{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "skyvern",
    "name": "Skyvern",
    "vendor": "Ikonomos Inc. (Skyvern)",
    "vendorUrl": "https://www.skyvern.com",
    "kind": "http-api",
    "category": "browser",
    "summary": "Skyvern is a browser agent that completes multi-step web workflows from natural-language goals using language models and computer vision. It runs as an AGPL-3.0 open-source server or a hosted cloud with a REST API and MCP server.",
    "url": "https://www.anchorterminal.com/tools/skyvern",
    "markdownUrl": "https://www.anchorterminal.com/tools/skyvern.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/skyvern.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/skyvern.json",
    "repo": "https://github.com/Skyvern-AI/skyvern",
    "license": "AGPL-3.0 for the open-source server, SDKs and MCP server. Skyvern Cloud is a proprietary service under Skyvern's terms, and its anti-bot measures aren't in the repository",
    "transports": [
      "http",
      "streamable-http",
      "stdio"
    ],
    "remoteUrl": "https://api.skyvern.com/v1",
    "packages": [
      {
        "registry": "pypi",
        "name": "skyvern"
      },
      {
        "registry": "npm",
        "name": "@skyvern/client"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. Sign up at app.skyvern.com and copy the organisation API key from Settings, sent as `x-api-key`. MCP clients can use OAuth 2.0 with browser sign-in, PKCE and dynamic client registration, with no client ID to configure. Both credentials carry full authority over the organisation. OAuth scopes are identity claims, and there are no read-only or per-endpoint keys (https://www.skyvern.com/docs/developers/api/authentication-and-permissions.md).",
    "pricing": "freemium",
    "pricingNotes": "Free with 5,000 one-time credits and 1 concurrent run, no card and no contract. Hobby $29 a month with 30,000 credits and 10 concurrent runs. Pro $149 with 150,000 credits and 25 concurrent runs. Enterprise is custom. Extra credits can be bought from the Billing page at a price that isn't published. The billing docs count one credit a browser action, while the pricing page puts 5,000 credits at about 170 actions. Self-hosting the AGPL-3.0 server is free with your own model keys (https://www.skyvern.com/pricing, https://www.skyvern.com/docs/cloud/account-settings/billing-usage.md, checked 2026-10-08).",
    "priceSummary": "$29 / mo",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs (llms-full.txt), llms.txt or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 114,
    "popularity": {
      "githubStars": 23155,
      "npmWeekly": 3193,
      "pypiWeekly": 1636,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.skyvern.com/docs",
    "llmsTxt": "https://www.skyvern.com/docs/llms.txt",
    "openapi": "https://www.skyvern.com/docs/api-reference/openapi.json",
    "registryName": "io.github.Skyvern-AI/skyvern",
    "capabilities": [
      "browser.control",
      "browser.hosted",
      "web.extract",
      "automation.workflows",
      "browser.debug"
    ],
    "tags": [
      "official",
      "hosted",
      "open-source",
      "freemium",
      "no-card",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "python",
      "typescript",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-10-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 63.1,
      "grade": "B",
      "agentReady": false,
      "rank": 288,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 10,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 76,
        "maintenance": 85,
        "payments": 32,
        "reliability": 57,
        "schema": 88,
        "security": 59,
        "transparency": 72
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 57,
          "points": 11.4,
          "reason": "Graded as a hosted service, Skyvern Cloud at api.skyvern.com. status.skyvern.com is a Statuspage site with three components (API, web application, async workers), 90-day uptime bars and an incident feed back to March 2025 (20). The feed has one incident in the 90 days to 8 October 2026, marked major by Skyvern, on 6 August, when an upstream model provider rejected requests and task and workflow runs failed at elevated rates from about 21:20 UTC to 22:30, roughly 70 minutes. A 29-minute run of 503s on 3 July falls just outside the window (10). The pricing page gives concurrent runs per plan (1, 10, 25, 100) and API responses carry `ratelimit-policy: \"submit-run\";q=50;w=60`, but we found no documented request limits (8). The OpenAPI document describes 503 with `Retry-After` on run submission and 429 on two recipe endpoints, and the SDKs retry network errors and 5xx with backoff. `Idempotency-Key` exists only on POST /v1/agents, so retried run submissions rely on the 503 saying no run was created (9). The pricing FAQ mentions custom SLAs for Enterprise and nothing is published (0). `/v1` is declared stable (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 88,
          "points": 14.3,
