{
  "data": {
    "a": {
      "slug": "mattermost",
      "name": "Mattermost",
      "vendor": "Mattermost, Inc.",
      "vendorUrl": "https://mattermost.com",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Mattermost is an open-core team chat server from Mattermost, Inc. that its owner hosts, with channels, threads, calls and playbooks. Agents reach it through the REST API v4, bot accounts, personal access tokens, webhooks and an MCP server.",
      "url": "https://www.anchorterminal.com/tools/mattermost",
      "markdownUrl": "https://www.anchorterminal.com/tools/mattermost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mattermost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mattermost.json",
      "repo": "https://github.com/mattermost/mattermost",
      "license": "Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@mattermost/client"
        },
        {
          "registry": "go",
          "name": "github.com/mattermost/mattermost/server/public"
        }
      ],
      "auth": "mixed",
      "authNotes": "Granted by the server's own admin, with no vendor approval. The API takes a Bearer token in the `Authorization` header, either a session token from `POST /api/v4/users/login` or a personal access token. Personal access tokens are off until an admin enables them and lets the account create them, have a description, no scopes and no expiry, and can be revoked or disabled. Bot accounts hold such tokens, cannot be logged into and are created by a System Admin or a plugin once bot creation is enabled. OAuth 2.0 applications are also off by default, support PKCE and optional dynamic client registration, and have no scopes. The MCP server takes OAuth or a personal access token.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Team Edition and the Entry edition are free with no card or vendor account. Entry shows 10,000 messages of history and has community support only. Professional, Enterprise and Enterprise Advanced are annual per-seat subscriptions with no public price, and Mattermost Cloud is single-tenant and sold through sales (https://mattermost.com/pricing/). API calls are not charged, and bot accounts do not count as licensed users. An agent's owner can start on a free edition without a contract. The site's trial environment lasts one hour.",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API introduction, the OpenAPI source or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 39301,
        "npmWeekly": 7727,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.mattermost.com/api",
      "openapi": "https://github.com/mattermost/mattermost/tree/master/api/v4/source",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "freemium",
        "sales-led",
        "pat",
        "oauth",
        "openapi",
        "mcp",
        "typescript",
        "go",
        "webhooks",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.8,
        "grade": "B",
        "agentReady": false,
        "rank": 310,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 89,
          "payments": 50,
          "reliability": 83,
          "schema": 76,
          "security": 63,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "2025-10-28 to 2026-10-08. The v11 changelog marks 52 dot releases in twelve months as carrying security fixes. Three are rated critical, 11.0.4 on 28 October 2025 in the server and 11.0.6 and 11.1.1 on 21 November 2025 in the bundled Jira plugin, and 21 more include high-severity fixes. All were fixed in a release and announced, with details published 30 days later, so 5 points. The advisory table itself is drawn by script and was not read (https://docs.mattermost.com/product-overview/mattermost-v11-changelog)."
        ],
        "verdict": "The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.",
        "bestFor": "A team that runs its own chat server and wants an agent to read channels, post, search and manage members through a bot account, including in air-gapped networks.",
        "strengths": [
          "Public OpenAPI 3.0 source for API v4, every operation described, 548 of 604 stating the permission needed",
          "Sixteen server releases between 11 July and 8 October 2026, each with a dated changelog entry and an API changes list",
          "Team Edition is free under MIT as a compiled binary, and the free Entry edition needs no card or vendor account",
          "Bot accounts are separate from people, do not count as licensed users, and their tokens can be revoked or disabled",
          "Public Bugcrowd bounty, and a SOC 2 Type II report and ISO 27001:2022 certificate listed on the trust centre"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes and no expiry. A token does whatever its account can do",
          "52 dot releases from 28 October 2025 to 8 October 2026 carried security fixes, three rated critical and 21 including high-severity fixes",
          "No public price for Professional, Enterprise or Enterprise Advanced, and Mattermost Cloud is sold through sales only",
          "No idempotency key on `POST /api/v4/posts`, so a retried send can post twice",
          "Rate limiting is off by default on a self-hosted server, and no llms.txt or security.txt was found"
        ],
        "agentNotes": [
          "Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console",
          "Send `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cserver\u003e/api/v4`. Use `me` in place of a user id for the token's own account",
