registry"
      },
      {
        "label": "SDKs and CLI",
        "value": "`sendblue` on npm 3.19.1 and on PyPI 1.31.1, both 7 October 2026, Apache-2.0, generated by Stainless. `@sendblue/cli` 0.10.0 (17 August 2026, MIT). Community Go, Rust and Ruby clients"
      },
      {
        "label": "Verify",
        "value": "An inverted one-time code under `/api/v2/verify`. The user texts a code to a Sendblue number and the verification turns `approved`"
      },
      {
        "label": "Sandboxes",
        "value": "Cloud Linux machines under `/v3/sandboxes`, a separate product on the same keys, with $100 of compute for new free accounts per the docs"
      },
      {
        "label": "Status",
        "value": "status.sendblue.com on UptimeRobot, five monitors (API health, API ingestion health, API root, Dashboard, Datacenter) with 90 days of daily ratios and no written incidents"
      },
      {
        "label": "Certifications",
        "value": "Sendblue says it is SOC 2 Type 2 audited, with the report and penetration test reports on request, and HIPAA on a dedicated instance"
      }
    ],
    "unitPrices": [
      {
        "item": "AI Agent plan, dedicated line",
        "unit": "month",
        "usd": 100,
        "note": "Per line, inbound-first, no per-message fee. Outbound plans are priced through sales"
      }
    ],
    "provenance": {
      "legalEntity": "Round One, Inc.",
      "domain": "sendblue.com",
      "domainRegistered": "2011-06-25",
      "endpointOnVendorDomain": true,
      "terms": "https://www.sendblue.com/terms-of-service",
      "privacy": "https://www.sendblue.com/privacy-policy",
      "statusPage": "https://status.sendblue.com",
      "changelog": "https://github.com/sendblue-api/sendblue-ts/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service (effective 19 March 2025) and the privacy policy (effective 1 May 2024) both name Round One, Inc. as Sendblue. The site footer gives 344 West End Avenue, New York NY 10024.",
        "The terms cover registering for and using the services, so they govern API use. The privacy policy covers the website and the services and says Sendblue is a processor for its business customers.",
        "The API answers at api.sendblue.com, and the SDKs default to api.sendblue.co, a second domain the vendor uses.",
        "`/.well-known/security.txt` returns 404 on www.sendblue.com, docs.sendblue.com and api.sendblue.com.",
        "There is no API changelog in the docs. The changelog link is the TypeScript SDK's, whose recent entries mostly read as regenerated clients.",
        "RDAP for sendblue.com gives a registration date of 2011-06-25."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Round One, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "sendblue.com, registered 2011-06-25 (15 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.sendblue.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 5 of the 8 things a reader expects",
          "points": 7.8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.sendblue.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.sendblue.com/terms-of-service",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-03-19",
          "words": 4281,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective Date: Mar 19th, 2025",
              "says": "Last updated 2025-03-19"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement shall be governed by and construed in accordance with the laws of New York, without regard to its conflict of law principles.",
              "says": "The law of New York"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "SENDBLUE'S TOTAL LIABILITY FOR ALL CLAIMS UNDER THESE TERMS, INCLUDING FOR ANY IMPLIED WARRANTIES, IS LIMITED TO THE AMOUNT YOU PAID US TO USE THE SERVICES DURING THE SIX (6) MONTHS BEFORE THE CLAIM.",
              "says": "Capped at the fees paid in the 6 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If a User is found to have violated any of these restrictions, or there is reasonable suspicion of such violation, Sendblue reserves the right to terminate the Services immediately without prior notice."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "IF YOU DO NOT AGREE TO THIS AGREEMENT, YOU MUST NOT ACCESS OR USE ANY Sendblue SERVICES."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "If a User is found to have violated any of these restrictions, or there is reasonable suspicion of such violation, Sendblue reserves the right to terminate the Services immediately without prior notice."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "THIS AGREEMENT IS LEGALLY BINDING UPON YOUR ACCEPTANCE.THIS AGREEMENT INCLUDES A MANDATORY ARBITRATION PROVISION THAT REQUIRES THE USE OF ARBITRATION ON AN INDIVIDUAL BASIS TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS ACTIONS, AND ALSO LIMITS THE REMEDIES AVAILABLE TO YOU IN THE EVENT OF A DISPUTE."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Customers grant Sendblue and its partners a global licence to use, modify, publish and distribute their content for operating, promoting and enhancing the services and developing new ones.",
              "quote": "By submitting, uploading, or sharing content via our services, you grant Sendblue and its partners a global license to host, use, reproduce, modify, create derivative works, communicate, publish, publicly display, and distribute your content."
            },
            {
              "date": "2026-10-08",
              "text": "Sendblue may use Customer Data and interactions with its services to develop and improve its systems and offerings.",
              "quote": "Sendblue may use Customer Data and interactions with its services to develop and improve its systems and offerings."
            },
            {
              "date": "2026-10-08",
              "text": "A phone number is returned to the upstream carrier once the subscription is no longer active and can then no longer be ported out.",
              "quote": "Once a subscription is no longer active, the number will be returned to the upstream carrier and can no longer be ported out."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.sendblue.com/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-05-01",
          "words": 3552,
          "points": 7.8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective Date: May 1, 2024",
              "says": "Last updated 2024-05-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This document explains how we collect, use, protect, and disclose your personal information as you engage with our lead engagement platform and related services (\"Services\")."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "As a service provider, Sendblue acts as a processor of personal data on behalf of our Business Customers."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Right to Rectification: You have the right to have inaccurate personal data corrected."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "To make a CCPA request, contact us via email at [email protected], or send postal mail to our designated address.",
              "says": "Gives an email address, hidden from our reader by the page"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The privacy policy says users agree Sendblue is not liable for claims or losses arising from their improper use of collected data or failure to comply with data privacy laws.",
              "quote": "By using Sendblue’s services, Users agree that Sendblue is not liable for any actions, claims, losses, or damages arising from or related to the Users' improper use of collected data or failure to comply with applicable data privacy laws."
            },
            {
              "date": "2026-10-08",
              "text": "A business user must immediately notify affected individuals, Sendblue and the relevant authorities of a data breach affecting information collected through the services.",
              "quote": "In the event of a data breach affecting information collected through Sendblue’s services, you are responsible for immediately notifying the affected individuals, Sendblue, and relevant authorities in accordance with applicable laws."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/sendblue.json",
    "live": {
      "slug": "sendblue",
      "probe": {
        "target": "https://api.sendblue.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:21.131570615Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 731,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 772,
        "p95ms24h": 921,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.sendblue.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:39:09.808226694Z"
      },
      "updatedAt": "2026-10-08T21:12:21.131570615Z"
    }
  }
}
