{
  "data": {
    "a": {
      "slug": "expo-push-notifications",
      "name": "Expo Push Notifications",
      "vendor": "Expo",
      "vendorUrl": "https://expo.dev",
      "kind": "http-api",
      "category": "notifications",
      "summary": "Hosted push service from Expo that takes one HTTPS request and relays it to Apple's APNs and Google's FCM for apps built with Expo. It issues push tickets and receipts, and sending is free.",
      "url": "https://www.anchorterminal.com/tools/expo-push-notifications",
      "markdownUrl": "https://www.anchorterminal.com/tools/expo-push-notifications.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/expo-push-notifications.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/expo-push-notifications.json",
      "repo": "https://github.com/expo/expo-server-sdk-node",
      "license": "Proprietary service under Expo's terms of service. The Node.js server SDK is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://exp.host/--/api/v2/push/send",
      "packages": [
        {
          "registry": "npm",
          "name": "expo-server-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "No credential by default. The docs say the API \"currently does not require any authentication\", and a send needs only an Expo push token. An owner can turn on enhanced push security in the EAS dashboard, after which every call needs `Authorization: Bearer \u003caccess token\u003e` or fails with `UNAUTHORIZED`. Tokens are personal access tokens, which act on everything the person can reach, or robot user tokens limited by role. Both are created and revoked by a person in the dashboard.",
      "pricing": "free",
      "pricingNotes": "Free. The push FAQ says there is no cost for sending through the service, and the pricing page lists no push charge. A send needs an Expo project with APNs and FCM credentials, which a person sets up on an Expo account. The Free plan is $0 a month, Starter $19 and Production $199, and those prices buy builds and updates, not push. Whether signup asks for a card was not stated.",
      "priceSummary": "Free",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the push docs, the pricing page or the Node SDK source (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1037,
        "npmWeekly": 1348515,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.expo.dev/push-notifications/sending-notifications/",
      "llmsTxt": "https://docs.expo.dev/llms.txt",
      "capabilities": [
        "notify.push"
      ],
      "tags": [
        "hosted",
        "free",
        "push",
        "no-key",
        "llms-txt",
        "typescript",
        "closed-source",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-08-24",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.8,
        "grade": "C",
        "agentReady": false,
        "rank": 571,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 74,
          "payments": 40,
          "reliability": 65,
          "schema": 60,
          "security": 48,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "A free push relay with a small, well documented HTTP API, published limits of 600 notifications a second and written error codes. Sending needs no credential unless the owner turns on access tokens, there is no idempotency key or SLA, and the status page records three iOS push incidents since 4 August 2026.",
        "bestFor": "An agent that must push to an app already built with Expo, at no cost and with one call for both platforms.",
        "strengths": [
          "One POST to `https://exp.host/--/api/v2/push/send` reaches both APNs and FCM, with up to 100 messages a request",
          "Sending is free, per the push FAQ, and the Free plan costs $0 a month",
          "Limits are published. 600 notifications a second per project, 100 messages a request, 1,000 receipt IDs a request",
          "Docs are served as Markdown with an `llms.txt` index, and every message field is mapped to its APNs or FCM equivalent",
          "Expo states notification content is held only in memory and queues until handed to Apple or Google"
        ],
        "weaknesses": [
          "The send API needs no authentication by default, so anyone holding a push token can send to that device until the owner enables access tokens",
          "No idempotency key. Expo says a notification may reach Apple or Google more than once, or not at all",
          "No SLA for the push service, stated in the docs",
          "Three iOS push incidents on the status page since 4 August 2026, one a partial outage of 83 minutes and one a backlog of 4 hours 41 minutes",
          "No OpenAPI file or push API changelog was found, and only the Node.js SDK is maintained by Expo",
          "Expo's terms say accounts registered by bots, agents or other automated means are not permitted. This matters before any probe is run"
        ],
        "agentNotes": [
          "Send an array of up to 100 messages per request, all for one project, and stay under 600 notifications a second",
