{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "sprout-social",
    "name": "Sprout Social API",
    "vendor": "Sprout Social, Inc.",
    "vendorUrl": "https://sproutsocial.com",
    "kind": "http-api",
    "category": "social-media",
    "summary": "Sprout Social is a social media management suite. Its REST API reads profile and post analytics, inbox messages, listening topics and cases for connected profiles, and creates draft posts with media, on plans that include API access.",
    "url": "https://www.anchorterminal.com/tools/sprout-social",
    "markdownUrl": "https://www.anchorterminal.com/tools/sprout-social.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sprout-social.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sprout-social.json",
    "license": "Proprietary service under the Sprout Social Developer Terms and Terms of Service",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.sproutsocial.com",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access needs a Sprout account on a plan with API access, a user holding the API Permissions permission, and acceptance of the API terms on the API page of Settings. That user then creates an OAuth client or an API token in the same page, with no review by Sprout described. OAuth 2.0 is the recommended route. A client ID and secret are exchanged at identity.sproutsocial.com for a short-lived JWT with the client credentials grant and `scope=organization_id`, or a user-based flow signs a Sprout user in. API tokens are named and can be invalidated. Either credential goes in the `Authorization: Bearer` header. No per-endpoint scopes are documented.",
    "pricing": "paid",
    "pricingNotes": "The Sprout API is listed on the Advanced plan at $399 per seat a month and on Enterprise (custom price). Standard is $199 and Professional $299 per seat a month, without the API. The page shows these prices beside an annual billing note. A 30-day trial needs no credit card. Whether the trial includes API access was not established, and there is no sandbox or per-call price (https://sproutsocial.com/pricing/, checked 2026-10-09).",
    "priceSummary": "$399 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the Developer Terms or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://api.sproutsocial.com/docs/",
    "capabilities": [
      "social.analytics",
      "social.comments",
      "social.media-upload"
    ],
    "tags": [
      "hosted",
      "enterprise",
      "oauth",
      "closed-source",
      "status-page",
      "soc2",
      "iso27001",
      "analytics",
      "listening",
      "drafts-only"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 54.7,
      "grade": "C",
      "agentReady": false,
      "rank": 679,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 8,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 59,
        "maintenance": 38,
        "payments": 20,
        "reliability": 71,
        "schema": 51,
        "security": 61,
        "transparency": 70
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 71,
          "points": 14.2,
          "reason": "Hosted lines. A public status page on Atlassian Statuspage with a separate Sprout Social API component and incident history (20). The history feed shows six incidents in the 90 days to 9 October 2026. Four were traced to Meta, Reddit or Threads, two were on Sprout's Trellis assistant (one a 22-minute outage on 6 August), and one on 20 July was platform performance trouble resolved in about two hours with no severity stated. None named the API component, so we read the record as minor incidents only (20). Rate limits are published as 60 requests a minute and 250,000 a month (15). 429 is documented with the advice to slow down, and the media upload section advises exponential back-off on 5xx, but no `Retry-After` header or idempotency key for post creation was found (6). No SLA was found in the Terms of Service or Developer Terms. The security page gives 99.9 per cent uptime as an internal target (0). The API is not labelled beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 51,
          "points": 8.29,
          "reason": "No OpenAPI file or other machine-readable description was found in the docs (0). The site's llms.txt lists marketing articles and no API page, and the docs are one HTML page with no Markdown twin (2). Each endpoint group states its purpose and has a Limitations section, and the overview lists what the API does not include (14). Request keys are tabulated with example values, limits and a few enumerations such as `media_type`, but filters are strings in a small expression syntax such as `created_time.in(...)` (9). Every endpoint has an example request and response, and a status code table gives a corrective action for each code. The error body is one free-text string (11). Versioning is MAJOR.MINOR with version response headers, and the changelog is dated from November 2020 to 6 October 2026 (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 59,
          "points": 9.59,
