{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "shipbob",
    "name": "ShipBob",
    "vendor": "ShipBob, Inc.",
    "vendorUrl": "https://www.shipbob.com",
    "kind": "http-api",
    "category": "shipping",
    "summary": "Outsourced fulfilment service from ShipBob, Inc. of Chicago. Merchants send orders, products, inbound stock and returns to its warehouse network through a REST API with date-based versions, a hosted MCP server and webhooks, with a separate sandbox.",
    "url": "https://www.anchorterminal.com/tools/shipbob",
    "markdownUrl": "https://www.anchorterminal.com/tools/shipbob.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shipbob.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shipbob.json",
    "repo": "https://github.com/ShipBob/mcp-ai-tutorials",
    "license": "Proprietary service under ShipBob's Terms of Service. The MCP tutorials repository on GitHub has no licence file",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.shipbob.com",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Self-serve, with no review. A person signs up in a browser and creates a Personal Access Token in the dashboard under Integrations, API Tokens, sent as `Authorization: Bearer \u003ctoken\u003e`. These tokens have every scope, don't expire, act as the account's root user and can be revoked. Multi-user apps use the OAuth 2.0 authorisation code grant with PKCE at auth.shipbob.com, with read and write scopes per domain, one-hour access tokens and 30-day refresh tokens. The hosted MCP server uses OAuth with dynamic client registration, or a token as Bearer. Writes need a `shipbob_channel_id` header. Logistics API credentials come from a ShipBob representative.",
    "pricing": "paid",
    "pricingNotes": "Quote only. The pricing page names the fee types (implementation, receiving, storage, and pick, pack and ship) with no figures and a form for a quote. The developer docs say an account is free until physical inventory arrives and that the sandbox is free, so an agent can build and test without a contract. The API and MCP server carry no separate charge (https://www.shipbob.com/pricing/, https://developer.shipbob.com/introduction).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 73,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.shipbob.com",
    "llmsTxt": "https://developer.shipbob.com/llms.txt",
    "openapi": "https://marketplaceapi.shipbob.com/docs/2026-07.json",
    "capabilities": [
      "shipping.rates",
      "shipping.tracking",
      "shipping.returns",
      "shipping.labels"
    ],
    "tags": [
      "hosted",
      "paid",
      "sales-led",
      "api-key",
      "oauth",
      "mcp",
      "openapi",
      "llms-txt",
      "webhooks",
      "sandbox",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-07-31",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 60.8,
      "grade": "C",
      "agentReady": false,
      "rank": 387,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 56,
        "maintenance": 41,
        "payments": 20,
        "reliability": 77,
        "schema": 85,
        "security": 55,
        "transparency": 77
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 77,
          "points": 15.4,
          "reason": "Read with the hosted lines and scored on the REST API at api.shipbob.com. Statuspage at status.shipbob.com with three components and 90-day uptime bars (20). The history shows no incident from August to October 2026 and the incident feed is empty. The page says it reports major outages of the website or dashboard, has no API component and has posted no incident since it was created in July 2024, so the clean record says little about the API. We scored it as minor only instead of clean, a departure from the checklist (20 of 30). 150 requests a minute, sliding window, per user and application (15). A 429 carries `x-retry-after`, the errors page recommends exponential backoff, and a duplicate `reference_id` returns 422, which makes a retried create safe. No idempotency key (12 of 15). The terms publish fulfilment turnaround SLAs with 14 exclusions. No uptime SLA for the API was found (0). The dated API versions are generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 85,
          "points": 13.81,
          "reason": "OpenAPI 3.0 spec for each version at marketplaceapi.shipbob.com, 89 operations in 2026-07. The `openapi.json` link in the docs index returns an HTML page, not the spec (25). llms.txt per version and a Markdown copy of each page (10). 88 of 89 operations have a description, and some say when to use them, such as the inventory level call for current stock questions. Few say when not to (14 of 20). All 199 parameters have a schema, with 46 enums and required fields marked. Sort order and shipping method are free strings, and many filters are comma-separated lists (10 of 15). 504 examples. 401 and 403 are documented on 64 operations, 400 on 58 and 422 on 18, 429 on none, and error bodies differ by domain, with RFC 7807 problem details in some and an `errors` array in others (11 of 15). Date-based versions, an upgrade guide per version and dated release notes (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 56,
