{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "zulip",
    "name": "Zulip",
    "vendor": "Kandra Labs, Inc.",
    "vendorUrl": "https://zulip.com",
    "kind": "http-api",
    "category": "productivity",
    "summary": "Zulip is open-source team chat organised into channels and topics, from Kandra Labs, hosted as Zulip Cloud or self-hosted. Agents reach it through a REST API with bot accounts, an events queue and Python and JavaScript client libraries.",
    "url": "https://www.anchorterminal.com/tools/zulip",
    "markdownUrl": "https://www.anchorterminal.com/tools/zulip.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zulip.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zulip.json",
    "repo": "https://github.com/zulip/zulip",
    "license": "Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "pypi",
        "name": "zulip"
      },
      {
        "registry": "npm",
        "name": "zulip-js"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve. Every user and every bot has one API key, sent with HTTP Basic authentication as the account's email and the key. A member creates a bot under Personal settings, Bots, unless an administrator has restricted bot creation, and copies its key or downloads a `zuliprc` file. Generating a new key invalidates the old one. Keys carry no scopes or expiry. What a key can do follows the account's role (owner, administrator, moderator, member, guest), its channel subscriptions and, for bots, the bot type. No OAuth for API clients. `POST /fetch_api_key` exchanges a user's password for the key.",
    "pricing": "freemium",
    "pricingNotes": "Zulip Cloud Free costs nothing and needs no card, with 10,000 messages of search history and 5 GB of files in total. Standard is $6.67 a user a month billed annually or $8 monthly, and Plus is $10 or $12 with a 10-user minimum (https://zulip.com/plans/). API calls are not charged, and the plan comparison lists REST API custom integrations. A self-hosted server is free, with paid plans from $3.50 a user a month for mobile notifications and support. An agent's owner can start on the Free plan or a demo organisation without a contract.",
    "priceSummary": "$6.67 / seat-mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API documentation, the OpenAPI file or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 26014,
      "npmWeekly": 7094,
      "pypiWeekly": 157209,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://zulip.com/api/rest",
    "openapi": "https://github.com/zulip/zulip/blob/main/zerver/openapi/zulip.yaml",
    "capabilities": [
      "work.chat"
    ],
    "tags": [
      "hosted",
      "self-hosted",
      "open-source",
      "freemium",
      "api-key",
      "openapi",
      "python",
      "javascript",
      "webhooks",
      "status-page"
    ],
    "lastRelease": "2026-09-21",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 61.5,
      "grade": "C",
      "agentReady": false,
      "rank": 422,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 68,
        "maintenance": 77,
        "payments": 30,
        "reliability": 83,
        "schema": 82,
        "security": 42,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 83,
          "points": 16.6,
          "reason": "Graded on the hosted Zulip Cloud API with the hosted lines. Status page at status.zulip.com on Statuspage with nine components (20). The history lists no incidents from June to 8 October 2026 and one minor incident on 21 May. The Static asset CDN component was marked degraded on the day with no incident posted (30). The API docs give 200 requests a minute per user as the default configuration and say limits can vary by server and over time (13). A 429 returns `RATE_LIMIT_HIT` with `retry-after`, and every response has `X-RateLimit-*` headers. No idempotency key on `POST /messages` and no retry guidance for writes (10). No SLA found (0). The API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "Public OpenAPI 3.0.1 file in the repository, 166 operations on 119 paths (25). No llms.txt. The docs are Markdown in the public repository and are served as HTML only (2). All 166 operations have a description, median 295 characters, many saying which clients an endpoint is for (16). 263 enums and 322 closed objects, but one `maxLength`, five minimums and several parameters that are JSON encoded inside form fields, such as `narrow` (11). 819 example values, curl, Python and JavaScript samples per endpoint, and a shared error page with codes (14). No version beyond `/api/v1`. Changes are tracked by feature level in a public API changelog with 499 entries and 975 inline change notes, none dated (14)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 68,
          "points": 11.05,
