{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "vercel-connect",
    "name": "Vercel Connect",
    "vendor": "Vercel Inc.",
    "vendorUrl": "https://vercel.com",
    "kind": "http-api",
    "category": "agent-auth",
    "summary": "Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user.",
    "url": "https://www.anchorterminal.com/tools/vercel-connect",
    "markdownUrl": "https://www.anchorterminal.com/tools/vercel-connect.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vercel-connect.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vercel-connect.json",
    "repo": "https://github.com/vercel/vercel",
    "license": "Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.vercel.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@vercel/connect"
      }
    ],
    "auth": "mixed",
    "authNotes": "Access is self-serve with a Vercel account, on every plan. A deployment calls Connect with its project OIDC token (`VERCEL_OIDC_TOKEN`), which Connect checks against the connector's project links and their environments. Locally, `vercel env pull` writes a development OIDC token that lasts about 12 hours. Outside Vercel, a Vercel access token goes in `vercelToken`, and it can request only the app subject or its own user. Connect then holds the provider side. Vercel registers the OAuth client for managed connectors (Slack, GitHub, Linear, Microsoft, Snowflake, Salesforce), and the customer supplies a client or an API key for the others. End users consent in a browser at a URL from `startAuthorization`.",
    "pricing": "freemium",
    "pricingNotes": "Billed per token request and per trigger. Hobby includes 500 token requests and 1,000 triggers a month at no extra charge, and Vercel's fair use guidelines limit Hobby to non-commercial, personal use. Pro is $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on top of the plan. Enterprise is negotiated. A trigger is counted once per destination, and once per event when no destination is set. The SDK's in-process cache means many provider calls in one invocation cost one token request (https://vercel.com/docs/connect/pricing, checked 2026-10-08).",
    "priceSummary": "$3 / 1k req",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Connect docs, the pricing page or the Connect operations of the OpenAPI document (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 16354,
      "npmWeekly": 738165,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://vercel.com/docs/connect",
    "llmsTxt": "https://vercel.com/llms.txt",
    "openapi": "https://openapi.vercel.sh/",
    "capabilities": [
      "auth.tokens",
      "auth.oauth",
      "auth.consent",
      "auth.audit"
    ],
    "tags": [
      "hosted",
      "freemium",
      "free-tier",
      "oauth",
      "oidc",
      "openapi",
      "llms-txt",
      "typescript",
      "cli",
      "webhooks",
      "status-page",
      "soc2",
      "iso27001"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.8,
      "grade": "B",
      "agentReady": false,
      "rank": 195,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 75,
        "maintenance": 81,
        "payments": 40,
        "reliability": 63,
        "schema": 84,
        "security": 83,
        "transparency": 77
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 63,
          "points": 12.6,
          "reason": "Graded on the hosted lines. Connect is a component on www.vercel-status.com with an incident feed (20). The feed has elevated error rates on Connect and Passport for 1 hour 34 minutes on 10 September 2026, marked major, and elevated KMS and Connect errors posted for 18 September, which we read as one major (10). Rate limits published with numbers, 200 reads and 50 writes a minute per team and 6,000 a minute on the OAuth gateway and trigger endpoints (15). A 429 is documented with a one-minute wait and token requests are safe to repeat, but we found no Retry-After header or idempotency keys for writes (8). Vercel's SLA says it does not apply to the APIs or CLI (0). Generally available since 25 August 2026, with Salesforce and Linq connectors still beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 84,
          "points": 13.65,