          "points": 9.1,
          "reason": "Scored on the REST API, with the MCP server noted. Lists take a page size (up to 250 on products) but there's no field selection, and an order returns every shipment and line. The MCP server has 73 tools, with no toolsets or read-only subset documented (13 of 25). Page or cursor pagination on every list, a `next-page` response header, and filters by date, reference ID, tracking state and SKU. Two pagination styles are in use (16 of 20). A status code table, 422 for a duplicate reference ID and 410 with `api_version_deprecated` for a retired version. Error bodies are not uniform (12 of 20). Unique `reference_id` per channel on creates, and bulk hold and release are described as idempotent. No idempotency key. The MCP tool annotations sit behind sign-in and weren't read (10 of 20). No official SDK was found, and every write needs a `shipbob_channel_id` header looked up first (5 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 55,
          "points": 9.63,
          "reason": "OAuth 2.0 authorisation code grant with PKCE, read and write scopes per domain, one-hour access tokens, 30-day refresh tokens rotated on use, and a revocation endpoint. The MCP server adds dynamic client registration. Personal Access Tokens have every scope and no expiry, and can be revoked (27 of 30). An OAuth app can ask for read scopes only, MCP writes are limited to the channel created at consent, and inventory is read-only over MCP. A token has no read-only option, and no confirmation step for cancels was found (12 of 20). Orders, addresses, gift messages and return notes are written by third parties. The MCP security page covers token handling and consent, with nothing on injected text (3 of 15). No log of API calls for the operator was found. Shipment logs record warehouse events (2 of 15). The trust page says SOC 2 and ISO 27001 audits are complete and lists penetration testing. No security.txt, disclosure policy or bug bounty was found (11 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402, MPP or L402 (0). The pricing page lists the fee types (implementation, receiving, storage, pick, pack and ship) with no figures and a quote form (0). An account is free until physical inventory arrives, per the developer docs, and the sandbox is free and takes a test card number. We didn't open an account to confirm (20). A person signs up in a browser and creates the token or approves OAuth. Dynamic client registration on the MCP server still ends in a browser sign-in (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 41,
          "points": 3.59,
          "reason": "API version 2026-07 was released on 31 July 2026, 69 days before the check (20 of 30). The release notes have two entries under July 2026, the 2026-07 version and PKCE, and the second has no day, so it can't be placed inside the 90 days. The tutorials repository had four commits from 17 to 20 August. We gave half for this line (10 of 20). Closed service with dated release notes and a support address that promises a first reply within one business day (9 of 15). The MCP server isn't in the official registry, and no official SDK was found (0 of 15). OpenAPI specs are kept for each version. Nothing else to judge package health on (2 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 77,
          "points": 6.74,
          "note": "editorial 69, provenance 85",
          "reason": "Closed service. The Terms of Service, updated 22 May 2026, name ShipBob, Inc. and Illinois law. The tutorials repository has no licence file (15 of 30). A privacy policy dated 29 March 2024, which says it doesn't apply where a commercial contract governs, and a DPA dated April 2026 under which ShipBob deletes or returns personal data at the end of the service if the merchant asks. No retention period is stated in days, and the terms grant ShipBob a perpetual right to use merchant content for product improvement (17 of 30). A written version policy with 24 months of support for each version, end dates in a table, and the phased shutdown of 1.0 published with dates (20 of 20). A public list of about 30 subprocessors with purpose and location, all in the United States, with no date on the page (17 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Scored on the REST API, with the MCP server noted. Lists take a page size (up to 250 on products) but there's no field selection, and an order returns every shipment and line. The MCP server has 73 tools, with no toolsets or read-only subset documented (13 of 25). Page or cursor pagination on every list, a `next-page` response header, and filters by date, reference ID, tracking state and SKU. Two pagination styles are in use (16 of 20). A status code table, 422 for a duplicate reference ID and 410 with `api_version_deprecated` for a retired version. Error bodies are not uniform (12 of 20). Unique `reference_id` per channel on creates, and bulk hold and release are described as idempotent. No idempotency key. The MCP tool annotations sit behind sign-in and weren't read (10 of 20). No official SDK was found, and every write needs a `shipbob_channel_id` header looked up first (5 of 15).",