          "reason": "Messages and posts requests take a `fields` list and return only `guid` without it, and analytics requests name their metrics (20). Paging by page number or `page_cursor`, `limit` up to 100, filters and sort are documented, with a 10,000 result cap on numbered pages (18). The status code table tells the caller what to do for each code and every response carries `X-Sprout-Request-ID`, but there are no machine-readable error codes (11). No idempotency key was found. Post creation is draft-only, which limits the harm of a repeated call, and media parts are numbered so a part can be resent (5). No SDK was found, and every call needs a customer ID looked up first (5)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 61,
          "points": 10.68,
          "reason": "OAuth 2.0 client credentials issue short-lived JWT access tokens, a user-based flow is available, and API tokens are named and can be invalidated. The only scope documented is `organization_id`, so a credential is not limited to reading or to one endpoint group. Credentials travel in the Authorization header only (22). No read-only credential is documented. The API can write only draft posts and media, the app has approval workflows, and API access can be limited to IP ranges per the product security page (12). The messages and listening endpoints return text written by the public, and no guidance on untrusted content was found (2). The app has a customer-facing audit trail of over fifty events. Whether API calls appear in it was not established (8). Responsible Disclosure Policy with a Bugcrowd vulnerability disclosure programme, SOC 2 Type 2, ISO 27001, ISO 27701 and CSA STAR Level 1 on the trust centre. No security.txt and no paid bounty stated (17)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402 or other machine payment protocol (0). Plan prices are public and the API is listed on Advanced at $399 per seat a month, with no per-call price (10). A 30-day trial needs no credit card, but whether it includes API access was not established, so half marks (10). A person has to sign up, hold the API Permissions permission and accept the API terms in settings (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 38,
          "points": 3.33,
          "reason": "The newest changelog entry is dated 6 October 2026 (30). It is the only dated entry in the 90 days to 9 October 2026. The two before it are 15 June and 10 June (0). A public changelog, a help centre and a community site are linked. The Developer Terms say they entitle the developer to no support for the API (8). No official SDK was found (0). No package to assess (0)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 70,
          "points": 6.13,
          "note": "editorial 55, provenance 85",
          "reason": "Closed service with published Developer Terms (9 May 2024) and Terms of Service (9 May 2025) from Sprout Social, Inc. (15). The privacy policy of 16 September 2026 covers the services and states the processor role, the Terms of Service allow account content to be removed within 30 days of termination, and the docs say uploaded media is kept for 24 hours. The policy gives no retention periods, and the DPA is a PDF we did not read (20). The changelog carries dated notices of removed metrics, most of them forced by Meta. The Developer Terms promise only reasonable efforts, when possible, to give notice that a version will stop being supported (8). Hosting is disclosed to the cloud region, all in the United States. The privacy policy lists service providers by category, and a named sub-processor list was not found on the pages read (12)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Messages and posts requests take a `fields` list and return only `guid` without it, and analytics requests name their metrics (20). Paging by page number or `page_cursor`, `limit` up to 100, filters and sort are documented, with a 10,000 result cap on numbered pages (18). The status code table tells the caller what to do for each code and every response carries `X-Sprout-Request-ID`, but there are no machine-readable error codes (11). No idempotency key was found. Post creation is draft-only, which limits the harm of a repeated call, and media parts are numbered so a part can be resent (5). No SDK was found, and every call needs a customer ID looked up first (5).",
          "maintenance": "The newest changelog entry is dated 6 October 2026 (30). It is the only dated entry in the 90 days to 9 October 2026. The two before it are 15 June and 10 June (0). A public changelog, a help centre and a community site are linked. The Developer Terms say they entitle the developer to no support for the API (8). No official SDK was found (0). No package to assess (0).",
          "payments": "No x402 or other machine payment protocol (0). Plan prices are public and the API is listed on Advanced at $399 per seat a month, with no per-call price (10). A 30-day trial needs no credit card, but whether it includes API access was not established, so half marks (10). A person has to sign up, hold the API Permissions permission and accept the API terms in settings (0).",
