{
  "data": {
    "a": {
      "slug": "mattermost",
      "name": "Mattermost",
      "vendor": "Mattermost, Inc.",
      "vendorUrl": "https://mattermost.com",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Mattermost is an open-core team chat server from Mattermost, Inc. that its owner hosts, with channels, threads, calls and playbooks. Agents reach it through the REST API v4, bot accounts, personal access tokens, webhooks and an MCP server.",
      "url": "https://www.anchorterminal.com/tools/mattermost",
      "markdownUrl": "https://www.anchorterminal.com/tools/mattermost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mattermost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mattermost.json",
      "repo": "https://github.com/mattermost/mattermost",
      "license": "Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@mattermost/client"
        },
        {
          "registry": "go",
          "name": "github.com/mattermost/mattermost/server/public"
        }
      ],
      "auth": "mixed",
      "authNotes": "Granted by the server's own admin, with no vendor approval. The API takes a Bearer token in the `Authorization` header, either a session token from `POST /api/v4/users/login` or a personal access token. Personal access tokens are off until an admin enables them and lets the account create them, have a description, no scopes and no expiry, and can be revoked or disabled. Bot accounts hold such tokens, cannot be logged into and are created by a System Admin or a plugin once bot creation is enabled. OAuth 2.0 applications are also off by default, support PKCE and optional dynamic client registration, and have no scopes. The MCP server takes OAuth or a personal access token.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Team Edition and the Entry edition are free with no card or vendor account. Entry shows 10,000 messages of history and has community support only. Professional, Enterprise and Enterprise Advanced are annual per-seat subscriptions with no public price, and Mattermost Cloud is single-tenant and sold through sales (https://mattermost.com/pricing/). API calls are not charged, and bot accounts do not count as licensed users. An agent's owner can start on a free edition without a contract. The site's trial environment lasts one hour.",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API introduction, the OpenAPI source or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 39301,
        "npmWeekly": 7727,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.mattermost.com/api",
      "openapi": "https://github.com/mattermost/mattermost/tree/master/api/v4/source",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "freemium",
        "sales-led",
        "pat",
        "oauth",
        "openapi",
        "mcp",
        "typescript",
        "go",
        "webhooks",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.8,
        "grade": "B",
        "agentReady": false,
        "rank": 310,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 89,
          "payments": 50,
          "reliability": 83,
          "schema": 76,
          "security": 63,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "2025-10-28 to 2026-10-08. The v11 changelog marks 52 dot releases in twelve months as carrying security fixes. Three are rated critical, 11.0.4 on 28 October 2025 in the server and 11.0.6 and 11.1.1 on 21 November 2025 in the bundled Jira plugin, and 21 more include high-severity fixes. All were fixed in a release and announced, with details published 30 days later, so 5 points. The advisory table itself is drawn by script and was not read (https://docs.mattermost.com/product-overview/mattermost-v11-changelog)."
        ],
        "verdict": "The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.",
        "bestFor": "A team that runs its own chat server and wants an agent to read channels, post, search and manage members through a bot account, including in air-gapped networks.",
        "strengths": [
          "Public OpenAPI 3.0 source for API v4, every operation described, 548 of 604 stating the permission needed",
          "Sixteen server releases between 11 July and 8 October 2026, each with a dated changelog entry and an API changes list",
          "Team Edition is free under MIT as a compiled binary, and the free Entry edition needs no card or vendor account",
          "Bot accounts are separate from people, do not count as licensed users, and their tokens can be revoked or disabled",
          "Public Bugcrowd bounty, and a SOC 2 Type II report and ISO 27001:2022 certificate listed on the trust centre"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes and no expiry. A token does whatever its account can do",
          "52 dot releases from 28 October 2025 to 8 October 2026 carried security fixes, three rated critical and 21 including high-severity fixes",
          "No public price for Professional, Enterprise or Enterprise Advanced, and Mattermost Cloud is sold through sales only",
          "No idempotency key on `POST /api/v4/posts`, so a retried send can post twice",
          "Rate limiting is off by default on a self-hosted server, and no llms.txt or security.txt was found"
        ],
        "agentNotes": [
          "Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console",