          "maintenance": "API version 2026-07 was released on 31 July 2026, 69 days before the check (20 of 30). The release notes have two entries under July 2026, the 2026-07 version and PKCE, and the second has no day, so it can't be placed inside the 90 days. The tutorials repository had four commits from 17 to 20 August. We gave half for this line (10 of 20). Closed service with dated release notes and a support address that promises a first reply within one business day (9 of 15). The MCP server isn't in the official registry, and no official SDK was found (0 of 15). OpenAPI specs are kept for each version. Nothing else to judge package health on (2 of 10).",
          "payments": "No x402, MPP or L402 (0). The pricing page lists the fee types (implementation, receiving, storage, pick, pack and ship) with no figures and a quote form (0). An account is free until physical inventory arrives, per the developer docs, and the sandbox is free and takes a test card number. We didn't open an account to confirm (20). A person signs up in a browser and creates the token or approves OAuth. Dynamic client registration on the MCP server still ends in a browser sign-in (0).",
          "reliability": "Read with the hosted lines and scored on the REST API at api.shipbob.com. Statuspage at status.shipbob.com with three components and 90-day uptime bars (20). The history shows no incident from August to October 2026 and the incident feed is empty. The page says it reports major outages of the website or dashboard, has no API component and has posted no incident since it was created in July 2024, so the clean record says little about the API. We scored it as minor only instead of clean, a departure from the checklist (20 of 30). 150 requests a minute, sliding window, per user and application (15). A 429 carries `x-retry-after`, the errors page recommends exponential backoff, and a duplicate `reference_id` returns 422, which makes a retried create safe. No idempotency key (12 of 15). The terms publish fulfilment turnaround SLAs with 14 exclusions. No uptime SLA for the API was found (0). The dated API versions are generally available (10).",
          "schema": "OpenAPI 3.0 spec for each version at marketplaceapi.shipbob.com, 89 operations in 2026-07. The `openapi.json` link in the docs index returns an HTML page, not the spec (25). llms.txt per version and a Markdown copy of each page (10). 88 of 89 operations have a description, and some say when to use them, such as the inventory level call for current stock questions. Few say when not to (14 of 20). All 199 parameters have a schema, with 46 enums and required fields marked. Sort order and shipping method are free strings, and many filters are comma-separated lists (10 of 15). 504 examples. 401 and 403 are documented on 64 operations, 400 on 58 and 422 on 18, 429 on none, and error bodies differ by domain, with RFC 7807 problem details in some and an `errors` array in others (11 of 15). Date-based versions, an upgrade guide per version and dated release notes (15).",
          "security": "OAuth 2.0 authorisation code grant with PKCE, read and write scopes per domain, one-hour access tokens, 30-day refresh tokens rotated on use, and a revocation endpoint. The MCP server adds dynamic client registration. Personal Access Tokens have every scope and no expiry, and can be revoked (27 of 30). An OAuth app can ask for read scopes only, MCP writes are limited to the channel created at consent, and inventory is read-only over MCP. A token has no read-only option, and no confirmation step for cancels was found (12 of 20). Orders, addresses, gift messages and return notes are written by third parties. The MCP security page covers token handling and consent, with nothing on injected text (3 of 15). No log of API calls for the operator was found. Shipment logs record warehouse events (2 of 15). The trust page says SOC 2 and ISO 27001 audits are complete and lists penetration testing. No security.txt, disclosure policy or bug bounty was found (11 of 20).",
          "transparency": "Closed service. The Terms of Service, updated 22 May 2026, name ShipBob, Inc. and Illinois law. The tutorials repository has no licence file (15 of 30). A privacy policy dated 29 March 2024, which says it doesn't apply where a commercial contract governs, and a DPA dated April 2026 under which ShipBob deletes or returns personal data at the end of the service if the merchant asks. No retention period is stated in days, and the terms grant ShipBob a perpetual right to use merchant content for product improvement (17 of 30). A written version policy with 24 months of support for each version, end dates in a table, and the phased shutdown of 1.0 published with dates (20 of 20). A public list of about 30 subprocessors with purpose and location, all in the United States, with no date on the page (17 of 20)."