          "reason": "`GET /messages` sizes responses with `num_before`, `num_after` and `apply_markdown`, and `POST /register` with `fetch_event_types`. No field selection (15). Anchor-based paging with flags for more results, and `narrow` filters using the search operators (18). Errors carry a stable `code` and extra keys such as `var_name`, with `msg` translated. Many failures share `BAD_REQUEST` (17). No idempotency keys. `local_id` and `queue_id` on `POST /messages` serve local echo, and the docs tell clients to repeat `delete-topic` until `complete` is true (6). Three required parameters to send a message, official Python and JavaScript libraries, the Python one last tagged in September 2025 (12)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 42,
          "points": 7.35,
          "reason": "One revocable API key per account with no scopes or expiry, and no OAuth for API clients, read as plain revocable keys (20). Incoming webhook URLs carry the key as `api_key` in the query string as a documented option (less 10). Bots are separate accounts, an incoming webhook bot can only send, roles and channel permissions apply to bots, and administrators can restrict bot creation. No read-only key and no confirmation for deletes (12). Messages are other users' text and no prompt-injection guidance was found (2). The security page claims an audit log of administrative actions. No help article or per-call log for an operator was found (5). A disclosure policy, a private HackerOne programme, advisories published with CVE numbers and CodeQL in CI. No security.txt, SOC 2 or ISO 27001 found (13)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Prices are public per user a month, $6.67 to $12 on the cloud plans, with nothing per call (10). The Free cloud plan needs no card (20). A person creates the organisation and the bot in a browser, and no programmatic route to a first key was found (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 77,
          "points": 6.74,
          "reason": "Zulip Server 12.3 was released on 21 September 2026, 18 days before the check, and the main branch had a commit on 8 October (30). Two tagged releases since 11 July 2026, 12.2 and 12.3. The API changelog adds 13 undated feature levels for 13.0 and the cloud runs ahead of the tags, so half marks (10). The newest open issues were all updated between 1 and 8 October 2026, with about 1,200 issues and 874 pull requests open on a repository of 26,014 stars, and a public development community chat (20). Official Python and JavaScript libraries exist. The Python tag 0.9.1 dates from 30 September 2025 and the JavaScript repository's last commit from December 2025 (8). CI, CodeQL and zizmor workflows, and dependency updates in each maintenance release (9)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 77, provenance 74",
          "reason": "The server is open source under Apache 2.0 (30). Terms, a privacy policy, rules of use, a DPA and a GDPR page agree that Kandra Labs is processor for customer data. The privacy policy keeps personal data while an account is open and states no periods, and the DPA is a PDF we did not read (20). The release lifecycle keeps the API compatible with apps released in the last 12 months, and the changelog marks removals by feature level, 50 fields are marked deprecated, with no dates (13). Seven sub-processors are named with their roles, and the service is hosted in the United States. No country per sub-processor and no change log for the list (14)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`GET /messages` sizes responses with `num_before`, `num_after` and `apply_markdown`, and `POST /register` with `fetch_event_types`. No field selection (15). Anchor-based paging with flags for more results, and `narrow` filters using the search operators (18). Errors carry a stable `code` and extra keys such as `var_name`, with `msg` translated. Many failures share `BAD_REQUEST` (17). No idempotency keys. `local_id` and `queue_id` on `POST /messages` serve local echo, and the docs tell clients to repeat `delete-topic` until `complete` is true (6). Three required parameters to send a message, official Python and JavaScript libraries, the Python one last tagged in September 2025 (12).",
          "maintenance": "Zulip Server 12.3 was released on 21 September 2026, 18 days before the check, and the main branch had a commit on 8 October (30). Two tagged releases since 11 July 2026, 12.2 and 12.3. The API changelog adds 13 undated feature levels for 13.0 and the cloud runs ahead of the tags, so half marks (10). The newest open issues were all updated between 1 and 8 October 2026, with about 1,200 issues and 874 pull requests open on a repository of 26,014 stars, and a public development community chat (20). Official Python and JavaScript libraries exist. The Python tag 0.9.1 dates from 30 September 2025 and the JavaScript repository's last commit from December 2025 (8). CI, CodeQL and zizmor workflows, and dependency updates in each maintenance release (9).",
          "payments": "No x402, MPP or L402 (0). Prices are public per user a month, $6.67 to $12 on the cloud plans, with nothing per call (10). The Free cloud plan needs no card (20). A person creates the organisation and the bot in a browser, and no programmatic route to a first key was found (0).",