          "Send `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cserver\u003e/api/v4`. Use `me` in place of a user id for the token's own account",
          "Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error",
          "Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint",
          "If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded`"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.8
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 89,
          "payments": 50,
          "reliability": 83,
          "schema": 76,
          "security": 63,
          "transparency": 80
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "docker run --name mattermost-preview -d --publish 8065:8065 mattermost/mattermost-preview",
        "http": "curl -X POST https://your-mattermost-server.com/api/v4/posts -H 'Authorization: Bearer \u003cTOKEN\u003e' -H 'Content-Type: application/json' -d '{\"channel_id\": \"\u003cCHANNEL_ID\u003e\", \"message\": \"Status update from API\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/mattermost"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Team Edition (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, MIT binary, REST API included"
        },
        {
          "item": "Entry (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, 10,000 messages of viewable history, community support only; paid editions have no public price"
        }
      ],
      "provenance": {
        "legalEntity": "Mattermost, Inc.",
        "domain": "mattermost.com",
        "domainRegistered": "2012-12-22",
        "endpointOnVendorDomain": false,
        "terms": "https://mattermost.com/software-services-license-agreement/",
        "privacy": "https://mattermost.com/privacy-policy/",
        "statusPage": "https://status.mattermost.com",
        "changelog": "https://docs.mattermost.com/product-overview/mattermost-v11-changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Software and Services Licence Agreement (effective 12 January 2023) is a contract with Mattermost, Inc. and covers both Cloud Edition and On-Premise subscriptions. The privacy policy (effective 30 December 2024) gives the address 530 Lytton Avenue, Suite 201, Palo Alto, CA 94301.",
          "The graded API answers on the owner's own server at https://\u003cserver\u003e/api/v4, so the endpoint is not on the vendor's domain.",
          "The compiled Team Edition is under MIT and needs no agreement with the vendor. The agreement linked here governs the Enterprise Edition binary, subscriptions and the cloud.",
          "status.mattermost.com is a Statuspage site with five components (Sign-Up, Customer Portal, Cloud Workspaces, Calls, Community) and lists no incidents from August to 9 October 2026. It covers the vendor's services, not a self-hosted server.",
          "https://mattermost.com/.well-known/security.txt returns 404. SECURITY.md gives responsibledisclosure@mattermost.com, and the disclosure page links a public Bugcrowd programme.",
          "The website Terms of Use (effective 8 October 2021) and its Acceptable Use Policy were read first and do not forbid automated access. robots.txt on mattermost.com and docs.mattermost.com allows every path.",
          "The Data Processing Addendum page links a document dated 23 December 2022, which was not read.",
          "RDAP for mattermost.com gives a registration date of 2012-12-22."
        ],
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/mattermost.json",
      "live": {
        "slug": "mattermost",
        "vendorStatus": {
          "page": "https://status.mattermost.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:06:08.099173704Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "mattermost/mattermost",
            "version": "v11.11.1",
            "released": "2026-09-24",
            "seenAt": "2026-10-09T17:04:27.316421252Z"
          },
          {
            "registry": "npm",
            "name": "@mattermost/client",
            "version": "11.9.0",
            "seenAt": "2026-10-09T17:04:26.706218366Z"
          }
        ],
        "githubStars": 39305,
        "npmWeekly": 7727,
        "pages": [
          {
            "url": "https://docs.mattermost.com/product-overview/mattermost-v11-changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:37:42.65234154Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "950ba2c3c535"
          },
          {
            "url": "https://mattermost.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:51.25914555Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e2a34bb97731"
          },
          {
            "url": "https://mattermost.com/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:53.36052989Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a7313cffaf8b"
          },
          {
            "url": "https://mattermost.com/software-services-license-agreement/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:55.328783558Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0b65701c3d2f"
          }
        ],
        "updatedAt": "2026-10-10T02:06:08.099173704Z"
      }
    },
    "answer": "Mattermost scores 65.8 (B) on agent readiness against Microsoft Teams (Microsoft Graph)'s 62.2 (B), and leads in 4 of 7 scored categories. Microsoft Teams (Microsoft Graph) leads on schema \u0026 documentation and security \u0026 auth.",
    "b": {