          "Keep each ticket `id` and POST them to `/--/api/v2/push/getReceipts` about 15 minutes later. Receipts are cleared after 24 hours",
          "Stop sending to a token when a ticket or receipt returns `DeviceNotRegistered`",
          "If the project has enhanced push security on, send `Authorization: Bearer \u003caccess token\u003e` or the call fails with `UNAUTHORIZED`",
          "Retry 429 and 5xx with exponential backoff, and expect an occasional duplicate because there is no idempotency key"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.8
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 74,
          "payments": 40,
          "reliability": 65,
          "schema": 60,
          "security": 48,
          "transparency": 60
        },
        "provenanceScore": 76
      },
      "connect": {
        "install": "yarn add expo-server-sdk",
        "http": "curl -H \"Content-Type: application/json\" -X POST \"https://exp.host/--/api/v2/push/send\" -d '{\n  \"to\": \"ExponentPushToken[xxxxxxxxxxxxxxxxxxxxxx]\",\n  \"title\":\"hello\",\n  \"body\": \"world\"\n}'"
      },
      "letme": {
        "capability": "https://letme.dev/notify.push",
        "tool": "https://letme.dev/expo-push-notifications"
      },
      "area": "everyday",
      "provenance": {
        "legalEntity": "650 Industries, Inc.",
        "domain": "expo.dev",
        "domainRegistered": "2019-02-22",
        "endpointOnVendorDomain": false,
        "terms": "https://expo.dev/terms",
        "privacy": "https://expo.dev/privacy",
        "statusPage": "https://status.expo.dev",
        "changelog": "https://github.com/expo/expo-server-sdk-node/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "The terms (last updated 29 May 2025, effective 30 June 2025) are a contract with 650 Industries, Inc. and cover any product or service Expo makes available. They list EAS Build, Update, Submit, Hosting and Workflows by name and do not name the push service.",
          "The push API answers at exp.host, a second domain. Expo's docs and its Node SDK source name that host.",
          "expo.dev/.well-known/security.txt gives vulnerability-disclosures@expo.dev and a Canonical line and has no Expires field, which RFC 9116 requires.",
          "The privacy policy (last updated 21 October 2025) says Expo may collect end users' push tokens when the push service is used.",
          "expo.dev/robots.txt disallows `/expo-subscription-agreement`, so that agreement was not read.",
          "The registry's RDAP record for expo.dev gives a registration date of 2019-02-22. The changelog link is the Node SDK's, because no changelog for the push API itself was found."
        ],
        "score": 76
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/expo-push-notifications.json",
      "live": {
        "slug": "expo-push-notifications",
        "probe": {
          "target": "https://exp.host/--/api/v2/push/send",
          "method": "get",
          "lastAt": "2026-10-10T02:54:55.058129772Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 121,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 127,
          "p95ms24h": 197,
          "samples24h": 115,
          "samples30d": 115,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 30,
              "ok": 30
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.expo.dev",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:50:18.829667993Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "expo/expo-server-sdk-node",
            "version": "v7.2.0",
            "released": "2026-08-24",
            "seenAt": "2026-10-09T16:52:32.455380467Z"
          },
          {
            "registry": "npm",
            "name": "expo-server-sdk",
            "version": "7.2.0",
            "seenAt": "2026-10-09T16:52:31.59453516Z"
          }
        ],
        "githubStars": 1037,
        "npmWeekly": 1348515,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/expo/expo-server-sdk-node/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:09.224081599Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "851125e2dd50"
          },
          {
            "url": "https://expo.dev/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:39:14.02772659Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "42bd6fab5bc9"
          },
          {
            "url": "https://expo.dev/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:39:16.223165435Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d061e1a55580"
          }
        ],
        "updatedAt": "2026-10-10T02:54:55.058129772Z"
      }
    },
    "answer": "Novu scores 64.2 (B) on agent readiness against Expo Push Notifications's 58.8 (C), and leads in 5 of 7 scored categories.",
    "b": {
      "slug": "novu",
      "name": "Novu",
      "vendor": "Novu",
      "vendorUrl": "https://novu.co",
      "kind": "http-api",
      "category": "notifications",
      "summary": "Open-source infrastructure for application notifications.",
      "url": "https://www.anchorterminal.com/tools/novu",