        },
        "sources": [
          {
            "what": "docs index (llms.txt)",
            "url": "https://developer.shipbob.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "2026-07 docs index",
            "url": "https://developer.shipbob.com/2026-07/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "introduction and API access",
            "url": "https://developer.shipbob.com/introduction.md",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://developer.shipbob.com/auth.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limit",
            "url": "https://developer.shipbob.com/rate-limit.md",
            "seen": "2026-10-08"
          },
          {
            "what": "errors",
            "url": "https://developer.shipbob.com/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning policy",
            "url": "https://developer.shipbob.com/versioning.md",
            "seen": "2026-10-08"
          },
          {
            "what": "upgrade guide to 2026-07",
            "url": "https://developer.shipbob.com/versioning/2026-07.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://developer.shipbob.com/release-notes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox setup",
            "url": "https://developer.shipbob.com/sandbox/setup.md",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox simulations",
            "url": "https://developer.shipbob.com/sandbox/simulations.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://developer.shipbob.com/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "concepts (channels, reference IDs)",
            "url": "https://developer.shipbob.com/concepts.md",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ (pagination, spec downloads)",
            "url": "https://developer.shipbob.com/faq.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server overview",
            "url": "https://developer.shipbob.com/mcp-server/overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server setup",
            "url": "https://developer.shipbob.com/mcp-server/setup.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tools",
            "url": "https://developer.shipbob.com/mcp-server/tools.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP troubleshooting and security",
            "url": "https://developer.shipbob.com/mcp-server/troubleshooting.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP setup with API token",
            "url": "https://developer.shipbob.com/mcp-server/setup-with-token.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Logistics API overview",
            "url": "https://developer.shipbob.com/logistics/overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI spec, 2026-07",
            "url": "https://marketplaceapi.shipbob.com/docs/2026-07.json",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected-resource metadata",
            "url": "https://api.shipbob.com/.well-known/oauth-protected-resource/developer-api/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP authorisation server metadata",
            "url": "https://api.shipbob.com/developer-api/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "docs search MCP descriptor",
            "url": "https://developer.shipbob.com/_mcp/server",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.shipbob.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://status.shipbob.com/history",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents (JSON)",
            "url": "https://status.shipbob.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.shipbob.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Service",
            "url": "https://www.shipbob.com/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.shipbob.com/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Agreement, April 2026",
            "url": "https://7282580.fs1.hubspotusercontent-na1.net/hubfs/7282580/CDL%20PDFs/ShipBob%20DPA%20(April%202026).pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "subprocessor list",
            "url": "https://www.shipbob.com/shipbob-data-subprocessor-list/",
            "seen": "2026-10-08"
          },
          {
            "what": "trust page",
            "url": "https://www.shipbob.com/trust/",
            "seen": "2026-10-08"
          },
          {
            "what": "Trust Center",
            "url": "https://trust.shipbob.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.shipbob.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tutorials repository",
            "url": "https://github.com/ShipBob/mcp-ai-tutorials",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search (no entry)",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=shipbob",
            "seen": "2026-10-08"
          },
          {
            "what": "npm search for SDKs",
            "url": "https://registry.npmjs.org/-/v1/search?text=shipbob",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for shipbob.com",
            "url": "https://rdap.verisign.com/com/v1/domain/shipbob.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the hosted MCP server's tool definitions, input schemas and annotations, which need a ShipBob sign-in. The count of 73 is from the docs",
          "unchecked: the turnaround times and SLA article on support.shipbob.com that the terms link to. We read the SLA clause in the terms only, and found no API uptime commitment there",
          "unchecked: whether signup asks for a real card before a production token is issued. The docs say accounts are free until inventory arrives",
          "unchecked: the SOC 2 and ISO 27001 reports and their dates, which the Trust Center gives on request",
          "unchecked: the Claude connector directory entry for ShipBob MCP that the troubleshooting page describes",
          "Whether the API has had outages in the last 90 days. The status page has no API component and no incident posted",
          "Whether an official SDK exists. None is mentioned in the docs or found under the ShipBob GitHub organisation",
          "Unit prices for fulfilment. None are public, so the listing has no price table",
          "The day in July 2026 on which PKCE was added to the OAuth flow, and when the MCP server grew from 27 to 73 tools"