      "slug": "microsoft-teams",
      "name": "Microsoft Teams (Microsoft Graph)",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/graph/teams-concept-overview",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Microsoft Graph endpoints for Microsoft Teams. An app lists teams, channels and chats, reads and sends messages, manages members and receives change notifications over REST, with OAuth tokens from Microsoft Entra ID for work or school accounts.",
      "url": "https://www.anchorterminal.com/tools/microsoft-teams",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-teams.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-teams.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-teams.json",
      "repo": "https://github.com/microsoftgraph/msgraph-sdk-javascript",
      "license": "MIT (SDKs)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0",
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/microsoft-graph-client"
        },
        {
          "registry": "pypi",
          "name": "msgraph-sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Work or school accounts only. Every Teams reference page we read marks personal Microsoft accounts as not supported. Delegated permissions such as `Chat.Read`, `ChatMessage.Send` and `ChannelMessage.Send` need only the user's consent, while delegated `ChannelMessage.Read.All` and all tenant-wide application permissions need admin consent. Application permissions can send messages only for migration. Resource-specific consent lets a team or chat owner grant an installed app access to that one team or chat.",
      "pricing": "byo-plan",
      "pricingNotes": "Teams calls aren't charged. Microsoft stopped metering the Teams APIs on 25 August 2025 and no billing setup is needed (https://learn.microsoft.com/en-us/graph/metered-api-list). The tenant needs Microsoft 365 or Teams licences, and Microsoft's plan price page answered our request with a block page on 8 October 2026, so licence prices are unread. No free route for personal accounts was found. The Microsoft 365 developer programme sandbox, with Teams and 25 user licences, is free only to members who qualify. The Teams MCP server needs a Microsoft 365 Copilot licence.",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Teams reference or the metered API list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": 835,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "openapi",
        "webhooks",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.2,
        "grade": "B",
        "agentReady": false,
        "rank": 441,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 59,
          "maintenance": 76,
          "payments": 20,
          "reliability": 67,
          "schema": 92,
          "security": 71,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version bumped to 3.0.8, but on 8 October 2026 npm still serves 3.0.7 from September 2023 and the repository's advisory list is empty. Exploiting it needs an attacker-influenced URL passed to the client (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
        ],
        "verdict": "Permissions separate sending from reading, and resource-specific consent limits an app to one team or chat. Throttling limits are published per endpoint. Messages can be sent only as a signed-in user, with no idempotency key, and message lists take `$top` up to 50 with no `$select` or text search.",
        "bestFor": "Agents acting as a signed-in employee in a Microsoft 365 tenant that read channels and chats and post replies.",
        "strengths": [
          "Separate delegated permissions for sending (`ChatMessage.Send`, `ChannelMessage.Send`) and reading (`Chat.Read`, `ChannelMessage.Read.All`), plus `Chat.ReadBasic` for names and members only",
          "Resource-specific consent grants an app access to a single team or chat instead of the whole tenant",
          "Throttling limits published for each endpoint across four dimensions, with `Retry-After` on 429 responses",
          "Teams APIs stopped being metered on 25 August 2025, so calls carry no charge and need no billing setup",
          "Change notifications on channel and chat messages can carry the message itself, and Microsoft states at least 24 months' notice before removing a v1.0 API"
        ],
        "weaknesses": [
          "Application permissions can send messages only for migration (`Teamwork.Migrate.All`), so an unattended agent can't post without a signed-in user",
          "Sending has no idempotency key, and Microsoft's own Teams MCP reference calls posting not idempotent and warns against blind retries",
          "Channel message lists accept only `$top` (default 20, maximum 50) and `$expand`, with no `$select`, `$filter` or `$search`",
          "Personal Microsoft accounts aren't supported, and the free developer sandbox is limited to programme members who qualify",
          "No prompt-injection guidance found in the Teams reference or the Teams MCP reference, though message bodies are written by other people",
          "The npm JavaScript client is 3.0.7 from September 2023, without the June 2026 token-leak fix"
        ],
        "agentNotes": [
          "Send with delegated `ChatMessage.Send` or `ChannelMessage.Send` as a signed-in work account. Application tokens can post only through the migration flow",