          "reason": "OpenAPI 3.1.0 at /docs/api-reference/openapi.json with 94 operations on 71 paths and 261 schemas, and MCP tools with typed parameters (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). The MCP server ships a routing table that says which tool to use for each kind of job, what each costs in model calls and what not to use it for, and tool docstrings repeat it. Many REST operations have one-line descriptions such as \"Run a task\" (16). Inputs are typed with enums and ranges, such as `limit` 1 to 500 on the audit export, but `skyvern_workflow_create` takes the whole definition as a JSON or YAML string and the spec marks `x-api-key` as optional on every operation (11). Code samples in Python, TypeScript and cURL and a full error-handling guide, while 422 is the only error documented on most operations, with 404 on 31 of 94 and 429 on two (11). `/v1` path versioning with a written compatibility policy and a weekly dated changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "The full MCP surface is 114 tools by the docs' count (5). Scopes cut that to 29 (`operate`), 32 (`lean`), 54 (`browser`) or 60 (`build`) through a URL such as /mcp/x/lean or the `X-Skyvern-Scope` header, and page reads are size-capped and selector-scoped (9, so 14). List endpoints take `page` and `page_size`, with `status`, `search_key`, tag and date filters, and `max_steps` bounds a run (17). MCP results return codes such as SELECTOR_NOT_FOUND and SESSION_EXPIRED with a hint, runs report `status`, `failure_reason` and a caller-defined `error_code_mapping`, and the SDKs raise typed errors. HTTP error bodies are mostly unspecified (16). Every tool has readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source. `Idempotency-Key` covers agent creation only, not run submission (14). A task needs only a prompt, and official SDKs exist for Python and TypeScript (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 59,
          "points": 10.33,
          "reason": "An organisation-wide API key in the `x-api-key` header, revocable and rotated from Settings, or OAuth 2.0 with PKCE, dynamic client registration and rotating single-use refresh tokens. The docs say plainly that OAuth scopes are identity claims and that there are no read-only, per-endpoint or per-resource credentials, so we scored plain revocable keys. No secret travels in a URL (20). MCP tool scopes are documented as a usability filter and not a permission boundary. Separate organisations are the only isolation, Human Interaction blocks are listed for Enterprise, and `skyvern_act` rejects prompts that contain passwords (6). Web pages are untrusted content. Stored credentials reach the browser directly and appear to the model as placeholders, the May 2026 changelog records sanitising of page content in prompt templates, and one tool description says page content is data, not instructions. We found no guidance page on prompt injection (8). GET /v1/audit-events/export returns organisation audit events for a default 90 days as JSON or CSV, and each run keeps a recording, screenshots, an action timeline and a HAR file (14). The site claims SOC 2 Type II and HIPAA on Enterprise, with a trust centre that didn't render for us. SECURITY.md routes reports to GitHub private advisories and its supported-versions table still says 0.1.x. No security.txt and no bug bounty found. The webhook page warns that its verifier examples before August 2026 accepted any signature of the right length (11)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 32,
          "points": 4,
          "reason": "No x402, MPP or L402 in the docs, llms.txt or pricing page (0). Plan prices are public with credit allowances, Free 5,000 credits once, Hobby $29 for 30,000 a month, Pro $149 for 150,000, Enterprise custom. The price of extra credits isn't published, and the pages disagree on what a credit buys, one credit an action in the billing docs against about 170 or about 200 actions for 5,000 credits (12). The Free plan needs no card, per the pricing page (20). Signup is a browser flow, including `skyvern signup` from the CLI, so a person has to create the account (0). The open-source server is free to run under AGPL-3.0 with your own model keys, and we scored the hosted service because that is what the MCP and API docs point agents to."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 85,
          "points": 7.44,
          "reason": "Version 1.0.55 on PyPI and npm on 1 October 2026, seven days before this check (30). Twelve weekly changelog entries since 13 July 2026, and PyPI releases 1.0.47, 1.0.48 and 1.0.55 in the same period (20). The repository had 200 commits between 16 September and 7 October and 48 open issues, several opened in the last fortnight. GitHub didn't show us the replies, and an issue of 8 September 2026 asks whether anyone watches the private advisory queue, so we scored this below full (14). Listed in the official MCP registry as io.github.Skyvern-AI/skyvern, active, but the entry is version 1.0.23 from 13 March 2026 and lists only the API-key header (13). CI runs pre-commit hooks, a migration check, pytest and pip smoke tests on Python 3.11 and 3.13, with a locked dependency file. We couldn't read whether the default branch passes (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 72,
