{
  "data": {
    "a": {
      "slug": "melius",
      "name": "Melius",
      "vendor": "Melius AI, Inc.",
      "vendorUrl": "https://www.melius.com",
      "kind": "http-api",
      "category": "design",
      "summary": "Melius is a hosted node-based canvas for generating images, video, audio and text with many third-party models. Outside agents read and write projects, canvases, nodes, edges, runs and comments through a REST API, an MCP server and the mel CLI.",
      "url": "https://www.anchorterminal.com/tools/melius",
      "markdownUrl": "https://www.anchorterminal.com/tools/melius.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/melius.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/melius.json",
      "license": "Proprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository found",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.melius.com/api/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@melius-ai/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an API key in the Melius app under Team settings, Integrations. The REST API, the CLI and the MCP endpoint at https://api.melius.com/mcp take it as a Bearer token, with an optional `x-team-id` header. The MCP endpoint at https://mcp.melius.com/mcp uses OAuth (authorisation code with S256 PKCE and dynamic client registration), where the user signs in, picks one team and Melius creates a connector key. Keys have no scopes. A key works with its creator's access and that user's role in each team. Access is self-serve, with no app review or sales approval.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with trial credits, amount not published. Creator $20 a month for 20,000 credits, Growth $50 for 50,000, Professional $110 for 110,000, Team $70 a seat for 70,000 pooled credits (2 to 10 seats), Enterprise custom. Annual billing cuts 15 to 20 per cent. API, CLI and MCP calls have no separate charge and generations draw team credits. Per-model credit costs come from an authenticated endpoint, not the pricing page. The page's comparison table shows different figures ($18, $45, $99+, $63). Whether Free teams can create API keys is not stated (https://www.melius.com/pricing, checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API, MCP or CLI docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 75,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 9,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.melius.com",
      "llmsTxt": "https://docs.melius.com/llms.txt",
      "openapi": "https://docs.melius.com/api/openapi.json",
      "capabilities": [
        "design.canvas",
        "design.comments",
        "design.files",
        "image.generate",
        "image.edit",
        "image.upscale",
        "video.generate",
        "speech.tts"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "closed-source",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "cli",
        "async-jobs",
        "status-page",
        "pre-1.0"
      ],
      "lastRelease": "2026-09-10",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.1,
        "grade": "C",
        "agentReady": false,
        "rank": 473,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 66,
          "payments": 20,
          "reliability": 69,
          "schema": 70,
          "security": 43,
          "transparency": 55
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.",
        "bestFor": "An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.",
        "strengths": [
          "Public OpenAPI 3.0.2 spec with 59 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
          "Hosted MCP server with OAuth sign-in (PKCE, dynamic client registration) or a bearer API key, tied to one team chosen at authorisation",
          "429 responses carry `Retry-After` and `retryAfterSeconds`, and the docs give a bounded retry policy",
          "The mel CLI prints JSON only, uses six fixed exit codes and returns errors with a `code` and a `suggestion`",
          "status.melius.com lists no incidents for Web app or MCP from July to October 2026"
        ],
        "weaknesses": [
          "API keys have no scopes. A key works with its creator's role in every team the creator belongs to",
          "No rate-limit numbers, SLA, public changelog or API deprecation policy found in the reviewed documentation",
          "The MCP reference lists 75 tools, and the setup guide tells users to select Always Allow for all of them",
          "Per-model credit costs are returned by an authenticated endpoint and shown in the app, not on the pricing page",
          "No security.txt or disclosure policy found, and the Vanta trust centre at trust.melius.com needs JavaScript we couldn't run"
        ],
        "agentNotes": [
          "Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until `status` is finished or failed",