          "Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error",
          "Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint",
          "If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded`"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.8
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 89,
          "payments": 50,
          "reliability": 83,
          "schema": 76,
          "security": 63,
          "transparency": 80
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "docker run --name mattermost-preview -d --publish 8065:8065 mattermost/mattermost-preview",
        "http": "curl -X POST https://your-mattermost-server.com/api/v4/posts -H 'Authorization: Bearer \u003cTOKEN\u003e' -H 'Content-Type: application/json' -d '{\"channel_id\": \"\u003cCHANNEL_ID\u003e\", \"message\": \"Status update from API\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/mattermost"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Team Edition (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, MIT binary, REST API included"
        },
        {
          "item": "Entry (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, 10,000 messages of viewable history, community support only; paid editions have no public price"
        }
      ],
      "provenance": {
        "legalEntity": "Mattermost, Inc.",
        "domain": "mattermost.com",
        "domainRegistered": "2012-12-22",
        "endpointOnVendorDomain": false,
        "terms": "https://mattermost.com/software-services-license-agreement/",
        "privacy": "https://mattermost.com/privacy-policy/",
        "statusPage": "https://status.mattermost.com",
        "changelog": "https://docs.mattermost.com/product-overview/mattermost-v11-changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Software and Services Licence Agreement (effective 12 January 2023) is a contract with Mattermost, Inc. and covers both Cloud Edition and On-Premise subscriptions. The privacy policy (effective 30 December 2024) gives the address 530 Lytton Avenue, Suite 201, Palo Alto, CA 94301.",
          "The graded API answers on the owner's own server at https://\u003cserver\u003e/api/v4, so the endpoint is not on the vendor's domain.",
          "The compiled Team Edition is under MIT and needs no agreement with the vendor. The agreement linked here governs the Enterprise Edition binary, subscriptions and the cloud.",
          "status.mattermost.com is a Statuspage site with five components (Sign-Up, Customer Portal, Cloud Workspaces, Calls, Community) and lists no incidents from August to 9 October 2026. It covers the vendor's services, not a self-hosted server.",
          "https://mattermost.com/.well-known/security.txt returns 404. SECURITY.md gives responsibledisclosure@mattermost.com, and the disclosure page links a public Bugcrowd programme.",
          "The website Terms of Use (effective 8 October 2021) and its Acceptable Use Policy were read first and do not forbid automated access. robots.txt on mattermost.com and docs.mattermost.com allows every path.",
          "The Data Processing Addendum page links a document dated 23 December 2022, which was not read.",
          "RDAP for mattermost.com gives a registration date of 2012-12-22."
        ],
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/mattermost.json",
      "live": {
        "slug": "mattermost",
        "vendorStatus": {
          "page": "https://status.mattermost.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T03:58:27.91525052Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "mattermost/mattermost",
            "version": "v11.11.1",
            "released": "2026-09-24",
            "seenAt": "2026-10-09T17:04:27.316421252Z"
          },
          {
            "registry": "npm",
            "name": "@mattermost/client",
            "version": "11.9.0",
            "seenAt": "2026-10-09T17:04:26.706218366Z"
          }
        ],
        "githubStars": 39305,
        "npmWeekly": 7727,
        "pages": [
          {
            "url": "https://docs.mattermost.com/product-overview/mattermost-v11-changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:37:42.65234154Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "950ba2c3c535"
          },
          {
            "url": "https://mattermost.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:51.25914555Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e2a34bb97731"
          },
          {
            "url": "https://mattermost.com/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:53.36052989Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a7313cffaf8b"
          },
          {
            "url": "https://mattermost.com/software-services-license-agreement/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:55.328783558Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0b65701c3d2f"
          }
        ],
        "updatedAt": "2026-10-10T03:58:27.91525052Z"
      }
    },
    "answer": "Mattermost scores 65.8 (B) on agent readiness against Zulip's 61.5 (C), and leads in 3 of 7 scored categories. Zulip leads on schema \u0026 documentation and agent ergonomics.",
    "b": {
      "slug": "zulip",
      "name": "Zulip",
      "vendor": "Kandra Labs, Inc.",