        ]
      },
      "negative": 0,
      "verdict": "OAuth with PKCE and read and write scopes per domain, a free sandbox, a public OpenAPI spec per version and a 24-month support window for each API version are documented. Fulfilment prices are by quote only, the status page has no API component, no official SDK was found, and Personal Access Tokens never expire and carry full account access.",
      "bestFor": "An agent working for a merchant that already stores stock with ShipBob, to create and track orders, check inventory, book inbound stock and handle returns.",
      "strengths": [
        "OAuth 2.0 with PKCE, separate read and write scopes for nine domains, one-hour access tokens and 30-day refresh tokens",
        "Free sandbox at `sandbox-api.shipbob.com` with its own accounts, a test card number and a simulation terminal for shipments, receiving and stock changes",
        "OpenAPI 3.0 spec for each API version with 89 operations and 504 examples in 2026-07, plus llms.txt and a Markdown copy of each docs page",
        "A new API version each January and July, each supported for 24 months, with an upgrade guide per step",
        "Hosted MCP server with 73 tools, OAuth with dynamic client registration, and writes limited to the channel created at consent",
        "Rate limit of 150 requests a minute published, with `x-retry-after` and `x-remaining-calls` response headers"
      ],
      "weaknesses": [
        "No public price. Receiving, storage and pick, pack and ship fees come only in a quote from sales",
        "The status page lists the merchant dashboard and two warehouse systems, with no component for the API and no incident posted",
        "Personal Access Tokens don't expire and carry every scope, with no read-only option",
        "No official SDK was found, and the MCP server is not in the official MCP registry",
        "No idempotency key. A retried create is caught only by the unique `reference_id`, which returns 422",
        "No security.txt, disclosure policy or bug bounty was found, and no API uptime SLA is published"
      ],
      "agentNotes": [
        "Call `GET /2026-07/channel` first and send the ID of the channel with `_write` scopes in the `shipbob_channel_id` header on every write",
        "Build against `https://sandbox-api.shipbob.com` with a sandbox account. Sandbox and production accounts, tokens and data are separate",
        "Set a stable `reference_id` on each order, product and return. A duplicate returns 422, which is the only guard against a double create",
        "Stay under 150 requests a minute per user and application, and wait the seconds given in `x-retry-after` after a 429",
        "Over MCP, writes work only on records in the channel created at consent. A 403 or 404 on a cancel usually means the record belongs to another channel"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 60.8
        }
      ],
      "editorialScores": {
        "ergonomics": 56,
        "maintenance": 41,
        "payments": 20,
        "reliability": 77,
        "schema": 85,
        "security": 55,
        "transparency": 69
      },
      "provenanceScore": 85
    },
    "connect": {
      "http": "curl -X GET \"https://api.shipbob.com/2026-07/channel\" \\\n  -H \"Authorization: Bearer YOUR_API_TOKEN\"",
      "claudeCode": "claude mcp add --transport http shipbob-mcp --scope user https://api.shipbob.com/developer-api/mcp",
      "config": {
        "mcpServers": {
          "shipbob": {
            "url": "https://api.shipbob.com/developer-api/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/shipping.rates",
      "tool": "https://letme.dev/shipbob"
    },
    "notable": [
      "The lead named only the docs search server at `developer.shipbob.com/_mcp/server`, which has one tool, `searchDocs`. The product MCP server is separate, at https://api.shipbob.com/developer-api/mcp, with 73 tools (https://developer.shipbob.com/mcp-server/tools)",
      "The MCP server launched in January 2026 with 27 tools and now lists 73 across eleven domains, among them 21 for orders, 16 for products and 9 read-only tools for inventory (https://developer.shipbob.com/release-notes)",
      "API versions are dated. 2026-07 was released on 31 July 2026 and is supported until 31 July 2028, and versions 1.0 and 2.0 reached end of support on 31 July 2026 (https://developer.shipbob.com/versioning)",
      "Requests to version 1.0 were blocked in steps of 25 per cent a week from 8 August 2026 and all return `410 Gone` since 29 August 2026 (https://developer.shipbob.com/versioning)",
      "Accounts are free until physical inventory arrives, and the sandbox is free, per the developer docs. The pricing page gives no figures and asks for a quote request (https://developer.shipbob.com/introduction, https://www.shipbob.com/pricing/)",
      "The status page says it reports major outages of the website or dashboard. Its incident feed is empty and its history shows none for August to October 2026 (https://status.shipbob.com/history)",
      "The Logistics API for label creation and rate shopping sits on a separate host, and the docs say a ShipBob representative guides setup and supplies credentials (https://developer.shipbob.com/logistics/overview)",
      "The docs index opens with a block addressed to AI agents (append `.md` for Markdown, connect to the docs MCP server). We record it as a fact about the page (https://developer.shipbob.com/llms.txt)",
      "The trust page says SOC 2 and ISO 27001 audits are complete, and the Vanta trust centre lists penetration testing among its controls (https://www.shipbob.com/trust/)"
    ],
    "area": "business",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.shipbob.com/2026-07, 77 paths and 89 operations in the OpenAPI 3.0 spec, across channels, orders, products, inventory, receiving, returns, tracking, billing, locations and webhooks"
      },
      {
        "label": "Access",
        "value": "Self-serve. A person signs up in a browser, then creates a Personal Access Token under Integrations, API Tokens, or creates an OAuth app. The Logistics API needs credentials from a ShipBob representative"
      },
      {
        "label": "Sandbox",