          "reliability": "Hosted lines. A public status page on Atlassian Statuspage with a separate Sprout Social API component and incident history (20). The history feed shows six incidents in the 90 days to 9 October 2026. Four were traced to Meta, Reddit or Threads, two were on Sprout's Trellis assistant (one a 22-minute outage on 6 August), and one on 20 July was platform performance trouble resolved in about two hours with no severity stated. None named the API component, so we read the record as minor incidents only (20). Rate limits are published as 60 requests a minute and 250,000 a month (15). 429 is documented with the advice to slow down, and the media upload section advises exponential back-off on 5xx, but no `Retry-After` header or idempotency key for post creation was found (6). No SLA was found in the Terms of Service or Developer Terms. The security page gives 99.9 per cent uptime as an internal target (0). The API is not labelled beta (10).",
          "schema": "No OpenAPI file or other machine-readable description was found in the docs (0). The site's llms.txt lists marketing articles and no API page, and the docs are one HTML page with no Markdown twin (2). Each endpoint group states its purpose and has a Limitations section, and the overview lists what the API does not include (14). Request keys are tabulated with example values, limits and a few enumerations such as `media_type`, but filters are strings in a small expression syntax such as `created_time.in(...)` (9). Every endpoint has an example request and response, and a status code table gives a corrective action for each code. The error body is one free-text string (11). Versioning is MAJOR.MINOR with version response headers, and the changelog is dated from November 2020 to 6 October 2026 (15).",
          "security": "OAuth 2.0 client credentials issue short-lived JWT access tokens, a user-based flow is available, and API tokens are named and can be invalidated. The only scope documented is `organization_id`, so a credential is not limited to reading or to one endpoint group. Credentials travel in the Authorization header only (22). No read-only credential is documented. The API can write only draft posts and media, the app has approval workflows, and API access can be limited to IP ranges per the product security page (12). The messages and listening endpoints return text written by the public, and no guidance on untrusted content was found (2). The app has a customer-facing audit trail of over fifty events. Whether API calls appear in it was not established (8). Responsible Disclosure Policy with a Bugcrowd vulnerability disclosure programme, SOC 2 Type 2, ISO 27001, ISO 27701 and CSA STAR Level 1 on the trust centre. No security.txt and no paid bounty stated (17).",
          "transparency": "Closed service with published Developer Terms (9 May 2024) and Terms of Service (9 May 2025) from Sprout Social, Inc. (15). The privacy policy of 16 September 2026 covers the services and states the processor role, the Terms of Service allow account content to be removed within 30 days of termination, and the docs say uploaded media is kept for 24 hours. The policy gives no retention periods, and the DPA is a PDF we did not read (20). The changelog carries dated notices of removed metrics, most of them forced by Meta. The Developer Terms promise only reasonable efforts, when possible, to give notice that a version will stop being supported (8). Hosting is disclosed to the cloud region, all in the United States. The privacy policy lists service providers by category, and a named sub-processor list was not found on the pages read (12)."
        },
        "sources": [
          {
            "what": "API documentation (one page)",
            "url": "https://api.sproutsocial.com/docs/",
            "seen": "2026-10-09"
          },
          {
            "what": "API changelog",
            "url": "https://api.sproutsocial.com/docs/changelog/",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://sproutsocial.com/pricing/",
            "seen": "2026-10-09"
          },
          {
            "what": "Sprout Social Developer Terms, last updated 9 May 2024",
            "url": "https://sproutsocial.com/legal/api-terms-of-service/",
            "seen": "2026-10-09"
          },
          {
            "what": "Terms of Service, effective 9 May 2025",
            "url": "https://sproutsocial.com/legal/terms/",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy, last updated 16 September 2026",
            "url": "https://sproutsocial.com/legal/privacy-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "security centre",
            "url": "https://sproutsocial.com/security/",
            "seen": "2026-10-09"
          },
          {
            "what": "product security page for the Sprout application",
            "url": "https://sproutsocial.com/security/sprout-social-application/",
            "seen": "2026-10-09"
          },
          {
            "what": "trust centre (certifications)",
            "url": "https://sproutsocial.com/trust-center/",
            "seen": "2026-10-09"
          },
          {
            "what": "Responsible Disclosure Policy",
