{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "teamwork",
    "name": "Teamwork.com",
    "vendor": "Teamwork Crew Limited",
    "vendorUrl": "https://www.teamwork.com",
    "kind": "http-api",
    "category": "project-management",
    "summary": "Teamwork.com is a hosted project management and professional services platform for client work, covering projects, tasks, time, resourcing and budgets. Agents reach it through REST API v3 and an official MCP server, hosted at mcp.ai.teamwork.com or run locally.",
    "url": "https://www.anchorterminal.com/tools/teamwork",
    "markdownUrl": "https://www.anchorterminal.com/tools/teamwork.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/teamwork.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/teamwork.json",
    "repo": "https://github.com/Teamwork/mcp",
    "license": "Proprietary service under Teamwork.com's terms of service. The MCP server on GitHub is MIT",
    "transports": [
      "http",
      "streamable-http",
      "sse",
      "stdio"
    ],
    "remoteUrl": "https://mcp.ai.teamwork.com",
    "packages": [
      {
        "registry": "go",
        "name": "github.com/teamwork/twapi-go-sdk"
      },
      {
        "registry": "npm",
        "name": "@teamwork/get-bearer-token"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. Any user with an active seat, client users and collaborators included, copies an API key from their profile and sends it over Basic auth, which the docs suggest for personal use and testing. Apps use the OAuth 2.0 authorisation code flow with a client ID and secret from the Developer Portal, or register themselves by dynamic client registration, with PKCE (S256). Scopes are per product (`projects`, `desk`, `spaces`, `chat`), and the token is described as permanent. An app works only on its own site until Teamwork verifies it for publication, which takes up to 5 working days. The MCP server takes the same bearer token or browser sign-in, after an administrator enables MCP under Settings, AI.",
    "pricing": "freemium",
    "pricingNotes": "The API is open to every active user and Teamwork charges nothing per call. Free is $0 for up to 5 users and 5 projects, Basics $9.99 and Accelerate $24.99 a user a month billed annually (minimum 3 and 5 users), and the two larger plans are quoted by sales. A 14-day trial needs no card, so an agent's owner can start on Free or the trial without a contract. Webhooks need a paid plan, and the API rate limit rises with the plan (checked 2026-10-08).",
    "priceSummary": "$9.99 / seat-mo",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API docs, the MCP repository or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 225,
    "popularity": {
      "githubStars": 26,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://apidocs.teamwork.com",
    "openapi": "https://apidocs.teamwork.com/api/oas/download?slug=teamwork\u0026api_version=v3",
    "capabilities": [
      "tasks.create",
      "tasks.update",
      "projects.manage",
      "tasks.comments",
      "projects.reporting",
      "automation.webhooks"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "api-key",
      "openapi",
      "webhooks",
      "freemium",
      "free-tier",
      "no-card",
      "go",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 65.9,
      "grade": "B",
      "agentReady": false,
      "rank": 251,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 68,
        "maintenance": 88,
        "payments": 30,
        "reliability": 73,
        "schema": 72,
        "security": 58,
        "transparency": 80
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 73,
          "points": 14.6,
          "reason": "Graded on the hosted lines for REST API v3 and the hosted MCP server. status.teamwork.com is a Statuspage site with 22 components, among them Teamwork Projects for the US and EU regions, the Developer Portal and the API docs, though none for the API or the MCP server by name (20). In the 90 days to 8 October 2026 it lists one incident, a 40-minute problem with task creation in Projects in both regions on 24 September, marked with no impact level (20). The pricing page gives the API limit per plan, 150 requests a minute on Free, Basics and Accelerate, 300 on the plan above it and 500 on Enterprise (15). A 429 comes with `X-Rate-Limit-Limit`, `X-Rate-Limit-Remaining` and `X-Rate-Limit-Reset` and the guide says access returns after 60 seconds. No Retry-After header and no idempotency keys were found (8 of 15). No SLA found. The terms promise reasonable endeavours and the security page states a goal of over 99.9 per cent (0). API v3 and MCP server 1.x carry no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "A