{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "shortcut",
    "name": "Shortcut",
    "vendor": "Shortcut Software Company",
    "vendorUrl": "https://www.shortcut.com",
    "kind": "http-api",
    "category": "project-management",
    "summary": "Shortcut is a hosted project tracker for software teams, with stories, epics, iterations, objectives and docs. Agents reach it through REST API v3 with a personal token, or the hosted MCP server at mcp.shortcut.com/mcp with OAuth.",
    "url": "https://www.anchorterminal.com/tools/shortcut",
    "markdownUrl": "https://www.anchorterminal.com/tools/shortcut.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shortcut.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shortcut.json",
    "repo": "https://github.com/useshortcut/shortcut-client-js",
    "license": "Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.app.shortcut.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@shortcut/client"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. Any workspace member creates an API token under Settings, API Tokens, with no app review. REST API v3 takes it in the `Shortcut-Token` header, and tokens can be read-only or read-write since 20 January 2026. An Observer's token can read but not change data. The hosted MCP server at mcp.shortcut.com/mcp takes OAuth only (authorisation code with PKCE, dynamic client registration) with the scopes read, write, story-write, comment-write and admin, and access can be revoked in Shortcut settings. The v4 alpha uses `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens.",
    "pricing": "freemium",
    "pricingNotes": "The API, webhooks and the MCP server are listed on every plan, and Shortcut charges nothing per call. Free is $0 for up to 10 users, Team $8.50 a user a month billed yearly ($10 monthly), Business $12 ($16 monthly), and Enterprise is quoted by sales. A 14-day trial needs no card, so an agent's owner can start on Free or the trial without a contract (checked 2026-10-08).",
    "priceSummary": "$8.50 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI files, llms.txt or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 142,
      "npmWeekly": 102825,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.shortcut.com/api/rest/v3",
    "llmsTxt": "https://www.shortcut.com/llms.txt",
    "openapi": "https://developer.shortcut.com/api/rest/v3/shortcut.openapi.json",
    "capabilities": [
      "tasks.create",
      "tasks.update",
      "projects.manage",
      "tasks.comments",
      "projects.reporting",
      "automation.webhooks"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "webhooks",
      "freemium",
      "free-tier",
      "no-card",
      "closed-source",
      "typescript",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-09-22",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 60.2,
      "grade": "C",
      "agentReady": false,
      "rank": 411,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 9,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 57,
        "maintenance": 73,
        "payments": 30,
        "reliability": 64,
        "schema": 75,
        "security": 54,
        "transparency": 73
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 64,
          "points": 12.8,
          "reason": "Graded on the hosted lines for REST API v3 and the hosted MCP server. status.shortcut.com is a Statuspage site with API and Shortcut MCP components and history back to March 2023 (20). In the 90 days to 8 October 2026 it shows three incidents, the MCP server unavailable for about 6 minutes on 14 July, tokens newly created through the MCP server unable to write for 2 hours 21 minutes on 15 July (rated major by Shortcut, fix in place after 22 minutes), and search indexing behind on 4 August. None names the API component. One vendor-rated major that affected only new MCP tokens sits between the minor and major lines (15 of 30). The docs give 200 requests a minute (15). A 429 is documented, with no Retry-After header, backoff guidance or idempotency keys found (4 of 15). The Enterprise plan lists 'Premier support SLAs', and no uptime SLA was found (0). v3 is described as the current version with backwards-compatible changes only, and the hosted MCP server carries no beta label. v4 is alpha and isn't graded (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "Swagger 2.0 and OpenAPI 3.0 files for v3 are downloadable from the docs (143 operations on 85 paths), and an OpenAPI 3.0.3 file for the v4 alpha (247 operations) is at www.shortcut.com/openapi.json. The hosted MCP server's tool schemas need an account and were not read (25). www.shortcut.com/llms.txt links the spec, and help centre pages have Markdown copies. developer.shortcut.com has no llms.txt and is a single HTML page per version (7 of 10). 127 of 143 operations carry a description, mostly one line, with a few usage rules such as the `workflow_state_id` or `project_id` choice on story creation (12 of 20). Enums, maxLength, formats and required flags throughout (13 of 15). Every endpoint has a curl example and an example response, but errors are the same three lines everywhere (400 schema mismatch, 404, 422) with no documented error body (9 of 15). Versions are in the path (v2 deprecated, v3 current, v4 alpha). No API changelog was found, although the v4 page refers to one, and API changes appear in the product release notes (9 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 57,