            "url": "https://sproutsocial.com/legal/responsible-disclosure-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://www.sproutsocialstatus.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "status history feed linked from the status page (25 incidents, 5 December 2025 to 25 September 2026)",
            "url": "https://www.sproutsocialstatus.com/history.atom",
            "seen": "2026-10-09"
          },
          {
            "what": "llms.txt (marketing articles only)",
            "url": "https://sproutsocial.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt (answered 404)",
            "url": "https://sproutsocial.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt for sproutsocial.com (200, no disallow rules)",
            "url": "https://sproutsocial.com/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt for api.sproutsocial.com (answered 404, so no rules published)",
            "url": "https://api.sproutsocial.com/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt for the status host (200, disallows /api/ and /embed/, neither read)",
            "url": "https://www.sproutsocialstatus.com/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP record for sproutsocial.com (the registry's robots.txt answered 400)",
            "url": "https://rdap.verisign.com/com/v1/domain/sproutsocial.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: whether the 30-day trial includes API access. The pricing page lists the API on Advanced and the docs send readers to sales or support, so Payments takes half marks for the trial",
          "unchecked: the Data Processing Addendum (a PDF on media.sproutsocial.com) and the Customer Trust Portal at trust.sproutsocial.com, so a named sub-processor list and retention periods may exist that we did not read",
          "unchecked: the Bugcrowd programme page, so whether rewards are paid is not established",
          "unchecked: the help centre at support.sproutsocial.com, which the docs link for plan requirements, media limits and audit trail details",
          "unchecked: whether API calls are recorded in the audit trail",
          "The status feed gives no severity for the 20 July 2026 performance incident (09:46 to 11:39 CDT). Read as a major outage it would lower Reliability by 10",
          "The lead was right about the interface. One correction, the API creates draft posts only and cannot publish, so `social.post` and `social.schedule` are left out of the capabilities",
          "The Developer Terms forbid monitoring the API's availability, performance or functionality for benchmarking (section 3s), combining the API with software not authorised by Sprout Social (3l) and testing the vulnerability of its systems (3o). No deduction taken. The owner should read these before any probe is run",
          "The docs name no MCP server, SDK or OpenAPI file. We did not search beyond the pages the docs and the main site link"
        ]
      },
      "negative": 0,
      "verdict": "The API reads analytics, inbox messages, listening topics and cases across the main networks, with OAuth client credentials, field selection and a dated changelog. It creates draft posts only, so a person must publish them in Sprout. Access needs the Advanced plan at $399 per seat a month, and no OpenAPI file or SDK was found.",
      "bestFor": "Reporting agents that pull profile, post, inbox, listening and case data for a company that already pays for Sprout Social, and for drafting posts a person will approve.",
      "strengths": [
        "OAuth 2.0 client credentials issue short-lived JWT access tokens, and named API tokens can be invalidated in settings",
        "Rate limits are published as 60 requests a minute and 250,000 a month",
        "Messages and post requests take a `fields` list and return only `guid` when it is omitted, with `limit` up to 100 and cursor paging",
        "The status page has a separate Sprout Social API component, and no incident in the 90 days to 9 October 2026 named it",
        "SOC 2 Type 2, ISO 27001 and ISO 27701 are listed on the trust centre, with a vulnerability disclosure programme on Bugcrowd"
      ],
      "weaknesses": [
        "Posts can be created only as drafts (`is_draft: true`), so the API cannot publish or schedule a post without a person in Sprout",
        "API access is listed on the Advanced plan at $399 per seat a month and on Enterprise, with no per-call price",
        "No OpenAPI file, SDK or MCP server was found in the reviewed documentation",
        "No idempotency key on post creation, and no `Retry-After` header documented for 429 responses",
        "The Developer Terms of 9 May 2024 forbid monitoring the API's availability or performance for benchmarking, and combining the API with software Sprout Social has not authorised. Recorded as a fact with no deduction. It matters before any probe is run"
      ],
      "agentNotes": [
        "Call `GET /v1/metadata/client` first for the customer ID, then `GET /v1/\u003ccustomer ID\u003e/metadata/customer` for profile and group IDs. Every other path needs them",
        "Send `is_draft: true` on `POST /v1/\u003ccustomer ID\u003e/publishing/posts`. Tell the user the draft waits in the Sprout calendar for a person to publish",