          "reliability": "Graded on the hosted Zulip Cloud API with the hosted lines. Status page at status.zulip.com on Statuspage with nine components (20). The history lists no incidents from June to 8 October 2026 and one minor incident on 21 May. The Static asset CDN component was marked degraded on the day with no incident posted (30). The API docs give 200 requests a minute per user as the default configuration and say limits can vary by server and over time (13). A 429 returns `RATE_LIMIT_HIT` with `retry-after`, and every response has `X-RateLimit-*` headers. No idempotency key on `POST /messages` and no retry guidance for writes (10). No SLA found (0). The API is generally available (10).",
          "schema": "Public OpenAPI 3.0.1 file in the repository, 166 operations on 119 paths (25). No llms.txt. The docs are Markdown in the public repository and are served as HTML only (2). All 166 operations have a description, median 295 characters, many saying which clients an endpoint is for (16). 263 enums and 322 closed objects, but one `maxLength`, five minimums and several parameters that are JSON encoded inside form fields, such as `narrow` (11). 819 example values, curl, Python and JavaScript samples per endpoint, and a shared error page with codes (14). No version beyond `/api/v1`. Changes are tracked by feature level in a public API changelog with 499 entries and 975 inline change notes, none dated (14).",
          "security": "One revocable API key per account with no scopes or expiry, and no OAuth for API clients, read as plain revocable keys (20). Incoming webhook URLs carry the key as `api_key` in the query string as a documented option (less 10). Bots are separate accounts, an incoming webhook bot can only send, roles and channel permissions apply to bots, and administrators can restrict bot creation. No read-only key and no confirmation for deletes (12). Messages are other users' text and no prompt-injection guidance was found (2). The security page claims an audit log of administrative actions. No help article or per-call log for an operator was found (5). A disclosure policy, a private HackerOne programme, advisories published with CVE numbers and CodeQL in CI. No security.txt, SOC 2 or ISO 27001 found (13).",
          "transparency": "The server is open source under Apache 2.0 (30). Terms, a privacy policy, rules of use, a DPA and a GDPR page agree that Kandra Labs is processor for customer data. The privacy policy keeps personal data while an account is open and states no periods, and the DPA is a PDF we did not read (20). The release lifecycle keeps the API compatible with apps released in the last 12 months, and the changelog marks removals by feature level, 50 fields are marked deprecated, with no dates (13). Seven sub-processors are named with their roles, and the service is hosted in the United States. No country per sub-processor and no change log for the list (14)."
        },
        "sources": [
          {
            "what": "REST API overview",
            "url": "https://zulip.com/api/rest",
            "seen": "2026-10-09"
          },
          {
            "what": "HTTP headers, authentication and rate limits",
            "url": "https://zulip.com/api/http-headers",
            "seen": "2026-10-09"
          },
          {
            "what": "error handling",
            "url": "https://zulip.com/api/rest-error-handling",
            "seen": "2026-10-09"
          },
          {
            "what": "API keys and zuliprc files",
            "url": "https://zulip.com/api/api-keys",
            "seen": "2026-10-09"
          },
          {
            "what": "client libraries",
            "url": "https://zulip.com/api/client-libraries",
            "seen": "2026-10-09"
          },
          {
            "what": "roles and permissions",
            "url": "https://zulip.com/api/roles-and-permissions",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI file, 166 operations",
            "url": "https://github.com/zulip/zulip/blob/main/zerver/openapi/zulip.yaml",
            "seen": "2026-10-09"
          },
          {
            "what": "API changelog source",
            "url": "https://github.com/zulip/zulip/blob/main/api_docs/changelog.md",
            "seen": "2026-10-09"
          },
          {
            "what": "server changelog and advisories by release",
            "url": "https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md",
            "seen": "2026-10-09"
          },
          {
            "what": "release lifecycle",
            "url": "https://github.com/zulip/zulip/blob/main/docs/overview/release-lifecycle.md",
            "seen": "2026-10-09"
          },
          {
            "what": "bots overview",
            "url": "https://zulip.com/help/bots-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "incoming webhook URL format",
            "url": "https://github.com/zulip/zulip/blob/main/docs/webhooks/incoming-webhooks-overview.md",
            "seen": "2026-10-09"
          },
          {
            "what": "plans and pricing",
            "url": "https://zulip.com/plans/",
            "seen": "2026-10-09"
          },
          {
            "what": "security page",
            "url": "https://zulip.com/security/",