          "points": 6.3,
          "note": "editorial 66, provenance 78",
          "reason": "The core is AGPL-3.0, an OSI licence, in a public repository. The README says anti-bot measures are in the managed cloud only (27). The privacy policy (last modified 1 October 2026) keeps data \"as long as necessary\" with deletion on request and no stated periods. The terms (27 February 2026) say data may go to third-party model providers such as OpenAI and Anthropic and that anonymised data may train models unless you opt out by email. Section 7.3 of the terms says the services aren't designed to comply with HIPAA, while the pricing page lists HIPAA compliance on Enterprise. No public DPA found (12). The deprecation policy promises at least six months' notice, 12 for a major version, a changelog entry, `Deprecation` and `Sunset` headers and `deprecated` flags in the spec (20). Model providers are named only as examples, artifact URLs point to Amazon S3, and no subprocessor list or data location statement was readable. The open-source server discloses PostHog usage telemetry in its README with `SKYVERN_TELEMETRY=false` to turn it off (7)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The full MCP surface is 114 tools by the docs' count (5). Scopes cut that to 29 (`operate`), 32 (`lean`), 54 (`browser`) or 60 (`build`) through a URL such as /mcp/x/lean or the `X-Skyvern-Scope` header, and page reads are size-capped and selector-scoped (9, so 14). List endpoints take `page` and `page_size`, with `status`, `search_key`, tag and date filters, and `max_steps` bounds a run (17). MCP results return codes such as SELECTOR_NOT_FOUND and SESSION_EXPIRED with a hint, runs report `status`, `failure_reason` and a caller-defined `error_code_mapping`, and the SDKs raise typed errors. HTTP error bodies are mostly unspecified (16). Every tool has readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source. `Idempotency-Key` covers agent creation only, not run submission (14). A task needs only a prompt, and official SDKs exist for Python and TypeScript (15).",
          "maintenance": "Version 1.0.55 on PyPI and npm on 1 October 2026, seven days before this check (30). Twelve weekly changelog entries since 13 July 2026, and PyPI releases 1.0.47, 1.0.48 and 1.0.55 in the same period (20). The repository had 200 commits between 16 September and 7 October and 48 open issues, several opened in the last fortnight. GitHub didn't show us the replies, and an issue of 8 September 2026 asks whether anyone watches the private advisory queue, so we scored this below full (14). Listed in the official MCP registry as io.github.Skyvern-AI/skyvern, active, but the entry is version 1.0.23 from 13 March 2026 and lists only the API-key header (13). CI runs pre-commit hooks, a migration check, pytest and pip smoke tests on Python 3.11 and 3.13, with a locked dependency file. We couldn't read whether the default branch passes (8).",
          "payments": "No x402, MPP or L402 in the docs, llms.txt or pricing page (0). Plan prices are public with credit allowances, Free 5,000 credits once, Hobby $29 for 30,000 a month, Pro $149 for 150,000, Enterprise custom. The price of extra credits isn't published, and the pages disagree on what a credit buys, one credit an action in the billing docs against about 170 or about 200 actions for 5,000 credits (12). The Free plan needs no card, per the pricing page (20). Signup is a browser flow, including `skyvern signup` from the CLI, so a person has to create the account (0). The open-source server is free to run under AGPL-3.0 with your own model keys, and we scored the hosted service because that is what the MCP and API docs point agents to.",
          "reliability": "Graded as a hosted service, Skyvern Cloud at api.skyvern.com. status.skyvern.com is a Statuspage site with three components (API, web application, async workers), 90-day uptime bars and an incident feed back to March 2025 (20). The feed has one incident in the 90 days to 8 October 2026, marked major by Skyvern, on 6 August, when an upstream model provider rejected requests and task and workflow runs failed at elevated rates from about 21:20 UTC to 22:30, roughly 70 minutes. A 29-minute run of 503s on 3 July falls just outside the window (10). The pricing page gives concurrent runs per plan (1, 10, 25, 100) and API responses carry `ratelimit-policy: \"submit-run\";q=50;w=60`, but we found no documented request limits (8). The OpenAPI document describes 503 with `Retry-After` on run submission and 429 on two recipe endpoints, and the SDKs retry network errors and 5xx with backoff. `Idempotency-Key` exists only on POST /v1/agents, so retried run submissions rely on the 503 saying no run was created (9). The pricing FAQ mentions custom SLAs for Enterprise and nothing is published (0). `/v1` is declared stable (10).",