        "Name the `fields` you want on messages and posts requests. Without the list only `guid` comes back",
        "Stay under 60 requests a minute and 250,000 a month, and back off on 429 on your own because no `Retry-After` is documented",
        "Check the response when a draft names several profiles. A profile that cannot take the attached media is dropped with no error"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 54.7
        }
      ],
      "editorialScores": {
        "ergonomics": 59,
        "maintenance": 38,
        "payments": 20,
        "reliability": 71,
        "schema": 51,
        "security": 61,
        "transparency": 55
      },
      "provenanceScore": 85
    },
    "connect": {
      "http": "curl https://api.sproutsocial.com/v1/metadata/client -H \"Authorization: Bearer $TOKEN\" -H \"Accept: application/json\""
    },
    "letme": {
      "capability": "https://letme.dev/social.analytics",
      "tool": "https://letme.dev/sprout-social"
    },
    "notable": [
      "Create Publishing Post accepts only drafts, and a post read back by `publishing_post_id` always shows `delivery_status: PENDING`, even after it was published (https://api.sproutsocial.com/docs/#publishing-post-endpoints)",
      "The API leaves out paid (ad account) data, listening data from X, message-level listening data from Reddit, and review data from Yelp, Trustpilot, Tripadvisor and Glassdoor (https://api.sproutsocial.com/docs/)",
      "X data needs a separate Sprout API X Content End User Licence Agreement accepted in settings before the API returns it (https://api.sproutsocial.com/docs/#x-data-x-content-end-user-license-agreement)",
      "Uploaded media is kept for 24 hours unless a post uses it. Single uploads take up to 50 MiB, and larger files go in parts of 5 MiB (https://api.sproutsocial.com/docs/#simple-media-upload)",
      "Responses are capped at 10,000 results with page numbers, and cursor paging is documented for larger sets (https://api.sproutsocial.com/docs/)",
      "The Developer Terms require cached data to be refreshed at least every 24 hours and a user's data deleted within 30 days of a deletion request (https://sproutsocial.com/legal/api-terms-of-service/)",
      "The changelog runs from an initial release in November 2020 to an entry of 6 October 2026 (https://api.sproutsocial.com/docs/changelog/)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Endpoints",
        "value": "20 documented operations under `https://api.sproutsocial.com/v1`. Eight metadata reads, profile and post analytics, inbox messages, listening topic messages and metrics, cases, create and retrieve publishing post, and four media upload calls"
      },
      {
        "label": "Networks",
        "value": "Analytics for X, Facebook, Instagram, LinkedIn, YouTube, Pinterest, Threads, TikTok and Bluesky. Draft posts for Instagram Business and Creator, Facebook Pages, Threads, X, LinkedIn Pages and personal profiles, YouTube, TikTok, Pinterest and Google My Business"
      },
      {
        "label": "Writes",
        "value": "Draft posts and media uploads only. No reply, tag, case update, delete or direct publish call is documented"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 from identity.sproutsocial.com (client credentials for machine-to-machine, or a user-based flow with redirect URIs), or an API token created on the API page of Settings. Both go in the `Authorization: Bearer` header"
      },
      {
        "label": "Plan gate",
        "value": "The pricing page lists the Sprout API on Advanced ($399 per seat a month) and Enterprise. A user needs the API Permissions permission, and the account must accept the API terms in settings"
      },
      {
        "label": "Rate limits",
        "value": "60 requests a minute and 250,000 a month. 429 means too fast or the monthly allowance is used up"
      },
      {
        "label": "Paging",
        "value": "Profiles 1,000 results a page, posts 50, messages and cases `limit` up to 100 with `page_cursor` (next page only). 10,000 results at most by page number"
      },
      {
        "label": "Versioning",
        "value": "MAJOR.MINOR. The path carries the major version, and `X-Sprout-API-Version` and `X-Sprout-Server-Version` response headers carry the rest. `X-Sprout-Request-ID` on every response"
      },
      {
        "label": "Status",
        "value": "www.sproutsocialstatus.com on Atlassian Statuspage, with components for the web application and the API. Six incidents between 20 July and 25 September 2026, four of them traced to Meta, Reddit or Threads and two to Sprout's Trellis assistant"
      },
      {
        "label": "Hosting",
        "value": "AWS us-east-1 (primary) and us-west-2 (secondary), with Google Cloud us-central1 for disaster recovery and backup, all in the United States"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2, ISO 27001, ISO 27701 and CSA STAR Level 1 per the trust centre. Vulnerability disclosure programme on Bugcrowd"
      },
      {
        "label": "Tableau",
        "value": "A Tableau web data connector at `https://api.sproutsocial.com/tableau/` takes the same API token"