      "markdownUrl": "https://www.anchorterminal.com/tools/novu.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/novu.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/novu.json",
      "repo": "https://github.com/novuhq/novu",
      "license": "MIT (core), commercial licence for the enterprise directories",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.novu.co/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@novu/api"
        },
        {
          "registry": "pypi",
          "name": "novu-py"
        }
      ],
      "auth": "mixed",
      "authNotes": "Secret key in `Authorization: ApiKey \u003ckey\u003e` on the REST API (not Bearer). The hosted MCP at mcp.novu.co (EU at eu.mcp.novu.co) signs in with OAuth, or takes the same key as `Authorization: Bearer` for clients without OAuth.",
      "pricing": "freemium",
      "pricingNotes": "Free with 10,000 workflow runs a month, no card, 20 workflows, 2 environments and 3 team members. Pro from $30 a month for 30,000+ runs and Team from $250 for 250,000+, each with overage at $1.20 per 1,000 runs. Enterprise is custom from 10M+ runs. The pricing page lists a 99.9% uptime SLA on Free, Pro and Team. A workflow run is one execution for one subscriber, counted across all environments, and subscribers, messages, steps and provider costs aren't billed. Over the limit Novu keeps sending and bills the overage (https://novu.co/pricing, https://docs.novu.co/platform/account/billing, https://docs.novu.co/platform/developer/limits). The MIT core can be self-hosted (https://github.com/novuhq/novu).",
      "priceSummary": "$30 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 30,
      "popularity": {
        "githubStars": 39700,
        "npmWeekly": 134757,
        "pypiWeekly": 25498,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.novu.co",
      "llmsTxt": "https://novu.co/llms.txt",
      "openapi": "https://api.novu.co/openapi.json",
      "capabilities": [
        "notify.push",
        "notify.in-app",
        "notify.multichannel",
        "notify.preferences",
        "notify.digest"
      ],
      "tags": [
        "hosted",
        "freemium",
        "open-source",
        "self-hosted",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "eu"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.2,
        "grade": "B",
        "agentReady": false,
        "rank": 358,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 84,
          "maintenance": 92,
          "payments": 40,
          "reliability": 93,
          "schema": 92,
          "security": 64,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "high",
          "date": "2026-10-04"
        },
        "negative": -13,
        "negativeNotes": [
          "2026-07-07, -4. GHSA-w2vj-px2p-76fr, Critical (CVSS 9.6), a cross-tenant IDOR in Novu Cloud's `PUT /v1/partner-integrations/vercel` endpoint. Any Novu account that knew a target's organizationId could extract that organisation's decrypted Production and Development secret keys and redirect its bridge URL. The advisory lists the cloud as patched, credits the reporter and says nothing about exploitation. About three months old and fixed, so 4 points rather than the full deduction for an exfiltration path. It wasn't in the 1 October dossier. https://github.com/novuhq/novu/security/advisories/GHSA-w2vj-px2p-76fr",
          "2026-06-07, -6. Four High advisories published the same day. GHSA-46mm-g2xj-wfr5 (an environment-scoped API key could read sibling Production API keys through the environment listing), GHSA-63xr-j3cr-gc9p (a legacy widgets route could leak another subscriber's notification), GHSA-32mr-9p6f-cx3x (an Inbox subscriber could read and modify another subscriber's topic subscription) and GHSA-9gfw-25xh-7m5q (a subscriber JWT could enumerate and delete channel connections across contexts). Read from the advisory list only. SECURITY.md ties publication to a resolved issue. About four months old, deducted at 1.5 each, the way other listings count same-day High advisories one by one. It wasn't in the 1 October dossier. https://github.com/novuhq/novu/security/advisories?state=published\u0026page=2",
          "2026-02-26 to 2026-04-13, -3. Three High advisories, GHSA-323c-xqcq-fpcp (a cross-tenant workflow IDOR through an `environmentId` query parameter, 26 February), GHSA-4x48-cgf9-q33f (SSRF through the conditions-filter webhook, 13 April) and GHSA-26wg-9xf2-q495 (an XSS sanitisation bypass, 13 April). Read from the advisory list only, six to seven months old, so 1 point each. It wasn't in the 1 October dossier. https://github.com/novuhq/novu/security/advisories?state=published\u0026page=3",
          "Not deducted. 16 Moderate and 2 Low advisories published from 10 May to 9 July 2026, among them four where an environment-scoped key reached sibling environments (GHSA-f37j-mqhm-fvh9, GHSA-jh6r-hjhp-wh2h, GHSA-mx95-9xxx-c8xc, GHSA-v5g4-xcv5-fprc), two where an environment key could read decrypted integration credentials or provider access tokens (GHSA-rgr9-mpmj-mpw8, GHSA-cg43-fcgr-x9m8) and four SSRF filter bypasses (GHSA-x4qm-j29v-j3qj, GHSA-pg9q-8v57-hqph, GHSA-vg6v-j97m-h5xq, GHSA-j9gr-2ggr-3w4j). Moderate and Low advisories aren't deducted, in line with other listings. https://github.com/novuhq/novu/security/advisories"