          "schema": "OpenAPI 3.1.0 at /docs/api-reference/openapi.json with 94 operations on 71 paths and 261 schemas, and MCP tools with typed parameters (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). The MCP server ships a routing table that says which tool to use for each kind of job, what each costs in model calls and what not to use it for, and tool docstrings repeat it. Many REST operations have one-line descriptions such as \"Run a task\" (16). Inputs are typed with enums and ranges, such as `limit` 1 to 500 on the audit export, but `skyvern_workflow_create` takes the whole definition as a JSON or YAML string and the spec marks `x-api-key` as optional on every operation (11). Code samples in Python, TypeScript and cURL and a full error-handling guide, while 422 is the only error documented on most operations, with 404 on 31 of 94 and 429 on two (11). `/v1` path versioning with a written compatibility policy and a weekly dated changelog (15).",
          "security": "An organisation-wide API key in the `x-api-key` header, revocable and rotated from Settings, or OAuth 2.0 with PKCE, dynamic client registration and rotating single-use refresh tokens. The docs say plainly that OAuth scopes are identity claims and that there are no read-only, per-endpoint or per-resource credentials, so we scored plain revocable keys. No secret travels in a URL (20). MCP tool scopes are documented as a usability filter and not a permission boundary. Separate organisations are the only isolation, Human Interaction blocks are listed for Enterprise, and `skyvern_act` rejects prompts that contain passwords (6). Web pages are untrusted content. Stored credentials reach the browser directly and appear to the model as placeholders, the May 2026 changelog records sanitising of page content in prompt templates, and one tool description says page content is data, not instructions. We found no guidance page on prompt injection (8). GET /v1/audit-events/export returns organisation audit events for a default 90 days as JSON or CSV, and each run keeps a recording, screenshots, an action timeline and a HAR file (14). The site claims SOC 2 Type II and HIPAA on Enterprise, with a trust centre that didn't render for us. SECURITY.md routes reports to GitHub private advisories and its supported-versions table still says 0.1.x. No security.txt and no bug bounty found. The webhook page warns that its verifier examples before August 2026 accepted any signature of the right length (11).",
          "transparency": "The core is AGPL-3.0, an OSI licence, in a public repository. The README says anti-bot measures are in the managed cloud only (27). The privacy policy (last modified 1 October 2026) keeps data \"as long as necessary\" with deletion on request and no stated periods. The terms (27 February 2026) say data may go to third-party model providers such as OpenAI and Anthropic and that anonymised data may train models unless you opt out by email. Section 7.3 of the terms says the services aren't designed to comply with HIPAA, while the pricing page lists HIPAA compliance on Enterprise. No public DPA found (12). The deprecation policy promises at least six months' notice, 12 for a major version, a changelog entry, `Deprecation` and `Sunset` headers and `deprecated` flags in the spec (20). Model providers are named only as examples, artifact URLs point to Amazon S3, and no subprocessor list or data location statement was readable. The open-source server discloses PostHog usage telemetry in its README with `SKYVERN_TELEMETRY=false` to turn it off (7)."
        },
        "sources": [
          {
            "what": "home page",
            "url": "https://www.skyvern.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.skyvern.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index",
            "url": "https://www.skyvern.com/docs/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "full docs text",
            "url": "https://www.skyvern.com/docs/llms-full.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and permissions",
            "url": "https://www.skyvern.com/docs/developers/api/authentication-and-permissions.md",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning and deprecation",
            "url": "https://www.skyvern.com/docs/developers/api/versioning-and-deprecation.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server setup",
            "url": "https://www.skyvern.com/docs/developers/getting-started/mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI document",
            "url": "https://www.skyvern.com/docs/api-reference/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "error handling",
            "url": "https://www.skyvern.com/docs/developers/going-to-production/error-handling.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK error handling and retries",