Swagger 2.0 file for API v3 downloads from each reference page (319 paths, 430 operations) with no security scheme declared, and every MCP tool has a typed JSON Schema input in the public source (23 of 25). apidocs.teamwork.com/llms.txt returns 404. The main site has an llms.txt about the company and a Markdown pricing page, and the MCP tool reference is Markdown on GitHub (3 of 10). MCP descriptions say when to use a tool and name pitfalls, for example that a workflow from another project is ignored without a warning. API parameter descriptions are one line each (15 of 20). Enums, minimums and maximums and required fields in both, with nullable unions on many MCP inputs (12 of 15). Reference pages show response examples and 400, 403, 404 and 409 responses, while the error guide is brief and has no error body format (10 of 15). The API is versioned v1, v2 and v3 and the MCP server has tagged releases on GitHub, but no changelog for the REST API was found (9 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 68,
          "points": 11.05,
          "reason": "The generated tool reference lists 225 tools on the main MCP endpoint, 147 of them for Projects, which earns 5. Profile endpoints, 14 named toolsets, a `-read-only` flag on the local server and `verbose=false` on list tools add 9 back, and API v3 has sparse fieldsets (14 of 25). `page` and `pageSize` (default 50, up to 500 on most v3 endpoints), date, status and custom field filters, sorting and sideloading through `include` (20). MCP tools return text errors that name the bad parameter. The API error guide lists six status codes with causes and no body format (12 of 20). Tools carry readOnlyHint, destructiveHint and openWorldHint annotations, and batch tools validate every item before writing. No idempotency keys were found (12 of 20). Creating a task needs a name and a tasklist id. The one official SDK found is for Go (9 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 58,
          "points": 10.15,
          "reason": "OAuth 2.0 authorisation code flow with PKCE (S256) and dynamic client registration, with scopes at product level only (`projects`, `desk`, `spaces`, `chat`). The app login flow guide calls the access token permanent, and personal use is by a per-user API key or username and password over Basic auth. Credentials travel in the `Authorization` header (20 of 30). Every credential acts with its user's permissions. An administrator has to enable MCP for the site, the shipped servers register no delete tools, and the local server has a `-read-only` flag. The hosted server has no documented read-only mode or confirmation step (12 of 20). Task descriptions, comments, tickets and chat messages written by other people reach the model, and no injection guidance was found (3 of 15). An activity tool and a guide to project change history exist. No log of API or MCP calls for the operator was found (8 of 15). security.txt is valid until 17 July 2027 and names security@teamwork.com, the MCP repository has a security policy with a 48-hour acknowledgement, and the security page lists ISO/IEC 27001:2022 and SOC 2 Type 2. No bug bounty or public advisories found (15 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices are public, Free $0, Basics $9.99 and Accelerate $24.99 a user a month billed annually, with the two larger plans quoted by sales. API calls aren't priced (10). The Free plan covers up to 5 users and 5 projects, and the 14-day trial needs no card (20). A person signs up in a browser and creates the key or approves the OAuth app (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 88,
          "points": 7.7,
          "reason": "MCP server v1.51.1 was tagged on 6 October 2026 (30). The repository has 57 tags between 27 July and 6 October 2026 (20). The GitHub API shows 3 open issues, and a bug report of 6 October (#581) was fixed and released the same day (20 of 25). The repository's `server.json` names `com.teamwork/mcp`, but the official MCP registry timed out on both attempts, so the entry is unchecked. The Go SDK `twapi-go-sdk` was last pushed on 1 October 2026 and is the only official SDK found (10 of 15). A test workflow runs on every push, and dependency updates are merged within days (8 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "note": "editorial 63, provenance 96",