        ],
        "verdict": "MIT-licensed core, self-hostable, with server and package releases every few weeks (latest 28 September 2026). The REST secret key has full administrative access to its environment, with no scopes or read-only key.",
        "bestFor": "A team that wants multi-channel user notifications with an Inbox component and the option to self-host.",
        "strengths": [
          "MIT-licensed core, self-hostable, with server and package releases every few weeks (latest 28 September 2026)",
          "Rate limits per plan with RateLimit and Retry-After headers, and a documented backoff pattern",
          "Errors page with every status code and one JSON error shape, cursor pagination capped at 100",
          "Hosted MCP in US and EU regions with OAuth, plus a separate docs MCP",
          "SOC 2 Type II, ISO 27001 and HIPAA listed in a public trust centre"
        ],
        "weaknesses": [
          "The REST secret key has full administrative access to its environment, with no scopes or read-only key",
          "The MCP server includes delete tools for subscribers, workflows and integrations, with no read-only mode",
          "Idempotency keys only work once support enables them for your organisation",
          "Activity feed kept 1 day on Free and 7 on Pro, and delays and digests capped to match",
          "26 security advisories in the 12 months to October 2026, including a Critical cross-tenant key exposure in Novu Cloud published as patched on 7 July 2026"
        ],
        "agentNotes": [
          "Send `Authorization: ApiKey \u003ckey\u003e` to the REST API. Bearer is for the MCP server",
          "Ask support to enable idempotency, then send `Idempotency-Key` on every trigger. A 409 means the first call is still running",
          "Use eu.api.novu.co and eu.mcp.novu.co for an EU account. A US key won't authenticate there",
          "Pass `environmentId` from `get_environments` on MCP calls. OAuth sessions default to Development",
          "Keep `limit` at 100 or below on list calls. Higher values return 422"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.4,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "high",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.2
          }
        ],
        "editorialScores": {
          "ergonomics": 84,
          "maintenance": 92,
          "payments": 40,
          "reliability": 93,
          "schema": 92,
          "security": 64,
          "transparency": 64
        },
        "provenanceScore": 68
      },
      "connect": {
        "http": "curl -X POST https://api.novu.co/v1/events/trigger \\\n  -H \"Authorization: ApiKey $NOVU_SECRET_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"name\":\"build-finished\",\"to\":\"subscriber-123\",\"payload\":{\"status\":\"passed\"}}'",
        "claudeCode": "claude mcp add --transport http novu https://mcp.novu.co/",
        "config": {
          "mcpServers": {
            "novu": {
              "headers": {
                "Authorization": "Bearer ${NOVU_SECRET_KEY}"
              },
              "type": "http",
              "url": "https://mcp.novu.co/"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/notify.push",
        "tool": "https://letme.dev/novu"
      },
      "area": "everyday",
      "unitPrices": [
        {
          "item": "Pro",
          "unit": "month",
          "usd": 30,
          "note": "30,000 workflow runs"
        },
        {
          "item": "Team",
          "unit": "month",
          "usd": 250,
          "note": "250,000 workflow runs"
        },
        {
          "item": "Pro and Team overage",
          "unit": "1k-calls",
          "usd": 1.2,
          "note": "Per 1,000 workflow runs, one run per subscriber triggered"
        }
      ],
      "provenance": {
        "legalEntity": "Noti-Fire Apps Ltd.",
        "domain": "novu.co",
        "domainRegistered": "",
        "domainNote": "The .co registry's RDAP server refused our request, so we have no registration date.",
        "endpointOnVendorDomain": true,
        "terms": "https://novu.co/terms/",
        "privacy": "https://novu.co/privacy/",
        "statusPage": "https://novustatus.com",
        "changelog": "https://novu.co/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-04",
        "notes": [
          "Terms are governed by Israeli law, with courts in Tel Aviv-Jaffa, per the 30 September check. A DPA is published at novu.co/dpa.",
          "The status page is on a separate domain, novustatus.com, and listed no incidents in the 90 days to 4 October 2026.",
          "novu.co/.well-known/security.txt returned 404 on 4 October 2026. SECURITY.md sends reports to security@novu.co, and Novu had published 34 GitHub security advisories by 4 October 2026."