            "seen": "2026-10-09"
          },
          {
            "what": "security policy",
            "url": "https://github.com/zulip/zulip/blob/main/SECURITY.md",
            "seen": "2026-10-09"
          },
          {
            "what": "security advisories",
            "url": "https://github.com/zulip/zulip/security/advisories",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://status.zulip.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "status history",
            "url": "https://status.zulip.com/history",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of service",
            "url": "https://zulip.com/policies/terms",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://zulip.com/policies/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "rules of use",
            "url": "https://zulip.com/policies/rules",
            "seen": "2026-10-09"
          },
          {
            "what": "sub-processors",
            "url": "https://zulip.com/policies/subprocessors",
            "seen": "2026-10-09"
          },
          {
            "what": "GDPR compliance",
            "url": "https://zulip.com/help/gdpr-compliance",
            "seen": "2026-10-09"
          },
          {
            "what": "repository page, stars and open issues",
            "url": "https://github.com/zulip/zulip",
            "seen": "2026-10-09"
          },
          {
            "what": "open issues",
            "url": "https://github.com/zulip/zulip/issues",
            "seen": "2026-10-09"
          },
          {
            "what": "Python client repository and tags",
            "url": "https://github.com/zulip/python-zulip-api",
            "seen": "2026-10-09"
          },
          {
            "what": "npm registry, zulip-js",
            "url": "https://registry.npmjs.org/zulip-js/latest",
            "seen": "2026-10-09"
          },
          {
            "what": "npm downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/zulip-js",
            "seen": "2026-10-09"
          },
          {
            "what": "PyPI downloads",
            "url": "https://pypistats.org/api/packages/zulip/recent",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt, 404",
            "url": "https://zulip.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "llms.txt, 404",
            "url": "https://zulip.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP for zulip.com",
            "url": "https://rdap.verisign.com/com/v1/domain/zulip.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the Data Processing Addendum, a PDF at zulip.com/static/images/policies/Zulip-Data-Processing-Addendum.pdf",
          "unchecked: the PyPI project page for `zulip`, which needs JavaScript. The version and date come from the repository tag 0.9.1",
          "unchecked: the rate limits Zulip Cloud applies. The 200 a minute figure is the documented default configuration",
          "unchecked: whether a bot counts as a paid user on Standard and Plus",
          "unchecked: the status API and uptime figures. status.zulip.com disallows `/api/` in robots.txt, so the history pages were read instead",
          "unchecked: severity ratings of the advisories, and whether a second page of advisories lists more than the changelog does",
          "The lead gave docs.zulip.com/api/rest. The API documentation read is at zulip.com/api/rest, and docs.zulip.com was not requested",
          "The lead named the vendor Zulip. The legal entity in the terms is Kandra Labs, Inc.",
          "No official MCP server was found in the help centre, API docs or server documentation",
          "No SLA, SOC 2 or ISO 27001 statement was found on the pages read. One may exist under a sales agreement",
          "The Rules of Use say not to permit any third party to access an account's credentials. How that applies to an agent run by a third party was not established",
          "The audit log named on the security page has no help article we could find, so what an organisation administrator can see on Zulip Cloud was not established"
        ]
      },
      "negative": -4,
      "negativeNotes": [
        "2026-08-10 and 2026-09-21. GHSA-5r8f-gq2h-fcgp let a guest receive new messages from public channels it was not subscribed to by registering an event queue, fixed in 12.2. GHSA-42mq-rxcr-wj72 let a member forge the sender of a group direct message through the API, fixed in 12.3. Both are reachable with an ordinary API key. Fixed and published, so 2 points (https://github.com/zulip/zulip/security/advisories/GHSA-5r8f-gq2h-fcgp, https://github.com/zulip/zulip/security/advisories/GHSA-42mq-rxcr-wj72).",
        "2026-02-05 to 2026-09-21. Eleven further advisories in twelve months across releases 11.5, 11.6, 12.0, 12.2 and 12.3, among them CVE-2026-25742 (attachments still public after web-public access was disabled), CVE-2026-40300 (edit history exposing original content in the API) and GHSA-xw9h-9rcm-hx4m (OpenID Connect ignoring `email_verified`). All fixed and published by the vendor, so 2 points (https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md)."