          "reason": "Closed service under terms naming Teamwork Crew Limited, with the MCP server, the Go SDK and the token helper open on GitHub and the MCP server under MIT (18 of 30). The privacy notice, last updated 19 August 2024, sends customer data to the DPA. The DPA and the terms agree that data is deleted after termination unless a copy is requested within 10 days, and the AI policy says customer data isn't used to train models. No retention periods are given (20 of 30). No written deprecation policy. The removal of localhost redirect URIs for dynamically registered OAuth apps was announced on 16 June 2026 for 1 August 2026 with Deprecation and Sunset headers, and the paging guide dates the end of total record counts to 6 January 2025 (12 of 20). The DPA lists ten sub-processors by function without locations, the AI list names AWS, OpenAI, Anthropic and Google with locations given as varying, and the security page says hosting is on AWS in the US and the EU (13 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The generated tool reference lists 225 tools on the main MCP endpoint, 147 of them for Projects, which earns 5. Profile endpoints, 14 named toolsets, a `-read-only` flag on the local server and `verbose=false` on list tools add 9 back, and API v3 has sparse fieldsets (14 of 25). `page` and `pageSize` (default 50, up to 500 on most v3 endpoints), date, status and custom field filters, sorting and sideloading through `include` (20). MCP tools return text errors that name the bad parameter. The API error guide lists six status codes with causes and no body format (12 of 20). Tools carry readOnlyHint, destructiveHint and openWorldHint annotations, and batch tools validate every item before writing. No idempotency keys were found (12 of 20). Creating a task needs a name and a tasklist id. The one official SDK found is for Go (9 of 15).",
          "maintenance": "MCP server v1.51.1 was tagged on 6 October 2026 (30). The repository has 57 tags between 27 July and 6 October 2026 (20). The GitHub API shows 3 open issues, and a bug report of 6 October (#581) was fixed and released the same day (20 of 25). The repository's `server.json` names `com.teamwork/mcp`, but the official MCP registry timed out on both attempts, so the entry is unchecked. The Go SDK `twapi-go-sdk` was last pushed on 1 October 2026 and is the only official SDK found (10 of 15). A test workflow runs on every push, and dependency updates are merged within days (8 of 10).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public, Free $0, Basics $9.99 and Accelerate $24.99 a user a month billed annually, with the two larger plans quoted by sales. API calls aren't priced (10). The Free plan covers up to 5 users and 5 projects, and the 14-day trial needs no card (20). A person signs up in a browser and creates the key or approves the OAuth app (0).",
          "reliability": "Graded on the hosted lines for REST API v3 and the hosted MCP server. status.teamwork.com is a Statuspage site with 22 components, among them Teamwork Projects for the US and EU regions, the Developer Portal and the API docs, though none for the API or the MCP server by name (20). In the 90 days to 8 October 2026 it lists one incident, a 40-minute problem with task creation in Projects in both regions on 24 September, marked with no impact level (20). The pricing page gives the API limit per plan, 150 requests a minute on Free, Basics and Accelerate, 300 on the plan above it and 500 on Enterprise (15). A 429 comes with `X-Rate-Limit-Limit`, `X-Rate-Limit-Remaining` and `X-Rate-Limit-Reset` and the guide says access returns after 60 seconds. No Retry-After header and no idempotency keys were found (8 of 15). No SLA found. The terms promise reasonable endeavours and the security page states a goal of over 99.9 per cent (0). API v3 and MCP server 1.x carry no beta label (10).",
          "schema": "A Swagger 2.0 file for API v3 downloads from each reference page (319 paths, 430 operations) with no security scheme declared, and every MCP tool has a typed JSON Schema input in the public source (23 of 25). apidocs.teamwork.com/llms.txt returns 404. The main site has an llms.txt about the company and a Markdown pricing page, and the MCP tool reference is Markdown on GitHub (3 of 10). MCP descriptions say when to use a tool and name pitfalls, for example that a workflow from another project is ignored without a warning. API parameter descriptions are one line each (15 of 20). Enums, minimums and maximums and required fields in both, with nullable unions on many MCP inputs (12 of 15). Reference pages show response examples and 400, 403, 404 and 409 responses, while the error guide is brief and has no error body format (10 of 15). The API is versioned v1, v2 and v3 and the MCP server has tagged releases on GitHub, but no changelog for the REST API was found (9 of 15).",
