{
  "data": {
    "a": {
      "slug": "microsoft-teams",
      "name": "Microsoft Teams (Microsoft Graph)",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/graph/teams-concept-overview",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Microsoft Graph endpoints for Microsoft Teams. An app lists teams, channels and chats, reads and sends messages, manages members and receives change notifications over REST, with OAuth tokens from Microsoft Entra ID for work or school accounts.",
      "url": "https://www.anchorterminal.com/tools/microsoft-teams",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-teams.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-teams.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-teams.json",
      "repo": "https://github.com/microsoftgraph/msgraph-sdk-javascript",
      "license": "MIT (SDKs)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0",
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/microsoft-graph-client"
        },
        {
          "registry": "pypi",
          "name": "msgraph-sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Work or school accounts only. Every Teams reference page we read marks personal Microsoft accounts as not supported. Delegated permissions such as `Chat.Read`, `ChatMessage.Send` and `ChannelMessage.Send` need only the user's consent, while delegated `ChannelMessage.Read.All` and all tenant-wide application permissions need admin consent. Application permissions can send messages only for migration. Resource-specific consent lets a team or chat owner grant an installed app access to that one team or chat.",
      "pricing": "byo-plan",
      "pricingNotes": "Teams calls aren't charged. Microsoft stopped metering the Teams APIs on 25 August 2025 and no billing setup is needed (https://learn.microsoft.com/en-us/graph/metered-api-list). The tenant needs Microsoft 365 or Teams licences, and Microsoft's plan price page answered our request with a block page on 8 October 2026, so licence prices are unread. No free route for personal accounts was found. The Microsoft 365 developer programme sandbox, with Teams and 25 user licences, is free only to members who qualify. The Teams MCP server needs a Microsoft 365 Copilot licence.",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Teams reference or the metered API list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 25,
      "popularity": {
        "githubStars": 835,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/teams-api-overview",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "openapi",
        "webhooks",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.2,
        "grade": "B",
        "agentReady": false,
        "rank": 399,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 59,
          "maintenance": 76,
          "payments": 20,
          "reliability": 67,
          "schema": 92,
          "security": 71,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version bumped to 3.0.8, but on 8 October 2026 npm still serves 3.0.7 from September 2023 and the repository's advisory list is empty. Exploiting it needs an attacker-influenced URL passed to the client (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
        ],
        "verdict": "Permissions separate sending from reading, and resource-specific consent limits an app to one team or chat. Throttling limits are published per endpoint. Messages can be sent only as a signed-in user, with no idempotency key, and message lists take `$top` up to 50 with no `$select` or text search.",
        "bestFor": "Agents acting as a signed-in employee in a Microsoft 365 tenant that read channels and chats and post replies.",
        "strengths": [
          "Separate delegated permissions for sending (`ChatMessage.Send`, `ChannelMessage.Send`) and reading (`Chat.Read`, `ChannelMessage.Read.All`), plus `Chat.ReadBasic` for names and members only",
          "Resource-specific consent grants an app access to a single team or chat instead of the whole tenant",
          "Throttling limits published for each endpoint across four dimensions, with `Retry-After` on 429 responses",
          "Teams APIs stopped being metered on 25 August 2025, so calls carry no charge and need no billing setup",
          "Change notifications on channel and chat messages can carry the message itself, and Microsoft states at least 24 months' notice before removing a v1.0 API"
        ],
        "weaknesses": [
          "Application permissions can send messages only for migration (`Teamwork.Migrate.All`), so an unattended agent can't post without a signed-in user",
          "Sending has no idempotency key, and Microsoft's own Teams MCP reference calls posting not idempotent and warns against blind retries",
          "Channel message lists accept only `$top` (default 20, maximum 50) and `$expand`, with no `$select`, `$filter` or `$search`",
          "Personal Microsoft accounts aren't supported, and the free developer sandbox is limited to programme members who qualify",
          "No prompt-injection guidance found in the Teams reference or the Teams MCP reference, though message bodies are written by other people",
          "The npm JavaScript client is 3.0.7 from September 2023, without the June 2026 token-leak fix"
        ],
        "agentNotes": [
          "Send with delegated `ChatMessage.Send` or `ChannelMessage.Send` as a signed-in work account. Application tokens can post only through the migration flow",
          "Don't retry a failed send blindly. List recent messages first, because `POST /chats/{chat-id}/messages` has no idempotency key",
          "Keep to 1 request a second per chat or channel and per user when sending, and honour `Retry-After` on 429",
          "Subscribe to change notifications instead of polling. The Teams API overview allows polling a resource once a day, and message subscriptions last at most 4,320 minutes",