      ],
      "verdict": "The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published.",
      "bestFor": "A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.",
      "strengths": [
        "Public OpenAPI 3.0 file with 166 operations, all described, and curl, Python and JavaScript examples per endpoint",
        "Every API change is recorded against a numbered feature level that clients read from `GET /server_settings`",
        "status.zulip.com lists no incidents from 11 July to 8 October 2026 and one minor incident in May 2026",
        "Bot accounts come in three types, and an incoming webhook bot can only send messages",
        "The server is Apache 2.0, and the Free cloud plan needs no card"
      ],
      "weaknesses": [
        "One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do",
        "Thirteen security advisories between February and September 2026, among them guests reading unsubscribed public channels and forged senders through the API",
        "`POST /messages` has no idempotency key, so a retried send can post twice",
        "Incoming webhook URLs carry the bot's key in the query string as `api_key`",
        "No SLA, SOC 2 or ISO 27001 statement, security.txt or llms.txt was found"
      ],
      "agentNotes": [
        "Ask the organisation for a bot of the most limited type that fits. Use an incoming webhook bot when the task only posts messages",
        "Authenticate with HTTP Basic, the bot's email as user and its API key as password, against https://\u003corganisation\u003e.zulipchat.com/api/v1",
        "Read `code`, not `msg`, on errors. `msg` is translated into the account's language",
        "On `RATE_LIMIT_HIT` wait the seconds in `retry-after`. The default limit is 200 requests a minute per user",
        "Fetch history with `GET /messages`, a `narrow` filter, an `anchor` and `num_before` or `num_after`, at most 1,000 a batch as the docs recommend"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 61.5
        }
      ],
      "editorialScores": {
        "ergonomics": 68,
        "maintenance": 77,
        "payments": 30,
        "reliability": 83,
        "schema": 82,
        "security": 42,
        "transparency": 77
      },
      "provenanceScore": 74
    },
    "connect": {
      "install": "pip install zulip",
      "http": "curl -X POST https://your-org.zulipchat.com/api/v1/messages -u EMAIL_ADDRESS:API_KEY --data-urlencode type=stream --data-urlencode 'to=\"Denmark\"' --data-urlencode topic=Castle --data-urlencode 'content=Hello'"
    },
    "letme": {
      "capability": "https://letme.dev/work.chat",
      "tool": "https://letme.dev/zulip"
    },
    "notable": [
      "The REST API is the one the web, desktop and mobile apps use, and the docs say anything a user can do in Zulip can be done through it (https://zulip.com/api/rest)",
      "Bots are accounts of three types. Generic acts like a normal user, incoming webhook can only send messages, and outgoing webhook also receives mentions and direct messages by HTTP POST (https://zulip.com/help/bots-overview)",
      "All responses carry `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`, and the default configuration limits each user to 200 API requests a minute (https://zulip.com/api/http-headers)",
      "Zulip Server 12.3 of 21 September 2026 fixed four advisories and 12.2 of 10 August 2026 fixed five (https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md)",
      "The Rules of Use say a product that embeds Zulip as its chat backend must self-host, and that account credentials must not be shared with a third party (https://zulip.com/policies/rules)",
      "The security policy reports through security@zulip.com or a private HackerOne programme, and fixes are announced on the blog with CVE numbers (https://github.com/zulip/zulip/blob/main/SECURITY.md)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "The REST API of the hosted Zulip Cloud service at https://\u003corganisation\u003e.zulipchat.com/api/v1. The same API ships in the self-hosted server"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.0.1, 166 operations on 119 paths. Users (45 operations), channels (29), server and organisation settings (28), messages (20), drafts (8), invitations (6), real-time events (5), scheduled messages (4). Request bodies are form-encoded"