          "Over MCP, call `get_guide` first, `show_presence` before node changes and `canvas_plan_layout` before `bulk_create_nodes`",
          "On 429 wait `Retry-After` seconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys",
          "Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits",
          "Downloads arrive as a ZIP from a signed URL. Fetch that URL without the `Authorization` header"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.1
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 66,
          "payments": 20,
          "reliability": 69,
          "schema": 70,
          "security": 43,
          "transparency": 38
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "npm install -g @melius-ai/cli",
        "http": "curl -s -H \"Authorization: Bearer $MEL_API_KEY\" https://api.melius.com/api/v1/teams",
        "claudeCode": "claude mcp add melius --transport http https://mcp.melius.com/mcp --scope user",
        "config": {
          "mcpServers": {
            "melius": {
              "url": "https://mcp.melius.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.canvas",
        "tool": "https://letme.dev/melius"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Creator plan",
          "unit": "month",
          "usd": 20,
          "note": "20,000 credits a month, $17 a month on annual billing"
        },
        {
          "item": "Growth plan",
          "unit": "month",
          "usd": 50,
          "note": "50,000 credits a month, $43 on annual billing"
        },
        {
          "item": "Professional plan",
          "unit": "month",
          "usd": 110,
          "note": "110,000 credits a month, $93 on annual billing. A 300,000-credit option is also listed"
        },
        {
          "item": "Team plan",
          "unit": "seat-month",
          "usd": 70,
          "note": "70,000 pooled credits a seat, 2 to 10 seats, $56 on annual billing"
        }
      ],
      "provenance": {
        "legalEntity": "Melius AI, Inc.",
        "domain": "melius.com",
        "domainRegistered": "1998-11-24",
        "endpointOnVendorDomain": true,
        "terms": "https://www.melius.com/terms",
        "privacy": "https://www.melius.com/privacy",
        "statusPage": "https://status.melius.com",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (effective 28 August 2026) name Melius AI, Inc., 420 Lexington Avenue, New York, as the contracting party and are governed by Delaware law.",
          "The API answers at api.melius.com, the OAuth MCP endpoint at mcp.melius.com and the docs at docs.melius.com, all melius.com subdomains.",
          "/.well-known/security.txt returns 404 on www.melius.com, docs.melius.com and api.melius.com.",
          "RDAP for melius.com gives a registration date of 1998-11-24, which predates the company. The site says it is not affiliated with other organisations that share the Melius name.",
          "No public changelog was found. docs.melius.com/changelog and www.melius.com/changelog return 404, and release dates come from the npm registry.",
          "trust.melius.com is a Vanta trust centre that renders only with JavaScript, so its contents were not read."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/melius.json",
      "live": {
        "slug": "melius",
        "probe": {
          "target": "https://api.melius.com/api/v1",
          "method": "get",
          "lastAt": "2026-10-08T19:08:52.818187603Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 351,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 335,
          "p95ms24h": 375,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.melius.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:45.945421984Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@melius-ai/cli",
            "version": "0.16.2",
            "seenAt": "2026-10-08T16:20:12.72497812Z"
          }
        ],
        "npmWeekly": 9,
        "securityTxt": {
          "url": "https://melius.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:50.537934736Z"
        },
        "pages": [
          {
            "url": "https://www.melius.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:07.616845141Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e10be360cae0"
          },
          {
            "url": "https://www.melius.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:09.848367293Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1f3a2bb3eee9"
          },
          {
            "url": "https://www.melius.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:11.947870163Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a03166dbf644"
          }
        ],
        "updatedAt": "2026-10-08T19:08:52.818187603Z"
      }
    },
    "answer": "Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "penpot",
      "name": "Penpot API + MCP",
      "vendor": "Penpot (Kaleidos)",
