{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "youtrack",
    "name": "YouTrack",
    "vendor": "JetBrains s.r.o.",
    "vendorUrl": "https://www.jetbrains.com/youtrack/",
    "kind": "http-api",
    "category": "project-management",
    "summary": "YouTrack is JetBrains' issue tracker and project management tool, with a knowledge base, helpdesk and time tracking. Agents reach each YouTrack Cloud or Server instance through its REST API and a built-in remote MCP server at `/mcp`.",
    "url": "https://www.anchorterminal.com/tools/youtrack",
    "markdownUrl": "https://www.anchorterminal.com/tools/youtrack.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/youtrack.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/youtrack.json",
    "license": "Proprietary service under the JetBrains YouTrack Cloud Terms of Service. YouTrack Server is licensed separately for self-hosting",
    "transports": [
      "http",
      "streamable-http"
    ],
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access is self-serve. Each user creates a permanent token in their profile (Account Security) and sends it as a Bearer token. Tokens never expire, can be deleted, and carry one or both of two scopes, YouTrack and YouTrack Administration. OAuth 2.0 comes from the built-in Hub service, with authorisation code and PKCE (S256), client credentials and a deprecated implicit flow. From YouTrack 2026.2 a system administrator registers OAuth clients or enables automatic registration through Client ID Metadata Documents (off by default). Dynamic Client Registration is not supported. Every call acts with the authorising user's permissions. No app review or partner approval is described.",
    "pricing": "freemium",
    "pricingNotes": "The free plan covers up to ten users and three helpdesk agents, with 30 GB of storage, and the REST API is always enabled, so an agent can start without a contract. Paid Cloud subscriptions are priced per user on a sliding scale. JetBrains announced USD 5.40 a user a month on monthly billing and USD 4.50 on annual billing from 1 October 2025, and USD 6 or USD 5.50 per helpdesk agent beyond three. The pricing page served pounds to our network on 2026-10-08 (GBP 4.30 monthly, GBP 43 a year). API and MCP calls are not priced. A 14-day trial covers up to 100 users. No separate sandbox was found (https://www.jetbrains.com/youtrack/buy/, checked 2026-10-08).",
    "priceSummary": "$4.50 / seat-mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer portal, the OpenAPI document or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 23,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.jetbrains.com/help/youtrack/devportal/youtrack-rest-api.html",
    "llmsTxt": "https://www.jetbrains.com/help/youtrack/devportal/llms.txt",
    "openapi": "https://youtrack.jetbrains.com/api/openapi.json",
    "capabilities": [
      "tasks.create",
      "tasks.update",
      "projects.manage",
      "tasks.comments",
      "work.issues",
      "work.docs"
    ],
    "tags": [
      "official",
      "hosted",
      "self-hosted",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "freemium",
      "free-tier",
      "status-page",
      "soc2",
      "project-management",
      "issue-tracker"
    ],
    "lastRelease": "2026-10-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 49.9,
      "grade": "D",
      "agentReady": false,
      "rank": 601,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 12,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 55,
        "maintenance": 64,
        "payments": 30,
        "reliability": 30,
        "schema": 72,
        "security": 67,
        "transparency": 82
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 30,
          "points": 6,
          "reason": "Graded on YouTrack Cloud's REST API and built-in remote MCP server, with the hosted lines. The status page at jetbrains.com/youtrack/cloud/status shows availability for four zones over 24 hours and 30 days, with no components and no incident history (10 of 20). Its feed gave 30 daily figures a zone for 9 September to 8 October 2026. The lowest days were 99.70 per cent in the EU zone on 10 September and 99.85 per cent in the US zone on 3 October, and the 30-day figure across zones was 99.99 per cent. No incident descriptions and nothing before 9 September could be read (10 of 30). No rate limits were found in the reviewed documentation (0). No 429 handling, backoff guidance or idempotency keys were found (0). The Cloud terms promise commercially reasonable efforts and no SLA was found, and a two-hour maintenance window is scheduled each week (0). The REST API and the MCP server (since 2025.3) are not marked beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "Every instance serves an OpenAPI 3.0.1 document at `/api/openapi.json`. The copy on youtrack.jetbrains.com is public, at version 2026.3, with 281 operations on 157 paths and 232 schemas. The MCP tool schemas need a token and were not read (25). Both docs sites have an llms.txt and a Markdown copy of each page, and the instance serves its own `/llms.txt` (10). Only 3 of 281 operations carry a summary or description in the spec, though parameters do. The reference pages describe each resource with required permissions, and the MCP tools page says what each of the 23 tools returns and which tool to call first (13 of 20). The spec marks read-only attributes and has 394 `required` entries, but only 3 enums, timestamps are Unix milliseconds, and custom fields are polymorphic by `$type` (8 of 15). Reference pages carry sample requests and responses. Every operation in the spec documents only a 200 response, and the only error material found was the OAuth error tables and two troubleshooting pages (6 of 15). A REST API changelog lists additions and deprecations for 2026.1 and 2026.2 by version, without dates, and the path carries no version (10 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 55,