            "url": "https://www.skyvern.com/docs/sdk-reference/error-handling.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks and signature verification",
            "url": "https://www.skyvern.com/docs/developers/going-to-production/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "cost control",
            "url": "https://www.skyvern.com/docs/developers/optimization/cost-control.md",
            "seen": "2026-10-08"
          },
          {
            "what": "billing and usage",
            "url": "https://www.skyvern.com/docs/cloud/account-settings/billing-usage.md",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://www.skyvern.com/docs/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.skyvern.com",
            "seen": "2026-10-08"
          },
          {
            "what": "incident feed",
            "url": "https://status.skyvern.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth protected-resource metadata",
            "url": "https://api.skyvern.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-08"
          },
          {
            "what": "API response headers, unauthenticated request",
            "url": "https://api.skyvern.com/v1/runs",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.skyvern.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.skyvern.com/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre (didn't render)",
            "url": "https://trust.skyvern.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.skyvern.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "repository at v1.0.55, licence, MCP tool source, CI workflows, SECURITY.md",
            "url": "https://github.com/Skyvern-AI/skyvern",
            "seen": "2026-10-08"
          },
          {
            "what": "open issues list",
            "url": "https://github.com/Skyvern-AI/skyvern/issues",
            "seen": "2026-10-08"
          },
          {
            "what": "SSRF issue",
            "url": "https://github.com/Skyvern-AI/skyvern/issues/6915",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory queue issue",
            "url": "https://github.com/Skyvern-AI/skyvern/issues/8482",
            "seen": "2026-10-08"
          },
          {
            "what": "published advisories (none)",
            "url": "https://github.com/Skyvern-AI/skyvern/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "OSV records for the PyPI package",
            "url": "https://api.osv.dev/v1/query",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=skyvern",
            "seen": "2026-10-08"
          },
          {
            "what": "Python package on PyPI",
            "url": "https://pypi.org/pypi/skyvern/json",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript SDK on npm",
            "url": "https://registry.npmjs.org/@skyvern/client",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/skyvern.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the trust centre at trust.skyvern.com is a JavaScript application that didn't render for our reader, so the SOC 2 Type II report, the HIPAA statement and any subprocessor list rest on the pricing and home pages",
          "unchecked: reply times on GitHub issues and whether CI passes on the default branch. The GitHub API refused us for rate limits and the issue pages didn't show comments",
          "unchecked: whether the SSRF reported in issue 6915 affected Skyvern Cloud, and which release added the SSRF-guarded resolver. The changelog doesn't mention it",
          "What a credit buys. The billing docs say one credit a browser action, the pricing page says 5,000 credits is about 170 actions, the cost-control page about 200, and the pricing FAQ says credits depend on run complexity and duration",
          "Whether the `ratelimit-policy` header (50 run submissions in 60 seconds) is the enforced limit on every plan. It isn't documented",
          "Enterprise concurrency is 100 on the pricing page and unlimited in the billing docs",
          "Whether the permissive webhook verifier examples before August 2026 merit a deduction. We recorded them in the security note and didn't deduct, because the page discloses the fault and we couldn't date the fix",
          "The audit export says only organisation admins and full API keys may export, which implies a restricted key type that the authentication page says doesn't exist",
          "firstReleased is left empty. PyPI's earliest file is 0.1.53 from 6 February 2025, and the repository is older"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "2026-06-30. A public issue reports non-blind SSRF from workflow `http_request` and file download blocks to loopback, private and metadata addresses in version 1.0.39, with a reproduction (https://github.com/Skyvern-AI/skyvern/issues/6915). The issue is still open on 8 October 2026 and no advisory is published, but the 1.0.55 source routes these requests through an SSRF-guarded resolver, so we deduct 3 and not more. We didn't reproduce it, and whether Skyvern Cloud was exposed isn't stated."