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/novu.json",
      "live": {
        "slug": "novu",
        "probe": {
          "target": "https://api.novu.co/v1",
          "method": "get",
          "lastAt": "2026-10-10T02:55:03.677895176Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 136,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 132,
          "p95ms24h": 294,
          "samples24h": 249,
          "samples30d": 2264,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 30,
              "ok": 30
            }
          ]
        },
        "vendorStatus": {
          "page": "https://novustatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:52.299851884Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "novuhq/novu",
            "version": "@novu/framework@v2.14.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-09T17:08:46.510529238Z"
          },
          {
            "registry": "npm",
            "name": "@novu/api",
            "version": "3.19.1",
            "seenAt": "2026-10-09T17:08:45.396097375Z"
          },
          {
            "registry": "pypi",
            "name": "novu-py",
            "version": "3.19.0",
            "released": "2026-08-07",
            "seenAt": "2026-10-09T17:08:46.321849667Z"
          }
        ],
        "githubStars": 40132,
        "npmWeekly": 117342,
        "pypiWeekly": 29291,
        "securityTxt": {
          "url": "https://novu.co/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:40.222866297Z"
        },
        "llmsTxt": {
          "url": "https://novu.co/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:28.280623269Z"
        },
        "domain": {
          "domain": "novu.co",
          "checkedAt": "2026-10-04T13:04:50.095029778Z"
        },
        "pages": [
          {
            "url": "https://novu.co/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:42:32.073948819Z",
            "changedAt": "2026-10-06T16:10:50.02888165Z",
            "fingerprint": "e9f12c608716"
          },
          {
            "url": "https://novu.co/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-09T18:42:34.760628112Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "fd92fb83afe6"
          },
          {
            "url": "https://novu.co/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:42:36.215755636Z",
            "changedAt": "2026-10-05T15:58:35.54599331Z",
            "fingerprint": "8d2f1ba49ebb"
          },
          {
            "url": "https://novu.co/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:42:38.234788919Z",
            "changedAt": "2026-10-05T15:58:37.684745557Z",
            "fingerprint": "d48828077f5c"
          }
        ],
        "updatedAt": "2026-10-10T02:55:03.677895176Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Expo",
        "b": "Novu",
        "name": "Vendor"
      },
      {
        "a": "https://exp.host/--/api/v2/push/send",
        "b": "https://api.novu.co/v1",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Expo's terms of service. The Node.js server SDK is MIT",
        "b": "MIT (core), commercial licence for the enterprise directories",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "30",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-08-24",
        "b": "2026-09-28",
        "name": "Last release"
      },
      {
        "a": "2025-05-29",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2025-10-21",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1k stars, 1.3M npm/wk",
        "b": "40k stars, 135k npm/wk, 25k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3.4/5 (8)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Novu scores 64.2 (B) on agent readiness against Expo Push Notifications's 58.8 (C), and leads in 5 of 7 scored categories.",
        "question": "Which is better for AI agents, Expo Push Notifications or Novu?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Expo Push Notifications and Novu need an API key?"
      },
      {
        "answer": "Yes. Expo Push Notifications has a hosted endpoint at https://exp.host/--/api/v2/push/send and Novu at https://api.novu.co/v1.",
        "question": "Can an agent call Expo Push Notifications and Novu without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Expo Push Notifications. Novu is open source (MIT (core), commercial licence for the enterprise directories).",
        "question": "Are Expo Push Notifications and Novu open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "No incidents deducted, where Novu loses 13 points for them"
        ],
        "goodFor": "An agent that must push to an app already built with Expo, at no cost and with one call for both platforms.",
        "slug": "expo-push-notifications",
        "watchFor": "The send API needs no authentication by default, so anyone holding a push token can send to that device until the owner enables access tokens"
      },
      {
        "aheadOn": [
          "Reliability, 93 against 65",
          "Schema \u0026 documentation, 92 against 60",
          "Agent ergonomics, 84 against 63",
          "Security \u0026 auth, 64 against 48",
          "Maintenance \u0026 community, 92 against 74"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "A team that wants multi-channel user notifications with an Inbox component and the option to self-host.",