          "reason": "Vercel's public OpenAPI 3.0.3 document has 13 Connect paths, the token and authorise calls among them (25). Docs are served as Markdown on request and vercel.com/llms.txt exists (10). The docs say when to use Connect and when a Vercel Integration fits better, and give a use-when line for each subject type (16). The token body types the subject as a union with enums, but most variants allow extra properties, `authorizationDetails` is open and scopes are provider strings (10). Examples are plentiful and six SDK error classes are documented with fixes, while the OpenAPI error responses for the token call have empty descriptions (11). Paths are versioned and the SDK follows semver with a dated product changelog, though the package changelog in the public repository stops at 2.0.2 (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 75,
          "points": 12.19,
          "reason": "A token call returns one token with its expiry and identifiers, so there is little to size (22). Listing connectors takes `limit`, `cursor`, `search`, `projectId` and `type` (18). Errors are typed and each maps to a next step, such as starting consent or attaching the project, but the 429 carries no documented wait header (17). Token requests are cached and safe to repeat, and we found no idempotency keys for create, attach or revoke (10). Only the connector and subject are required and scopes default to the connector's own, but the one official SDK is TypeScript, with a CLI and plain HTTP for everything else (8)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 83,
          "points": 14.53,
          "reason": "Callers present a project-bound OIDC token or a Vercel access token, provider tokens are short-lived and scoped per request, refresh tokens stay with Vercel, and grants can be revoked from the SDK, CLI or dashboard (28). Project links limit which environments may ask, requests can narrow scopes and resources, and Pro and Enterprise can restrict who manages connectors. There is no approval step before a token is issued, omitted scopes default to `['*']`, and revocation depends on the provider (14). The API returns tokens, not untrusted content (10). Token requests, authorisations and revocations are logged with correlation IDs, kept 12 hours on Hobby, 3 days on Pro and 30 days on Enterprise, with drains on paid plans (13). Valid security.txt, HackerOne, SOC 2 Type 2 and ISO 27001:2022 as Vercel states them, and a public bulletin for the April 2026 incident (18)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Unit prices are public without a login, $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on Pro (20). Hobby includes 500 token requests and 1,000 triggers a month at no charge, for non-commercial use, and the Hobby plan page names no card (20). A person signs up in a browser, and connectors and user consent also pass through a browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 81,
          "points": 7.09,
          "reason": "`@vercel/connect` 2.4.1 was published on 6 October 2026 (30). npm shows 30 versions since 2 July 2026, and the changelog has Connect entries on 11 and 25 August and 11 and 21 September (20). Closed service with a dated public changelog. The public copy of the SDK in vercel/vercel was last synced on 8 September 2026 and stops at 2.0.2, and we didn't read issue replies (10). One current official SDK, with 738,165 npm downloads in the week to 4 October 2026 (15). One runtime dependency and 13 test files in the package. We didn't confirm CI status on the default branch (6)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 77,
          "points": 6.74,
          "note": "editorial 55, provenance 99",
          "reason": "Closed service under the Terms of Service of 1 June 2026 plus short Connect product terms, with an Apache-2.0 SDK and CLI (20). A privacy notice and a DPA exist, and the docs say refresh tokens are stored on Vercel's infrastructure and give event retention by plan. We found no retention period or encryption statement for stored provider credentials, and the DPA covers Pro and Enterprise only (18). No deprecation policy found. The product terms let Vercel remove third-party platforms without notice, though the beta price change was announced with a date of 25 September 2026 (5). The DPA points to a subprocessor list on security.vercel.com and says primary processing is in the United States. We saw the list's page but could not read its entries (12)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "A token call returns one token with its expiry and identifiers, so there is little to size (22). Listing connectors takes `limit`, `cursor`, `search`, `projectId` and `type` (18). Errors are typed and each maps to a next step, such as starting consent or attaching the project, but the 429 carries no documented wait header (17). Token requests are cached and safe to repeat, and we found no idempotency keys for create, attach or revoke (10). Only the connector and subject are required and scopes default to the connector's own, but the one official SDK is TypeScript, with a CLI and plain HTTP for everything else (8).",