      ],
      "verdict": "The hosted MCP server annotates every tool as read-only or destructive and can advertise a 29 or 32-tool subset in place of 114, and the API has a written six-month deprecation policy. Every key and OAuth token carries full organisation authority, with no read-only or scoped credential, and no request rate limits are documented.",
      "bestFor": "Agents that must finish a multi-step job on sites with logins, 2FA and forms, where stored credentials, saved workflows and cached scripts matter more than raw browser time.",
      "strengths": [
        "Every MCP tool carries readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in the 1.0.55 source",
        "Hosted MCP scopes cut the advertised tools from 114 to 29 (`operate`) or 32 (`lean`) by URL or `X-Skyvern-Scope` header",
        "Written deprecation policy with six months' notice, 12 for a major version, and `Deprecation` and `Sunset` response headers",
        "OpenAPI 3.1.0 with 94 operations, llms.txt, Markdown twins of every docs page and a weekly dated changelog",
        "Stored passwords, cards and TOTP secrets are injected into the browser and replaced by placeholders in prompts, recordings and logs, per the docs"
      ],
      "weaknesses": [
        "Every API key and OAuth token has full organisation authority. The docs state there are no read-only, per-endpoint or per-resource keys",
        "No request rate limits in the docs. Responses carry `ratelimit-policy: \"submit-run\";q=50;w=60`, and only plan concurrency is published",
        "What a credit buys is stated three ways (one credit an action, 5,000 credits for about 170 or about 200 actions, by run complexity)",
        "An SSRF report against 1.0.39 from 30 June 2026 is still open with no advisory, though 1.0.55 source has SSRF guards",
        "Retention is \"as long as necessary\", anonymised data may train models unless you opt out by email, and no subprocessor list was readable"
      ],
      "agentNotes": [
        "Connect to https://api.skyvern.com/mcp/x/lean or /x/operate, or send `X-Skyvern-Scope`, so the client loads 32 or 29 tools. The scope filters the list and does not limit permissions",
        "Use a separate Skyvern organisation for each blast radius. Any key or OAuth token can read and write stored credentials and delete workflows",
        "Never pass passwords to `skyvern_act` or `skyvern_type`. Store them as credentials and call `skyvern_login`",
        "Set `max_steps` on tasks, or `x-max-steps-override` on agent runs, to cap credits. A run that reaches the cap ends as `timed_out`",
        "On 503 from POST /v1/run/agents, wait `Retry-After` seconds. No run was created, so resubmitting is safe"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 63.1
        }
      ],
      "editorialScores": {
        "ergonomics": 76,
        "maintenance": 85,
        "payments": 32,
        "reliability": 57,
        "schema": 88,
        "security": 59,
        "transparency": 66
      },
      "provenanceScore": 78
    },
    "connect": {
      "install": "pip install skyvern",
      "http": "curl -X POST \"https://api.skyvern.com/v1/run/tasks\" -H \"x-api-key: YOUR_API_KEY\" -H \"Content-Type: application/json\" -d '{ \"url\": \"https://example.com\", \"prompt\": \"Extract the pricing table\" }'",
      "claudeCode": "claude mcp add --transport http skyvern https://api.skyvern.com/mcp/ --scope user",
      "config": {
        "mcpServers": {
          "Skyvern": {
            "headers": {
              "x-api-key": "YOUR_SKYVERN_API_KEY"
            },
            "type": "streamable-http",
            "url": "https://api.skyvern.com/mcp/"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/browser.control",
      "tool": "https://letme.dev/skyvern"
    },
    "notable": [
      "The hosted MCP server at https://api.skyvern.com/mcp accepts OAuth or `x-api-key`, and scopes `operate`, `build`, `browser` and `lean` narrow the advertised tools without narrowing permissions (https://www.skyvern.com/docs/developers/api/authentication-and-permissions.md)",
      "Every MCP tool is registered with readOnlyHint, destructiveHint and openWorldHint annotations, 117 registrations in skyvern/cli/mcp_tools/__init__.py at v1.0.55 (https://github.com/Skyvern-AI/skyvern)",
      "The deprecation policy promises at least six months' notice, 12 months for a major version, and `Deprecation` and `Sunset` headers (https://www.skyvern.com/docs/developers/api/versioning-and-deprecation.md)",
      "One incident in the 90 days to 8 October 2026, elevated task and workflow failures for about 70 minutes on 6 August after an upstream model provider rejected requests (https://status.skyvern.com/api/v2/incidents.json)",
      "A public issue of 30 June 2026 reports SSRF from workflow HTTP and download blocks in 1.0.39. It is still open, and the 1.0.55 source has an SSRF-guarded resolver (https://github.com/Skyvern-AI/skyvern/issues/6915)",
