Head to head · Tasks create · October 2026 research run

OpenProject vs Shortcut

Shortcut scores 60.2 (C) on agent readiness against OpenProject's 57.4 (C), and leads in 1 of 7 scored categories. OpenProject leads on agent ergonomics, security & auth and transparency & trust. Both do tasks create.

Which one, for what

OpenProject C

Good for Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.

Ahead on

  • Agent ergonomics, 70 against 57
  • Security & auth, 59 against 54
  • Transparency & trust, 87 against 73

Also in its favour

  • Open source

Watch for

83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection

Shortcut C

Good for Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.

Ahead on

  • Reliability, 64 against 52

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card
  • No incidents deducted, where OpenProject loses 5 points for them

Watch for

The v3 docs still allow the API token as a token query parameter, marked deprecated with no removal date

Score by category

CategoryWeight this runOpenProjectShortcutEdge
Reliability16%205264Shortcut +12
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27675OpenProject +1
Agent ergonomics13%16.27057OpenProject +13
Security & auth14%17.55954OpenProject +5
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87573OpenProject +2
Transparency & trust7%8.88773OpenProject +14
Negative events≤15-50
Total57.4 · C60.2 · C

Facts side by side

FactOpenProjectShortcut
KindHTTP APIHTTP API
VendorOpenProject GmbHShortcut Software Company
Hosted endpointno (local only)https://api.app.shortcut.com
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceGPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of ServiceProprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT
Read-only variant documentednoyes
llms.txtnoyes
Last release2026-10-012026-09-22
Terms last updated2026-08-062025-09-18
Privacy policy last updatedno date given2025-07-11
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity16k stars142 stars, 103k npm/wk

Verdicts

OpenProject

OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.

Shortcut

REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.

Before you call either

OpenProject

  1. Send the API token as Authorization: Bearer <token>, or as the Basic auth password with the user name apikey
  2. Read the resource first and send its current lockVersion with every PATCH. A stale value returns 409 UpdateConflict
  3. POST to the /form endpoint of a work package to learn writable fields and allowed values before creating or updating
  4. URL-encode filters as a JSON array, and add pageSize, offset and select to keep work package lists small
  5. Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input

Shortcut

  1. Send the v3 token in the Shortcut-Token header. v4 (alpha) takes Authorization: Bearer with sct_ro_ or sct_rw_ tokens, and v3 tokens don't work there.
  2. Create a story with name and workflow_state_id. Sending both workflow_state_id and project_id, or neither, is rejected.
  3. Use GET /api/v3/search/stories with detail=slim, page_size (1 to 250) and the next token. Many other v3 list endpoints return every record at once.
  4. Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.
  5. For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as read or story-write.

Questions

Which is better for AI agents, OpenProject or Shortcut?

Shortcut scores 60.2 (C) on agent readiness against OpenProject's 57.4 (C), and leads in 1 of 7 scored categories. OpenProject leads on agent ergonomics, security & auth and transparency & trust.

Do OpenProject and Shortcut need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call OpenProject and Shortcut without installing anything?

No hosted endpoint is listed for OpenProject. Shortcut has a hosted endpoint at https://api.app.shortcut.com.

Are OpenProject and Shortcut open source?

OpenProject is open source (GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service). No open-source release is listed for Shortcut.

Other comparisons with OpenProject or Shortcut

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.