      },
      {
        "label": "Messages",
        "value": "`POST /messages` needs `type`, `to` and `content`, plus `topic` for a channel. `GET /messages` takes a `narrow` filter with the search operators, an `anchor`, `num_before` and `num_after`, up to 5,000 a request with 1,000 recommended"
      },
      {
        "label": "Events",
        "value": "`POST /register` opens an event queue and `GET /events` long-polls it. Outgoing webhook bots receive mentions and direct messages by HTTP POST instead"
      },
      {
        "label": "Credentials",
        "value": "One API key per user or bot over HTTP Basic. No scopes, expiry or OAuth. Regenerating the key revokes the old one. Bot types are generic, incoming webhook and outgoing webhook"
      },
      {
        "label": "Rate limits",
        "value": "200 API requests a minute per user in the default configuration, lower limits on login. `X-RateLimit-*` headers on every response. A 429 body has `code` `RATE_LIMIT_HIT` and `retry-after` in seconds"
      },
      {
        "label": "Errors",
        "value": "JSON with `result`, `msg` and a machine-readable `code` such as `INVALID_API_KEY`, `REQUEST_VARIABLE_MISSING` or `RATE_LIMIT_HIT`. Success responses list `ignored_parameters_unsupported`"
      },
      {
        "label": "Versioning",
        "value": "No version beyond `/api/v1`. Each change gets a feature level (513 on the main branch on 8 October 2026), returned as `zulip_feature_level` and listed in the API changelog"
      },
      {
        "label": "Client libraries",
        "value": "Official Python `zulip` 0.9.1 (tagged 30 September 2025) and JavaScript `zulip-js` 2.1.0. Eight user-maintained libraries are listed, among them Go, Java, C# and Ruby"
      },
      {
        "label": "Releases",
        "value": "Zulip Server 12.3 on 21 September 2026, 12.2 on 10 August, 12.1 on 26 June, 12.0 on 27 April. The cloud pages reported server version 12.0-1057 on the day"
      },
      {
        "label": "Status",
        "value": "status.zulip.com on Statuspage with nine components. No incidents from June to 8 October 2026, one minor incident on 21 May 2026"
      },
      {
        "label": "Sub-processors",
        "value": "Amazon Web Services, DigitalOcean, Google, Front, Sentry, Mailgun and Stripe. The privacy policy says the service is hosted in the United States"
      }
    ],
    "unitPrices": [
      {
        "item": "Zulip Cloud Standard",
        "unit": "seat-month",
        "usd": 6.67,
        "note": "billed annually, $8 billed monthly"
      },
      {
        "item": "Zulip Cloud Plus",
        "unit": "seat-month",
        "usd": 10,
        "note": "billed annually, $12 billed monthly, 10 users minimum"
      },
      {
        "item": "Self-hosted Basic",
        "unit": "seat-month",
        "usd": 3.5,
        "note": "billed monthly, for a server the owner runs"
      },
      {
        "item": "Self-hosted Business",
        "unit": "seat-month",
        "usd": 6.67,
        "note": "billed annually, $8 billed monthly, 25 users minimum"
      }
    ],
    "provenance": {
      "legalEntity": "Kandra Labs, Inc.",
      "domain": "zulip.com",
      "domainRegistered": "2010-12-01",
      "endpointOnVendorDomain": false,
      "terms": "https://zulip.com/policies/terms",
      "privacy": "https://zulip.com/policies/privacy",
      "statusPage": "https://status.zulip.com",
      "changelog": "https://zulip.com/api/changelog",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Terms of Service (effective 7 February 2022) are a contract with Kandra Labs, Inc., 584 Castro St #3175, San Francisco, CA 94114, and cover the websites, products, services and applications.",
        "Cloud organisations answer at https://\u003corganisation\u003e.zulipchat.com/api/v1, a second domain. zulip.com's own footer links its terms and privacy policy at zulipchat.com, and the OpenAPI file names the host.",
        "https://zulip.com/.well-known/security.txt returns 404. SECURITY.md in the repository gives security@zulip.com and a private HackerOne programme.",
        "The privacy policy is effective 1 January 2022. A Data Processing Addendum is published as a PDF and was not read.",
        "RDAP for zulip.com gives a registration date of 2010-12-01."