          "security": "OAuth 2.0 authorisation code flow with PKCE (S256) and dynamic client registration, with scopes at product level only (`projects`, `desk`, `spaces`, `chat`). The app login flow guide calls the access token permanent, and personal use is by a per-user API key or username and password over Basic auth. Credentials travel in the `Authorization` header (20 of 30). Every credential acts with its user's permissions. An administrator has to enable MCP for the site, the shipped servers register no delete tools, and the local server has a `-read-only` flag. The hosted server has no documented read-only mode or confirmation step (12 of 20). Task descriptions, comments, tickets and chat messages written by other people reach the model, and no injection guidance was found (3 of 15). An activity tool and a guide to project change history exist. No log of API or MCP calls for the operator was found (8 of 15). security.txt is valid until 17 July 2027 and names security@teamwork.com, the MCP repository has a security policy with a 48-hour acknowledgement, and the security page lists ISO/IEC 27001:2022 and SOC 2 Type 2. No bug bounty or public advisories found (15 of 20).",
          "transparency": "Closed service under terms naming Teamwork Crew Limited, with the MCP server, the Go SDK and the token helper open on GitHub and the MCP server under MIT (18 of 30). The privacy notice, last updated 19 August 2024, sends customer data to the DPA. The DPA and the terms agree that data is deleted after termination unless a copy is requested within 10 days, and the AI policy says customer data isn't used to train models. No retention periods are given (20 of 30). No written deprecation policy. The removal of localhost redirect URIs for dynamically registered OAuth apps was announced on 16 June 2026 for 1 August 2026 with Deprecation and Sunset headers, and the paging guide dates the end of total record counts to 6 January 2025 (12 of 20). The DPA lists ten sub-processors by function without locations, the AI list names AWS, OpenAI, Anthropic and Google with locations given as varying, and the security page says hosting is on AWS in the US and the EU (13 of 20)."
        },
        "sources": [
          {
            "what": "API docs home",
            "url": "https://apidocs.teamwork.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "API getting started (site URL, API key, who has access)",
            "url": "https://apidocs.teamwork.com/guides/teamwork/getting-started-with-the-teamwork-com-api",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication guide",
            "url": "https://apidocs.teamwork.com/guides/teamwork/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "app login flow (OAuth 2.0)",
            "url": "https://apidocs.teamwork.com/guides/teamwork/app-login-flow",
            "seen": "2026-10-08"
          },
          {
            "what": "developer portal and app verification",
            "url": "https://apidocs.teamwork.com/guides/teamwork/app-verification",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limit guide",
            "url": "https://apidocs.teamwork.com/guides/teamwork/rate-limit",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes guide",
            "url": "https://apidocs.teamwork.com/guides/teamwork/error-codes",
            "seen": "2026-10-08"
          },
          {
            "what": "paging guide",
            "url": "https://apidocs.teamwork.com/guides/teamwork/how-does-paging-work",
            "seen": "2026-10-08"
          },
          {
            "what": "sparse fieldsets guide",
            "url": "https://apidocs.teamwork.com/guides/teamwork/sparse-fieldsets",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks setup",
            "url": "https://apidocs.teamwork.com/guides/teamwork/setting-up-webhooks",
            "seen": "2026-10-08"
          },
          {
            "what": "deprecation notice for localhost redirect URIs",
            "url": "https://apidocs.teamwork.com/guides/teamwork/auth-dcr-localhost-deprecation",
            "seen": "2026-10-08"
          },
          {
            "what": "sunset notice for localhost redirect URIs",
            "url": "https://apidocs.teamwork.com/guides/teamwork/auth-dcr-localhost-sunset",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference index",
            "url": "https://apidocs.teamwork.com/docs/teamwork",
            "seen": "2026-10-08"
          },
          {
            "what": "create task reference",
            "url": "https://apidocs.teamwork.com/docs/teamwork/v3/tasks/post-projects-api-v3-tasklists-tasklist-id-tasks-json",
            "seen": "2026-10-08"
          },
          {
            "what": "list tasks reference",
            "url": "https://apidocs.teamwork.com/docs/teamwork/v3/tasks/get-projects-api-v3-tasks-json",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger 2.0 file for API v3",