      "The webhook docs warn that verifier examples published before August 2026 accepted any signature of the right length (https://www.skyvern.com/docs/developers/going-to-production/webhooks.md)",
      "The MCP registry entry is version 1.0.23 from 13 March 2026, while PyPI and npm are at 1.0.55 from 1 October 2026 (https://registry.modelcontextprotocol.io/v0/servers?search=skyvern)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Graded surface",
        "value": "Skyvern Cloud, the REST API at https://api.skyvern.com/v1 and the hosted MCP server at https://api.skyvern.com/mcp. The same code is open source under AGPL-3.0 for self-hosting with your own model keys"
      },
      {
        "label": "MCP server",
        "value": "Official. Hosted over streamable HTTP with OAuth or `x-api-key`, or local stdio with `python -m skyvern run mcp` against a self-hosted server. 114 tools at full scope, 29 `operate`, 60 `build`, 54 `browser`, 32 `lean`, chosen by /mcp/x/\u003cscope\u003e or `X-Skyvern-Scope`"
      },
      {
        "label": "Credentials",
        "value": "Organisation-wide API key in `x-api-key`, no expiry, rotated in Settings. OAuth 2.0 authorisation code with PKCE S256, dynamic client registration and rotating refresh tokens. OAuth scopes are identity claims only. No read-only or scoped credential"
      },
      {
        "label": "Free tier",
        "value": "5,000 credits once, 1 concurrent run, no card. The pricing page estimates about 170 actions and the billing docs about 200"
      },
      {
        "label": "Plans",
        "value": "Hobby $29 a month, 30,000 credits, 10 concurrent runs. Pro $149, 150,000 credits, 25 concurrent, residential proxies, TOTP and 1Password. Enterprise custom, 100 concurrent, HIPAA and the SOC 2 report"
      },
      {
        "label": "Rate limits",
        "value": "Concurrent runs per plan are published. No request limits in the docs. Responses carry `ratelimit-policy: \"submit-run\";q=50;w=60`, and run submission can answer 503 with `Retry-After`"
      },
      {
        "label": "Errors",
        "value": "Terminal run statuses include `completed`, `failed`, `terminated` and `timed_out`, with `failure_reason` and a caller-defined `error_code_mapping`. MCP results carry codes such as SELECTOR_NOT_FOUND with a hint"
      },
      {
        "label": "SDKs",
        "value": "Python `skyvern` 1.0.55 (Python 3.11 to 3.14) and TypeScript `@skyvern/client` 1.0.55, both 1 October 2026, generated from the OpenAPI document"
      },
      {
        "label": "Audit",
        "value": "GET /v1/audit-events/export, default window 90 days, JSON or CSV, up to 500 a page. Each run keeps a recording, screenshots, an action timeline and a HAR file"
      },
      {
        "label": "Deprecations",
        "value": "At least six months' notice, 12 for a major version, `Deprecation` and `Sunset` headers, `deprecated` flags in the OpenAPI document. No /v1 endpoint is deprecated today"
      },
      {
        "label": "Status",
        "value": "status.skyvern.com on Statuspage, three components. One incident in the 90 days to 8 October 2026, about 70 minutes of elevated run failures on 6 August"
      },
      {
        "label": "Reuse terms",
        "value": "You are responsible for the target site's terms and for authorisation to automate it. Data may be sent to third-party model providers, and anonymised data may train models unless you opt out by email"
      }
    ],
    "unitPrices": [
      {
        "item": "Hobby plan",
        "unit": "month",
        "usd": 29,
        "note": "30,000 credits, 10 concurrent runs"
      },
      {
        "item": "Pro plan",
        "unit": "month",
        "usd": 149,
        "note": "150,000 credits, 25 concurrent runs"
      },
      {
        "item": "Skyvern SMS number, Pro plan",
        "unit": "month",
        "usd": 10,
        "note": "per number, for SMS 2FA codes"
      }
    ],
    "provenance": {
      "legalEntity": "Ikonomos Inc.",
      "domain": "skyvern.com",
      "domainRegistered": "2023-10-16",
      "endpointOnVendorDomain": true,
      "terms": "https://www.skyvern.com/terms",
      "privacy": "https://www.skyvern.com/privacy",
      "statusPage": "https://status.skyvern.com",
      "changelog": "https://www.skyvern.com/docs/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms (last modified 27 February 2026) and privacy policy (last modified 1 October 2026) name Ikonomos Inc., doing business as Skyvern, with Delaware law governing the terms.",
        "The API and the hosted MCP server answer at api.skyvern.com. OAuth is issued through clerk.skyvern.com, backed by Clerk.",
        "www.skyvern.com/.well-known/security.txt and api.skyvern.com/.well-known/security.txt both return 404. SECURITY.md in the repository sends reports to GitHub private advisories.",
        "RDAP for skyvern.com gives a registration date of 2023-10-16.",
        "docs.skyvern.com redirects to www.skyvern.com/docs."