          "Treat message bodies as untrusted input. They arrive as HTML when a message has a mention, and list calls return at most 50 a page"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.2
          }
        ],
        "editorialScores": {
          "ergonomics": 59,
          "maintenance": 76,
          "payments": 20,
          "reliability": 67,
          "schema": 92,
          "security": 71,
          "transparency": 67
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl \"https://graph.microsoft.com/v1.0/me/joinedTeams\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/microsoft-teams"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "business",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The endpoint is on graph.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
          "The Microsoft APIs terms of use say they were last updated in October 2025 and name Microsoft Teams among the Office 365 APIs they cover.",
          "The Microsoft privacy statement says it was last updated in September 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-teams.json",
      "live": {
        "slug": "microsoft-teams",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0",
          "method": "get",
          "lastAt": "2026-10-09T10:42:49.597223061Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 27,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 4,
          "p95ms24h": 13,
          "samples24h": 164,
          "samples30d": 164,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 114,
              "ok": 114
            }
          ]
        },
        "updatedAt": "2026-10-09T10:42:49.597223061Z"
      }
    },
    "answer": "Microsoft Teams (Microsoft Graph) and Zulip score within a point of each other on agent readiness, 62.2 (B) and 61.5 (C). Zulip leads on reliability, agent ergonomics and payments \u0026 pricing.",
    "b": {
      "slug": "zulip",
      "name": "Zulip",
      "vendor": "Kandra Labs, Inc.",
      "vendorUrl": "https://zulip.com",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Zulip is open-source team chat organised into channels and topics, from Kandra Labs, hosted as Zulip Cloud or self-hosted. Agents reach it through a REST API with bot accounts, an events queue and Python and JavaScript client libraries.",
      "url": "https://www.anchorterminal.com/tools/zulip",
      "markdownUrl": "https://www.anchorterminal.com/tools/zulip.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zulip.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zulip.json",
      "repo": "https://github.com/zulip/zulip",
      "license": "Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "zulip"
        },
        {
          "registry": "npm",
          "name": "zulip-js"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve. Every user and every bot has one API key, sent with HTTP Basic authentication as the account's email and the key. A member creates a bot under Personal settings, Bots, unless an administrator has restricted bot creation, and copies its key or downloads a `zuliprc` file. Generating a new key invalidates the old one. Keys carry no scopes or expiry. What a key can do follows the account's role (owner, administrator, moderator, member, guest), its channel subscriptions and, for bots, the bot type. No OAuth for API clients. `POST /fetch_api_key` exchanges a user's password for the key.",
      "pricing": "freemium",
      "pricingNotes": "Zulip Cloud Free costs nothing and needs no card, with 10,000 messages of search history and 5 GB of files in total. Standard is $6.67 a user a month billed annually or $8 monthly, and Plus is $10 or $12 with a 10-user minimum (https://zulip.com/plans/). API calls are not charged, and the plan comparison lists REST API custom integrations. A self-hosted server is free, with paid plans from $3.50 a user a month for mobile notifications and support. An agent's owner can start on the Free plan or a demo organisation without a contract.",
      "priceSummary": "$6.67 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API documentation, the OpenAPI file or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 26014,
        "npmWeekly": 7094,
        "pypiWeekly": 157209,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://zulip.com/api/rest",
      "openapi": "https://github.com/zulip/zulip/blob/main/zerver/openapi/zulip.yaml",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "api-key",
        "openapi",
        "python",
        "javascript",
        "webhooks",
        "status-page"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.5,
        "grade": "C",
        "agentReady": false,
        "rank": 422,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 83,
          "schema": 82,
          "security": 42,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-08-10 and 2026-09-21. GHSA-5r8f-gq2h-fcgp let a guest receive new messages from public channels it was not subscribed to by registering an event queue, fixed in 12.2. GHSA-42mq-rxcr-wj72 let a member forge the sender of a group direct message through the API, fixed in 12.3. Both are reachable with an ordinary API key. Fixed and published, so 2 points (https://github.com/zulip/zulip/security/advisories/GHSA-5r8f-gq2h-fcgp, https://github.com/zulip/zulip/security/advisories/GHSA-42mq-rxcr-wj72).",
          "2026-02-05 to 2026-09-21. Eleven further advisories in twelve months across releases 11.5, 11.6, 12.0, 12.2 and 12.3, among them CVE-2026-25742 (attachments still public after web-public access was disabled), CVE-2026-40300 (edit history exposing original content in the API) and GHSA-xw9h-9rcm-hx4m (OpenID Connect ignoring `email_verified`). All fixed and published by the vendor, so 2 points (https://github.com/zulip/zulip/blob/main/docs/overview/changelog.md)."