            "url": "https://apidocs.teamwork.com/api/oas/download?slug=teamwork\u0026api_version=v3",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server repository (README, tool reference, usage guides, source, tags)",
            "url": "https://github.com/Teamwork/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tool reference",
            "url": "https://github.com/Teamwork/mcp/blob/main/docs/tool-reference.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected resource metadata",
            "url": "https://mcp.ai.teamwork.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth authorisation server metadata",
            "url": "https://teamwork.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "GitHub API, repository and issues",
            "url": "https://api.github.com/repos/Teamwork/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing in Markdown",
            "url": "https://www.teamwork.com/pricing.md",
            "seen": "2026-10-08"
          },
          {
            "what": "site llms.txt",
            "url": "https://www.teamwork.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents feed",
            "url": "https://status.teamwork.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components feed",
            "url": "https://status.teamwork.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.teamwork.com/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.teamwork.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.teamwork.com/legal/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://www.teamwork.com/legal/privacy-notice/",
            "seen": "2026-10-08"
          },
          {
            "what": "data processing agreement and sub-processors",
            "url": "https://www.teamwork.com/legal/teamwork-com-data-processing-agreement/",
            "seen": "2026-10-08"
          },
          {
            "what": "AI policy",
            "url": "https://www.teamwork.com/legal/teamwork-com-ai-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "AI sub-processors",
            "url": "https://www.teamwork.com/legal/teamwork-com-ai-sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for teamwork.com",
            "url": "https://rdap.org/domain/teamwork.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the official MCP registry. registry.modelcontextprotocol.io timed out on both attempts, so whether `com.teamwork/mcp` from the repository's `server.json` is published there was not established.",
          "unchecked: the live tool list. tools/list on the hosted server answers 401 without a token, so the count of 225 and the annotations are read from the generated tool reference and the source at v1.51.1.",
          "unchecked: whether the Free plan includes the MCP server and webhooks. The webhooks guide says webhooks need a paid plan, and the pricing page lists an API rate limit for Free.",
          "unchecked: whether OAuth access tokens can be revoked by the user or expire. The app login flow guide calls the token permanent.",
          "The rate limit guide still names the Grow and Scale plans (150 and 300 a minute), which the pricing page no longer lists. The listing uses the pricing page's figures.",
          "The lead named Teamwork Crew Ltd. The terms and DPA name Teamwork Crew Limited, registered number 313652, trading as Teamwork.com. The lead gave only the REST API. Teamwork also has an official MCP server, which the listing grades alongside the API.",
          "www.teamwork.com/llms.txt has a section of instructions addressed to AI assistants on how to describe the company. Recorded as a fact, with no deduction, and not acted on.",
          "No REST API changelog, SLA, bug bounty or audit log of API calls was found in the pages read. The trust reports behind the security page's Learn more links were not read.",
          "Terms carry no visible version date. The privacy notice says it was last updated on 19 August 2024."
        ]
      },
      "negative": 0,
      "verdict": "The official MCP server is MIT licensed, released almost daily, and has typed tools with annotations, profile endpoints and no delete tools on the shipped servers. OAuth scopes stop at product level, access tokens are permanent, and no SLA, API changelog or prompt-injection guidance was found in the reviewed documentation.",
      "bestFor": "Agencies and services firms already on Teamwork.com that want an assistant to create and update tasks, log time, read workload and budgets, and answer Desk tickets.",
      "strengths": [
        "Official MCP server under MIT at https://mcp.ai.teamwork.com, with profile endpoints such as `/project-manager` that load a subset of tools",