      }
    ],
    "unitPrices": [
      {
        "item": "Advanced",
        "unit": "seat-month",
        "usd": 399,
        "note": "Cheapest plan that lists the Sprout API. Price shown beside an annual billing note"
      },
      {
        "item": "Professional",
        "unit": "seat-month",
        "usd": 299,
        "note": "No API access listed"
      },
      {
        "item": "Standard",
        "unit": "seat-month",
        "usd": 199,
        "note": "No API access listed"
      }
    ],
    "provenance": {
      "legalEntity": "Sprout Social, Inc.",
      "domain": "sproutsocial.com",
      "domainRegistered": "2009-09-22",
      "endpointOnVendorDomain": true,
      "terms": "https://sproutsocial.com/legal/api-terms-of-service/",
      "privacy": "https://sproutsocial.com/legal/privacy-policy/",
      "statusPage": "https://www.sproutsocialstatus.com/",
      "changelog": "https://api.sproutsocial.com/docs/changelog/",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Sprout Social Developer Terms (last updated 9 May 2024) are the agreement the API docs link, between the developer and Sprout Social, Inc. They sit on top of the Terms of Service (effective 9 May 2025) at https://sproutsocial.com/legal/terms/.",
        "The Terms of Service give the notice address as Sprout Social, Inc., 131 S. Dearborn Suite 700, Chicago, Illinois 60603.",
        "The privacy policy (last updated 16 September 2026) says it applies to the websites and services, app.sproutsocial.com among them, and that Sprout Social is a data processor for customer data.",
        "https://sproutsocial.com/.well-known/security.txt answered 404. Reports go through the Bugcrowd programme named in the Responsible Disclosure Policy.",
        "The API answers at api.sproutsocial.com and tokens come from identity.sproutsocial.com.",
        "RDAP for sproutsocial.com gives a registration date of 2009-09-22 and GoDaddy Corporate Domains, LLC as registrar."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Sprout Social, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "sproutsocial.com, registered 2009-09-22 (17 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.sproutsocial.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "www.sproutsocialstatus.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://sproutsocial.com/legal/api-terms-of-service/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2024-05-09",
          "words": 6048,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: May 9, 2024",
              "says": "Last updated 2024-05-09"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms will be interpreted, construed, and enforced in all respects in accordance with the local laws of the State of Illinois, U.S.A., without reference to its choice of law rules and not including the provisions of the 1980 U.N.",
              "says": "The law of the State of Illinois"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "TO THE FULLEST EXTENT PERMITTED UNDER APPLICABLE LAW, IN NO EVENT WILL WE BE LIABLE TO YOU OR TO ANY THIRD PARTY UNDER ANY TORT, CONTRACT, NEGLIGENCE, STRICT LIABILITY, OR OTHER LEGAL OR EQUITABLE THEORY FOR (a) ANY LOST PROFITS, LOST OR CORRUPTED DATA, COMPUTER FAILURE OR MALFUNCTION, INTERRUPTION OF BUSINESS, OR OTH…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Sprout Social may, in its sole discretion, suspend, limit, or terminate access to the Beta Features at any time."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "You acknowledge and agree that we have the right, in our sole discretion, to modify these Terms from time to time by posting the revised version on our website or communicating it to you through your Sprout Social account.",
              "says": "Changes are posted, with no other notice named"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "IF YOU DO NOT HAVE AUTHORITY TO ACCEPT THESE TERMS OR YOU DO NOT AGREE WITH THESE TERMS, YOU MAY NOT ACCESS OR USE THE SPROUT SOCIAL SERVICES OR APIS."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "access, store, display, or facilitate the transfer of any content available in the Sprout Social Services obtained through the following methods: scraping, crawling, spidering or using any other technology or software to access such content outside of the APIs",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "monitor the availability, performance, or functionality of the APIs or the Sprout Social Services for competitive or performance analysis, including for benchmarking purposes;",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may immediately terminate or suspend these Terms, any rights granted herein, and/or your licenses or access granted under these Terms, in our sole discretion with or without cause, and with or without notice to you."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Sprout Social's total liability under the developer terms is capped at 500 US dollars.",
              "quote": "ANY DAMAGES, IN THE AGGREGATE, IN EXCESS OF $500 U.S. DOLLARS EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR DAMAGES AND WHETHER OR NOT SUCH LOSS OR DAMAGES ARE FORESEEABLE."