          "points": 9.26,
          "reason": "Graded on the API. Search takes `detail=slim` to drop descriptions and comments, and list responses use slim types. Field selection (`fields`) exists only in the v4 alpha (17 of 25). Search has operators, `page_size` up to 250 and a `next` token, and epics have a paginated list, but the v4 migration note says v3 list endpoints return all results at once (14 of 20). Errors are HTTP codes with one-line meanings. A live 401 returned JSON with `message` and `tag`, which the reference doesn't catalogue (9 of 20). No idempotency keys. `external_id` fields exist on some entities. The archived MCP source (v0.25.0) sets readOnlyHint, destructiveHint and idempotentHint on its 78 tools, and the hosted server's annotations were not read (8 of 20). A story needs only a name and a workflow state. One official SDK, `@shortcut/client` for JavaScript and TypeScript (9 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 54,
          "points": 9.45,
          "reason": "The hosted MCP server uses the OAuth authorisation code flow with PKCE (S256), dynamic client registration and the scopes read, write, story-write, comment-write and admin. REST tokens are created per user, can be read-only or read-write since 20 January 2026, and the v4 alpha lets an admin list and disable workspace tokens. The v3 docs still accept the token as a `token` query parameter, marked deprecated, which costs 10 (20 of 30). Read-only tokens, a read scope, narrow story and comment scopes and the view-only Observer role. No confirmation step for deletes was found (14 of 20). Stories, comments and docs written by other people reach the model, and no injection guidance was found (3 of 15). Story history is readable by API. No workspace audit log of API or MCP calls was found in the pages read (5 of 15). No security.txt (404). A disclosure policy promises acknowledgement within a week, and the security page states SOC 2 Type 2 with the report on request. No bug bounty or public advisories found (12 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices are public, Free $0 for up to 10 users, Team $8.50 a user a month billed yearly or $10 monthly, Business $12 or $16, Enterprise by quote. API calls aren't priced (10). The Free plan lists API and webhook access and the MCP server, and the 14-day trial needs no card (20). A person signs up in a browser and creates a token or approves the OAuth grant (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "reason": "The newest release notes are dated 18 September 2026 and `@shortcut/client` 3.4.1 was published on 22 September 2026 (30). Release notes on 31 July, 14 August and 18 September, and four client releases in September (20). Closed service with public release notes, a community Slack and a support address. Response times were not checked (9 of 15). The official client is current, but the official MCP registry has only third-party Shortcut servers (com.mcparmory/shortcut, io.github.stayce/shortcut-mcp) (8 of 15). The client repository was last pushed on 1 October 2026 under MIT. The MCP server repository is archived at v0.25.0 (23 June 2026) with a notice that development moved to the hosted server (6 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "note": "editorial 57, provenance 88",
          "reason": "Closed service under terms naming Shortcut Software Company, with an MIT client library and the archived MIT MCP server (15). The privacy policy of 11 July 2025 covers the platform and says inputs and outputs aren't used to train models by default. Retention is 'only for as long as it serves the purpose', the terms give at least 30 days of data access after termination, and the DPA (last updated 23 August 2018) is sent on request, not published (17 of 30). No deprecation policy found. v2, the Projects endpoints and the token query parameter are marked deprecated with no dates (5 of 20). The sub-processor list, updated 12 November 2025, names 33 providers with product, type and country, hosting on AWS in the US (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the API. Search takes `detail=slim` to drop descriptions and comments, and list responses use slim types. Field selection (`fields`) exists only in the v4 alpha (17 of 25). Search has operators, `page_size` up to 250 and a `next` token, and epics have a paginated list, but the v4 migration note says v3 list endpoints return all results at once (14 of 20). Errors are HTTP codes with one-line meanings. A live 401 returned JSON with `message` and `tag`, which the reference doesn't catalogue (9 of 20). No idempotency keys. `external_id` fields exist on some entities. The archived MCP source (v0.25.0) sets readOnlyHint, destructiveHint and idempotentHint on its 78 tools, and the hosted server's annotations were not read (8 of 20). A story needs only a name and a workflow state. One official SDK, `@shortcut/client` for JavaScript and TypeScript (9 of 15).",