        "value": "Free, at https://sandbox-api.shipbob.com with accounts from webstage.shipbob.dev. Uses the test card 4111 1111 1111 1111, and a simulation terminal moves shipments, receiving orders and stock through their states"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://api.shipbob.com/developer-api/mcp (sandbox at https://sandbox-api.shipbob.com/developer-api/mcp), streamable HTTP only, 73 tools, OAuth with dynamic client registration or a Personal Access Token as Bearer. Free for customers"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 authorisation code grant with PKCE (S256) and a client secret, access tokens for 1 hour, refresh tokens for 30 days and rotated on use. Personal Access Tokens have every scope, no expiry, and can be revoked in the dashboard"
      },
      {
        "label": "Scopes",
        "value": "Read and write pairs for orders, products, inventory, fulfilments, receiving, returns and webhooks, plus `channels_read`, `locations_read`, `billing_read`, `pricing_read`, `tracking_read` and `offline_access`"
      },
      {
        "label": "Rate limits",
        "value": "150 requests a minute on a sliding window, per user and application. A 429 carries `x-retry-after` in seconds, and the errors page recommends exponential backoff"
      },
      {
        "label": "Versioning",
        "value": "Date-based (YYYY-MM) in the URL path. A new version each January and July, each supported for 24 months. Endpoints under `/experimental` can change without notice"
      },
      {
        "label": "Webhooks",
        "value": "15 topics for orders, shipments and returns, signed with a `webhook-signature` header, retried with exponential backoff over 24 hours"
      },
      {
        "label": "Costs through the API",
        "value": "`POST /2026-07/order:estimate` returns a fulfilment cost estimate for a possible order, and the billing endpoints return invoices and transactions"
      },
      {
        "label": "SDKs",
        "value": "None found from ShipBob. `shipbob-node-sdk` on npm is published by an individual"
      },
      {
        "label": "Compliance",
        "value": "SOC 2 and ISO 27001 audits completed, per the trust page. The Trust Center runs on Vanta. A DPA dated April 2026 and a list of about 30 subprocessors, all in the United States, are public"
      },
      {
        "label": "Status",
        "value": "status.shipbob.com on Statuspage, three components (merchant dashboard and two warehouse systems), none for the API"
      }
    ],
    "provenance": {
      "legalEntity": "ShipBob, Inc.",
      "domain": "shipbob.com",
      "domainRegistered": "2014-03-12",
      "endpointOnVendorDomain": true,
      "terms": "https://www.shipbob.com/terms-of-service/",
      "privacy": "https://www.shipbob.com/privacy-policy/",
      "statusPage": "https://status.shipbob.com",
      "changelog": "https://developer.shipbob.com/release-notes",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service (updated 22 May 2026) define ShipBob as ShipBob, Inc. and its affiliates, give 120 N Racine Ave, Suite 100, Chicago, IL 60607, and are governed by Illinois law. They are the agreement for the fulfilment service and its platform, and no separate API terms were found.",
        "The privacy policy (last updated 29 March 2024) names ShipBob, Inc. and says it doesn't apply where commercial contracts govern the processing. Merchant data is covered by the DPA dated April 2026, which the terms incorporate.",
        "The API answers at api.shipbob.com and sandbox-api.shipbob.com, OAuth at auth.shipbob.com, and the MCP server at api.shipbob.com/developer-api/mcp. Sandbox accounts are created at webstage.shipbob.dev.",
        "security.txt returns 404 on www.shipbob.com, developer.shipbob.com and api.shipbob.com. No disclosure address was found on the trust page.",
        "RDAP for shipbob.com gives a registration date of 2014-03-12.",
        "The status page has components for the merchant dashboard and two warehouse systems, and none for the API."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "ShipBob, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "shipbob.com, registered 2014-03-12 (12 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.shipbob.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 6,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.shipbob.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.shipbob.com/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-05-22",
          "words": 19077,
          "points": 6,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Date of Last Revision: May 22, 2026",
              "says": "Last updated 2026-05-22"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement and all Claims or disputes between the parties shall be governed by the laws of the State of Illinois without regard to its conflicts of law provisions.",
              "says": "The law of the State of Illinois"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "With the exception of claims for loss or damage to Goods or delayed delivery of Goods, ShipBob’s liability for its actions as a property broker shall be limited to $50.00 per incident.",
              "says": "Capped at $50.00"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "…or do not comply with the other requirements set out in this Clause 2 within thirty (30) days, ShipBob may reject your application for an Account or suspend or terminate the Services and this Agreement until ShipBob has received and verified the requested information."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "ShipBob may give notice to you of any modifications, however, it is your responsibility to regularly review this Agreement.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "…the Software solely in connection with the Services during the term of this Agreement, provided that you shall not (and shall not allow any third party to) copy, modify, publish, distribute, create a derivative work of, reverse engineer, reverse assemble or otherwise attempt to discover any source code or sell, assign…"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "ShipBob’s service level agreements (“SLAs”) can be found at the following link: Turnaround Times, Policies, and SLAs."