          "maintenance": "`@vercel/connect` 2.4.1 was published on 6 October 2026 (30). npm shows 30 versions since 2 July 2026, and the changelog has Connect entries on 11 and 25 August and 11 and 21 September (20). Closed service with a dated public changelog. The public copy of the SDK in vercel/vercel was last synced on 8 September 2026 and stops at 2.0.2, and we didn't read issue replies (10). One current official SDK, with 738,165 npm downloads in the week to 4 October 2026 (15). One runtime dependency and 13 test files in the package. We didn't confirm CI status on the default branch (6).",
          "payments": "No x402, MPP or L402 (0). Unit prices are public without a login, $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on Pro (20). Hobby includes 500 token requests and 1,000 triggers a month at no charge, for non-commercial use, and the Hobby plan page names no card (20). A person signs up in a browser, and connectors and user consent also pass through a browser (0).",
          "reliability": "Graded on the hosted lines. Connect is a component on www.vercel-status.com with an incident feed (20). The feed has elevated error rates on Connect and Passport for 1 hour 34 minutes on 10 September 2026, marked major, and elevated KMS and Connect errors posted for 18 September, which we read as one major (10). Rate limits published with numbers, 200 reads and 50 writes a minute per team and 6,000 a minute on the OAuth gateway and trigger endpoints (15). A 429 is documented with a one-minute wait and token requests are safe to repeat, but we found no Retry-After header or idempotency keys for writes (8). Vercel's SLA says it does not apply to the APIs or CLI (0). Generally available since 25 August 2026, with Salesforce and Linq connectors still beta (10).",
          "schema": "Vercel's public OpenAPI 3.0.3 document has 13 Connect paths, the token and authorise calls among them (25). Docs are served as Markdown on request and vercel.com/llms.txt exists (10). The docs say when to use Connect and when a Vercel Integration fits better, and give a use-when line for each subject type (16). The token body types the subject as a union with enums, but most variants allow extra properties, `authorizationDetails` is open and scopes are provider strings (10). Examples are plentiful and six SDK error classes are documented with fixes, while the OpenAPI error responses for the token call have empty descriptions (11). Paths are versioned and the SDK follows semver with a dated product changelog, though the package changelog in the public repository stops at 2.0.2 (12).",
          "security": "Callers present a project-bound OIDC token or a Vercel access token, provider tokens are short-lived and scoped per request, refresh tokens stay with Vercel, and grants can be revoked from the SDK, CLI or dashboard (28). Project links limit which environments may ask, requests can narrow scopes and resources, and Pro and Enterprise can restrict who manages connectors. There is no approval step before a token is issued, omitted scopes default to `['*']`, and revocation depends on the provider (14). The API returns tokens, not untrusted content (10). Token requests, authorisations and revocations are logged with correlation IDs, kept 12 hours on Hobby, 3 days on Pro and 30 days on Enterprise, with drains on paid plans (13). Valid security.txt, HackerOne, SOC 2 Type 2 and ISO 27001:2022 as Vercel states them, and a public bulletin for the April 2026 incident (18).",
          "transparency": "Closed service under the Terms of Service of 1 June 2026 plus short Connect product terms, with an Apache-2.0 SDK and CLI (20). A privacy notice and a DPA exist, and the docs say refresh tokens are stored on Vercel's infrastructure and give event retention by plan. We found no retention period or encryption statement for stored provider credentials, and the DPA covers Pro and Enterprise only (18). No deprecation policy found. The product terms let Vercel remove third-party platforms without notice, though the beta price change was announced with a date of 25 September 2026 (5). The DPA points to a subprocessor list on security.vercel.com and says primary processing is in the United States. We saw the list's page but could not read its entries (12)."