          "maintenance": "The newest release notes are dated 18 September 2026 and `@shortcut/client` 3.4.1 was published on 22 September 2026 (30). Release notes on 31 July, 14 August and 18 September, and four client releases in September (20). Closed service with public release notes, a community Slack and a support address. Response times were not checked (9 of 15). The official client is current, but the official MCP registry has only third-party Shortcut servers (com.mcparmory/shortcut, io.github.stayce/shortcut-mcp) (8 of 15). The client repository was last pushed on 1 October 2026 under MIT. The MCP server repository is archived at v0.25.0 (23 June 2026) with a notice that development moved to the hosted server (6 of 10).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public, Free $0 for up to 10 users, Team $8.50 a user a month billed yearly or $10 monthly, Business $12 or $16, Enterprise by quote. API calls aren't priced (10). The Free plan lists API and webhook access and the MCP server, and the 14-day trial needs no card (20). A person signs up in a browser and creates a token or approves the OAuth grant (0).",
          "reliability": "Graded on the hosted lines for REST API v3 and the hosted MCP server. status.shortcut.com is a Statuspage site with API and Shortcut MCP components and history back to March 2023 (20). In the 90 days to 8 October 2026 it shows three incidents, the MCP server unavailable for about 6 minutes on 14 July, tokens newly created through the MCP server unable to write for 2 hours 21 minutes on 15 July (rated major by Shortcut, fix in place after 22 minutes), and search indexing behind on 4 August. None names the API component. One vendor-rated major that affected only new MCP tokens sits between the minor and major lines (15 of 30). The docs give 200 requests a minute (15). A 429 is documented, with no Retry-After header, backoff guidance or idempotency keys found (4 of 15). The Enterprise plan lists 'Premier support SLAs', and no uptime SLA was found (0). v3 is described as the current version with backwards-compatible changes only, and the hosted MCP server carries no beta label. v4 is alpha and isn't graded (10).",
          "schema": "Swagger 2.0 and OpenAPI 3.0 files for v3 are downloadable from the docs (143 operations on 85 paths), and an OpenAPI 3.0.3 file for the v4 alpha (247 operations) is at www.shortcut.com/openapi.json. The hosted MCP server's tool schemas need an account and were not read (25). www.shortcut.com/llms.txt links the spec, and help centre pages have Markdown copies. developer.shortcut.com has no llms.txt and is a single HTML page per version (7 of 10). 127 of 143 operations carry a description, mostly one line, with a few usage rules such as the `workflow_state_id` or `project_id` choice on story creation (12 of 20). Enums, maxLength, formats and required flags throughout (13 of 15). Every endpoint has a curl example and an example response, but errors are the same three lines everywhere (400 schema mismatch, 404, 422) with no documented error body (9 of 15). Versions are in the path (v2 deprecated, v3 current, v4 alpha). No API changelog was found, although the v4 page refers to one, and API changes appear in the product release notes (9 of 15).",
          "security": "The hosted MCP server uses the OAuth authorisation code flow with PKCE (S256), dynamic client registration and the scopes read, write, story-write, comment-write and admin. REST tokens are created per user, can be read-only or read-write since 20 January 2026, and the v4 alpha lets an admin list and disable workspace tokens. The v3 docs still accept the token as a `token` query parameter, marked deprecated, which costs 10 (20 of 30). Read-only tokens, a read scope, narrow story and comment scopes and the view-only Observer role. No confirmation step for deletes was found (14 of 20). Stories, comments and docs written by other people reach the model, and no injection guidance was found (3 of 15). Story history is readable by API. No workspace audit log of API or MCP calls was found in the pages read (5 of 15). No security.txt (404). A disclosure policy promises acknowledgement within a week, and the security page states SOC 2 Type 2 with the report on request. No bug bounty or public advisories found (12 of 20).",
          "transparency": "Closed service under terms naming Shortcut Software Company, with an MIT client library and the archived MIT MCP server (15). The privacy policy of 11 July 2025 covers the platform and says inputs and outputs aren't used to train models by default. Retention is 'only for as long as it serves the purpose', the terms give at least 30 days of data access after termination, and the DPA (last updated 23 August 2018) is sent on request, not published (17 of 30). No deprecation policy found. v2, the Projects endpoints and the token query parameter are marked deprecated with no dates (5 of 20). The sub-processor list, updated 12 November 2025, names 33 providers with product, type and country, hosting on AWS in the US (20)."