      ],
      "score": 74,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Kandra Labs, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "zulip.com, registered 2010-12-01 (15 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on zulip.com",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects",
          "points": 9.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.zulip.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://zulip.com/policies/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2022-02-07",
          "words": 7266,
          "points": 9.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective date: February 7, 2022. View change history.",
              "says": "Last updated 2022-02-07"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms are governed by and will be construed under the Federal Arbitration Act, applicable federal law, and the laws of the State of California, without regard to the conflicts of laws provisions thereof.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…(B) ANY SUBSTITUTE GOODS, SERVICES OR TECHNOLOGY, (C) ANY AMOUNT, IN THE AGGREGATE, IN EXCESS OF THE GREATER OF (I) ONE-HUNDRED ($100) DOLLARS OR (II) THE AMOUNTS PAID AND/OR PAYABLE BY YOU TO ZULIP IN CONNECTION WITH THE SERVICES IN THE TWELVE (12) MONTH PERIOD PRECEDING THIS APPLICABLE CLAIM OR (D) ANY MATTER BEYOND…",
              "says": "Capped at the greater of $100 and the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may suspend or discontinue any part of the Services, or we may introduce new features or impose limits on certain features or restrict access to parts or all of the Services."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We will generally aim to provide such notice about changes to the Terms at least 14 days in advance of the new Terms taking effect.",
              "says": "Gives 14 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "IF YOU DO NOT AGREE TO ALL OF THE FOLLOWING, YOU MAY NOT USE OR ACCESS THE SERVICES IN ANY MANNER."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Zulip is also free to terminate (or suspend access to) your use of the Services or your account for any reason at our sole discretion, including your breach of these Terms."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "These Terms include information about future changes to these Terms, automatic renewals, limitations of liability, a class action waiver and resolution of disputes by arbitration instead of in court."
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Effective date: February 7, 2022. View change history."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Use is limited to the user's own internal, personal use and may not be on behalf of or for the benefit of a third party.",
              "quote": "You will only use the Services for your own internal, personal use, and not on behalf of or for the benefit of any third party, and only in a manner that complies with all laws that apply to you."
            },
            {
              "date": "2026-10-08",
              "text": "Paid plans renew automatically for the same term at the then-current non-promotional rate unless auto-renewal is switched off in billing settings.",
              "quote": "Unless you opt out of auto-renewal, which can be done through your billing settings, any Paid Services you have signed up for will be automatically extended for successive renewal periods of the same duration as the subscription term originally selected, at the then-current non-promotional rate."
            },
            {
              "date": "2026-10-08",
              "text": "A user may opt out of the arbitration agreement by written notice postmarked within 30 days of first accepting the terms.",
              "quote": "You have the right to opt out of the provisions of this Arbitration Agreement by sending written notice of your decision to opt out to the following address: 584 Castro St #3175, San Francisco, CA 94114 postmarked within thirty (30) days of first accepting these Terms."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://zulip.com/policies/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2022-01-01",
          "words": 5228,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective date: January 1, 2022. View change history.",
              "says": "Last updated 2022-01-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This chart details the categories of Personal Data that we may collect and may have collected from or about you over the past 12 months."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you with our Services.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We will only share your data with third parties to help make our Services a reality."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We will not sell your personal information to third parties.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Under the CCPA, this right is subject to certain exceptions: for example, we may need to retain your Personal Data to provide you with the Services or complete a transaction or other action you have requested."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you believe that a child under the age of thirteen (13) or below the minimum age of consent in their country may have provided us personal information, please contact us at privacy@zulip.com.",
              "says": "privacy@zulip.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "servers, and you authorize Zulip to transfer, store and process your information to and in the U.S., and possibly other countries."
            }
          ],
          "toKnow": [
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Effective date: January 1, 2022. View change history."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Messages sent to another user are not deleted when an account is deleted and stay associated with a Deleted User.",
              "quote": "Please note that we will not be able to delete messages or other content that you have sent to another Zulip user."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/zulip.json",
    "live": {
      "slug": "zulip",
      "vendorStatus": {
        "page": "https://status.zulip.com",
        "indicator": "minor",
        "summary": "Partially Degraded Service",
        "checkedAt": "2026-10-09T10:11:26.208588166Z"
      },
      "updatedAt": "2026-10-09T10:11:26.208588166Z"
    }
  }
}