        ],
        "verdict": "The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published.",
        "bestFor": "A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.",
        "strengths": [
          "Public OpenAPI 3.0 file with 166 operations, all described, and curl, Python and JavaScript examples per endpoint",
          "Every API change is recorded against a numbered feature level that clients read from `GET /server_settings`",
          "status.zulip.com lists no incidents from 11 July to 8 October 2026 and one minor incident in May 2026",
          "Bot accounts come in three types, and an incoming webhook bot can only send messages",
          "The server is Apache 2.0, and the Free cloud plan needs no card"
        ],
        "weaknesses": [
          "One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do",
          "Thirteen security advisories between February and September 2026, among them guests reading unsubscribed public channels and forged senders through the API",
          "`POST /messages` has no idempotency key, so a retried send can post twice",
          "Incoming webhook URLs carry the bot's key in the query string as `api_key`",
          "No SLA, SOC 2 or ISO 27001 statement, security.txt or llms.txt was found"
        ],
        "agentNotes": [
          "Ask the organisation for a bot of the most limited type that fits. Use an incoming webhook bot when the task only posts messages",
          "Authenticate with HTTP Basic, the bot's email as user and its API key as password, against https://\u003corganisation\u003e.zulipchat.com/api/v1",
          "Read `code`, not `msg`, on errors. `msg` is translated into the account's language",
          "On `RATE_LIMIT_HIT` wait the seconds in `retry-after`. The default limit is 200 requests a minute per user",
          "Fetch history with `GET /messages`, a `narrow` filter, an `anchor` and `num_before` or `num_after`, at most 1,000 a batch as the docs recommend"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.5
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 83,
          "schema": 82,
          "security": 42,
          "transparency": 77
        },
        "provenanceScore": 74
      },
      "connect": {
        "install": "pip install zulip",
        "http": "curl -X POST https://your-org.zulipchat.com/api/v1/messages -u EMAIL_ADDRESS:API_KEY --data-urlencode type=stream --data-urlencode 'to=\"Denmark\"' --data-urlencode topic=Castle --data-urlencode 'content=Hello'"
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/zulip"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Zulip Cloud Standard",
          "unit": "seat-month",
          "usd": 6.67,
          "note": "billed annually, $8 billed monthly"
        },
        {
          "item": "Zulip Cloud Plus",
          "unit": "seat-month",
          "usd": 10,
          "note": "billed annually, $12 billed monthly, 10 users minimum"
        },
        {
          "item": "Self-hosted Basic",
          "unit": "seat-month",
          "usd": 3.5,
          "note": "billed monthly, for a server the owner runs"
        },
        {
          "item": "Self-hosted Business",
          "unit": "seat-month",
          "usd": 6.67,
          "note": "billed annually, $8 billed monthly, 25 users minimum"
        }
      ],
      "provenance": {
        "legalEntity": "Kandra Labs, Inc.",
        "domain": "zulip.com",
        "domainRegistered": "2010-12-01",
        "endpointOnVendorDomain": false,
        "terms": "https://zulip.com/policies/terms",
        "privacy": "https://zulip.com/policies/privacy",
        "statusPage": "https://status.zulip.com",
        "changelog": "https://zulip.com/api/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Service (effective 7 February 2022) are a contract with Kandra Labs, Inc., 584 Castro St #3175, San Francisco, CA 94114, and cover the websites, products, services and applications.",
          "Cloud organisations answer at https://\u003corganisation\u003e.zulipchat.com/api/v1, a second domain. zulip.com's own footer links its terms and privacy policy at zulipchat.com, and the OpenAPI file names the host.",
          "https://zulip.com/.well-known/security.txt returns 404. SECURITY.md in the repository gives security@zulip.com and a private HackerOne programme.",
          "The privacy policy is effective 1 January 2022. A Data Processing Addendum is published as a PDF and was not read.",
          "RDAP for zulip.com gives a registration date of 2010-12-01."