        },
        "sources": [
          {
            "what": "REST API v3 reference (auth, rate limit, endpoints)",
            "url": "https://developer.shortcut.com/api/rest/v3",
            "seen": "2026-10-08"
          },
          {
            "what": "v3 Swagger 2.0 file",
            "url": "https://developer.shortcut.com/api/rest/v3/shortcut.swagger.json",
            "seen": "2026-10-08"
          },
          {
            "what": "REST API v4 alpha reference",
            "url": "https://developer.shortcut.com/api/rest/v4",
            "seen": "2026-10-08"
          },
          {
            "what": "v4 OpenAPI 3.0.3 file",
            "url": "https://www.shortcut.com/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "outgoing webhooks reference",
            "url": "https://developer.shortcut.com/api/webhook/v1",
            "seen": "2026-10-08"
          },
          {
            "what": "hosted MCP server landing page",
            "url": "https://mcp.shortcut.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected-resource metadata",
            "url": "https://mcp.shortcut.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth authorisation server metadata",
            "url": "https://api.app.shortcut.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre article on the MCP server",
            "url": "https://www.shortcut.com/help/integrations/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre article on webhooks",
            "url": "https://www.shortcut.com/help/admin/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre article on user roles",
            "url": "https://www.shortcut.com/help/admin/user-roles.md",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre article on GDPR and the DPA",
            "url": "https://www.shortcut.com/help/admin/gdpr.md",
            "seen": "2026-10-08"
          },
          {
            "what": "archived MCP server repository",
            "url": "https://github.com/useshortcut/mcp-server-shortcut",
            "seen": "2026-10-08"
          },
          {
            "what": "JavaScript client repository",
            "url": "https://github.com/useshortcut/shortcut-client-js",
            "seen": "2026-10-08"
          },
          {
            "what": "npm, @shortcut/client",
            "url": "https://registry.npmjs.org/@shortcut/client",
            "seen": "2026-10-08"
          },
          {
            "what": "npm, @shortcut/mcp",
            "url": "https://registry.npmjs.org/@shortcut/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=shortcut",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents feed",
            "url": "https://status.shortcut.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components",
            "url": "https://status.shortcut.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.shortcut.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://www.shortcut.com/release-notes/",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://www.shortcut.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.shortcut.com/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.shortcut.com/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "GDPR and Data Privacy Framework notice",
            "url": "https://www.shortcut.com/gdpr-privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://www.shortcut.com/gdpr-subprocessors/",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.shortcut.com/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "responsible disclosure policy",
            "url": "https://www.shortcut.com/disclosure/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.shortcut.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for shortcut.com",
            "url": "https://rdap.verisign.com/com/v1/domain/shortcut.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the hosted MCP server's tool list, schemas and annotations, because tools/list needs a Shortcut account (the endpoint answers 401 without a token). The 78 tools counted are in the archived source at v0.25.0, so `toolCount` is left empty.",
          "unchecked: whether the read-only and read-write tokens of 20 January 2026 work on v3 as well as v4. The v4 page describes the `sct_ro_` and `sct_rw_` prefixes and says v3 tokens don't work on v4.",
          "unchecked: whether the live API sends a Retry-After header on 429. None is documented.",
          "unchecked: the DPA (last updated 23 August 2018) and the SOC 2 report, which are sent on request only.",
          "unchecked: response times in the community Slack and from support.",
          "No API changelog was found, although the v4 page tells readers to review one. No workspace audit log was found in the help centre pages read.",
          "The lead said the MCP server was unconfirmed. Shortcut runs a hosted one at https://mcp.shortcut.com/mcp, and the open-source `@shortcut/mcp` repository is archived. The lead also missed the v4 alpha.",
          "The Enterprise plan lists 'Premier support SLAs'. Whether an Enterprise contract carries an uptime commitment was not established."