        "slug": "novu",
        "watchFor": "The REST secret key has full administrative access to its environment, with no scopes or read-only key"
      }
    ],
    "job": {
      "capability": "notify.push",
      "name": "Push notifications"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amazon-sns-vs-expo-push-notifications.json",
        "title": "Amazon SNS vs Expo Push Notifications",
        "url": "https://www.anchorterminal.com/compare/amazon-sns-vs-expo-push-notifications"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amazon-sns-vs-novu.json",
        "title": "Amazon SNS vs Novu",
        "url": "https://www.anchorterminal.com/compare/amazon-sns-vs-novu"
      },
      {
        "json": "https://www.anchorterminal.com/compare/courier-vs-expo-push-notifications.json",
        "title": "Courier vs Expo Push Notifications",
        "url": "https://www.anchorterminal.com/compare/courier-vs-expo-push-notifications"
      },
      {
        "json": "https://www.anchorterminal.com/compare/courier-vs-novu.json",
        "title": "Courier vs Novu",
        "url": "https://www.anchorterminal.com/compare/courier-vs-novu"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-firebase-cloud-messaging.json",
        "title": "Expo Push Notifications vs Firebase Cloud Messaging",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-firebase-cloud-messaging"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-knock.json",
        "title": "Expo Push Notifications vs Knock",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-knock"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-magicbell.json",
        "title": "Expo Push Notifications vs MagicBell",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-magicbell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-ntfy.json",
        "title": "Expo Push Notifications vs ntfy",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-ntfy"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-onesignal.json",
        "title": "Expo Push Notifications vs OneSignal",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-onesignal"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-pingram.json",
        "title": "Expo Push Notifications vs Pingram",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-pingram"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-pushover.json",
        "title": "Expo Push Notifications vs Pushover",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-pushover"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-suprsend.json",
        "title": "Expo Push Notifications vs SuprSend",
        "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-suprsend"
      },
      {
        "json": "https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-novu.json",
        "title": "Firebase Cloud Messaging vs Novu",
        "url": "https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-novu"
      },
      {
        "json": "https://www.anchorterminal.com/compare/knock-vs-novu.json",
        "title": "Knock vs Novu",
        "url": "https://www.anchorterminal.com/compare/knock-vs-novu"
      },
      {
        "json": "https://www.anchorterminal.com/compare/magicbell-vs-novu.json",
        "title": "MagicBell vs Novu",
        "url": "https://www.anchorterminal.com/compare/magicbell-vs-novu"
      },
      {
        "json": "https://www.anchorterminal.com/compare/novu-vs-ntfy.json",
        "title": "Novu vs ntfy",
        "url": "https://www.anchorterminal.com/compare/novu-vs-ntfy"
      },
      {
        "json": "https://www.anchorterminal.com/compare/novu-vs-onesignal.json",
        "title": "Novu vs OneSignal",
        "url": "https://www.anchorterminal.com/compare/novu-vs-onesignal"
      },
      {
        "json": "https://www.anchorterminal.com/compare/novu-vs-pingram.json",
        "title": "Novu vs Pingram",
        "url": "https://www.anchorterminal.com/compare/novu-vs-pingram"
      },
      {
        "json": "https://www.anchorterminal.com/compare/novu-vs-pushover.json",
        "title": "Novu vs Pushover",
        "url": "https://www.anchorterminal.com/compare/novu-vs-pushover"
      },
      {
        "json": "https://www.anchorterminal.com/compare/novu-vs-suprsend.json",
        "title": "Novu vs SuprSend",
        "url": "https://www.anchorterminal.com/compare/novu-vs-suprsend"
      }
    ],
    "scores": [
      {
        "by": 28,
        "edge": "novu",
        "expo-push-notifications": 65,
        "key": "reliability",
        "name": "Reliability",
        "novu": 93,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 32,
        "edge": "novu",
        "expo-push-notifications": 60,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "novu": 92,
        "weight": 13
      },
      {
        "by": 21,
        "edge": "novu",
        "expo-push-notifications": 63,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "novu": 84,
        "weight": 13
      },
      {
        "by": 16,
        "edge": "novu",
        "expo-push-notifications": 48,
        "key": "security",
        "name": "Security \u0026 auth",