          "points": 8.94,
          "reason": "23 predefined MCP tools (15), and the `tools` and `ignoreTools` URL parameters cut the list a client receives (7 more, 22 of 25). On REST the `fields` parameter selects attributes and nested attributes, `$top` and `$skip` page most collections at 42 items by default, issue activities use cursors, `/api/issues` takes the search query language, and MCP list tools take offset and limit (20). No error reference was found for the REST API. The MCP docs say `manage_issue_tags` returns suggestions when a tag is not found (5 of 20). No idempotency keys were found, and `readOnlyHint` and `destructiveHint` could not be checked without a token. `muteUpdateNotifications` suppresses notifications on writes (2 of 20). Creating an issue needs only `summary` and `project`, but every read needs `fields` or it returns only `id` and `$type`. No current official SDK was found, and YouTrackSharp for .NET was last published on 31 March 2023 (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 67,
          "points": 11.73,
          "reason": "OAuth 2.0 through the built-in Hub service, with authorisation code and PKCE (S256), client credentials, a user consent setting and Client ID Metadata Documents from 2026.2. Permanent tokens can be deleted, never expire, and carry two scopes, YouTrack and YouTrack Administration. The deprecated implicit flow returns the token in a URL fragment (24 of 30). Calls act with the user's role permissions, administrators can hide projects and issues from AI tools, and automatic client registration is off by default. No read-only token scope and no server-side confirmation step were found (12 of 20). Tools return issue, comment and article text written by other people. The docs tell users to review tool calls and the client's data handling, and give no injection guidance (5 of 15). Audit Events log changes to users, groups and projects with author and IP address, issue changes sit in activity streams, and workflow rules can flag MCP changes through `isMcpRequest`. No per-call API log was found (10 of 15). security.txt with a contact and a Coordinated Disclosure Policy promising a reply in 24 hours, discretionary rewards with no formal bounty, SOC 2 stated from version 2023.2 with reports on request, and CVEs published in a security bulletin (16 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Prices are public per user on a sliding scale, with no per-call price. JetBrains announced USD 5.40 a user a month on monthly billing and USD 4.50 on annual billing from 1 October 2025, and the pricing page served GBP 4.30 and GBP 43 a year to our network on 8 October 2026 (10). The free plan covers ten users and three helpdesk agents with the REST API and MCP server. We did not go through signup to confirm no card is asked for (20). A person registers the instance and creates a token or approves OAuth in a browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "reason": "YouTrack 2026.2 build 19562 is dated 5 October 2026 in JetBrains' release feed (30). The feed lists 19 Server builds across 2025.3, 2026.1 and 2026.2 between 15 July and 5 October 2026 (20). Release notes for each build link to the public tracker at youtrack.jetbrains.com, and there is a support request form and a REST API changelog. Response times were not checked (11 of 15). The official MCP registry holds one YouTrack entry, from a third party, and no current official SDK was found (0). Docker images are published for each build. YouTrackSharp, the .NET library JetBrains names, was last published in March 2023 (3 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 82,
          "points": 7.18,
          "note": "editorial 65, provenance 98",
          "reason": "Closed service under the YouTrack Cloud Terms of Service, version 2.0 effective 14 August 2024, naming JetBrains s.r.o. and Czech law (15 of 30). The terms, the Privacy Notice (version 3.2, 12 June 2026) and the Data Processing Addendum agree. Backups are kept for one month after a deletion request and six months after termination, JetBrains says it will not train AI models on customer data, and native AI runs on models JetBrains deploys. The DPA dates from 27 April 2022 (24 of 30). Deprecations are announced by version (Hub endpoints in 2026.1, the implicit flow), with no policy or notice period, and the terms reserve the right to alter capabilities (8 of 20). The third-party list, version 3.15 effective 30 September 2026, names Amazon Web Services EMEA SARL for YouTrack Cloud, and the owner picks one of four AWS regions (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "23 predefined MCP tools (15), and the `tools` and `ignoreTools` URL parameters cut the list a client receives (7 more, 22 of 25). On REST the `fields` parameter selects attributes and nested attributes, `$top` and `$skip` page most collections at 42 items by default, issue activities use cursors, `/api/issues` takes the search query language, and MCP list tools take offset and limit (20). No error reference was found for the REST API. The MCP docs say `manage_issue_tags` returns suggestions when a tag is not found (5 of 20). No idempotency keys were found, and `readOnlyHint` and `destructiveHint` could not be checked without a token. `muteUpdateNotifications` suppresses notifications on writes (2 of 20). Creating an issue needs only `summary` and `project`, but every read needs `fields` or it returns only `id` and `$type`. No current official SDK was found, and YouTrackSharp for .NET was last published on 31 March 2023 (6 of 15).",