      "vendorUrl": "https://zulip.com",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Zulip is open-source team chat organised into channels and topics, from Kandra Labs, hosted as Zulip Cloud or self-hosted. Agents reach it through a REST API with bot accounts, an events queue and Python and JavaScript client libraries.",
      "url": "https://www.anchorterminal.com/tools/zulip",
      "markdownUrl": "https://www.anchorterminal.com/tools/zulip.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zulip.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zulip.json",
      "repo": "https://github.com/zulip/zulip",
      "license": "Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "zulip"
        },
        {
          "registry": "npm",
          "name": "zulip-js"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve. Every user and every bot has one API key, sent with HTTP Basic authentication as the account's email and the key. A member creates a bot under Personal settings, Bots, unless an administrator has restricted bot creation, and copies its key or downloads a `zuliprc` file. Generating a new key invalidates the old one. Keys carry no scopes or expiry. What a key can do follows the account's role (owner, administrator, moderator, member, guest), its channel subscriptions and, for bots, the bot type. No OAuth for API clients. `POST /fetch_api_key` exchanges a user's password for the key.",
      "pricing": "freemium",
      "pricingNotes": "Zulip Cloud Free costs nothing and needs no card, with 10,000 messages of search history and 5 GB of files in total. Standard is $6.67 a user a month billed annually or $8 monthly, and Plus is $10 or $12 with a 10-user minimum (https://zulip.com/plans/). API calls are not charged, and the plan comparison lists REST API custom integrations. A self-hosted server is free, with paid plans from $3.50 a user a month for mobile notifications and support. An agent's owner can start on the Free plan or a demo organisation without a contract.",
      "priceSummary": "$6.67 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API documentation, the OpenAPI file or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 26014,
        "npmWeekly": 7094,
        "pypiWeekly": 157209,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://zulip.com/api/rest",
      "openapi": "https://github.com/zulip/zulip/blob/main/zerver/openapi/zulip.yaml",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "api-key",
        "openapi",
        "python",
        "javascript",
        "webhooks",
        "status-page"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.5,
        "grade": "C",
        "agentReady": false,
        "rank": 466,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 83,
          "schema": 82,
          "security": 42,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-10 and 2026-09-21. GHSA-5r8f-gq2h-fcgp let a guest receive new messages from public channels it was not subscribed to by registering an event queue, fixed in 12.2. GHSA-42mq-rxcr-wj72 let a member forge the sender of a group direct message through the API, fixed in 12.3. Both are reachable with an ordinary API key. Fixed and published, so 2 points (https://github.com/zulip/zulip/security/advisories/GHSA-5r8f-gq2h-fcgp, https://github.com/zulip/zulip/security/advisories/GHSA-42mq-rxcr-wj72).",
          "2026-02-05 to 2026-09-21. Eleven further advisories in twelve months across releases 11.5, 11.6, 12.0, 12.2 and 12.3, among them CVE-2026-25742 (attachments still public after web-public access was disabled), CVE-2026-40300 (edit history exposing original content in the API) and GHSA-xw9h-9rcm-hx4m (OpenID Connect ignoring `email_verified`). All fixed and published by the vendor, so 2 points (https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md)."
        ],
        "verdict": "The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published.",
        "bestFor": "A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.",
        "strengths": [
          "Public OpenAPI 3.0 file with 166 operations, all described, and curl, Python and JavaScript examples per endpoint",
          "Every API change is recorded against a numbered feature level that clients read from `GET /server_settings`",
          "status.zulip.com lists no incidents from 11 July to 8 October 2026 and one minor incident in May 2026",
          "Bot accounts come in three types, and an incoming webhook bot can only send messages",
          "The server is Apache 2.0, and the Free cloud plan needs no card"
        ],
        "weaknesses": [
          "One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do",
          "Thirteen security advisories between February and September 2026, among them guests reading unsubscribed public channels and forged senders through the API",
          "`POST /messages` has no idempotency key, so a retried send can post twice",
          "Incoming webhook URLs carry the bot's key in the query string as `api_key`",
          "No SLA, SOC 2 or ISO 27001 statement, security.txt or llms.txt was found"
        ],
        "agentNotes": [
          "Ask the organisation for a bot of the most limited type that fits. Use an incoming webhook bot when the task only posts messages",
          "Authenticate with HTTP Basic, the bot's email as user and its API key as password, against https://\u003corganisation\u003e.zulipchat.com/api/v1",
          "Read `code`, not `msg`, on errors. `msg` is translated into the account's language",