          "Don't retry a failed send blindly. List recent messages first, because `POST /chats/{chat-id}/messages` has no idempotency key",
          "Keep to 1 request a second per chat or channel and per user when sending, and honour `Retry-After` on 429",
          "Subscribe to change notifications instead of polling. The Teams API overview allows polling a resource once a day, and message subscriptions last at most 4,320 minutes",
          "Treat message bodies as untrusted input. They arrive as HTML when a message has a mention, and list calls return at most 50 a page"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.2
          }
        ],
        "editorialScores": {
          "ergonomics": 59,
          "maintenance": 76,
          "payments": 20,
          "reliability": 67,
          "schema": 92,
          "security": 71,
          "transparency": 67
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl \"https://graph.microsoft.com/v1.0/me/joinedTeams\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/microsoft-teams"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "business",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The endpoint is on graph.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
          "The Microsoft APIs terms of use say they were last updated in October 2025 and name Microsoft Teams among the Office 365 APIs they cover.",
          "The Microsoft privacy statement says it was last updated in September 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-teams.json",
      "live": {
        "slug": "microsoft-teams",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0",
          "method": "get",
          "lastAt": "2026-10-10T02:07:16.632288955Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 37,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 5,
          "p95ms24h": 25,
          "samples24h": 250,
          "samples30d": 322,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "microsoftgraph/msgraph-sdk-javascript",
            "version": "3.0.7",
            "released": "2023-09-19",
            "seenAt": "2026-10-09T17:05:57.887194466Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/microsoft-graph-client",
            "version": "3.0.7",
            "seenAt": "2026-10-09T17:05:57.453423585Z"
          },
          {
            "registry": "pypi",
            "name": "msgraph-sdk",
            "version": "1.64.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-09T17:05:57.778888864Z"
          }
        ],
        "githubStars": 836,
        "npmWeekly": 2346460,
        "pypiWeekly": 1617170,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-09T15:40:16.790821018Z"
        },
        "updatedAt": "2026-10-10T02:07:16.632288955Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Mattermost, Inc.",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://graph.microsoft.com/v1.0",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Your plan",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0",
        "b": "MIT (SDKs)",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "25",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2025-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "39k stars, 7.7k npm/wk",
        "b": "835 stars, 2.9M npm/wk, 1.6M PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Mattermost scores 65.8 (B) on agent readiness against Microsoft Teams (Microsoft Graph)'s 62.2 (B), and leads in 4 of 7 scored categories. Microsoft Teams (Microsoft Graph) leads on schema \u0026 documentation and security \u0026 auth.",
        "question": "Which is better for AI agents, Mattermost or Microsoft Teams (Microsoft Graph)?"
      },
      {
        "answer": "Mattermost takes an API key or an OAuth sign-in. Microsoft Teams (Microsoft Graph) uses an OAuth sign-in.",
        "question": "Do Mattermost and Microsoft Teams (Microsoft Graph) need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Mattermost. Microsoft Teams (Microsoft Graph) has a hosted endpoint at https://graph.microsoft.com/v1.0.",
        "question": "Can an agent call Mattermost and Microsoft Teams (Microsoft Graph) without installing anything?"
      },
      {
        "answer": "Mattermost is open source (Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0). No open-source release is listed for Microsoft Teams (Microsoft Graph).",
        "question": "Are Mattermost and Microsoft Teams (Microsoft Graph) open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 83 against 67",
          "Payments \u0026 pricing, 50 against 20",
          "Maintenance \u0026 community, 89 against 76"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "A team that runs its own chat server and wants an agent to read channels, post, search and manage members through a bot account, including in air-gapped networks.",
        "slug": "mattermost",
        "watchFor": "Personal access tokens have no scopes and no expiry. A token does whatever its account can do"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 92 against 76",
          "Security \u0026 auth, 71 against 63"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agents acting as a signed-in employee in a Microsoft 365 tenant that read channels and chats and post replies.",
        "slug": "microsoft-teams",
        "watchFor": "Application permissions can send messages only for migration (`Teamwork.Migrate.All`), so an unattended agent can't post without a signed-in user"