        ],
        "score": 74
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/zulip.json",
      "live": {
        "slug": "zulip",
        "vendorStatus": {
          "page": "https://status.zulip.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-09T10:42:10.831592235Z"
        },
        "updatedAt": "2026-10-09T10:42:10.831592235Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Kandra Labs, Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://graph.microsoft.com/v1.0",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Your plan",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT (SDKs)",
        "b": "Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT",
        "name": "Licence"
      },
      {
        "a": "25",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-09-21",
        "name": "Last release"
      },
      {
        "a": "2025-10-01",
        "b": "2022-02-07",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-01",
        "b": "2022-01-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "835 stars, 2.9M npm/wk, 1.6M PyPI/wk",
        "b": "26k stars, 7.1k npm/wk, 157k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Teams (Microsoft Graph) and Zulip score within a point of each other on agent readiness, 62.2 (B) and 61.5 (C). Zulip leads on reliability, agent ergonomics and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Microsoft Teams (Microsoft Graph) or Zulip?"
      },
      {
        "answer": "Microsoft Teams (Microsoft Graph) uses an OAuth sign-in. Zulip needs an API key.",
        "question": "Do Microsoft Teams (Microsoft Graph) and Zulip need an API key?"
      },
      {
        "answer": "Microsoft Teams (Microsoft Graph) has a hosted endpoint at https://graph.microsoft.com/v1.0. No hosted endpoint is listed for Zulip.",
        "question": "Can an agent call Microsoft Teams (Microsoft Graph) and Zulip without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Microsoft Teams (Microsoft Graph). Zulip is open source (Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT).",
        "question": "Are Microsoft Teams (Microsoft Graph) and Zulip open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 92 against 82",
          "Security \u0026 auth, 71 against 42"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agents acting as a signed-in employee in a Microsoft 365 tenant that read channels and chats and post replies.",
        "slug": "microsoft-teams",
        "watchFor": "Application permissions can send messages only for migration (`Teamwork.Migrate.All`), so an unattended agent can't post without a signed-in user"
      },
      {
        "aheadOn": [
          "Reliability, 83 against 67",
          "Agent ergonomics, 68 against 59",
          "Payments \u0026 pricing, 30 against 20"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.",
        "slug": "zulip",
        "watchFor": "One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do"
      }
    ],
    "job": {
      "capability": "work.chat",
      "name": "Work chat"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-teams-vs-slack-mcp.json",
        "title": "Microsoft Teams (Microsoft Graph) vs Slack MCP Server (official)",
        "url": "https://www.anchorterminal.com/compare/microsoft-teams-vs-slack-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/slack-mcp-vs-zulip.json",
        "title": "Slack MCP Server (official) vs Zulip",
        "url": "https://www.anchorterminal.com/compare/slack-mcp-vs-zulip"
      }
    ],
    "scores": [
      {
        "by": 16,
        "edge": "zulip",
        "key": "reliability",
        "microsoft-teams": 67,
        "name": "Reliability",
        "weight": 16,
        "zulip": 83
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "microsoft-teams",
        "key": "schema",
        "microsoft-teams": 92,
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "zulip": 82
      },
      {
        "by": 9,
        "edge": "zulip",
        "key": "ergonomics",
        "microsoft-teams": 59,
        "name": "Agent ergonomics",
        "weight": 13,
        "zulip": 68
      },
      {
        "by": 29,
        "edge": "microsoft-teams",
        "key": "security",
        "microsoft-teams": 71,
        "name": "Security \u0026 auth",
        "weight": 14,
        "zulip": 42
      },
      {
        "by": 10,
        "edge": "zulip",
        "key": "payments",