        "No delete tool reaches a client. Delete operations sit behind an `allowDelete` flag that no shipped server enables",
        "A Swagger 2.0 file for API v3 downloads from the docs, with 319 paths and 430 operations",
        "OAuth 2.0 authorisation code flow with PKCE (S256) and dynamic client registration, per the authorisation server metadata",
        "The Free plan (up to 5 users) and the 14-day trial need no card, and the pricing page gives an API rate limit for every plan"
      ],
      "weaknesses": [
        "OAuth scopes are per product only (`projects`, `desk`, `spaces`, `chat`), and the token from the app login flow is described as permanent",
        "The main MCP endpoint loads every tool. The generated tool reference lists 225, 147 of them for Projects",
        "429 responses carry `X-Rate-Limit-Reset` but no Retry-After, and no idempotency keys were found",
        "No SLA found. The terms promise reasonable endeavours and the security page states a 99.9 per cent uptime goal",
        "No changelog for the REST API was found, and the docs site has no llms.txt"
      ],
      "agentNotes": [
        "Use a profile endpoint such as https://mcp.ai.teamwork.com/project-manager. The base URL loads every tool across Projects, Desk, Spaces and Chat.",
        "Ask a site administrator to enable MCP under Settings, AI before connecting.",
        "Build REST URLs from `installation.apiEndPoint` in the token response. Sites live at {site}.teamwork.com (US) or {site}.eu.teamwork.com (EU).",
        "Stay under 150 requests a minute on Free, Basics and Accelerate. The limit is shared by the whole site. On 429, wait until `X-Rate-Limit-Reset`.",
        "Pass `verbose=false` to `list_*` tools to get ids and names only, and use `twprojects-create_tasks` for many tasks in one call."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 65.9
        }
      ],
      "editorialScores": {
        "ergonomics": 68,
        "maintenance": 88,
        "payments": 30,
        "reliability": 73,
        "schema": 72,
        "security": 58,
        "transparency": 63
      },
      "provenanceScore": 96
    },
    "connect": {
      "http": "curl -i https://{yourSiteName}.teamwork.com/projects/api/v3/projects.json -H \"Authorization: Bearer {token}\"",
      "claudeCode": "claude mcp add --transport http teamwork https://mcp.ai.teamwork.com/",
      "config": {
        "mcpServers": {
          "Teamwork.com": {
            "args": [],
            "command": "tw-mcp",
            "env": {
              "TW_MCP_BEARER_TOKEN": "\u003ctoken\u003e"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/tasks.create",
      "tool": "https://letme.dev/teamwork"
    },
    "notable": [
      "The hosted MCP server answers at https://mcp.ai.teamwork.com over Streamable HTTP and at `/sse`, with profile endpoints `/project-manager`, `/support`, `/analyst`, `/knowledge-manager` and `/ops` (https://github.com/Teamwork/mcp/blob/main/docs/usage/README.md)",
      "The generated tool reference lists create, get, list and update tools across Projects, Desk, Spaces and Chat, and says delete operations are gated behind an `allowDelete` flag that no shipped server enables (https://github.com/Teamwork/mcp/blob/main/docs/tool-reference.md)",
      "The authorisation server metadata lists the authorisation code grant, S256 code challenges, a registration endpoint and the scopes `projects`, `desk`, `spaces` and `chat` (https://teamwork.com/.well-known/oauth-authorization-server)",
      "Localhost redirect URIs for dynamically registered OAuth apps were deprecated on 16 June 2026 and refused from 1 August 2026, with Deprecation and Sunset headers in between (https://apidocs.teamwork.com/guides/teamwork/auth-dcr-localhost-deprecation)",
      "The API rate limit is shared by the whole site, 150 requests a minute on Free, Basics and Accelerate, 300 on the plan above it and 500 on Enterprise (https://www.teamwork.com/pricing.md)",
      "A Swagger 2.0 file for API v3 with 319 paths and 430 operations downloads from the reference pages (https://apidocs.teamwork.com/api/oas/download?slug=teamwork\u0026api_version=v3)",
      "www.teamwork.com/llms.txt has a section of instructions addressed to AI assistants on how to describe the company. It is recorded here as a fact about the page (https://www.teamwork.com/llms.txt)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces",
        "value": "REST API v3 at https://{site}.teamwork.com/projects/api/v3 (EU sites at {site}.eu.teamwork.com), with v1 and v2 still documented, and the official MCP server, hosted at https://mcp.ai.teamwork.com (Streamable HTTP, SSE at `/sse`) or run locally as `tw-mcp` over stdio"