          "On `RATE_LIMIT_HIT` wait the seconds in `retry-after`. The default limit is 200 requests a minute per user",
          "Fetch history with `GET /messages`, a `narrow` filter, an `anchor` and `num_before` or `num_after`, at most 1,000 a batch as the docs recommend"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.5
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 83,
          "schema": 82,
          "security": 42,
          "transparency": 77
        },
        "provenanceScore": 74
      },
      "connect": {
        "install": "pip install zulip",
        "http": "curl -X POST https://your-org.zulipchat.com/api/v1/messages -u EMAIL_ADDRESS:API_KEY --data-urlencode type=stream --data-urlencode 'to=\"Denmark\"' --data-urlencode topic=Castle --data-urlencode 'content=Hello'"
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/zulip"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Zulip Cloud Standard",
          "unit": "seat-month",
          "usd": 6.67,
          "note": "billed annually, $8 billed monthly"
        },
        {
          "item": "Zulip Cloud Plus",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed annually, $12 billed monthly, 10 users minimum"
        },
        {
          "item": "Self-hosted Basic",
          "unit": "seat-month",
          "usd": 3.5,
          "note": "billed monthly, for a server the owner runs"
        },
        {
          "item": "Self-hosted Business",
          "unit": "seat-month",
          "usd": 6.67,
          "note": "billed annually, $8 billed monthly, 25 users minimum"
        }
      ],
      "provenance": {
        "legalEntity": "Kandra Labs, Inc.",
        "domain": "zulip.com",
        "domainRegistered": "2010-12-01",
        "endpointOnVendorDomain": false,
        "terms": "https://zulip.com/policies/terms",
        "privacy": "https://zulip.com/policies/privacy",
        "statusPage": "https://status.zulip.com",
        "changelog": "https://zulip.com/api/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Service (effective 7 February 2022) are a contract with Kandra Labs, Inc., 584 Castro St #3175, San Francisco, CA 94114, and cover the websites, products, services and applications.",
          "Cloud organisations answer at https://\u003corganisation\u003e.zulipchat.com/api/v1, a second domain. zulip.com's own footer links its terms and privacy policy at zulipchat.com, and the OpenAPI file names the host.",
          "https://zulip.com/.well-known/security.txt returns 404. SECURITY.md in the repository gives security@zulip.com and a private HackerOne programme.",
          "The privacy policy is effective 1 January 2022. A Data Processing Addendum is published as a PDF and was not read.",
          "RDAP for zulip.com gives a registration date of 2010-12-01."
        ],
        "score": 74
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/zulip.json",
      "live": {
        "slug": "zulip",
        "vendorStatus": {
          "page": "https://status.zulip.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-10T03:58:53.082589714Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "zulip/zulip",
            "version": "12.3",
            "released": "2026-09-21",
            "seenAt": "2026-10-09T17:30:07.049657928Z"
          },
          {
            "registry": "npm",
            "name": "zulip-js",
            "version": "2.1.0",
            "seenAt": "2026-10-09T17:30:06.195940769Z"
          },
          {
            "registry": "pypi",
            "name": "zulip",
            "version": "0.9.1",
            "released": "2025-09-30",
            "seenAt": "2026-10-09T17:30:06.012686013Z"
          }
        ],
        "githubStars": 26019,
        "npmWeekly": 5655,
        "pypiWeekly": 151572,
        "securityTxt": {
          "url": "https://zulip.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:24.200053772Z"
        },
        "pages": [
          {
            "url": "https://zulip.com/api/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:56:25.217900134Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c2353c54b4f2"
          },
          {
            "url": "https://zulip.com/policies/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:56:28.917326197Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5be1a4dfedda"
          },
          {
            "url": "https://zulip.com/policies/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:56:29.319732248Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d87e491cee86"
          }
        ],
        "updatedAt": "2026-10-10T03:58:53.082589714Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Mattermost, Inc.",
        "b": "Kandra Labs, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0",
        "b": "Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-09-21",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2022-02-07",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2022-01-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "39k stars, 7.7k npm/wk",
        "b": "26k stars, 7.1k npm/wk, 157k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Mattermost scores 65.8 (B) on agent readiness against Zulip's 61.5 (C), and leads in 3 of 7 scored categories. Zulip leads on schema \u0026 documentation and agent ergonomics.",
        "question": "Which is better for AI agents, Mattermost or Zulip?"