      "vendorUrl": "https://penpot.app",
      "kind": "http-api",
      "category": "design",
      "summary": "Open-source design and prototyping tool, used as SaaS at design.penpot.app or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/penpot",
      "markdownUrl": "https://www.anchorterminal.com/tools/penpot.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/penpot.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/penpot.json",
      "repo": "https://github.com/penpot/penpot",
      "license": "MPL-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://design.penpot.app/api/rpc/command",
      "packages": [
        {
          "registry": "npm",
          "name": "@penpot/mcp"
        }
      ],
      "auth": "pat",
      "authNotes": "Personal access tokens from account settings, sent as `Authorization: Token \u003ctoken\u003e`. The hosted MCP URL takes a separate MCP key in the `userToken` query parameter. The local MCP server (`npx @penpot/mcp@stable`) talks to the plugin over a WebSocket on localhost.",
      "pricing": "freemium",
      "pricingNotes": "Cloud Professional plan is free with unlimited files and team members. Unlimited $7 per editor a month, capped at $175 a month. Enterprise $25 per member a month, minimum $950 a month. Private server $50,000 a year. Self-hosting the community edition is free under MPL-2.0, and self-hosted Enterprise starts at $950 a month (https://penpot.app/pricing).",
      "priceSummary": "$7 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payment support in the API or MCP docs.",
        "endpoints": []
      },
      "toolCount": 5,
      "popularity": {
        "githubStars": 60534,
        "npmWeekly": 1259,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://help.penpot.app/technical-guide/integration/",
      "openapi": "https://design.penpot.app/api/main/doc/openapi",
      "capabilities": [
        "design.files",
        "design.components",
        "design.canvas",
        "design.comments",
        "design.code"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "openapi",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 43.5,
        "grade": "E",
        "agentReady": false,
        "rank": 581,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-3: 2026-05-19, three advisories published together, a critical pre-authenticated account takeover through team-invitation tokens (GHSA-4937-35vc-hqjj), an MCP REPL server bound to 0.0.0.0 with an unauthenticated /execute endpoint allowing remote code execution (GHSA-22qr-rp27-j9wm, high) and authenticated SSRF in remote image import (GHSA-35g2-w7f6-8v9h, high). Fixed and published, so the deduction is reduced (https://github.com/penpot/penpot/security).",
          "-1: 2026-02-16, arbitrary file read through the create-font-variant RPC endpoint (GHSA-xp3f-g8rq-9px2, high). Fixed and published (https://github.com/penpot/penpot/security).",
          "-1: 2.18.0 (2026-09-23) fixed MCP keys being usable as full API access tokens, while the documented hosted setup puts that key in a URL query string, and fixed the MCP REPL starting in multi-user mode on the main bind address. Fixed in the changelog with no advisory (https://github.com/penpot/penpot/blob/develop/CHANGES.md)."
        ],
        "verdict": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.",
        "bestFor": "Teams that want design files on their own servers and an agent working alongside a person in the editor.",
        "strengths": [
          "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan",
          "MCP `execute_code` reaches the whole plugin API, so an agent can create, move, restyle and delete shapes",
          "OpenAPI description served by every instance",
          "Five releases between 22 July and 1 October 2026, with issues labelled and milestoned within a day"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string",
          "No annotations on MCP tools and no read-only mode",
          "Four advisories in 2026, including MCP REPL remote code execution",
          "The MCP server needs the Penpot plugin open in a browser tab, so it can't run headless",
          "No status page, published rate limits or webhook documentation"
        ],
        "agentNotes": [
          "Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down",
          "Ask for JSON with `Accept: application/json`, since some commands default to Transit",
          "Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do",
          "Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls",
          "Give tokens an expiry. They carry full account access"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 43.5
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 76,
          "payments": 30,
          "reliability": 46,
          "schema": 66,
          "security": 33,
          "transparency": 61
        },