        ]
      },
      "negative": 0,
      "verdict": "REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.",
      "bestFor": "Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.",
      "strengths": [
        "REST API v3, webhooks and the MCP server are listed on every plan, Free (up to 10 users) among them, and the 14-day trial needs no card",
        "Swagger 2.0 and OpenAPI 3.0 files for v3 (143 operations) are downloadable, with enums, string limits and required fields",
        "The hosted MCP server uses OAuth with PKCE, dynamic client registration and the scopes read, write, story-write, comment-write and admin",
        "API tokens can be read-only or read-write since 20 January 2026, and Observers' tokens can read but not change data",
        "status.shortcut.com has separate API and Shortcut MCP components with incident history back to 2023"
      ],
      "weaknesses": [
        "The v3 docs still allow the API token as a `token` query parameter, marked deprecated with no removal date",
        "No idempotency keys, Retry-After header or backoff guidance found. The docs state only 200 requests a minute and a 429",
        "No API changelog or deprecation policy found. API changes appear as lines in the product release notes",
        "The open-source MCP server is archived at v0.25.0, and the hosted server's tool list can't be read without a Shortcut account",
        "One official SDK, `@shortcut/client` for JavaScript and TypeScript, and no vendor entry in the official MCP registry"
      ],
      "agentNotes": [
        "Send the v3 token in the `Shortcut-Token` header. v4 (alpha) takes `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens, and v3 tokens don't work there.",
        "Create a story with `name` and `workflow_state_id`. Sending both `workflow_state_id` and `project_id`, or neither, is rejected.",
        "Use `GET /api/v3/search/stories` with `detail=slim`, `page_size` (1 to 250) and the `next` token. Many other v3 list endpoints return every record at once.",
        "Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.",
        "For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as `read` or `story-write`."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 60.2
        }
      ],
      "editorialScores": {
        "ergonomics": 57,
        "maintenance": 73,
        "payments": 30,
        "reliability": 64,
        "schema": 75,
        "security": 54,
        "transparency": 57
      },
      "provenanceScore": 88
    },
    "connect": {
      "install": "npm install @shortcut/client",
      "http": "curl -X GET -H \"Content-Type: application/json\" -H \"Shortcut-Token: $SHORTCUT_API_TOKEN\" -L \"https://api.app.shortcut.com/api/v3/categories\"",
      "claudeCode": "claude mcp add --transport http shortcut https://mcp.shortcut.com/mcp",
      "config": {
        "mcpServers": {
          "shortcut": {
            "url": "https://mcp.shortcut.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/tasks.create",
      "tool": "https://letme.dev/shortcut"
    },
    "notable": [
      "The hosted MCP server is at https://mcp.shortcut.com/mcp with OAuth and no API token, and covers stories (with comments and sub-tasks), epics, iterations, docs and read-only objectives, teams, members and workflows (https://www.shortcut.com/help/integrations/mcp-server)",
      "The OAuth server metadata lists dynamic client registration, PKCE S256 and the scopes openid, admin, comment-write, read, story-write and write (https://api.app.shortcut.com/.well-known/oauth-authorization-server)",
      "The open-source MCP server repository is archived. Its README says all future development is on the hosted server, and the last npm release of `@shortcut/mcp` is 0.25.0 of 24 June 2026 (https://github.com/useshortcut/mcp-server-shortcut)",
      "REST API v4 has been in alpha since 12 May 2026, with a workspace slug in the path, cursor pagination, a `fields` parameter and `sct_ro_` or `sct_rw_` Bearer tokens (https://developer.shortcut.com/api/rest/v4)",
      "The v3 docs give a limit of 200 requests a minute and still accept the token as a `token` query parameter, marked deprecated (https://developer.shortcut.com/api/rest/v3)",
      "Outgoing webhooks fire on story and epic changes and can be signed with HMAC-SHA-256 in a `Payload-Signature` header (https://developer.shortcut.com/api/webhook/v1)",
      "On 15 July 2026 tokens newly created through the MCP server could not write for 2 hours 21 minutes, an incident Shortcut rated major (https://status.shortcut.com/history)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces",
        "value": "REST API v3 at https://api.app.shortcut.com/api/v3 (current), REST API v4 (alpha), outgoing webhooks v1, and the hosted MCP server at https://mcp.shortcut.com/mcp"