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "You agree not to access the Services by any means other than through the interface that is provided by ShipBob.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "ShipBob may give notice to you of any modifications, however, it is your responsibility to regularly review this Agreement.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "ShipBob may terminate this Agreement with or without cause by providing thirty (30) days’ prior written notice to the Registered Email Address associated with your Account."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer grants ShipBob a perpetual, irrevocable, sublicensable licence over its content, which also covers product development and aggregate, anonymous use for marketing.",
              "quote": "You grant ShipBob a worldwide, non-exclusive, perpetual, irrevocable, royalty-free, fully paid, sublicensable, and transferable right and license to access, collect, copy, use, store, host, transmit, modify, distribute, display, disclose, and otherwise process (“Process”) Your Content"
            },
            {
              "date": "2026-10-08",
              "text": "Total liability for all claims is capped at the lesser of 10,000 US dollars or the fees paid in the three months before the event.",
              "quote": "SHALL NOT EXCEED THE LESSER OF: (i) $10,000 OR (ii) 100% OF THE AGGREGATE AMOUNT OF FEES ACTUALLY PAID BY MERCHANT FOR SERVICES DURING THE THREE (3) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM."
            },
            {
              "date": "2026-10-08",
              "text": "ShipBob may permanently delete the customer's content when the account is terminated.",
              "quote": "Your Content may be permanently deleted by ShipBob upon any termination of your Account."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.shipbob.com/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-03-29",
          "words": 10890,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: March 29, 2024",
              "says": "Last updated 2024-03-29"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "the personal data we collect and process about you (we define “personal data” and “processing” below);"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "In some cases, primarily with respect to internet / network activity information collected should you visit our website, we may collect this automatically through technological measures like cookies or from third-party technology providers."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "In particular, we may use vendors and service providers for targeted advertising purposes to show you content that we think may interest you."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Right to Know: You may have the right to request information about the processing of your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "…Commissioner who can be contacted at GPO Box 5218, Sydney, NSW 2001, Telephone: 1300 363 992, Email: [email protected].",
              "says": "Gives an email address, hidden from our reader by the page"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…personal data from European Economic Area and United Kingdom to the United States, ShipBob implements standard contractual clauses approved by the European Commission and the United Kingdom Information Commissioner’s Office, and other appropriate solutions to address cross border transfers as required and/or permitted…",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Third-party AI chatbot providers receive the content of messages sent and received, along with information about those messages.",
              "quote": "These third-party chatbot partners receive the content of the messages you send and receive and information about those messages, such as when it was sent or received."
            },
            {
              "date": "2026-10-08",
              "text": "The policy does not apply where a commercial contract governs the processing of personal data.",
              "quote": "This Privacy Policy does not apply where commercial contracts govern the processing of your personal data."
            },
            {
              "date": "2026-10-08",
              "text": "ShipBob may update the policy at any time and apply the changes to information it collected earlier.",
              "quote": "We may update this Privacy Policy at any time and may apply changes to previously collected information, as permitted by applicable law."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/shipbob.json",
    "live": {
      "slug": "shipbob",
      "probe": {
        "target": "https://api.shipbob.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:21.341790184Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 122,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 134,
        "p95ms24h": 233,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.shipbob.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:06:25.746291947Z"
      },
      "updatedAt": "2026-10-08T21:12:21.341790184Z"
    }
  }
}