        "provenanceScore": 70
      },
      "connect": {
        "http": "curl -H \"Authorization: Token $PENPOT_TOKEN\" https://design.penpot.app/api/rpc/command/get-profile",
        "claudeCode": "claude mcp add --transport http penpot \"https://design.penpot.app/mcp/stream?userToken=$PENPOT_MCP_KEY\"",
        "config": {
          "mcpServers": {
            "penpot": {
              "url": "https://design.penpot.app/mcp/stream?userToken=${PENPOT_MCP_KEY}"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.files",
        "tool": "https://letme.dev/penpot"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Unlimited plan",
          "unit": "seat-month",
          "usd": 7,
          "note": "per editor, capped at $175 a month"
        },
        {
          "item": "Enterprise plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "minimum $950 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Kaleidos Subsidiary SL",
        "domain": "penpot.app",
        "domainRegistered": "2020-05-26",
        "domainNote": "The site footer names KALEIDOS Subsidiary SL; Penpot is built by Kaleidos in Madrid.",
        "endpointOnVendorDomain": true,
        "terms": "https://penpot.app/terms",
        "privacy": "https://penpot.app/privacy",
        "statusPage": "",
        "changelog": "https://github.com/penpot/penpot/blob/develop/CHANGES.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 70
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/penpot.json",
      "live": {
        "slug": "penpot",
        "probe": {
          "target": "https://design.penpot.app/api/rpc/command",
          "method": "get",
          "lastAt": "2026-10-08T19:08:55.46809748Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 81,
          "authRequired": false,
          "uptime24h": 99.26,
          "uptime30d": 99.91,
          "p50ms24h": 76,
          "p95ms24h": 159,
          "samples24h": 272,
          "samples30d": 2135,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 217,
              "ok": 215
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "penpot/penpot",
            "version": "2.18.3",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:25:04.847886147Z"
          },
          {
            "registry": "npm",
            "name": "@penpot/mcp",
            "version": "2.15.4",
            "seenAt": "2026-10-08T16:25:03.845868588Z"
          }
        ],
        "githubStars": 60819,
        "npmWeekly": 1325,
        "securityTxt": {
          "url": "https://penpot.app/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:42.635545118Z"
        },
        "domain": {
          "domain": "penpot.app",
          "registered": "2020-05-26",
          "source": "https://pubapi.registry.google/rdap/domain/penpot.app",
          "checkedAt": "2026-10-04T13:04:30.014939182Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/penpot/penpot/develop/CHANGES.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:37.830244856Z",
            "changedAt": "2026-10-07T18:09:22.72857124Z",
            "fingerprint": "d7de8bf8741b"
          },
          {
            "url": "https://penpot.app/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:53.270246884Z",
            "changedAt": "2026-10-08T18:22:53.270246884Z",
            "fingerprint": "fac322cd664f"
          },
          {
            "url": "https://penpot.app/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:55.558773603Z",
            "changedAt": "2026-10-08T18:22:55.558773603Z",
            "fingerprint": "435ffd85741d"
          },
          {
            "url": "https://penpot.app/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:57.540300931Z",
            "changedAt": "2026-10-08T18:22:57.540300931Z",
            "fingerprint": "e07ca8b29548"
          }
        ],
        "updatedAt": "2026-10-08T19:08:55.46809748Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Melius AI, Inc.",
        "b": "Penpot (Kaleidos)",
        "name": "Vendor"
      },
      {
        "a": "https://api.melius.com/api/v1",
        "b": "https://design.penpot.app/api/rpc/command",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "Token",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository found",
        "b": "MPL-2.0",
        "name": "Licence"
      },
      {
        "a": "75",
        "b": "5",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-10",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2025-08-05",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2025-08-05",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "9 npm/wk",
        "b": "61k stars, 1.3k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Melius or Penpot API + MCP?"
      },
      {
        "answer": "Melius takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.",
        "question": "Do Melius and Penpot API + MCP need an API key?"