      },
      {
        "label": "API coverage",
        "value": "143 operations on 85 paths in v3, among them stories (23), epics (17), objectives (9), documents (8), iterations (8), search (7), labels, files, custom fields, workflows and members"
      },
      {
        "label": "MCP server",
        "value": "Hosted, OAuth only. Stories can be retrieved, created and updated with comments and sub-tasks, epics and iterations retrieved and created, docs retrieved, created and updated, and objectives, teams, members and workflows read. The tool list needs an account and was not read"
      },
      {
        "label": "Credentials",
        "value": "Per-user API tokens in the `Shortcut-Token` header, read-only or read-write. OAuth authorisation code flow with PKCE and dynamic client registration for MCP"
      },
      {
        "label": "Scopes",
        "value": "read, write, story-write, comment-write, admin, plus openid for sign-in"
      },
      {
        "label": "Rate limits",
        "value": "200 requests a minute, answered with 429. No Retry-After header is documented"
      },
      {
        "label": "Pagination",
        "value": "Search endpoints take `page_size` (1 to 250), a `next` token and `detail=slim`. Epics have a paginated list. Other v3 lists return every record. v4 adds cursors with `limit` 1 to 100 and a `fields` parameter"
      },
      {
        "label": "Errors",
        "value": "400 schema mismatch, 404 resource does not exist and 422 unprocessable on every operation, 403 on 13. A live 401 returned JSON with `message` and `tag`"
      },
      {
        "label": "Webhooks",
        "value": "Story and epic create, update and delete events, with comments and tasks included. Registered by API at `/api/v3/integrations/webhook`, optional HMAC-SHA-256 signature in `Payload-Signature`"
      },
      {
        "label": "SDKs",
        "value": "`@shortcut/client` 3.4.1 for JavaScript and TypeScript (22 September 2026, MIT). `@shortcut/mcp` 0.25.0 is the last release of the archived local MCP server"
      },
      {
        "label": "Free tier",
        "value": "Free plan at $0 for up to 10 users with API and webhook access and the MCP server, 5 GB of storage. 14-day trial of paid plans with no card"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2 for security, availability and confidentiality per the security page, report by email request. A BAA for HIPAA on Business and Enterprise"
      },
      {
        "label": "Status",
        "value": "status.shortcut.com on Statuspage, with components for API, Shortcut MCP, Web App, Search and integrations, and incidents back to March 2023"
      },
      {
        "label": "Sub-processors",
        "value": "List updated 12 November 2025 with 33 providers and countries. Hosting on Amazon Web Services in the US. Anthropic is listed for Korey only"
      }
    ],
    "unitPrices": [
      {
        "item": "Free (API, webhooks and MCP server included)",
        "unit": "seat-month",
        "usd": 0,
        "note": "up to 10 users, 5 GB of storage"
      },
      {
        "item": "Team, billed yearly",
        "unit": "seat-month",
        "usd": 8.5,
        "note": "$10 billed monthly, as shown on 2026-10-08"
      },
      {
        "item": "Business, billed yearly",
        "unit": "seat-month",
        "usd": 12,
        "note": "$16 billed monthly, as shown on 2026-10-08"
      }
    ],
    "provenance": {
      "legalEntity": "Shortcut Software Company",
      "domain": "shortcut.com",
      "domainRegistered": "1997-08-01",
      "endpointOnVendorDomain": true,
      "terms": "https://www.shortcut.com/terms/",
      "privacy": "https://www.shortcut.com/privacy/",
      "statusPage": "https://status.shortcut.com",
      "changelog": "https://www.shortcut.com/release-notes/",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service (effective 18 September 2025) name Shortcut Software Company, govern the Service on shortcut.com and korey.ai, and are under New York law. The GDPR notice gives the address 201 Allen St, Unit #10004, New York, NY 10002.",
        "The privacy policy (effective 11 July 2025) covers the websites, the app and the platform.",
        "The API answers at api.app.shortcut.com and the MCP server at mcp.shortcut.com.",
        "www.shortcut.com/.well-known/security.txt returns 404. Reports go to security@shortcut.com under the disclosure policy at shortcut.com/disclosure.",
        "The changelog link is the product release notes. No separate API changelog was found.",
        "RDAP for shortcut.com gives a registration date of 1997-08-01. Shortcut was named Clubhouse until September 2021 per its llms.txt."