      },
      {
        "answer": "Mattermost takes an API key or an OAuth sign-in. Zulip needs an API key.",
        "question": "Do Mattermost and Zulip need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Mattermost. No hosted endpoint is listed for Zulip.",
        "question": "Can an agent call Mattermost and Zulip without installing anything?"
      },
      {
        "answer": "Yes. Mattermost is open source (Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0). Zulip is open source (Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT).",
        "question": "Are Mattermost and Zulip open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 63 against 42",
          "Payments \u0026 pricing, 50 against 30",
          "Maintenance \u0026 community, 89 against 77"
        ],
        "also": null,
        "goodFor": "A team that runs its own chat server and wants an agent to read channels, post, search and manage members through a bot account, including in air-gapped networks.",
        "slug": "mattermost",
        "watchFor": "Personal access tokens have no scopes and no expiry. A token does whatever its account can do"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 82 against 76",
          "Agent ergonomics, 68 against 63"
        ],
        "also": null,
        "goodFor": "A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.",
        "slug": "zulip",
        "watchFor": "One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do"
      }
    ],
    "job": {
      "capability": "work.chat",
      "name": "Team chat"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.json",
        "title": "Mattermost vs Microsoft Teams (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp.json",
        "title": "Mattermost vs Slack MCP Server (official)",
        "url": "https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.json",
        "title": "Microsoft Teams (Microsoft Graph) vs Zulip",
        "url": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/slack-mcp-vs-zulip.json",
        "title": "Slack MCP Server (official) vs Zulip",
        "url": "https://www.anchorterminal.com/compare/slack-mcp-vs-zulip"
      }
    ],
    "scores": [
      {
        "by": 0,
        "edge": "",
        "key": "reliability",
        "mattermost": 83,
        "name": "Reliability",
        "weight": 16,
        "zulip": 83
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "zulip",
        "key": "schema",
        "mattermost": 76,
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "zulip": 82
      },
      {
        "by": 5,
        "edge": "zulip",
        "key": "ergonomics",
        "mattermost": 63,
        "name": "Agent ergonomics",
        "weight": 13,
        "zulip": 68
      },
      {
        "by": 21,
        "edge": "mattermost",
        "key": "security",
        "mattermost": 63,
        "name": "Security \u0026 auth",
        "weight": 14,
        "zulip": 42
      },
      {
        "by": 20,
        "edge": "mattermost",
        "key": "payments",
        "mattermost": 50,
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "zulip": 30
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "mattermost",
        "key": "maintenance",
        "mattermost": 89,
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "zulip": 77
      },
      {
        "by": 1,
        "edge": "zulip",
        "key": "transparency",
        "mattermost": 75,
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "zulip": 76
      }
    ],
    "summary": "Mattermost scores 65.8 (B) on agent readiness against Zulip's 61.5 (C), and leads in 3 of 7 scored categories. Zulip leads on schema \u0026 documentation and agent ergonomics. Both do team chat.",
    "verdicts": {
      "mattermost": "The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.",
      "zulip": "The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/mattermost-vs-zulip",
    "json": "https://www.anchorterminal.com/compare/mattermost-vs-zulip.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/mattermost-vs-zulip.md",
    "slim": "https://www.anchorterminal.com/compare/mattermost-vs-zulip.min.md"
  },
  "markdown": "Mattermost scores 65.8 (B) on agent readiness against Zulip's 61.5 (C), and leads in 3 of 7 scored categories. Zulip leads on schema \u0026 documentation and agent ergonomics. Both do team chat.\n\n- Mattermost: grade B, 65.8/100, rank #310 of 950. Markdown https://www.anchorterminal.com/tools/mattermost.md · JSON https://www.anchorterminal.com/api/v1/tools/mattermost.json\n- Zulip: grade C, 61.5/100, rank #466 of 950. Markdown https://www.anchorterminal.com/tools/zulip.md · JSON https://www.anchorterminal.com/api/v1/tools/zulip.json\n- Best issue tracking, docs and chat tools for AI agents: https://www.anchorterminal.com/best/productivity/index.md\n- All 40 work comparisons: https://www.anchorterminal.com/compare/productivity/index.md\n\n## Which one, for what\n\n### Mattermost (B)\n\nGood for: A team that runs its own chat server and wants an agent to read channels, post, search and manage members through a bot account, including in air-gapped networks.