        "microsoft-teams": 20,
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "zulip": 30
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "zulip",
        "key": "maintenance",
        "microsoft-teams": 76,
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "zulip": 77
      },
      {
        "by": 0,
        "edge": "",
        "key": "transparency",
        "microsoft-teams": 76,
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "zulip": 76
      }
    ],
    "summary": "Microsoft Teams (Microsoft Graph) and Zulip score within a point of each other on agent readiness, 62.2 (B) and 61.5 (C). Zulip leads on reliability, agent ergonomics and payments \u0026 pricing. Both do work chat.",
    "verdicts": {
      "microsoft-teams": "Permissions separate sending from reading, and resource-specific consent limits an app to one team or chat. Throttling limits are published per endpoint. Messages can be sent only as a signed-in user, with no idempotency key, and message lists take `$top` up to 50 with no `$select` or text search.",
      "zulip": "The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip",
    "json": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.min.md"
  },
  "markdown": "Microsoft Teams (Microsoft Graph) and Zulip score within a point of each other on agent readiness, 62.2 (B) and 61.5 (C). Zulip leads on reliability, agent ergonomics and payments \u0026 pricing. Both do work chat.\n\n- Microsoft Teams (Microsoft Graph): grade B, 62.2/100, rank #399 of 842. Markdown https://www.anchorterminal.com/tools/microsoft-teams.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-teams.json\n- Zulip: grade C, 61.5/100, rank #422 of 842. Markdown https://www.anchorterminal.com/tools/zulip.md · JSON https://www.anchorterminal.com/api/v1/tools/zulip.json\n\n## Which one, for what\n\n### Microsoft Teams (Microsoft Graph) (B)\n\nGood for: Agents acting as a signed-in employee in a Microsoft 365 tenant that read channels and chats and post replies.\n\nAhead on:\n- Schema \u0026 documentation, 92 against 82\n- Security \u0026 auth, 71 against 42\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: Application permissions can send messages only for migration (`Teamwork.Migrate.All`), so an unattended agent can't post without a signed-in user\n\n### Zulip (C)\n\nGood for: A team that already talks in Zulip and wants an agent to read channels and topics, post, react and manage users through a bot.\n\nAhead on:\n- Reliability, 83 against 67\n- Agent ergonomics, 68 against 59\n- Payments \u0026 pricing, 30 against 20\n\nAlso in its favour:\n- Open source\n\nWatch for: One API key per account, with no scopes, expiry or OAuth. A generic bot's key does what a normal member can do\n\n\n## Score by category\n\n| Category | Weight | Microsoft Teams (Microsoft Graph) | Zulip | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 67 | 83 | Zulip +16 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 92 | 82 | Microsoft Teams (Microsoft Graph) +10 |\n| Agent ergonomics | 13% (16.2 this run) | 59 | 68 | Zulip +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 42 | Microsoft Teams (Microsoft Graph) +29 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 30 | Zulip +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 77 | Zulip +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 76 | even |\n| Negative events | ≤15 | -4 | -4 | |\n| **Total** | | **62.2 · B** | **61.5 · C** | |\n\n## Facts side by side\n\n| Fact | Microsoft Teams (Microsoft Graph) | Zulip |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Microsoft | Kandra Labs, Inc. |\n| Hosted endpoint | `https://graph.microsoft.com/v1.0` | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | OAuth | API key |\n| Pricing | Your plan | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs) | Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT |\n| Tools exposed | 25 | none |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-06 | 2026-09-21 |\n| Terms last updated | 2025-10-01 | 2022-02-07 |\n| Privacy policy last updated | 2026-09-01 | 2022-01-01 |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 835 stars, 2.9M npm/wk, 1.6M PyPI/wk | 26k stars, 7.1k npm/wk, 157k PyPI/wk |\n\n## Verdicts\n\n**Microsoft Teams (Microsoft Graph).