        },
        "sources": [
          {
            "what": "Connect docs overview",
            "url": "https://vercel.com/docs/connect",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and the HTTP token call",
            "url": "https://vercel.com/docs/connect/concepts/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "tokens, scoping, revocation and errors",
            "url": "https://vercel.com/docs/connect/concepts/tokens",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://vercel.com/docs/connect/limits",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://vercel.com/docs/connect/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "observability events and retention",
            "url": "https://vercel.com/docs/connect/observability",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK reference",
            "url": "https://vercel.com/docs/connect/ts-sdk-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "Connect product terms",
            "url": "https://vercel.com/docs/connect/legal",
            "seen": "2026-10-08"
          },
          {
            "what": "project links",
            "url": "https://vercel.com/docs/connect/concepts/project-links",
            "seen": "2026-10-08"
          },
          {
            "what": "general availability changelog entry",
            "url": "https://vercel.com/changelog/vercel-connect-ga",
            "seen": "2026-10-08"
          },
          {
            "what": "connector permissions changelog entry",
            "url": "https://vercel.com/changelog/control-who-can-manage-connectors-in-vercel-connect",
            "seen": "2026-10-08"
          },
          {
            "what": "connector catalogue",
            "url": "https://vercel.com/connect/browse",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI document",
            "url": "https://openapi.vercel.sh/",
            "seen": "2026-10-08"
          },
          {
            "what": "status page incidents feed",
            "url": "https://www.vercel-status.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status page components",
            "url": "https://www.vercel-status.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry, versions and dates",
            "url": "https://registry.npmjs.org/@vercel%2Fconnect",
            "seen": "2026-10-08"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@vercel%2Fconnect",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK source in the public repository (shallow clone)",
            "url": "https://github.com/vercel/vercel/tree/main/packages/connect",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Service",
            "url": "https://vercel.com/legal/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "Privacy Notice",
            "url": "https://vercel.com/legal/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Addendum",
            "url": "https://vercel.com/legal/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "SLA",
            "url": "https://vercel.com/legal/sla",
            "seen": "2026-10-08"
          },
          {
            "what": "compliance page",
            "url": "https://vercel.com/docs/security/compliance",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://vercel.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "April 2026 security bulletin",
            "url": "https://vercel.com/kb/bulletin/vercel-april-2026-security-incident",
            "seen": "2026-10-08"
          },
          {
            "what": "Hobby plan",
            "url": "https://vercel.com/docs/plans/hobby",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for vercel.com",
            "url": "https://rdap.verisign.com/com/v1/domain/vercel.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the entries of the subprocessor list on security.vercel.com, which is drawn by script. We saw only that the page has a Subprocessors section.",
          "unchecked: whether Hobby signup asks for a card. The Hobby plan page names none, and we did not open the signup flow.",
          "unchecked: CI status for packages/connect on the default branch of vercel/vercel, and issue replies there.",
          "Whether failed or cached token requests are billed. The pricing page defines a token request as a call that returns a provider token.",
          "How stored provider refresh tokens and API keys are encrypted and how long they are kept after a connector is deleted. Not found in the reviewed documentation.",
          "Whether a REST path for revocation is public. The docs say tokens can be revoked through the REST API, and the OpenAPI document has no Connect revoke path.",
          "The deduction of 3 for the April 2026 incident is a judgement call. The existing vercel-sandbox listing took none for the same bulletin.",
          "The 18 September 2026 status entry for KMS and Connect errors has no duration, so its length is unknown.",
          "The count of 1,083 catalogue services is ours, from the Markdown of /connect/browse. Vercel's own figure at launch was 100+ preset connectors."
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "April 2026. Vercel's security bulletin says an attacker took over an employee's account through a compromised third-party AI tool, reached internal systems and decrypted non-sensitive environment variables of a limited subset of customers. It predates Connect's general availability on 25 August 2026 and is documented with remediation, so 3 of a possible 15 is taken, because Connect now keeps customers' provider refresh tokens on the same platform (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident)."