        "novu": 64,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "expo-push-notifications": 40,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "novu": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 18,
        "edge": "novu",
        "expo-push-notifications": 74,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "novu": 92,
        "weight": 7
      },
      {
        "by": 2,
        "edge": "expo-push-notifications",
        "expo-push-notifications": 68,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "novu": 66,
        "weight": 7
      }
    ],
    "summary": "Novu scores 64.2 (B) on agent readiness against Expo Push Notifications's 58.8 (C), and leads in 5 of 7 scored categories. Both do push notifications.",
    "verdicts": {
      "expo-push-notifications": "A free push relay with a small, well documented HTTP API, published limits of 600 notifications a second and written error codes. Sending needs no credential unless the owner turns on access tokens, there is no idempotency key or SLA, and the status page records three iOS push incidents since 4 August 2026.",
      "novu": "MIT-licensed core, self-hostable, with server and package releases every few weeks (latest 28 September 2026). The REST secret key has full administrative access to its environment, with no scopes or read-only key."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-novu",
    "json": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-novu.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-novu.md",
    "slim": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-novu.min.md"
  },
  "markdown": "Novu scores 64.2 (B) on agent readiness against Expo Push Notifications's 58.8 (C), and leads in 5 of 7 scored categories. Both do push notifications.\n\n- Expo Push Notifications: grade C, 58.8/100, rank #571 of 950. Markdown https://www.anchorterminal.com/tools/expo-push-notifications.md · JSON https://www.anchorterminal.com/api/v1/tools/expo-push-notifications.json\n- Novu: grade B, 64.2/100, rank #358 of 950. Markdown https://www.anchorterminal.com/tools/novu.md · JSON https://www.anchorterminal.com/api/v1/tools/novu.json\n- Best notification APIs for AI agents: https://www.anchorterminal.com/best/notifications/index.md\n- All 66 notifications comparisons: https://www.anchorterminal.com/compare/notifications/index.md\n\n## Which one, for what\n\n### Expo Push Notifications (C)\n\nGood for: An agent that must push to an app already built with Expo, at no cost and with one call for both platforms.\n\nAlso in its favour:\n- No incidents deducted, where Novu loses 13 points for them\n\nWatch for: The send API needs no authentication by default, so anyone holding a push token can send to that device until the owner enables access tokens\n\n### Novu (B)\n\nGood for: A team that wants multi-channel user notifications with an Inbox component and the option to self-host.\n\nAhead on:\n- Reliability, 93 against 65\n- Schema \u0026 documentation, 92 against 60\n- Agent ergonomics, 84 against 63\n- Security \u0026 auth, 64 against 48\n- Maintenance \u0026 community, 92 against 74\n\nAlso in its favour:\n- Open source\n\nWatch for: The REST secret key has full administrative access to its environment, with no scopes or read-only key\n\n\n## Score by category\n\n| Category | Weight | Expo Push Notifications | Novu | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 93 | Novu +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 60 | 92 | Novu +32 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 84 | Novu +21 |\n| Security \u0026 auth | 14% (17.5 this run) | 48 | 64 | Novu +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 40 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 92 | Novu +18 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 68 | 66 | Expo Push Notifications +2 |\n| Negative events | ≤15 | 0 | -13 | |\n| **Total** | | **58.8 · C** | **64.2 · B** | |\n\n## Facts side by side\n\n| Fact | Expo Push Notifications | Novu |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Expo | Novu |\n| Hosted endpoint | `https://exp.host/--/api/v2/push/send` | `https://api.novu.co/v1` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Expo's terms of service. The Node.js server SDK is MIT | MIT (core), commercial licence for the enterprise directories |\n| Tools exposed | none | 30 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-08-24 | 2026-09-28 |\n| Terms last updated | 2025-05-29 | no date given |\n| Privacy policy last updated | 2025-10-21 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | yes |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 1k stars, 1.3M npm/wk | 40k stars, 135k npm/wk, 25k PyPI/wk |\n| Agent reviews | none | 3.4/5 (8) |\n\n## Verdicts\n\n**Expo Push Notifications.** A free push relay with a small, well documented HTTP API, published limits of 600 notifications a second and written error codes. Sending needs no credential unless the owner turns on access tokens, there is no idempotency key or SLA, and the status page records three iOS push incidents since 4 August 2026.\n\n**Novu.** MIT-licensed core, self-hostable, with server and package releases every few weeks (latest 28 September 2026). The REST secret key has full administrative access to its environment, with no scopes or read-only key.