          "maintenance": "YouTrack 2026.2 build 19562 is dated 5 October 2026 in JetBrains' release feed (30). The feed lists 19 Server builds across 2025.3, 2026.1 and 2026.2 between 15 July and 5 October 2026 (20). Release notes for each build link to the public tracker at youtrack.jetbrains.com, and there is a support request form and a REST API changelog. Response times were not checked (11 of 15). The official MCP registry holds one YouTrack entry, from a third party, and no current official SDK was found (0). Docker images are published for each build. YouTrackSharp, the .NET library JetBrains names, was last published in March 2023 (3 of 10).",
          "payments": "No x402, MPP or L402 (0). Prices are public per user on a sliding scale, with no per-call price. JetBrains announced USD 5.40 a user a month on monthly billing and USD 4.50 on annual billing from 1 October 2025, and the pricing page served GBP 4.30 and GBP 43 a year to our network on 8 October 2026 (10). The free plan covers ten users and three helpdesk agents with the REST API and MCP server. We did not go through signup to confirm no card is asked for (20). A person registers the instance and creates a token or approves OAuth in a browser (0).",
          "reliability": "Graded on YouTrack Cloud's REST API and built-in remote MCP server, with the hosted lines. The status page at jetbrains.com/youtrack/cloud/status shows availability for four zones over 24 hours and 30 days, with no components and no incident history (10 of 20). Its feed gave 30 daily figures a zone for 9 September to 8 October 2026. The lowest days were 99.70 per cent in the EU zone on 10 September and 99.85 per cent in the US zone on 3 October, and the 30-day figure across zones was 99.99 per cent. No incident descriptions and nothing before 9 September could be read (10 of 30). No rate limits were found in the reviewed documentation (0). No 429 handling, backoff guidance or idempotency keys were found (0). The Cloud terms promise commercially reasonable efforts and no SLA was found, and a two-hour maintenance window is scheduled each week (0). The REST API and the MCP server (since 2025.3) are not marked beta (10).",
          "schema": "Every instance serves an OpenAPI 3.0.1 document at `/api/openapi.json`. The copy on youtrack.jetbrains.com is public, at version 2026.3, with 281 operations on 157 paths and 232 schemas. The MCP tool schemas need a token and were not read (25). Both docs sites have an llms.txt and a Markdown copy of each page, and the instance serves its own `/llms.txt` (10). Only 3 of 281 operations carry a summary or description in the spec, though parameters do. The reference pages describe each resource with required permissions, and the MCP tools page says what each of the 23 tools returns and which tool to call first (13 of 20). The spec marks read-only attributes and has 394 `required` entries, but only 3 enums, timestamps are Unix milliseconds, and custom fields are polymorphic by `$type` (8 of 15). Reference pages carry sample requests and responses. Every operation in the spec documents only a 200 response, and the only error material found was the OAuth error tables and two troubleshooting pages (6 of 15). A REST API changelog lists additions and deprecations for 2026.1 and 2026.2 by version, without dates, and the path carries no version (10 of 15).",
          "security": "OAuth 2.0 through the built-in Hub service, with authorisation code and PKCE (S256), client credentials, a user consent setting and Client ID Metadata Documents from 2026.2. Permanent tokens can be deleted, never expire, and carry two scopes, YouTrack and YouTrack Administration. The deprecated implicit flow returns the token in a URL fragment (24 of 30). Calls act with the user's role permissions, administrators can hide projects and issues from AI tools, and automatic client registration is off by default. No read-only token scope and no server-side confirmation step were found (12 of 20). Tools return issue, comment and article text written by other people. The docs tell users to review tool calls and the client's data handling, and give no injection guidance (5 of 15). Audit Events log changes to users, groups and projects with author and IP address, issue changes sit in activity streams, and workflow rules can flag MCP changes through `isMcpRequest`. No per-call API log was found (10 of 15). security.txt with a contact and a Coordinated Disclosure Policy promising a reply in 24 hours, discretionary rewards with no formal bounty, SOC 2 stated from version 2023.2 with reports on request, and CVEs published in a security bulletin (16 of 20).",
          "transparency": "Closed service under the YouTrack Cloud Terms of Service, version 2.0 effective 14 August 2024, naming JetBrains s.r.o. and Czech law (15 of 30). The terms, the Privacy Notice (version 3.2, 12 June 2026) and the Data Processing Addendum agree. Backups are kept for one month after a deletion request and six months after termination, JetBrains says it will not train AI models on customer data, and native AI runs on models JetBrains deploys. The DPA dates from 27 April 2022 (24 of 30). Deprecations are announced by version (Hub endpoints in 2026.1, the implicit flow), with no policy or notice period, and the terms reserve the right to alter capabilities (8 of 20). The third-party list, version 3.15 effective 30 September 2026, names Amazon Web Services EMEA SARL for YouTrack Cloud, and the owner picks one of four AWS regions (18 of 20)."
