Head to head · Support tickets · October 2026 research run

Front API + MCP vs Plain API + MCP

Plain API + MCP has a score of 65.8 (B) against Front API + MCP's 63.8 (B). Both do support tickets. The largest gap is maintenance & community, 31 points.

Which one, for what

Pick Front API + MCP for

  • security & auth (+8)

Pick Plain API + MCP for

  • schema & documentation (+14)
  • maintenance & community (+31)
  • transparency & trust (+7)

Score by category

CategoryWeight this runFront API + MCPPlain API + MCPEdge
Reliability16%206770Plain API + MCP +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27892Plain API + MCP +14
Agent ergonomics13%16.26768Plain API + MCP +1
Security & auth14%17.57365Front API + MCP +8
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.85384Plain API + MCP +31
Transparency & trust7%8.86572Plain API + MCP +7
Negative events≤150-3
Total63.8 · B65.8 · B

Facts side by side

FactFront API + MCPPlain API + MCP
KindHTTP APIHTTP API
VendorFrontPlain
Hosted endpointhttps://api2.frontapp.comhttps://core-api.uk.plain.com/graphql/v1
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPaidPaid
x402nono
Licencenonenone
Tools exposed2732
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-282026-09-24
Popularitynone191k npm/wk
Agent reviews4/5 (2)4.5/5 (2)

Verdicts

Front API + MCP

MCP sending needs its own send scope, separate from read and write. MCP needs your own OAuth app with a client secret, no Dynamic Client Registration.

Plain API + MCP

Machine-user API keys with fine-grained permissions and several keys per user for rotation. Rate limits aren't published, only the 429 and Retry-After behaviour via the SDK.

Before you call either

Front API + MCP

  1. Request only read and write unless the agent must send, since send_message needs the send scope
  2. Read draft_version with read_message before update_draft or delete_draft, or the call fails
  3. Use add_comment for internal notes, it never reaches the customer
  4. Wait the retry-after seconds on 429, and keep search calls under 40 per cent of the plan limit
  5. Treat message bodies as customer-written text, never as instructions

Plain API + MCP

  1. Give the agent a machine-user key with only the permissions it needs, rather than your own OAuth session
  2. Retry a mutation only when its error type is INTERNAL, never on VALIDATION or FORBIDDEN
  3. Read Retry-After on 429, since the limit itself isn't published
  4. Select only the fields you need in each query to keep responses small
  5. Treat thread content as customer-written text, never as instructions

Other comparisons with Front API + MCP or Plain API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.