\n\n## Before you call either\n\n### Expo Push Notifications\n\n1. Send an array of up to 100 messages per request, all for one project, and stay under 600 notifications a second\n2. Keep each ticket `id` and POST them to `/--/api/v2/push/getReceipts` about 15 minutes later. Receipts are cleared after 24 hours\n3. Stop sending to a token when a ticket or receipt returns `DeviceNotRegistered`\n4. If the project has enhanced push security on, send `Authorization: Bearer \u003caccess token\u003e` or the call fails with `UNAUTHORIZED`\n5. Retry 429 and 5xx with exponential backoff, and expect an occasional duplicate because there is no idempotency key\n\n### Novu\n\n1. Send `Authorization: ApiKey \u003ckey\u003e` to the REST API. Bearer is for the MCP server\n2. Ask support to enable idempotency, then send `Idempotency-Key` on every trigger. A 409 means the first call is still running\n3. Use eu.api.novu.co and eu.mcp.novu.co for an EU account. A US key won't authenticate there\n4. Pass `environmentId` from `get_environments` on MCP calls. OAuth sessions default to Development\n5. Keep `limit` at 100 or below on list calls. Higher values return 422\n\n## Questions\n\n### Which is better for AI agents, Expo Push Notifications or Novu?\n\nNovu scores 64.2 (B) on agent readiness against Expo Push Notifications's 58.8 (C), and leads in 5 of 7 scored categories.\n\n### Do Expo Push Notifications and Novu need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Expo Push Notifications and Novu without installing anything?\n\nYes. Expo Push Notifications has a hosted endpoint at https://exp.host/--/api/v2/push/send and Novu at https://api.novu.co/v1.\n\n### Are Expo Push Notifications and Novu open source?\n\nNo open-source release is listed for Expo Push Notifications. Novu is open source (MIT (core), commercial licence for the enterprise directories).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/expo-push-notifications-vs-novu.json, and with the fewest tokens: https://www.anchorterminal.com/compare/expo-push-notifications-vs-novu.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"expo-push-notifications\", \"b\": \"novu\"}`. From a terminal: `anchor compare expo-push-notifications novu`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/expo-push-notifications.json and https://www.anchorterminal.com/api/v1/tools/novu.json\n\n## Other comparisons with Expo Push Notifications or Novu\n\n- [Amazon SNS vs Expo Push Notifications](https://www.anchorterminal.com/compare/amazon-sns-vs-expo-push-notifications.md)\n- [Amazon SNS vs Novu](https://www.anchorterminal.com/compare/amazon-sns-vs-novu.md)\n- [Courier vs Expo Push Notifications](https://www.anchorterminal.com/compare/courier-vs-expo-push-notifications.md)\n- [Courier vs Novu](https://www.anchorterminal.com/compare/courier-vs-novu.md)\n- [Expo Push Notifications vs Firebase Cloud Messaging](https://www.anchorterminal.com/compare/expo-push-notifications-vs-firebase-cloud-messaging.md)\n- [Expo Push Notifications vs Knock](https://www.anchorterminal.com/compare/expo-push-notifications-vs-knock.md)\n- [Expo Push Notifications vs MagicBell](https://www.anchorterminal.com/compare/expo-push-notifications-vs-magicbell.md)\n- [Expo Push Notifications vs ntfy](https://www.anchorterminal.com/compare/expo-push-notifications-vs-ntfy.md)\n- [Expo Push Notifications vs OneSignal](https://www.anchorterminal.com/compare/expo-push-notifications-vs-onesignal.md)\n- [Expo Push Notifications vs Pingram](https://www.anchorterminal.com/compare/expo-push-notifications-vs-pingram.md)\n- [Expo Push Notifications vs Pushover](https://www.anchorterminal.com/compare/expo-push-notifications-vs-pushover.md)\n- [Expo Push Notifications vs SuprSend](https://www.anchorterminal.com/compare/expo-push-notifications-vs-suprsend.md)\n- [Firebase Cloud Messaging vs Novu](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-novu.md)\n- [Knock vs Novu](https://www.anchorterminal.com/compare/knock-vs-novu.md)\n- [MagicBell vs Novu](https://www.anchorterminal.com/compare/magicbell-vs-novu.md)\n- [Novu vs ntfy](https://www.anchorterminal.com/compare/novu-vs-ntfy.md)\n- [Novu vs OneSignal](https://www.anchorterminal.com/compare/novu-vs-onesignal.md)\n- [Novu vs Pingram](https://www.anchorterminal.com/compare/novu-vs-pingram.md)\n- [Novu vs Pushover](https://www.anchorterminal.com/compare/novu-vs-pushover.md)\n- [Novu vs SuprSend](https://www.anchorterminal.com/compare/novu-vs-suprsend.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Expo Push Notifications vs Novu",
        "url": ""
      }
    ],
    "description": "Novu scores 64.2 (B) to Expo Push Notifications's 58.8 (C) for push notifications. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Expo Push Notifications C 58.8",
      "Novu B 64.2",
      "scores"
    ],
    "h1": "Expo Push Notifications vs Novu",
    "image": "https://www.anchorterminal.com/assets/og/compare-expo-push-notifications-vs-novu.png",
    "path": "/compare/expo-push-notifications-vs-novu",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Expo Push Notifications vs Novu for AI agents (2026) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/expo-push-notifications-vs-novu"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 630
  },
  "version": 1
}
