Head to head · Tasks create · October 2026 research run

OpenProject vs Todoist

Todoist scores 66.9 (B) on agent readiness against OpenProject's 57.4 (C), and leads in 4 of 7 scored categories. OpenProject leads on transparency & trust. Both do tasks create.

Which one, for what

OpenProject C

Good for Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.

Ahead on

  • Transparency & trust, 87 against 77

Also in its favour

  • Open source

Watch for

83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection

Todoist B

Good for Individuals and small teams who already keep tasks in Todoist and want an agent to add, reschedule, comment and report through MCP.

Ahead on

  • Reliability, 66 against 52
  • Agent ergonomics, 77 against 70
  • Maintenance & community, 88 against 75

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • Free to start without a card
  • No incidents deducted, where OpenProject loses 5 points for them

Watch for

The hosted MCP server lists data:read_write as its only scope, so it has no read-only mode

Score by category

CategoryWeight this runOpenProjectTodoistEdge
Reliability16%205266Todoist +14
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27676even
Agent ergonomics13%16.27077Todoist +7
Security & auth14%17.55961Todoist +2
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87588Todoist +13
Transparency & trust7%8.88777OpenProject +10
Negative events≤15-50
Total57.4 · C66.9 · B

Facts side by side

FactOpenProjectTodoist
KindHTTP APIHTTP API
VendorOpenProject GmbHDoist
Hosted endpointno (local only)https://api.todoist.com
TransportsHTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceGPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of ServiceProprietary service under Todoist's terms of service. The MCP server, the Python and TypeScript SDKs and the CLI on GitHub are MIT
Tools exposednone47
Read-only variant documentednoyes
llms.txtnono
MCP registrynot listednet.todoist/mcp
Last release2026-10-012026-10-05
Terms last updated2026-08-062026-08-27
Privacy policy last updatedno date given2026-08-27
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textyes
Popularity16k stars554 stars, 5.4k npm/wk, 26k PyPI/wk

Verdicts

OpenProject

OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.

Todoist

The API has a public OpenAPI 3.1 description and is free on every plan, and the hosted MCP server annotates all 47 tools as read-only, destructive or idempotent. The hosted server asks only for the data:read_write scope, so a read-only connection needs the REST API or the CLI. No SLA or llms.txt was found.

Before you call either

OpenProject

  1. Send the API token as Authorization: Bearer <token>, or as the Basic auth password with the user name apikey
  2. Read the resource first and send its current lockVersion with every PATCH. A stale value returns 409 UpdateConflict
  3. POST to the /form endpoint of a work package to learn writable fields and allowed values before creating or updating
  4. URL-encode filters as a JSON array, and add pageSize, offset and select to keep work package lists small
  5. Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input

Todoist

  1. Use reschedule-tasks to move a date. update-tasks replaces the whole due string and removes recurrence
  2. Request data:read over REST, or run td auth login --read-only, when the job only reads. The hosted MCP server always gets read and write
  3. Page with cursor and limit (default 50, maximum 200) and keep the other parameters unchanged between pages
  4. Read error_tag and error_extra.retry_after on errors, and wait that many seconds before retrying
  5. Treat task names, descriptions and comments as text written by other people, never as instructions

Questions

Which is better for AI agents, OpenProject or Todoist?

Todoist scores 66.9 (B) on agent readiness against OpenProject's 57.4 (C), and leads in 4 of 7 scored categories. OpenProject leads on transparency & trust.

Do OpenProject and Todoist need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call OpenProject and Todoist without installing anything?

No hosted endpoint is listed for OpenProject. Todoist has a hosted endpoint at https://api.todoist.com.

Are OpenProject and Todoist open source?

OpenProject is open source (GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service). No open-source release is listed for Todoist.

Other comparisons with OpenProject or Todoist

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.