      ],
      "verdict": "Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.",
      "bestFor": "Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.",
      "strengths": [
        "Refresh tokens stay on Vercel's infrastructure. Code receives only short-lived access tokens, as the app or for a named user",
        "A deployment authenticates with its project OIDC token, checked against per-environment project links, so no provider secret sits in environment variables",
        "Public OpenAPI 3.0.3 document covers 13 Connect paths, including `/v1/connect/token/{connector}` and `/v1/connect/authorize/{connector}`",
        "Token requests, completed authorisations and revocations are logged with `tokenId` and `authorizationId`, and can be sent to a drain on Pro and Enterprise",
        "Rate limits are published with numbers, 200 reads and 50 writes a minute per team"
      ],
      "weaknesses": [
        "Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment",
        "Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page",
        "Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise",
        "Revocation depends on the provider. Without a revocation endpoint the provider credential can work until it expires",
        "The SDK is TypeScript only, and the public repository's copy stops at 2.0.2 while npm has 2.4.1"
      ],
      "agentNotes": [
        "Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry",
        "Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes",
        "Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser",
        "Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user",
        "On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.8
        }
      ],
      "editorialScores": {
        "ergonomics": 75,
        "maintenance": 81,
        "payments": 40,
        "reliability": 63,
        "schema": 84,
        "security": 83,
        "transparency": 55
      },
      "provenanceScore": 99
    },
    "connect": {
      "install": "pnpm add @vercel/connect",
      "http": "curl -X POST https://api.vercel.com/v1/connect/token/slack%2Facme-slack \\\n  -H \"Authorization: Bearer $VERCEL_OIDC_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"subject\":{\"type\":\"app\"},\"scopes\":[\"chat:write\"]}'"
    },
    "letme": {
      "capability": "https://letme.dev/auth.tokens",
      "tool": "https://letme.dev/vercel-connect"
    },
    "sameCompany": [
      "vercel-sandbox"
    ],
    "notable": [
      "Every token request is a POST to `https://api.vercel.com/v1/connect/token/:connector` with a Bearer OIDC or access token, and the connector uid is URL-encoded, so `slack/acme-slack` becomes `slack%2Facme-slack` (https://vercel.com/docs/connect/concepts/authentication)",
      "Generally available on all plans since 25 August 2026, with RBAC for connectors, audit logs and token observability added at that release (https://vercel.com/changelog/vercel-connect-ga)",
      "The catalogue page listed 1,083 services when we counted on 8 October 2026, 8 of them marked Managed, 882 with an API key method, 374 with MCP and 48 with OAuth. Salesforce and Linq are marked Beta (https://vercel.com/connect/browse)",
      "The product terms forbid routing cardholder data, protected health information, GLBA non-public personal information or ITAR data through Connect without Vercel's written approval, and let Vercel add or remove third-party platforms without notice (https://vercel.com/docs/connect/legal)",
      "Revocation calls the provider's revocation endpoint where one exists. Otherwise Connect marks the token for deletion in its own store and the provider credential may keep working until it expires (https://vercel.com/docs/connect/concepts/tokens)",
      "Project links decide which environments may request tokens but don't separate provider installations, so Vercel's docs advise one connector per environment for isolation (https://vercel.com/docs/connect/concepts/project-links)",
      "Vercel's security bulletin for April 2026 says an attacker reached internal systems through an employee account and decrypted some customers' non-sensitive environment variables. Connect was not generally available then (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Surface graded",
        "value": "The hosted Connect API at https://api.vercel.com (`/v1/connect/token/{connector}`, `/v1/connect/authorize/{connector}` and the connector management paths), reached through the `@vercel/connect` TypeScript SDK, the `vercel connect` CLI or plain HTTP"