      ],
      "score": 88,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Shortcut Software Company",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "shortcut.com, registered 1997-08-01 (29 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.app.shortcut.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.shortcut.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.shortcut.com/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-09-18",
          "words": 2683,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective as of September 18, 2025",
              "says": "Last updated 2025-09-18"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms of Service and performance hereunder shall be construed and governed by the laws of the State of New York without giving effect to conflicts of laws principles.",
              "says": "The law of the State of New York"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "SHORTCUT’S AGGREGATE LIABILITY FOR DIRECT DAMAGES UNDER THESE TERMS OF SERVICE WILL NOT EXCEED THE TOTAL FEES PAID BY SUBSCRIBER HEREUNDER DURING THE SIX (6) MONTHS IMMEDIATELY PRIOR TO THE EVENT GIVING RISE TO THE CLAIM.",
              "says": "Capped at the fees paid in the 6 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If we so choose, all amounts due must be paid by the date specified in the invoice or access and use of the Service may be terminated."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We may change these Terms of Service from time to time, and will post any changes on the Websites or notify you via email, at our option, as soon as such changes are in effect.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": false
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Shortcut may suspend or terminate your access to and use of the Service, in whole or in part, at any time and for any reason;"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The subscriber grants a licence for Shortcut to use its name, logos and trademarks for promotion and marketing, and may opt out by email.",
              "quote": "Subscriber grants Shortcut a non-exclusive, non-transferrable, non-sublicensable, and royalty-free license to use and reproduce Subscriber’s name, logos, and trademarks for promotional and marketing purposes including on Shortcut’s customer lists, advertising, and applicable Websites."
            },
            {
              "date": "2026-10-08",
              "text": "After suspension or termination Shortcut gives access to subscriber data for at least 30 days, except where the account was locked for fraud or potential harm.",
              "quote": "Shortcut will provide you with access to your Subscriber Data for at least 30 days following such termination."
            },
            {
              "date": "2026-10-08",
              "text": "A paying subscriber may end the account before paying the full committed subscription fees only where Shortcut has breached the terms and not cured the breach within 10 business days.",
              "quote": "your right to terminate your account before paying the full amount of fees for the subscription period that you have committed to will be limited to cases where Shortcut has breached these Terms of Service"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.shortcut.com/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-07-11",
          "words": 1942,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective as of July 11th, 2025",
              "says": "Last updated 2025-07-11"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We use one or more third-party analytics services (such as Google Analytics) to evaluate your use of our Websites, and the Platform, compile reports on activity (based on their collection of IP addresses, Internet service provider, browser type, operating system and language, referring and exit pages and URLs, data an…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will retain your personal information in a form that identifies you only for as long as it serves the purpose(s) for which it was initially collected as stated in this Privacy Policy, subsequently authorized, or as allowed under applicable law."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Jump to policy Terms of Service Security Privacy Policy GDPR \u0026 Data Privacy Framework Notice GDPR \u0026 Subprocessors Responsible Disclosure AI Info"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "In the event of a merger, dissolution or similar corporate event, or the sale of all or substantially all of our assets, we expect that the information that we have collected, including personal information, would be transferred to the surviving entity in a merger or the acquiring entity."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to access, correct, delete, or export your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions about this Privacy Policy, please e-mail us at privacy@shortcut.com.",
              "says": "privacy@shortcut.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Jump to policy Terms of Service Security Privacy Policy GDPR \u0026 Data Privacy Framework Notice GDPR \u0026 Subprocessors Responsible Disclosure AI Info",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Inputs and outputs are not used for model training by default, but material sent as explicit feedback or bug reports may be used to train Shortcut's models.",
              "quote": "Only if you explicitly report feedback or bugs to us or otherwise explicitly opt in to our model training (if/when we enable this in the future), then we may use the materials provided to train our models."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/shortcut.json",
    "live": {
      "slug": "shortcut",
      "probe": {
        "target": "https://api.app.shortcut.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:21.490163068Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 247,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 252,
        "p95ms24h": 306,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.shortcut.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:06:25.985770991Z"
      },
      "updatedAt": "2026-10-08T21:12:21.490163068Z"
    }
  }
}