        },
        "sources": [
          {
            "what": "REST API overview",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/youtrack-rest-api.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "developer portal index for agents",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI document on JetBrains' own instance",
            "url": "https://youtrack.jetbrains.com/api/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI specification page",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/youtrack-openapi-specification.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "permanent token authorisation",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/authentication-with-permanent-token.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "managing permanent tokens and scopes",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/Manage-Permanent-Token.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth 2.0 authorisation, CIMD and errors",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/OAuth-authorization-in-youtrack.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth clients in YouTrack Cloud",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/oauth-clients.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth authorisation server metadata for JetBrains' instance",
            "url": "https://hub.jetbrains.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "fields syntax",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/api-fields-syntax.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/api-concept-pagination.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "issues resource reference",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/resource-api-issues.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "REST API changelog",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/api-changelog.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Hub endpoints deprecated in 2026.1",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/hub-rest-api-deprecated-endpoints-2026-1.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tools overview and security",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/ai-tools.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "predefined MCP tools",
            "url": "https://www.jetbrains.com/help/youtrack/devportal/predefined-ai-tools.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "remote MCP server setup and URL parameters",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/model-context-protocol-server.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP endpoint response without a token",
            "url": "https://youtrack.jetbrains.com/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "instance llms.txt on JetBrains' own YouTrack",
            "url": "https://youtrack.jetbrains.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud security and hosting",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/security.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "audit events",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/audit-events.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "maintenance calendar",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/youtrack-cloud-maintenance-calendar.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "new instances, free plan and trial",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/new-youtrack-cloud-instances.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "storage limits",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/storage-limits.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "what's new in 2026.2",
            "url": "https://www.jetbrains.com/help/youtrack/cloud/whats-new.html.md",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://www.jetbrains.com/youtrack/cloud/status/",
            "seen": "2026-10-08"
          },
          {
            "what": "status feed the page loads, availability",
            "url": "https://myjetbrains.com/youtrack/youtrack-hosted-master/rest/stat/availability",
            "seen": "2026-10-08"
          },
          {
            "what": "status feed, 30 daily figures for the EU zone",
            "url": "https://myjetbrains.com/youtrack/youtrack-hosted-master/rest/stat/monthlyDetails?zone=eu",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page (prices embedded in the page, served in GBP)",
            "url": "https://www.jetbrains.com/youtrack/buy/",
            "seen": "2026-10-08"
          },
          {
            "what": "price announcement for 1 October 2025",
            "url": "https://blog.jetbrains.com/youtrack/2025/06/new-youtrack-prices-starting-from-october-2025/",
            "seen": "2026-10-08"
          },
          {
            "what": "release feed",
            "url": "https://data.services.jetbrains.com/products/releases?code=YTD\u0026type=release",
            "seen": "2026-10-08"
          },
          {
            "what": "YouTrack blog feed",
            "url": "https://blog.jetbrains.com/youtrack/feed/",