      },
      {
        "label": "Token subjects",
        "value": "`app` (the service or bot), `user` (a named user, after consent), `jwt-bearer` (a federated subject from the customer's own identity provider) and `token` (exchange of an existing subject token)"
      },
      {
        "label": "Scoping",
        "value": "`scopes`, `resources`, `authorizationDetails` and `audience` are forwarded to the provider per request. `installationId` picks the tenant, and `'*'` asks for a cross-installation token where the connector supports it"
      },
      {
        "label": "Connectors",
        "value": "Managed by Vercel: Slack, GitHub, Linear, Microsoft, Microsoft Teams, Snowflake, Salesforce (beta) and Linq (beta). Customer managed: custom OAuth with the authorisation code flow with PKCE or client credentials, static API keys, and MCP servers discovered from their OAuth metadata"
      },
      {
        "label": "Rate limits",
        "value": "200 reads a minute per team (`getToken`, `getTokenResponse`, `getConnectorMetadata`, list), 50 writes a minute per team (`revokeToken`, create, attach, detach, update, remove), 6,000 a minute on the OAuth gateway and trigger endpoints. A 429 means waiting one minute"
      },
      {
        "label": "Errors",
        "value": "Typed SDK classes: `UserAuthorizationRequiredError`, `ConnectorInstallationRequiredError`, `NoValidTokenError`, `ConnectorNotFoundError`, `ClientNotLinkedToProjectError`, `ClientNotEnabledForEnvironmentError`"
      },
      {
        "label": "Audit",
        "value": "Observability tab per connector with five event types and correlation IDs. Retention 12 hours on Hobby, 3 days on Pro, 30 days on Enterprise. Drains on Pro and Enterprise. Connector changes appear in the team Activity Log"
      },
      {
        "label": "Triggers",
        "value": "Connect verifies provider webhook signatures, re-attests each event with an OIDC identity and forwards it to up to 3 project destinations per connector"
      },
      {
        "label": "Access control",
        "value": "Project links per environment, including Custom Environments. On Pro and Enterprise an owner can restrict connector management to Owners and the Connector Manager permission"
      },
      {
        "label": "SDK",
        "value": "`@vercel/connect` 2.4.1 (6 October 2026), Apache-2.0, one runtime dependency (`@vercel/oidc`), with adapters for AI SDK, MCP clients, eve, Chat SDK, Better Auth and Auth.js"
      },
      {
        "label": "Certifications",
        "value": "Vercel states SOC 2 Type 2 (Security, Confidentiality, Availability) and ISO 27001:2022. security.txt points to HackerOne and expires 28 September 2027"
      },
      {
        "label": "Status",
        "value": "Connect has been a component on www.vercel-status.com since 18 September 2026"
      }
    ],
    "unitPrices": [
      {
        "item": "Token request (Pro)",
        "unit": "1k-requests",
        "usd": 3,
        "note": "Hobby includes 500 a month. Enterprise negotiated"
      },
      {
        "item": "Trigger, a forwarded provider webhook (Pro)",
        "unit": "1k-requests",
        "usd": 0.95,
        "note": "Counted per destination. Hobby includes 1,000 a month"
      }
    ],
    "provenance": {
      "legalEntity": "Vercel Inc.",
      "domain": "vercel.com",
      "domainRegistered": "1999-10-04",
      "endpointOnVendorDomain": true,
      "terms": "https://vercel.com/legal/terms",
      "privacy": "https://vercel.com/legal/privacy-policy",
      "statusPage": "https://www.vercel-status.com",
      "changelog": "https://vercel.com/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service (last updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, and California law. The DPA calls Vercel Inc. a Delaware corporation.",
        "Connect also has its own product terms at https://vercel.com/docs/connect/legal. The Terms of Service text we read does not mention Connect by name.",
        "The Privacy Notice (effective 1 June 2026) says it does not apply to personal information Vercel processes as a processor for customers, which the DPA covers. The DPA (effective 31 March 2026) applies to Pro and Enterprise plans.",
        "https://vercel.com/.well-known/security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28.",
        "RDAP gives vercel.com a registration date of 1999-10-04, long before Vercel, so the domain was bought later.",
        "The API answers at api.vercel.com and the OpenAPI document at openapi.vercel.sh."