** Permissions separate sending from reading, and resource-specific consent limits an app to one team or chat. Throttling limits are published per endpoint. Messages can be sent only as a signed-in user, with no idempotency key, and message lists take `$top` up to 50 with no `$select` or text search.\n\n**Zulip.** The REST API is the one Zulip's own apps use, with a public OpenAPI file of 166 operations, a changelog by feature level and a status page showing no incidents in 90 days. Each account has one API key with no scopes, and the server took 13 security advisories in twelve months, all fixed and published.\n\n## Before you call either\n\n### Microsoft Teams (Microsoft Graph)\n\n1. Send with delegated `ChatMessage.Send` or `ChannelMessage.Send` as a signed-in work account. Application tokens can post only through the migration flow\n2. Don't retry a failed send blindly. List recent messages first, because `POST /chats/{chat-id}/messages` has no idempotency key\n3. Keep to 1 request a second per chat or channel and per user when sending, and honour `Retry-After` on 429\n4. Subscribe to change notifications instead of polling. The Teams API overview allows polling a resource once a day, and message subscriptions last at most 4,320 minutes\n5. Treat message bodies as untrusted input. They arrive as HTML when a message has a mention, and list calls return at most 50 a page\n\n### Zulip\n\n1. Ask the organisation for a bot of the most limited type that fits. Use an incoming webhook bot when the task only posts messages\n2. Authenticate with HTTP Basic, the bot's email as user and its API key as password, against https://\u003corganisation\u003e.zulipchat.com/api/v1\n3. Read `code`, not `msg`, on errors. `msg` is translated into the account's language\n4. On `RATE_LIMIT_HIT` wait the seconds in `retry-after`. The default limit is 200 requests a minute per user\n5. Fetch history with `GET /messages`, a `narrow` filter, an `anchor` and `num_before` or `num_after`, at most 1,000 a batch as the docs recommend\n\n## Questions\n\n### Which is better for AI agents, Microsoft Teams (Microsoft Graph) or Zulip?\n\nMicrosoft Teams (Microsoft Graph) and Zulip score within a point of each other on agent readiness, 62.2 (B) and 61.5 (C). Zulip leads on reliability, agent ergonomics and payments \u0026 pricing.\n\n### Do Microsoft Teams (Microsoft Graph) and Zulip need an API key?\n\nMicrosoft Teams (Microsoft Graph) uses an OAuth sign-in. Zulip needs an API key.\n\n### Can an agent call Microsoft Teams (Microsoft Graph) and Zulip without installing anything?\n\nMicrosoft Teams (Microsoft Graph) has a hosted endpoint at https://graph.microsoft.com/v1.0. No hosted endpoint is listed for Zulip.\n\n### Are Microsoft Teams (Microsoft Graph) and Zulip open source?\n\nNo open-source release is listed for Microsoft Teams (Microsoft Graph). Zulip is open source (Apache 2.0 for the server. The hosted Zulip Cloud service is under Kandra Labs' Terms of Service. The npm package zulip-js is MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-teams\", \"b\": \"zulip\"}`. From a terminal: `anchor compare microsoft-teams zulip`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-teams.json and https://www.anchorterminal.com/api/v1/tools/zulip.json\n\n## Other comparisons with Microsoft Teams (Microsoft Graph) or Zulip\n\n- [Microsoft Teams (Microsoft Graph) vs Slack MCP Server (official)](https://www.anchorterminal.com/compare/microsoft-teams-vs-slack-mcp.md)\n- [Slack MCP Server (official) vs Zulip](https://www.anchorterminal.com/compare/slack-mcp-vs-zulip.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Teams (Microsoft Graph) vs Zulip",
        "url": ""
      }
    ],
    "description": "Microsoft Teams (Microsoft Graph) and Zulip score within a point of each other on agent readiness, 62.2 (B) and 61.5 (C). Zulip leads on reliability, agent ergonomics and payments \u0026 pricing. Both do work chat. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Teams (Microsoft Graph) B 62.2",
      "Zulip C 61.5",
      "scores"
    ],
    "h1": "Microsoft Teams (Microsoft Graph) vs Zulip",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-teams-vs-zulip.png",
    "path": "/compare/microsoft-teams-vs-zulip",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Teams (Microsoft Graph) vs Zulip for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/microsoft-teams-vs-zulip"
  },
  "tokens": {
    "markdown": 2050,
    "slim": 730
  },
  "version": 1
}