      },
      {
        "answer": "Yes. Melius has a hosted endpoint at https://api.melius.com/api/v1 and Penpot API + MCP at https://design.penpot.app/api/rpc/command.",
        "question": "Can an agent call Melius and Penpot API + MCP without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Melius. Penpot API + MCP is open source (MPL-2.0).",
        "question": "Are Melius and Penpot API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 69 against 46",
          "Agent ergonomics, 51 against 41",
          "Security \u0026 auth, 43 against 33"
        ],
        "also": [
          "No incidents deducted, where Penpot API + MCP loses 5 points for them"
        ],
        "goodFor": "An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.",
        "slug": "melius",
        "watchFor": "API keys have no scopes. A key works with its creator's role in every team the creator belongs to"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 30 against 20",
          "Maintenance \u0026 community, 76 against 66",
          "Transparency \u0026 trust, 66 against 55"
        ],
        "also": [
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "Teams that want design files on their own servers and an agent working alongside a person in the editor.",
        "slug": "penpot",
        "watchFor": "Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string"
      }
    ],
    "job": {
      "capability": "design.canvas",
      "name": "Design canvas"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-melius.json",
        "title": "Figma API + MCP vs Melius",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-melius"
      },
      {
        "json": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.json",
        "title": "Figma API + MCP vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/figma-mcp-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-melius.json",
        "title": "Framer Server API vs Melius",
        "url": "https://www.anchorterminal.com/compare/framer-vs-melius"
      },
      {
        "json": "https://www.anchorterminal.com/compare/framer-vs-penpot.json",
        "title": "Framer Server API vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/framer-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/miro-vs-penpot.json",
        "title": "Miro API + MCP vs Penpot API + MCP",
        "url": "https://www.anchorterminal.com/compare/miro-vs-penpot"
      },
      {
        "json": "https://www.anchorterminal.com/compare/melius-vs-miro.json",
        "title": "Melius vs Miro API + MCP",
        "url": "https://www.anchorterminal.com/compare/melius-vs-miro"
      }
    ],
    "scores": [
      {
        "by": 23,
        "edge": "melius",
        "key": "reliability",
        "melius": 69,
        "name": "Reliability",
        "penpot": 46,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "melius",
        "key": "schema",
        "melius": 70,
        "name": "Schema \u0026 documentation",
        "penpot": 66,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "melius",
        "key": "ergonomics",
        "melius": 51,
        "name": "Agent ergonomics",
        "penpot": 41,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "melius",
        "key": "security",
        "melius": 43,
        "name": "Security \u0026 auth",
        "penpot": 33,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "penpot",
        "key": "payments",
        "melius": 20,
        "name": "Payments \u0026 pricing",
        "penpot": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "penpot",
        "key": "maintenance",
        "melius": 66,
        "name": "Maintenance \u0026 community",
        "penpot": 76,
        "weight": 7
      },
      {
        "by": 11,
        "edge": "penpot",
        "key": "transparency",
        "melius": 55,
        "name": "Transparency \u0026 trust",
        "penpot": 66,
        "weight": 7
      }
    ],
    "summary": "Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do design canvas.",
    "verdicts": {
      "melius": "One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.",
      "penpot": "MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/melius-vs-penpot",
    "json": "https://www.anchorterminal.com/compare/melius-vs-penpot.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/melius-vs-penpot.md",
    "slim": "https://www.anchorterminal.com/compare/melius-vs-penpot.min.md"
  },
  "markdown": "Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do design canvas.\n\n- Melius: grade C, 54.1/100, rank #473 of 629. Markdown https://www.anchorterminal.com/tools/melius.md · JSON https://www.anchorterminal.com/api/v1/tools/melius.json\n- Penpot API + MCP: grade E, 43.5/100, rank #581 of 629. Markdown https://www.anchorterminal.com/tools/penpot.md · JSON https://www.anchorterminal.com/api/v1/tools/penpot.json\n\n## Which one, for what\n\n### Melius (C)\n\nGood for: An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.\n\nAhead on:\n- Reliability, 69 against 46\n- Agent ergonomics, 51 against 41\n- Security \u0026 auth, 43 against 33\n\nAlso in its favour:\n- No incidents deducted, where Penpot API + MCP loses 5 points for them\n\nWatch for: API keys have no scopes. A key works with its creator's role in every team the creator belongs to\n\n### Penpot API + MCP (E)\n\nGood for: Teams that want design files on their own servers and an agent working alongside a person in the editor.