      ],
      "score": 99,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Vercel Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "vercel.com, registered 1999-10-04 (27 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.vercel.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "www.vercel-status.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://vercel.com/legal/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-01",
          "words": 8171,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated June 1, 2026",
              "says": "Last updated 2026-06-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement shall be governed by the laws of the State of California without regard to its conflict of laws provisions.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN THESE STATES, VERCEL'S LIABILITY WILL BE LIMITED TO THE GREATEST EXTENT PERMITTED BY LAW."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Subject to earlier termination as provided below, Vercel may terminate your account and this Agreement at any time by providing thirty (30) days prior notice to the administrative email address associated with your account."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Vercel may change this Agreement from time to time by providing notice either by emailing the email address associated with your account or by posting a notice at https://vercel.com.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not have such authority, or if you do not agree with this Agreement, you must not accept this Agreement and may not use the Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Vercel's warranties, indemnities and SLA terms do not apply to Previews and Support Services are not provided for Previews."
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "In addition, if you are on a Hobby plan or trial Pro plan, you agree that we may use Your Content to train our artificial intelligence (\"AI\") and machine learning models, and we may share Your Content with third parties for the purpose of developing and improving their products, including training and improving their…"
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may shut down and terminate projects or deployments using the Hobby plan without notice for any reason or no reason."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "You and Vercel agree that any Claim will be settled by final and binding arbitration, using the English language, administered by JAMS under its Streamlined Arbitration Rules and Procedures (the \"JAMS Rules\")."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "A customer that lets its own or a third party's AI tools or agents access the service agrees to be legally bound by the actions those tools take on its behalf.",
              "quote": "you authorize and agree to be legally bound by the actions taken on your behalf by those Third Party Tools"
            },
            {
              "date": "2026-10-08",
              "text": "During the agreement Vercel may use the customer's trademarks, trade names and logos in its marketing materials and websites and name it as a customer.",
              "quote": "During the term of this Agreement, you grant Vercel a non-exclusive, royalty-free, fully-paid up license to use and reproduce your trademarks, trade names and logos in Vercel's marketing materials and website(s) and to indicate that you are a Vercel customer."
            },
            {
              "date": "2026-10-08",
              "text": "The licence over customer content is sublicensable and transferable and covers improving the services and developing new products and services.",
              "quote": "a worldwide, non-exclusive, royalty-free, fully paid, sublicensable and transferable license to use, copy, modify, adapt, reproduce, distribute, display, publish, store, perform, and create derivatives of Your Content to provide and improve the Services, develop new products and services"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://vercel.com/legal/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-01",
          "words": 7867,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated June 1, 2026",
              "says": "Last updated 2026-06-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The information that we collect depends on your interactions with us, the choices that you make, the products and features you use, your location, and applicable laws."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We receive information about Customers from third parties or Vercel partners that provide services or support our business operations."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We advertise our Services through third parties, and may use cookies and other tracking technologies to support targeted advertising and serve relevant ads."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to withdraw consent where you have provided your consent for us to process your personal information."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions about this Notice, please contact us at privacy@vercel.com or write to us:",
              "says": "privacy@vercel.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "To the extent required by applicable law, whenever we transfer your information, we take the appropriate steps to protect your information, including the use of standard contractual clauses or other appropriate legal mechanisms.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "Services, such as when we use your information to train the AI models"
            },
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We engage with several partners, such as third-party advertising networks, integration service partners, event sponsors, and resellers. We may share information with them to provide and support our Services, and to conduct our Advertising and Marketing Activities."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "For Hobby and Pro plans, subject to team settings, Vercel may disclose de-identified information to AI business partners for training and improving their models.",
              "quote": "we may disclose de-identified information (including de-identified AI Product Information) to AI business partners for their product improvement and development, including training and improving AI and machine learning models"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/vercel-connect.json",
    "live": {
      "slug": "vercel-connect",
      "probe": {
        "target": "https://api.vercel.com",
        "method": "get",
        "lastAt": "2026-10-09T10:14:31.554967166Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 570,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 569,
        "p95ms24h": 1136,
        "samples24h": 28,
        "samples30d": 28,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 28,
            "ok": 28
          }
        ]
      },
      "vendorStatus": {
        "page": "https://www.vercel-status.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-09T10:11:23.223038188Z"
      },
      "updatedAt": "2026-10-09T10:14:31.554967166Z"
    }
  }
}
