Head to head · Tasks create · October 2026 research run

Shortcut vs YouTrack

Shortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security & auth and transparency & trust. Both do tasks create.

Which one, for what

Shortcut C

Good for Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.

Ahead on

  • Reliability, 64 against 30
  • Maintenance & community, 73 against 64

Also in its favour

  • A hosted endpoint, with nothing to install
  • Free to start without a card
  • No incidents deducted, where YouTrack loses 5 points for them

Watch for

The v3 docs still allow the API token as a token query parameter, marked deprecated with no removal date

YouTrack D

Good for Software teams that already run YouTrack and want an agent to search, file and update issues, comment, log time and maintain knowledge base articles under each user's permissions.

Ahead on

  • Security & auth, 67 against 54
  • Transparency & trust, 82 against 73

Watch for

No rate limits, 429 handling, idempotency keys or error reference found in the reviewed documentation

Score by category

CategoryWeight this runShortcutYouTrackEdge
Reliability16%206430Shortcut +34
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27572Shortcut +3
Agent ergonomics13%16.25755Shortcut +2
Security & auth14%17.55467YouTrack +13
Payments & pricing10%12.53030even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87364Shortcut +9
Transparency & trust7%8.87382YouTrack +9
Negative events≤150-5
Total60.2 · C49.9 · D

Facts side by side

FactShortcutYouTrack
KindHTTP APIHTTP API
VendorShortcut Software CompanyJetBrains s.r.o.
Hosted endpointhttps://api.app.shortcut.comno (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MITProprietary service under the JetBrains YouTrack Cloud Terms of Service. YouTrack Server is licensed separately for self-hosting
Tools exposednone23
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-09-222026-10-05
Terms last updated2025-09-182024-08-14
Privacy policy last updated2025-07-112026-06-12
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity142 stars, 103k npm/wknone

Verdicts

Shortcut

REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.

YouTrack

Every instance serves an OpenAPI 3.0 document, a 23-tool MCP server with OAuth and PKCE, and field selection on each REST call, and the free plan covers ten users. No rate limits, 429 handling, error reference or SLA were found, and JetBrains disclosed two sets of critical vulnerabilities affecting YouTrack Cloud in 2026, both patched.

Before you call either

Shortcut

  1. Send the v3 token in the Shortcut-Token header. v4 (alpha) takes Authorization: Bearer with sct_ro_ or sct_rw_ tokens, and v3 tokens don't work there.
  2. Create a story with name and workflow_state_id. Sending both workflow_state_id and project_id, or neither, is rejected.
  3. Use GET /api/v3/search/stories with detail=slim, page_size (1 to 250) and the next token. Many other v3 list endpoints return every record at once.
  4. Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.
  5. For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as read or story-write.

YouTrack

  1. Send fields on every REST request. Without it the server returns only the database ID and $type of each entity
  2. Page collections with $top and $skip. Most resources return 42 items by default
  3. Call get_issue_fields_schema before create_issue or update_issue, because required custom fields differ by project
  4. Connect MCP clients to https://<instance>.youtrack.cloud/mcp. OAuth needs an administrator to enable CIMD or register the client, since Dynamic Client Registration is not supported
  5. Create permanent tokens with the YouTrack scope only, and add ?tools= to the MCP URL to limit the tools listed

Questions

Which is better for AI agents, Shortcut or YouTrack?

Shortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security & auth and transparency & trust.

Do Shortcut and YouTrack need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shortcut and YouTrack without installing anything?

Shortcut has a hosted endpoint at https://api.app.shortcut.com. No hosted endpoint is listed for YouTrack.

Other comparisons with Shortcut or YouTrack

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.