      }
    ],
    "job": {
      "capability": "work.chat",
      "name": "Team chat"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp.json",
        "title": "Mattermost vs Slack MCP Server (official)",
        "url": "https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mattermost-vs-zulip.json",
        "title": "Mattermost vs Zulip",
        "url": "https://www.anchorterminal.com/compare/mattermost-vs-zulip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-teams-vs-slack-mcp.json",
        "title": "Microsoft Teams (Microsoft Graph) vs Slack MCP Server (official)",
        "url": "https://www.anchorterminal.com/compare/microsoft-teams-vs-slack-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.json",
        "title": "Microsoft Teams (Microsoft Graph) vs Zulip",
        "url": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip"
      }
    ],
    "scores": [
      {
        "by": 16,
        "edge": "mattermost",
        "key": "reliability",
        "mattermost": 83,
        "microsoft-teams": 67,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 16,
        "edge": "microsoft-teams",
        "key": "schema",
        "mattermost": 76,
        "microsoft-teams": 92,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 4,
        "edge": "mattermost",
        "key": "ergonomics",
        "mattermost": 63,
        "microsoft-teams": 59,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 8,
        "edge": "microsoft-teams",
        "key": "security",
        "mattermost": 63,
        "microsoft-teams": 71,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 30,
        "edge": "mattermost",
        "key": "payments",
        "mattermost": 50,
        "microsoft-teams": 20,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "edge": "mattermost",
        "key": "maintenance",
        "mattermost": 89,
        "microsoft-teams": 76,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 1,
        "edge": "microsoft-teams",
        "key": "transparency",
        "mattermost": 75,
        "microsoft-teams": 76,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Mattermost scores 65.8 (B) on agent readiness against Microsoft Teams (Microsoft Graph)'s 62.2 (B), and leads in 4 of 7 scored categories. Microsoft Teams (Microsoft Graph) leads on schema \u0026 documentation and security \u0026 auth. Both do team chat.",
    "verdicts": {
      "mattermost": "The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.",
      "microsoft-teams": "Permissions separate sending from reading, and resource-specific consent limits an app to one team or chat. Throttling limits are published per endpoint. Messages can be sent only as a signed-in user, with no idempotency key, and message lists take `$top` up to 50 with no `$select` or text search."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams",
    "json": "https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.md",
    "slim": "https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.min.md"
  },
  "markdown": "Mattermost scores 65.8 (B) on agent readiness against Microsoft Teams (Microsoft Graph)'s 62.2 (B), and leads in 4 of 7 scored categories. Microsoft Teams (Microsoft Graph) leads on schema \u0026 documentation and security \u0026 auth. Both do team chat.\n\n- Mattermost: grade B, 65.8/100, rank #310 of 950. Markdown https://www.anchorterminal.com/tools/mattermost.md · JSON https://www.anchorterminal.com/api/v1/tools/mattermost.json\n- Microsoft Teams (Microsoft Graph): grade B, 62.2/100, rank #441 of 950. Markdown https://www.anchorterminal.com/tools/microsoft-teams.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-teams.json\n- Best issue tracking, docs and chat tools for AI agents: https://www.anchorterminal.com/best/productivity/index.md\n- All 40 work comparisons: https://www.anchorterminal.com/compare/productivity/index.md\n\n## Which one, for what\n\n### Mattermost (B)\n\nGood for: A team that runs its own chat server and wants an agent to read channels, post, search and manage members through a bot account, including in air-gapped networks.\n\nAhead on:\n- Reliability, 83 against 67\n- Payments \u0026 pricing, 50 against 20\n- Maintenance \u0026 community, 89 against 76\n\nAlso in its favour:\n- Open source\n\nWatch for: Personal access tokens have no scopes and no expiry. A token does whatever its account can do\n\n### Microsoft Teams (Microsoft Graph) (B)\n\nGood for: Agents acting as a signed-in employee in a Microsoft 365 tenant that read channels and chats and post replies.