      },
      {
        "label": "MCP tools",
        "value": "225 in the generated tool reference at v1.51.1. Projects 147 (tasks, tasklists, workflows, projects, milestones, comments, time, allocations, people), Desk 46, Spaces 24, Chat 8. No delete tools on the shipped servers"
      },
      {
        "label": "MCP profiles",
        "value": "`/project-manager`, `/support` (alias `/desk`), `/analyst`, `/knowledge-manager` and `/ops`, each loading a subset of 14 toolsets"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 authorisation code flow with PKCE (S256) and dynamic client registration, giving a bearer token the docs call permanent. Per-user API key or username and password over Basic auth for personal use"
      },
      {
        "label": "Scopes",
        "value": "`projects`, `desk`, `spaces`, `chat`. Access inside a product follows the user's permissions"
      },
      {
        "label": "Rate limits",
        "value": "150 requests a minute on Free, Basics and Accelerate, 300 on the top self-serve plan, 500 on Enterprise, shared across the site. 429 with `X-Rate-Limit-Limit`, `X-Rate-Limit-Remaining` and `X-Rate-Limit-Reset`"
      },
      {
        "label": "Pagination",
        "value": "`page` and `pageSize` (default 50, up to 500 on most v3 endpoints), a `meta.page` object with `hasMore`, sparse fieldsets through `fields[type]`, sideloading through `include`, and a cap of 50,000 records per query"
      },
      {
        "label": "Contract",
        "value": "Swagger 2.0 file for API v3 with 319 paths and 430 operations, downloadable from each reference page"
      },
      {
        "label": "Webhooks",
        "value": "Site and project webhooks on paid plans, with an optional token for an HMAC SHA-256 checksum in `X-Projects-Signature`. `fireWebhook=false` suppresses the event for one request"
      },
      {
        "label": "SDKs",
        "value": "Go only. `github.com/teamwork/twapi-go-sdk` v1.35.0, plus `desksdkgo` and `spacessdkgo`. The npm package `@teamwork/get-bearer-token` 1.6.1 fetches a bearer token"
      },
      {
        "label": "Free tier",
        "value": "Free plan at $0 for up to 5 users and 5 projects with 100 MB of storage. 14-day trial of paid plans with no card"
      },
      {
        "label": "Certifications",
        "value": "ISO/IEC 27001:2022 and SOC 2 Type 2 per teamwork.com/security"
      },
      {
        "label": "Status",
        "value": "status.teamwork.com on Statuspage, 22 components by product and region (US and EU)"
      },
      {
        "label": "Sub-processors",
        "value": "AWS, Mailgun, Sendgrid, Datadog, DigitalOcean, Zapier, Clicktel, Sentry, LaunchDarkly and Pendo in the DPA, without locations. AI processing by AWS, OpenAI, Anthropic and Google"
      }
    ],
    "unitPrices": [
      {
        "item": "Free (API included)",
        "unit": "seat-month",
        "usd": 0,
        "note": "Up to 5 users and 5 projects"
      },
      {
        "item": "Basics",
        "unit": "seat-month",
        "usd": 9.99,
        "note": "Billed annually, minimum 3 users, as shown on 2026-10-08"
      },
      {
        "item": "Accelerate",
        "unit": "seat-month",
        "usd": 24.99,
        "note": "Billed annually, minimum 5 users, as shown on 2026-10-08"
      }
    ],
    "provenance": {
      "legalEntity": "Teamwork Crew Limited",
      "domain": "teamwork.com",
      "domainRegistered": "1995-03-29",
      "endpointOnVendorDomain": true,
      "terms": "https://www.teamwork.com/legal/terms-of-service/",
      "privacy": "https://www.teamwork.com/legal/privacy-notice/",
      "statusPage": "https://status.teamwork.com",
      "changelog": "https://github.com/Teamwork/mcp/releases",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service are between the customer and Teamwork Crew Limited. The DPA gives registered number 313652 and a registered office at Teamwork Campus 1, Park House, Blackpool Retail Park, Blackpool, Cork, T23 F902, Ireland, trading as Teamwork.com.",
        "The terms govern the hosted service and incorporate the DPA. The privacy notice, last updated 19 August 2024, covers the websites and the platform and refers customer data processed for customers to the DPA.",
        "The API answers on each customer's teamwork.com subdomain and the MCP server at mcp.ai.teamwork.com.",
        "www.teamwork.com/.well-known/security.txt names security@teamwork.com and expires on 17 July 2027.",
        "RDAP for teamwork.com gives a registration date of 1995-03-29.",
        "The changelog link is the MCP server's GitHub releases. No changelog for the REST API was found."