            "seen": "2026-10-08"
          },
          {
            "what": "security post, CVE-2026-33392",
            "url": "https://blog.jetbrains.com/youtrack/2026/04/security-issue-in-youtrack-cve-2026-33392/",
            "seen": "2026-10-08"
          },
          {
            "what": "security post, June 2026",
            "url": "https://blog.jetbrains.com/youtrack/2026/06/youtrack-security-update-youtrack-server-upgrade-required/",
            "seen": "2026-10-08"
          },
          {
            "what": "YouTrack Cloud Terms of Service",
            "url": "https://www.jetbrains.com/legal/docs/youtrack/youtrack_cloud/",
            "seen": "2026-10-08"
          },
          {
            "what": "JetBrains Privacy Notice",
            "url": "https://www.jetbrains.com/legal/docs/privacy/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Addendum",
            "url": "https://www.jetbrains.com/legal/dpa/",
            "seen": "2026-10-08"
          },
          {
            "what": "third-party services list",
            "url": "https://www.jetbrains.com/legal/docs/privacy/third-parties/",
            "seen": "2026-10-08"
          },
          {
            "what": "Coordinated Disclosure Policy",
            "url": "https://www.jetbrains.com/legal/docs/terms/coordinated-disclosure/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.jetbrains.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=youtrack",
            "seen": "2026-10-08"
          },
          {
            "what": "YouTrackSharp versions on NuGet",
            "url": "https://api.nuget.org/v3/registration5-semver1/youtracksharp/index.json",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/jetbrains.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the MCP tool definitions (input schemas, `readOnlyHint` and `destructiveHint`), since `/mcp` answers 401 without a token. The count of 23 comes from the docs page",
          "unchecked: current US dollar prices. The pricing page served pounds to our network, so the dollar figures are those JetBrains announced for 1 October 2025",
          "unchecked: status history before 9 September 2026 and any incident descriptions. The status page publishes availability percentages only, drawn by script from a feed we read directly",
          "Whether YouTrack Cloud enforces rate limits. None were found in either docs index or the pages read",
          "Whether free plan signup asks for a card. We did not go through signup",
          "How REST errors are shaped. No error reference was found, and the OpenAPI document lists only 200 responses",
          "The SOC 2 report type and date. The security page says reports are available from support on request",
          "The Coordinated Disclosure Policy gives its last update as 10 October 2026, two days after our check",
          "The OpenAPI document on youtrack.jetbrains.com reports version 2026.3, while the newest public release is 2026.2",
          "The lead was right about the vendor and the REST API. It did not mention the built-in MCP server, which is graded here alongside the API"
        ]
      },
      "negative": -5,
      "negativeNotes": [
        "2026-04-17. CVE-2026-33392, a sandbox bypass allowing code execution by an administrator, reported in March 2026. JetBrains says the impact was greatest in YouTrack Cloud, where it could bypass cross-tenant isolation on shared hardware, that Cloud was mitigated within 48 hours, and that it found no evidence of exploitation. Fixed and disclosed, so 3 of a possible 15 (https://blog.jetbrains.com/youtrack/2026/04/security-issue-in-youtrack-cve-2026-33392/)",
        "2026-06-19. CVE-2026-56141 (admin account takeover through authentication token forgery) and CVE-2026-56142 (email verification bypass), found in May 2026, affected YouTrack Cloud, and CVE-2026-50242 affected Server. JetBrains says Cloud was patched before the post and that it found no evidence of exploitation outside testing. Fixed and disclosed, so 2 points (https://blog.jetbrains.com/youtrack/2026/06/youtrack-security-update-youtrack-server-upgrade-required/)"
      ],
      "verdict": "Every instance serves an OpenAPI 3.0 document, a 23-tool MCP server with OAuth and PKCE, and field selection on each REST call, and the free plan covers ten users. No rate limits, 429 handling, error reference or SLA were found, and JetBrains disclosed two sets of critical vulnerabilities affecting YouTrack Cloud in 2026, both patched.",
      "bestFor": "Software teams that already run YouTrack and want an agent to search, file and update issues, comment, log time and maintain knowledge base articles under each user's permissions.",
      "strengths": [
        "OpenAPI 3.0.1 document at `/api/openapi.json` on every instance, with 281 operations on 157 paths, plus llms.txt and a Markdown copy of each docs page",
        "Built-in remote MCP server at `/mcp` with 23 predefined tools, and `tools` and `ignoreTools` URL parameters that trim the tool list",