\n\nAhead on:\n- Payments \u0026 pricing, 30 against 20\n- Maintenance \u0026 community, 76 against 66\n- Transparency \u0026 trust, 66 against 55\n\nAlso in its favour:\n- Free to start without a card\n- Open source\n\nWatch for: Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string\n\n\n## Score by category\n\n| Category | Weight | Melius | Penpot API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 69 | 46 | Melius +23 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 66 | Melius +4 |\n| Agent ergonomics | 13% (16.2 this run) | 51 | 41 | Melius +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 43 | 33 | Melius +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 30 | Penpot API + MCP +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 66 | 76 | Penpot API + MCP +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 55 | 66 | Penpot API + MCP +11 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **54.1 · C** | **43.5 · E** | |\n\n## Facts side by side\n\n| Fact | Melius | Penpot API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Melius AI, Inc. | Penpot (Kaleidos) |\n| Hosted endpoint | `https://api.melius.com/api/v1` | `https://design.penpot.app/api/rpc/command` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | Token |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository found | MPL-2.0 |\n| Tools exposed | 75 | 5 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-09-10 | 2026-10-01 |\n| Terms last updated | no date given | 2025-08-05 |\n| Privacy policy last updated | no date given | 2025-08-05 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | yes |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 9 npm/wk | 61k stars, 1.3k npm/wk |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**Melius.** One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.\n\n**Penpot API + MCP.** MPL-2.0 and self-hostable, with API, webhooks and MCP on the free cloud plan. Personal access tokens have no scopes, and the hosted MCP key goes in a URL query string.\n\n## Before you call either\n\n### Melius\n\n1. Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until `status` is finished or failed\n2. Over MCP, call `get_guide` first, `show_presence` before node changes and `canvas_plan_layout` before `bulk_create_nodes`\n3. On 429 wait `Retry-After` seconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys\n4. Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits\n5. Downloads arrive as a ZIP from a signed URL. Fetch that URL without the `Authorization` header\n\n### Penpot API + MCP\n\n1. Call `get-profile` first to check the token, then `get-teams`, `get-projects` and `get-file` to walk down\n2. Ask for JSON with `Accept: application/json`, since some commands default to Transit\n3. Call `high_level_overview` and `penpot_api_info` before `execute_code`. They tell the model what the plugin API can do\n4. Keep the Penpot tab in the foreground. A backgrounded or frozen tab stalls MCP calls\n5. Give tokens an expiry. They carry full account access\n\n## Questions\n\n### Which is better for AI agents, Melius or Penpot API + MCP?\n\nMelius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do Melius and Penpot API + MCP need an API key?\n\nMelius takes an API key or an OAuth sign-in. Penpot API + MCP needs an access token.\n\n### Can an agent call Melius and Penpot API + MCP without installing anything?\n\nYes. Melius has a hosted endpoint at https://api.melius.com/api/v1 and Penpot API + MCP at https://design.penpot.app/api/rpc/command.\n\n### Are Melius and Penpot API + MCP open source?\n\nNo open-source release is listed for Melius. Penpot API + MCP is open source (MPL-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/melius-vs-penpot.json, and with the fewest tokens: https://www.anchorterminal.com/compare/melius-vs-penpot.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"melius\", \"b\": \"penpot\"}`. From a terminal: `anchor compare melius penpot`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/melius.json and https://www.anchorterminal.com/api/v1/tools/penpot.json\n\n## Other comparisons with Melius or Penpot API + MCP\n\n- [Figma API + MCP vs Melius](https://www.anchorterminal.com/compare/figma-mcp-vs-melius.md)\n- [Figma API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/figma-mcp-vs-penpot.md)\n- [Framer Server API vs Melius](https://www.anchorterminal.com/compare/framer-vs-melius.md)\n- [Framer Server API vs Penpot API + MCP](https://www.anchorterminal.com/compare/framer-vs-penpot.md)\n- [Miro API + MCP vs Penpot API + MCP](https://www.anchorterminal.com/compare/miro-vs-penpot.md)\n- [Melius vs Miro API + MCP](https://www.anchorterminal.com/compare/melius-vs-miro.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Melius vs Penpot API + MCP",
        "url": ""
      }
    ],
    "description": "Melius scores 54.1 (C) on agent readiness against Penpot API + MCP's 43.5 (E), and leads in 4 of 7 scored categories. Penpot API + MCP leads on payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do design canvas. Category scores, facts, verdicts and agent…",
    "facts": [
      "Melius C 54.1",
      "Penpot API + MCP E 43.5",
      "scores"
    ],
    "h1": "Melius vs Penpot API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-melius-vs-penpot.png",
    "path": "/compare/melius-vs-penpot",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Melius vs Penpot API + MCP for AI agents, C 54.1 vs E 43.5",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/melius-vs-penpot"
  },
  "tokens": {
    "markdown": 2000,
    "slim": 680
  },
  "version": 1
}