            },
            {
              "date": "2026-10-08",
              "text": "A developer that caches API data must refresh the cache at least every 24 hours.",
              "quote": "If You cache Data, You must refresh the cache at least every 24 hours."
            },
            {
              "date": "2026-10-08",
              "text": "Every API request must be identified as coming from the developer's application in the way Sprout Social specifies, and in a way that is clear to the application's users.",
              "quote": "You must also identify each request coming from Your Application as originating from Your Application in the manner specified by Sprout Social (for example, using a required Header value) and in a manner that is obvious to Your Users."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://sproutsocial.com/legal/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-09-16",
          "words": 11464,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 16, 2026",
              "says": "Last updated 2026-09-16"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This privacy policy (“Privacy Policy”) explains who we are, how we collect, share and use information about you and how you can exercise your privacy rights."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Consumers who are California, Colorado, or Virginia residents have the right to request that we delete the personal information we have collected about them (subject to certain exemptions) and the right to know certain information about our data practices in the preceding 12 months.",
              "says": "Names a period of 12 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "In connection with the provision of the Services to our customers, Sprout Social may act as a \"data processor\" or \"service provider\" under applicable data protection laws."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "To opt out of us using your data for Matched Ads and other audience matching, please click the “Do Not Sell or Share My Personal Information” link.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "This privacy policy (“Privacy Policy”) explains who we are, how we collect, share and use information about you and how you can exercise your privacy rights."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You may submit a request to opt out by clicking “Do Not Sell or Share My Personal Information”, by calling our toll-free number at (866) 878-3231, or by emailing us at privacy@sproutsocial.com.",
              "says": "privacy@sproutsocial.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "These include our use of European Commission-approved Standard Contractual Clauses (along with the UK Addendum, where appropriate) and, as applicable, our commitment (and commitments made by third party transferees) to honor the principles set forth in the Data Privacy Frameworks (defined below), to the extent each su…",
              "says": "Relies on standard contractual clauses and the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "For instance, we incorporate the Facebook pixel on our Services and may share your email address with Facebook as part of our use of Facebook Custom Audiences."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Sprout Social states that it is a data broker under Texas law for its Influencer Marketing platform.",
              "quote": "With respect to the operation of the Influencer Marketing platform, Sprout Social is a data broker under Texas law."
            },
            {
              "date": "2026-10-08",
              "text": "Sprout Social may use artificial intelligence and machine learning to generate insights about creators, such as estimated audience demographics.",
              "quote": "We may also generate insights about creators using artificial intelligence and machine learning, such as estimated audience demographics, engagement analysis, and content categorization."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/sprout-social.json",
    "live": {
      "slug": "sprout-social",
      "probe": {
        "target": "https://api.sproutsocial.com",
        "method": "get",
        "lastAt": "2026-10-10T03:53:45.226633106Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 249,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 256,
        "p95ms24h": 311,
        "samples24h": 125,
        "samples30d": 125,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 40,
            "ok": 40
          }
        ]
      },
      "vendorStatus": {
        "page": "https://www.sproutsocialstatus.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-10T03:58:47.55314655Z"
      },
      "pages": [
        {
          "url": "https://api.sproutsocial.com/docs/changelog/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:32:33.652887104Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "17ed54bb5b28"
        },
        {
          "url": "https://sproutsocial.com/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-09T18:45:50.581789307Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c990bf136e9b"
        },
        {
          "url": "https://sproutsocial.com/legal/privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:45:48.794215928Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c3bb94f08774"
        },
        {
          "url": "https://sproutsocial.com/legal/api-terms-of-service/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:45:46.501649959Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "51915d0f6e67"
        }
      ],
      "updatedAt": "2026-10-10T03:58:47.55314655Z"
    }
  }
}