        "OAuth 2.0 authorisation code flow with PKCE (S256) and Client ID Metadata Documents, or revocable permanent tokens with two scopes",
        "Free plan for up to ten users and three helpdesk agents, with the REST API always enabled",
        "19 Server builds published between 15 July and 5 October 2026, and a REST API changelog by version"
      ],
      "weaknesses": [
        "No rate limits, 429 handling, idempotency keys or error reference found in the reviewed documentation",
        "The status page shows availability percentages by region for 24 hours and 30 days, with no incident history, and no SLA was found",
        "Two security disclosures in 2026 affected YouTrack Cloud, a cross-tenant isolation bypass (CVE-2026-33392) and an admin account takeover (CVE-2026-56141). Both were patched",
        "Permanent tokens never expire and carry only two coarse scopes, YouTrack and YouTrack Administration",
        "No current official SDK. YouTrackSharp for .NET covers a subset of the API and was last published on 31 March 2023"
      ],
      "agentNotes": [
        "Send `fields` on every REST request. Without it the server returns only the database ID and `$type` of each entity",
        "Page collections with `$top` and `$skip`. Most resources return 42 items by default",
        "Call `get_issue_fields_schema` before `create_issue` or `update_issue`, because required custom fields differ by project",
        "Connect MCP clients to `https://\u003cinstance\u003e.youtrack.cloud/mcp`. OAuth needs an administrator to enable CIMD or register the client, since Dynamic Client Registration is not supported",
        "Create permanent tokens with the YouTrack scope only, and add `?tools=` to the MCP URL to limit the tools listed"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 49.9
        }
      ],
      "editorialScores": {
        "ergonomics": 55,
        "maintenance": 64,
        "payments": 30,
        "reliability": 30,
        "schema": 72,
        "security": 67,
        "transparency": 65
      },
      "provenanceScore": 98
    },
    "connect": {
      "http": "curl 'https://example.youtrack.cloud/api/users/me?fields=id,login,name' -H 'Accept: application/json' -H \"Authorization: Bearer $YOUTRACK_TOKEN\"",
      "claudeCode": "claude mcp add --header \"Authorization: Bearer \u003ctoken\u003e\" --transport http youtrack \u003cyoutrack-mcp-endpoint-url\u003e"
    },
    "letme": {
      "capability": "https://letme.dev/tasks.create",
      "tool": "https://letme.dev/youtrack"
    },
    "notable": [
      "The remote MCP server is built into every instance at `/mcp` since YouTrack 2025.3, and accepts OAuth or a permanent token in the `Authorization` header (https://www.jetbrains.com/help/youtrack/cloud/model-context-protocol-server.html)",
      "23 predefined MCP tools cover issues, comments, tags, links, articles, projects, groups, users and time tracking, and custom tools can be added in an app package (https://www.jetbrains.com/help/youtrack/devportal/predefined-ai-tools.html)",
      "The MCP URL takes `tools`, `ignoreTools`, `customToolPackages` and `enableToolOutputSchema` query parameters (https://www.jetbrains.com/help/youtrack/cloud/model-context-protocol-server.html)",
      "Administrators can hide projects and issues from AI tools, and workflow rules can detect MCP changes through `isMcpRequest` (https://www.jetbrains.com/help/youtrack/devportal/ai-tools.html)",
      "JetBrains disclosed CVE-2026-33392 on 17 April 2026 and CVE-2026-56141, CVE-2026-56142 and CVE-2026-50242 on 19 June 2026, and says YouTrack Cloud was patched with no evidence of exploitation (https://blog.jetbrains.com/youtrack/2026/06/youtrack-security-update-youtrack-server-upgrade-required/)",
      "JetBrains' own instance serves an `/llms.txt` and an `ai-instructions` meta tag telling AI clients that the page is a single-page application and to read `/llms.txt` and the REST API. Recorded as a fact, with no deduction (https://youtrack.jetbrains.com/llms.txt)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surfaces graded",
        "value": "YouTrack Cloud's REST API at `https://\u003cinstance\u003e.youtrack.cloud/api` and the built-in remote MCP server at `https://\u003cinstance\u003e.youtrack.cloud/mcp`. YouTrack Server exposes the same two on the owner's host"
      },
      {
        "label": "REST API",
        "value": "OpenAPI 3.0.1 at `/api/openapi.json`, version 2026.3 on youtrack.jetbrains.com, 281 operations on 157 paths (136 GET, 101 POST, 44 DELETE) and 232 schemas"
      },
      {
        "label": "MCP tools",
        "value": "23 predefined. Issues (12, including `search_issues`, `create_issue`, `update_issue`, `add_issue_comment`, `link_issues`), articles (4), projects (2), groups (2), users (2), time tracking (`log_work`). Custom tools through app packages"
      },
      {
        "label": "MCP URL parameters",
        "value": "`tools`, `ignoreTools`, `customToolPackages`, `enableToolOutputSchema`"
      },
      {
        "label": "Authentication",