      ],
      "score": 96,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Teamwork Crew Limited",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "teamwork.com, registered 1995-03-29 (31 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.ai.teamwork.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.teamwork.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.teamwork.com/legal/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 10534,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "…with them or their subject matter or formation (including non-contractual Disputes or claims) will be governed by and construed in accordance with Irish law and we each irrevocably agree to any dispute or claim arising out of or in connection with this Agreement or their subject matter or formation (including non-cont…"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In no event shall Teamwork.com, its employees, agents and subcontractors be liable to the Customer to the extent that the alleged infringement is based on:"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "…Subscriptions at the expiry of the Free Period, the Customer's right to access and use the Services will terminate at the end of the Free Period and the Customer instructs Teamwork.com to delete all of Customer Data in the Services save that Teamwork.com may retain copies in accordance with Teamwork.com's data retenti…"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "…become non-infringing or, if such remedies are not reasonably available, terminate this Agreement on 5 Business Days' notice to the Customer without any additional liability or obligation to pay liquidated damages or other additional costs to the Customer.",
              "says": "Gives 5 business days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "The Customer shall not access, store, distribute or transmit any Viruses, or any material during the course of its use of the Services that:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "access all or any part of the Services in order to build a product or service which competes with the Services and/or any documentation provided in relation to the Service by Teamwork.com; or",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Teamwork.com may terminate this Agreement with immediate effect without cause by giving five (5) days written notice to the Customer."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Teamwork.com may at its sole discretion charge additional fees if it believes the customer or its users have misused the services or used them excessively.",
              "quote": "use the Services in an excessive manner compared to the anticipated standard use (for instance, an inappropriate use of features etc.), to impose additional fees for the continued use of the Services."
            },
            {
              "date": "2026-10-08",
              "text": "After termination Teamwork.com may destroy customer data unless it receives a written request for the latest back-up within ten days.",
              "quote": "Teamwork.com may destroy or otherwise dispose of any of the Customer Data in its possession unless Teamwork.com receives, no later than ten (10) days after the effective date of the termination of this Agreement, a written request for the delivery to the Customer"
            },
            {
              "date": "2026-10-08",
              "text": "For customers on a monthly subscription, total liability is limited to the subscription fees paid in the month before the claim arose.",
              "quote": "for Customers whose Subscription Period is monthly, to the total Subscription Fees paid by the Customer for the Service Subscriptions in the month preceding the date on which the claim arose; and"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.teamwork.com/legal/privacy-notice/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-08-19",
          "words": 5929,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "This Privacy Notice was last updated on 19th August 2024, and is published in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (\"GDPR\").",
              "says": "Last updated 2024-08-19"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We and our third party processors will keep personal data in our active operating systems only for as long as necessary to fulfil the purposes we collected it for, including for the purposes of providing services to you or a customer, satisfying any legal, accounting, or reporting requirements.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Providing a link to third party websites does not mean that we endorse or warrant the Services provided by any third parties and this privacy notice does not govern such sites."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Where we rely on your consent to process your personal data, you have the right to withdraw your consent at any time, although withdrawal of your consent to process your personal data may render us unable to provide services to you (or your employer)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this privacy notice.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "The Teamwork.com Data Processing Agreement includes the European Commission’s Standard Contractual Clauses (SCCs) as the mechanism to transfer data from the EU to the US.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Teamwork.com says it collects, uses and shares aggregated data derived from personal data for any purpose.",
              "quote": "We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/teamwork.json",
    "live": {
      "slug": "teamwork",
      "probe": {
        "target": "https://mcp.ai.teamwork.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:23.254305997Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 413,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 336,
        "p95ms24h": 413,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.teamwork.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:06:27.817797618Z"
      },
      "updatedAt": "2026-10-08T21:12:23.254305997Z"
    }
  }
}