\n\nAhead on:\n- Security \u0026 auth, 63 against 42\n- Payments \u0026 pricing, 50 against 30\n- Maintenance \u0026 community, 89 against 77\n\nWatch for: Personal access tokens have no scopes and no expiry. A token does whatever its account can do\n\n### Zulip (C)\n\nGood for: A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.\n\nAhead on:\n- Schema \u0026 documentation, 82 against 76\n- Agent ergonomics, 68 against 63\n\nWatch for: One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do\n\n\n## Score by category\n\n| Category | Weight | Mattermost | Zulip | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 83 | 83 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 76 | 82 | Zulip +6 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 68 | Zulip +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 42 | Mattermost +21 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 30 | Mattermost +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 89 | 77 | Mattermost +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 76 | Zulip +1 |\n| Negative events | ≤15 | -5 | -4 | |\n| **Total** | | **65.8 · B** | **61.5 · C** | |\n\n## Facts side by side\n\n| Fact | Mattermost | Zulip |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Mattermost, Inc. | Kandra Labs, Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0 | Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-08 | 2026-09-21 |\n| Terms last updated | no date given | 2022-02-07 |\n| Privacy policy last updated | no date given | 2022-01-01 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 39k stars, 7.7k npm/wk | 26k stars, 7.1k npm/wk, 157k PyPI/wk |\n\n## Verdicts\n\n**Mattermost.** The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.\n\n**Zulip.** The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published.\n\n## Before you call either\n\n### Mattermost\n\n1. Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console\n2. Send `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cserver\u003e/api/v4`. Use `me` in place of a user id for the token's own account\n3. Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error\n4. Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint\n5. If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded`\n\n### Zulip\n\n1. Ask the organisation for a bot of the most limited type that fits. Use an incoming webhook bot when the task only posts messages\n2. Authenticate with HTTP Basic, the bot's email as user and its API key as password, against https://\u003corganisation\u003e.zulipchat.com/api/v1\n3. Read `code`, not `msg`, on errors. `msg` is translated into the account's language\n4. On `RATE_LIMIT_HIT` wait the seconds in `retry-after`. The default limit is 200 requests a minute per user\n5. Fetch history with `GET /messages`, a `narrow` filter, an `anchor` and `num_before` or `num_after`, at most 1,000 a batch as the docs recommend\n\n## Questions\n\n### Which is better for AI agents, Mattermost or Zulip?\n\nMattermost scores 65.8 (B) on agent readiness against Zulip's 61.5 (C), and leads in 3 of 7 scored categories. Zulip leads on schema \u0026 documentation and agent ergonomics.\n\n### Do Mattermost and Zulip need an API key?\n\nMattermost takes an API key or an OAuth sign-in. Zulip needs an API key.\n\n### Can an agent call Mattermost and Zulip without installing anything?\n\nNo hosted endpoint is listed for Mattermost. No hosted endpoint is listed for Zulip.\n\n### Are Mattermost and Zulip open source?\n\nYes. Mattermost is open source (Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0). Zulip is open source (Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/mattermost-vs-zulip.json, and with the fewest tokens: https://www.anchorterminal.com/compare/mattermost-vs-zulip.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"mattermost\", \"b\": \"zulip\"}`. From a terminal: `anchor compare mattermost zulip`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/mattermost.json and https://www.anchorterminal.com/api/v1/tools/zulip.json\n\n## Other comparisons with Mattermost or Zulip\n\n- [Mattermost vs Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.md)\n- [Mattermost vs Slack MCP Server (official)](https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp.md)\n- [Microsoft Teams (Microsoft Graph) vs Zulip](https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.md)\n- [Slack MCP Server (official) vs Zulip](https://www.anchorterminal.com/compare/slack-mcp-vs-zulip.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Mattermost vs Zulip",
        "url": ""
      }
    ],
    "description": "Mattermost scores 65.8 (B) to Zulip's 61.5 (C) for team chat. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Mattermost B 65.8",
      "Zulip C 61.5",
      "scores"
    ],
    "h1": "Mattermost vs Zulip",
    "image": "https://www.anchorterminal.com/assets/og/compare-mattermost-vs-zulip.png",
    "path": "/compare/mattermost-vs-zulip",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Mattermost vs Zulip for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/mattermost-vs-zulip"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 680
  },
  "version": 1
}