        "value": "Permanent token as Bearer (no expiry, scopes YouTrack and YouTrack Administration), or OAuth 2.0 through Hub with authorisation code and PKCE (S256), client credentials, and a deprecated implicit flow. CIMD from 2026.2, off by default. No Dynamic Client Registration"
      },
      {
        "label": "Rate limits",
        "value": "None found in the reviewed documentation"
      },
      {
        "label": "Response sizing",
        "value": "`fields` selects attributes, with nested syntax such as `customFields(name,value(name))`. Without it only `id` and `$type` return"
      },
      {
        "label": "Pagination",
        "value": "`$top` and `$skip`, 42 items by default on most resources. Issue activities use cursors. MCP list tools take offset and limit"
      },
      {
        "label": "Search",
        "value": "`query` on `/api/issues` takes YouTrack's search query language, and `customFields` limits the custom fields returned"
      },
      {
        "label": "Audit",
        "value": "Audit Events page for users, groups and projects with author and IP address, JSON download of the 1,000 most recent, and the Hub REST events endpoint. Issue and article changes sit in each activity stream"
      },
      {
        "label": "SDKs",
        "value": "No current official SDK found. YouTrackSharp (.NET, JetBrains) covers a subset and was last published as 2022.3.1 on 31 March 2023"
      },
      {
        "label": "Hosting",
        "value": "AWS, with the instance owner choosing US West (Northern California), Europe (Frankfurt or Ireland) or Asia Pacific (Singapore). 3 GB of storage per paid user"
      },
      {
        "label": "Certifications",
        "value": "The Cloud security page says YouTrack is SOC 2 compliant from version 2023.2, with reports on request from support"
      },
      {
        "label": "Status",
        "value": "https://www.jetbrains.com/youtrack/cloud/status/ shows availability for four zones over 24 hours and 30 days. A two-hour maintenance window is scheduled each week"
      },
      {
        "label": "Releases",
        "value": "YouTrack 2026.2 build 19562 on 5 October 2026. 19 Server builds across 2025.3, 2026.1 and 2026.2 between 15 July and 5 October 2026. Cloud is upgraded by JetBrains"
      },
      {
        "label": "Sub-processors",
        "value": "Third-party list version 3.15, effective 30 September 2026, names Amazon Web Services EMEA SARL for YouTrack Cloud hosting"
      }
    ],
    "unitPrices": [
      {
        "item": "Free plan (up to 10 users, 3 helpdesk agents)",
        "unit": "seat-month",
        "usd": 0,
        "note": "30 GB storage; REST API and MCP server included"
      },
      {
        "item": "Cloud user, annual billing",
        "unit": "seat-month",
        "usd": 4.5,
        "note": "starting price as announced for 1 October 2025; falls as users are added. Pricing page served GBP on 2026-10-08"
      },
      {
        "item": "Cloud user, monthly billing",
        "unit": "seat-month",
        "usd": 5.4,
        "note": "starting price as announced for 1 October 2025; pricing page showed GBP 4.30 on 2026-10-08"
      },
      {
        "item": "Helpdesk agent beyond three, monthly billing",
        "unit": "seat-month",
        "usd": 6,
        "note": "USD 5.50 on annual billing, as announced for 1 October 2025"
      }
    ],
    "provenance": {
      "legalEntity": "JetBrains s.r.o.",
      "domain": "jetbrains.com",
      "domainRegistered": "2001-11-09",
      "endpointOnVendorDomain": true,
      "terms": "https://www.jetbrains.com/legal/docs/youtrack/youtrack_cloud/",
      "privacy": "https://www.jetbrains.com/legal/docs/privacy/privacy/",
      "statusPage": "https://www.jetbrains.com/youtrack/cloud/status/",
      "changelog": "https://www.jetbrains.com/help/youtrack/devportal/api-changelog.html",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The YouTrack Cloud Terms of Service (version 2.0, effective 14 August 2024) name JetBrains s.r.o., Na Hřebenech II 1718/8, Prague, 14000, Czech Republic, ID No. 265 02 275, and are governed by Czech law.",
        "The JetBrains Privacy Notice (version 3.2, last updated 12 June 2026) covers JetBrains websites, products and services, and the Cloud terms point to it. Customer personal data is processed under the Data Processing Addendum (version 1.3, 27 April 2022).",
        "Cloud instances answer at \u003cinstance\u003e.youtrack.cloud, or \u003cinstance\u003e.myjetbrains.com/youtrack for instances registered before 2 November 2021. RDAP gives youtrack.cloud a registration date of 2021-04-30 through MarkMonitor, and the docs describe both domains as JetBrains'.",
        "www.jetbrains.com/.well-known/security.txt has a Contact line (security@jetbrains.com) and a Policy line pointing to the Coordinated Disclosure Policy, and no Expires field, which RFC 9116 requires.",
        "The status page draws its figures by script from myjetbrains.com/youtrack/youtrack-hosted-master/rest/stat, which we read directly.",
        "RDAP for jetbrains.com gives a registration date of 2001-11-09 and Network Solutions, LLC as registrar."