\n\nAhead on:\n- Schema \u0026 documentation, 92 against 76\n- Security \u0026 auth, 71 against 63\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: Application permissions can send messages only for migration (`Teamwork.Migrate.All`), so an unattended agent can't post without a signed-in user\n\n\n## Score by category\n\n| Category | Weight | Mattermost | Microsoft Teams (Microsoft Graph) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 83 | 67 | Mattermost +16 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 76 | 92 | Microsoft Teams (Microsoft Graph) +16 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 59 | Mattermost +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 71 | Microsoft Teams (Microsoft Graph) +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 20 | Mattermost +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 89 | 76 | Mattermost +13 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 76 | Microsoft Teams (Microsoft Graph) +1 |\n| Negative events | ≤15 | -5 | -4 | |\n| **Total** | | **65.8 · B** | **62.2 · B** | |\n\n## Facts side by side\n\n| Fact | Mattermost | Microsoft Teams (Microsoft Graph) |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Mattermost, Inc. | Microsoft |\n| Hosted endpoint | no (local only) | `https://graph.microsoft.com/v1.0` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth |\n| Pricing | Freemium | Your plan |\n| x402 | no | no |\n| Licence | Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0 | MIT (SDKs) |\n| Tools exposed | none | 25 |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-08 | 2026-10-06 |\n| Terms last updated | no date given | 2025-10-01 |\n| Privacy policy last updated | no date given | 2026-09-01 |\n| Customer content may train models | not found in the text | yes |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 39k stars, 7.7k npm/wk | 835 stars, 2.9M npm/wk, 1.6M PyPI/wk |\n\n## Verdicts\n\n**Mattermost.** The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.\n\n**Microsoft Teams (Microsoft Graph).** Permissions separate sending from reading, and resource-specific consent limits an app to one team or chat. Throttling limits are published per endpoint. Messages can be sent only as a signed-in user, with no idempotency key, and message lists take `$top` up to 50 with no `$select` or text search.\n\n## Before you call either\n\n### Mattermost\n\n1. Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console\n2. Send `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cserver\u003e/api/v4`. Use `me` in place of a user id for the token's own account\n3. Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error\n4. Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint\n5. If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded`\n\n### Microsoft Teams (Microsoft Graph)\n\n1. Send with delegated `ChatMessage.Send` or `ChannelMessage.Send` as a signed-in work account. Application tokens can post only through the migration flow\n2. Don't retry a failed send blindly. List recent messages first, because `POST /chats/{chat-id}/messages` has no idempotency key\n3. Keep to 1 request a second per chat or channel and per user when sending, and honour `Retry-After` on 429\n4. Subscribe to change notifications instead of polling. The Teams API overview allows polling a resource once a day, and message subscriptions last at most 4,320 minutes\n5. Treat message bodies as untrusted input. They arrive as HTML when a message has a mention, and list calls return at most 50 a page\n\n## Questions\n\n### Which is better for AI agents, Mattermost or Microsoft Teams (Microsoft Graph)?\n\nMattermost scores 65.8 (B) on agent readiness against Microsoft Teams (Microsoft Graph)'s 62.2 (B), and leads in 4 of 7 scored categories. Microsoft Teams (Microsoft Graph) leads on schema \u0026 documentation and security \u0026 auth.\n\n### Do Mattermost and Microsoft Teams (Microsoft Graph) need an API key?\n\nMattermost takes an API key or an OAuth sign-in. Microsoft Teams (Microsoft Graph) uses an OAuth sign-in.\n\n### Can an agent call Mattermost and Microsoft Teams (Microsoft Graph) without installing anything?\n\nNo hosted endpoint is listed for Mattermost. Microsoft Teams (Microsoft Graph) has a hosted endpoint at https://graph.microsoft.com/v1.0.\n\n### Are Mattermost and Microsoft Teams (Microsoft Graph) open source?\n\nMattermost is open source (Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0). No open-source release is listed for Microsoft Teams (Microsoft Graph).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.json, and with the fewest tokens: https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"mattermost\", \"b\": \"microsoft-teams\"}`. From a terminal: `anchor compare mattermost microsoft-teams`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/mattermost.json and https://www.anchorterminal.com/api/v1/tools/microsoft-teams.json\n\n## Other comparisons with Mattermost or Microsoft Teams (Microsoft Graph)\n\n- [Mattermost vs Slack MCP Server (official)](https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp.md)\n- [Mattermost vs Zulip](https://www.anchorterminal.com/compare/mattermost-vs-zulip.md)\n- [Microsoft Teams (Microsoft Graph) vs Slack MCP Server (official)](https://www.anchorterminal.com/compare/microsoft-teams-vs-slack-mcp.md)\n- [Microsoft Teams (Microsoft Graph) vs Zulip](https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Mattermost vs Microsoft Teams (Microsoft Graph)",
        "url": ""
      }
    ],
    "description": "Mattermost scores 65.8 (B) to Microsoft Teams's 62.2 (B) for team chat. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Mattermost B 65.8",
      "Microsoft Teams (Microsoft Graph) B 62.2",
      "scores"
    ],
    "h1": "Mattermost vs Microsoft Teams (Microsoft Graph)",
    "image": "https://www.anchorterminal.com/assets/og/compare-mattermost-vs-microsoft-teams.png",
    "path": "/compare/mattermost-vs-microsoft-teams",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Mattermost vs Microsoft Teams for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