      ],
      "score": 78,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Ikonomos Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "skyvern.com, registered 2023-10-16 (2 years)",
          "points": 7,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.skyvern.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects",
          "points": 9.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 7.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.skyvern.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.skyvern.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-02-27",
          "words": 3039,
          "points": 9.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Modified: 27 February, 2026",
              "says": "Last updated 2026-02-27"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms and any dispute arising out of or relating to these Terms or the Services shall be governed by and construed in accordance with the laws of the State of Delaware, without giving effect to any choice or conflict of law provision or rule.",
              "says": "The law of the State of Delaware"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Limitation of Liability: Our liability is limited to the fees you paid in the prior 12 months.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may modify, suspend, or discontinue any aspect of the Services at any time."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Your continued use of the Services following the posting of revised Terms constitutes your acceptance of such changes.",
              "says": "Changes are posted, with no other notice named"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to these Terms, you must not access or use the Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "We may use anonymized or aggregated data for service improvement and model training; and"
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may terminate or suspend your access to the Services immediately, without prior notice or liability, for any reason, including if you breach these Terms."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Dispute Resolution: Disputes are governed by Delaware law and subject to binding arbitration."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer alone is responsible for complying with the terms and acceptable use policies of any third-party website it accesses through the service.",
              "quote": "You are solely responsible for compliance with the terms of service, acceptable use policies, and other agreements of any third-party websites you access through the Services."
            },
            {
              "date": "2026-10-08",
              "text": "A claim must be started within one year of the cause of action arising or it is permanently barred.",
              "quote": "Any cause of action or claim you may have arising out of or relating to these Terms or the Services must be commenced within one (1) year after the cause of action accrues; otherwise, such cause of action or claim is permanently barred."
            },
            {
              "date": "2026-10-08",
              "text": "Customer data may be sent to and processed by third-party LLM providers, with OpenAI and Anthropic named as examples.",
              "quote": "Your data may be transmitted to and processed by third-party LLM providers (such as OpenAI and Anthropic);"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.skyvern.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-10-01",
          "words": 3903,
          "points": 7.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Modified: 1 October, 2026",
              "says": "Last updated 2026-10-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This policy describes the types of information we may collect from you or that you may provide when you use our website skyvern.com (our \"Website\") and our AI-powered browser automation platform and services (collectively, the \"Services\"), and our practices for collecting, using, maintaining, protecting, and disclosin…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain Google user data only as long as needed to provide the feature, which includes keeping it in the workflow run results you can view in Skyvern (see Data Retention below, including how to request deletion).",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "From third parties, including business-information providers, visitor-identification partners, and public professional sources such as company websites and professional profiles."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Residents of certain states under 13, 16, or 18 years of age may have additional rights regarding the collection and sale of their personal information."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "This disclosure does not limit your rights under applicable privacy laws."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "To ask questions or comment about this privacy policy and our privacy practices, contact us at:"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "To train and improve our machine learning models using anonymized data.",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Screenshots of automation sessions are sent to LLM providers including OpenAI, Anthropic, Google Gemini, Azure OpenAI and AWS Bedrock.",
              "quote": "We send screenshots to LLM providers (including OpenAI, Anthropic, Google Gemini, Azure OpenAI, and AWS Bedrock) for AI-powered visual analysis and automation processing."
            },
            {
              "date": "2026-10-08",
              "text": "Connecting the Google Drive integration grants Skyvern full access to the files in the customer's Google Drive, which it says it uses only for uploads and folder lookups.",
              "quote": "connecting this integration grants Skyvern full access to the files in your Google Drive; we use that access only for the uploads and folder lookups described here, and do not read, modify, or delete your other Drive content."
            },
            {
              "date": "2026-10-08",
              "text": "Automation tasks are performed through residential proxy networks.",
              "quote": "Proxy Network Providers: We use residential proxy networks to perform automation tasks."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/skyvern.json",
    "live": {
      "slug": "skyvern",
      "probe": {
        "target": "https://api.skyvern.com/v1",
        "method": "get",
        "lastAt": "2026-10-08T17:36:45.470189079Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 266,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 266,
        "p95ms24h": 395,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.skyvern.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:25:48.185671564Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "Skyvern-AI/skyvern",
          "version": "v1.0.55",
          "released": "2026-10-01",
          "seenAt": "2026-10-08T16:29:40.13703893Z"
        },
        {
          "registry": "npm",
          "name": "@skyvern/client",
          "version": "1.0.55",
          "seenAt": "2026-10-08T16:29:38.30771301Z"
        },
        {
          "registry": "pypi",
          "name": "skyvern",
          "version": "1.0.55",
          "released": "2026-10-01",
          "seenAt": "2026-10-08T16:29:38.116994413Z"
        }
      ],
      "githubStars": 23157,
      "npmWeekly": 3193,
      "pypiWeekly": 1636,
      "securityTxt": {
        "url": "https://skyvern.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:39:09.6365622Z"
      },
      "updatedAt": "2026-10-08T17:36:45.470189079Z"
    }
  }
}