      ],
      "score": 98,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "JetBrains s.r.o.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "jetbrains.com, registered 2001-11-09 (24 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "jetbrains.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "www.jetbrains.com/youtrack/cloud/status",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.jetbrains.com/legal/docs/youtrack/youtrack_cloud/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-08-14",
          "words": 7476,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Version 2.0, effective as of August 14, 2024",
              "says": "Last updated 2024-08-14"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These terms are governed by the laws of the Czech Republic, without reference to conflict of laws principles, and specifically excluding the United Nations Convention on Contracts for the International Sale of Goods.",
              "says": "The law of Czech Republic"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "(MAXIMUM LIABILITY) OUR MAXIMUM, OVERALL (‘AGGREGATE’) LIABILITY RELATING TO THESE TERMS IS LIMITED TO THE GREATER OF ONE HUNDRED (100) US DOLLARS OR THE AMOUNT THAT YOU ACTUALLY PAID TO US FOR YOUTRACK IN THE SIX (6) MONTHS BEFORE YOU CLAIMED THAT WE WERE LIABLE.",
              "says": "Capped at the fees paid in the 6 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If You stop using YouTrack, We will suspend the Trial Subscription and maintain Your Data for the period specified in the Documentation, in case You decide to purchase a Subscription within that time frame."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You must not, and You must make sure Your Users do not:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "the Dispute will be excluded from the jurisdiction of general courts and all such Disputes will be finally decided by the Arbitration Court attached to the Czech Chamber of Commerce and the Agricultural Chamber of the Czech Republic"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "A user account may belong to a bot as well as to an individual.",
              "quote": "“User” means an individual or a bot with a user account created by You granting the individual or bot the right to access YouTrack and use it to communicate with other Users as further detailed in the Documentation."
            },
            {
              "date": "2026-10-08",
              "text": "Liability is capped at the greater of 100 US dollars or the amount paid for YouTrack in the six months before the claim.",
              "quote": "(MAXIMUM LIABILITY) OUR MAXIMUM, OVERALL (‘AGGREGATE’) LIABILITY RELATING TO THESE TERMS IS LIMITED TO THE GREATER OF ONE HUNDRED (100) US DOLLARS OR THE AMOUNT THAT YOU ACTUALLY PAID TO US FOR YOUTRACK IN THE SIX (6) MONTHS BEFORE YOU CLAIMED THAT WE WERE LIABLE."
            },
            {
              "date": "2026-10-08",
              "text": "A customer that is a legal entity permits JetBrains to name it publicly as a customer and to display its logo and trademarks.",
              "quote": "If You are a legal entity, You give Us permission to publicly identify You as Our customer and refer to You by name or trade name, display Your logo and trademarks, and describe Your business in marketing materials, on the JetBrains Website, and in other public documents."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.jetbrains.com/legal/docs/privacy/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-12",
          "words": 7319,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Version 3.2, last updated: 12 June 2026",
              "says": "Last updated 2026-06-12"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "In this Privacy Notice, we describe the types of data, including Personal Data, (collectively, “data”) that we and our associated companies collect from you when you use JetBrains Websites and certain JetBrains products and services as described in this Privacy Notice (collectively, our “services”), how we and our ass…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We store the personal information we collect as described in this Privacy Notice for as long as you use JetBrains Products or as necessary to fulfill the purpose(s) for which it was collected, provide our products and services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purp…",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may use third-party service providers, acting as data processors, to assist us in providing JetBrains Products to you or in our operations."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell or share sensitive personal information, nor do we sell or share personal information about individuals we know are under the age of sixteen (16).",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Under certain circumstances, you may have the right to object at any time, on grounds relating to the particular situation, to the processing of your Personal Data by us, and we may be required to no longer process your Personal Data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "For more information, you can contact us anytime at privacy@jetbrains.com .",
              "says": "privacy@jetbrains.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "Through our JetBrains Website, we may share your Personal Data with third-party advertising partners."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Customers must keep their own copy of all data placed on JetBrains servers in case of loss.",
              "quote": "Please note, however, that you must retain a copy of all data that you have placed on our servers in case of any loss."
            },
            {
              "date": "2026-10-08",
              "text": "For JetBrains AI, JetBrains or its LLM providers may collect personal data related to AI service usage.",
              "quote": "If you are using JetBrains AI, we or our LLM providers may collect personal data related to your AI service usage."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/youtrack.json",
    "live": {
      "slug": "youtrack",
      "vendorStatus": {
        "page": "https://www.jetbrains.com/youtrack/cloud/status",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:39:21.794121817Z"
      },
      "updatedAt": "2026-10-08T19:39:21.794121817Z"
    }
  }
}
