Head to head · Tasks create · October 2026 research run
OpenProject vs Shortcut
Shortcut scores 60.2 (C) on agent readiness against OpenProject's 57.4 (C), and leads in 1 of 7 scored categories. OpenProject leads on agent ergonomics, security & auth and transparency & trust. Both do tasks create.
Which one, for what
Good for Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.
Ahead on
- Agent ergonomics, 70 against 57
- Security & auth, 59 against 54
- Transparency & trust, 87 against 73
Also in its favour
- Open source
Watch for
83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection
Shortcut C
Good for Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.
Ahead on
- Reliability, 64 against 52
Also in its favour
- A hosted endpoint, with nothing to install
- Free to start without a card
- No incidents deducted, where OpenProject loses 5 points for them
Watch for
The v3 docs still allow the API token as a token query parameter, marked deprecated with no removal date
Score by category
| Category | Weight this run | OpenProject | Shortcut | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 52 | 64 | Shortcut +12 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 76 | 75 | OpenProject +1 |
| Agent ergonomics | 13%16.2 | 70 | 57 | OpenProject +13 |
| Security & auth | 14%17.5 | 59 | 54 | OpenProject +5 |
| Payments & pricing | 10%12.5 | 30 | 30 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 75 | 73 | OpenProject +2 |
| Transparency & trust | 7%8.8 | 87 | 73 | OpenProject +14 |
| Negative events | ≤15 | -5 | 0 | |
| Total | 57.4 · C | 60.2 · C |
Facts side by side
| Fact | OpenProject | Shortcut |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | OpenProject GmbH | Shortcut Software Company |
| Hosted endpoint | no (local only) | https://api.app.shortcut.com |
| Transports | HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service | Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT |
| Read-only variant documented | no | yes |
| llms.txt | no | yes |
| Last release | 2026-10-01 | 2026-09-22 |
| Terms last updated | 2026-08-06 | 2025-09-18 |
| Privacy policy last updated | no date given | 2025-07-11 |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | not found in the text | not found in the text |
| Terms restrict benchmarking | not found in the text | not found in the text |
| Terms or service can change without notice | not found in the text | not found in the text |
| Arbitration or class-action waiver | not found in the text | not found in the text |
| Popularity | 16k stars | 142 stars, 103k npm/wk |
Verdicts
OpenProject
OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.
Shortcut
REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.
Before you call either
OpenProject
- Send the API token as
Authorization: Bearer <token>, or as the Basic auth password with the user nameapikey - Read the resource first and send its current
lockVersionwith every PATCH. A stale value returns 409UpdateConflict - POST to the
/formendpoint of a work package to learn writable fields and allowed values before creating or updating - URL-encode
filtersas a JSON array, and addpageSize,offsetandselectto keep work package lists small - Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input
Shortcut
- Send the v3 token in the
Shortcut-Tokenheader. v4 (alpha) takesAuthorization: Bearerwithsct_ro_orsct_rw_tokens, and v3 tokens don't work there. - Create a story with
nameandworkflow_state_id. Sending bothworkflow_state_idandproject_id, or neither, is rejected. - Use
GET /api/v3/search/storieswithdetail=slim,page_size(1 to 250) and thenexttoken. Many other v3 list endpoints return every record at once. - Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.
- For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as
readorstory-write.
Questions
Which is better for AI agents, OpenProject or Shortcut?
Shortcut scores 60.2 (C) on agent readiness against OpenProject's 57.4 (C), and leads in 1 of 7 scored categories. OpenProject leads on agent ergonomics, security & auth and transparency & trust.
Do OpenProject and Shortcut need an API key?
Both take an API key or an OAuth sign-in.
Can an agent call OpenProject and Shortcut without installing anything?
No hosted endpoint is listed for OpenProject. Shortcut has a hosted endpoint at https://api.app.shortcut.com.
Are OpenProject and Shortcut open source?
OpenProject is open source (GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service). No open-source release is listed for Shortcut.
Other comparisons with OpenProject or Shortcut
- Asana vs OpenProject
- Asana vs Shortcut
- Basecamp vs OpenProject
- Basecamp vs Shortcut
- ClickUp vs OpenProject
- ClickUp vs Shortcut
- monday.com vs OpenProject
- monday.com vs Shortcut
- OpenProject vs Plane
- OpenProject vs Roma
- OpenProject vs Taiga
- OpenProject vs Teamwork.com
- OpenProject vs Todoist
- OpenProject vs Trello
- OpenProject vs Wrike
- OpenProject vs YouTrack
- Plane vs Shortcut
- Roma vs Shortcut
- Shortcut vs Taiga
- Shortcut vs Teamwork.com
- Shortcut vs Todoist
- Shortcut vs Trello
- Shortcut vs Wrike
- Shortcut vs YouTrack
Machine-readable
- This page as Markdown
/compare/openproject-vs-shortcut.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/openproject.json·/api/v1/tools/shortcut.json - From a terminal
anchor compare openproject shortcut(the CLI) - Over MCP
compare_tools {"a": "openproject", "b": "shortcut"}at/mcp, no key