{
  "data": {
    "a": {
      "slug": "shortcut",
      "name": "Shortcut",
      "vendor": "Shortcut Software Company",
      "vendorUrl": "https://www.shortcut.com",
      "kind": "http-api",
      "category": "project-management",
      "summary": "Shortcut is a hosted project tracker for software teams, with stories, epics, iterations, objectives and docs. Agents reach it through REST API v3 with a personal token, or the hosted MCP server at mcp.shortcut.com/mcp with OAuth.",
      "url": "https://www.anchorterminal.com/tools/shortcut",
      "markdownUrl": "https://www.anchorterminal.com/tools/shortcut.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shortcut.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shortcut.json",
      "repo": "https://github.com/useshortcut/shortcut-client-js",
      "license": "Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.app.shortcut.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@shortcut/client"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Any workspace member creates an API token under Settings, API Tokens, with no app review. REST API v3 takes it in the `Shortcut-Token` header, and tokens can be read-only or read-write since 20 January 2026. An Observer's token can read but not change data. The hosted MCP server at mcp.shortcut.com/mcp takes OAuth only (authorisation code with PKCE, dynamic client registration) with the scopes read, write, story-write, comment-write and admin, and access can be revoked in Shortcut settings. The v4 alpha uses `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens.",
      "pricing": "freemium",
      "pricingNotes": "The API, webhooks and the MCP server are listed on every plan, and Shortcut charges nothing per call. Free is $0 for up to 10 users, Team $8.50 a user a month billed yearly ($10 monthly), Business $12 ($16 monthly), and Enterprise is quoted by sales. A 14-day trial needs no card, so an agent's owner can start on Free or the trial without a contract (checked 2026-10-08).",
      "priceSummary": "$8.50 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI files, llms.txt or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 142,
        "npmWeekly": 102825,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.shortcut.com/api/rest/v3",
      "llmsTxt": "https://www.shortcut.com/llms.txt",
      "openapi": "https://developer.shortcut.com/api/rest/v3/shortcut.openapi.json",
      "capabilities": [
        "tasks.create",
        "tasks.update",
        "projects.manage",
        "tasks.comments",
        "projects.reporting",
        "automation.webhooks"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "freemium",
        "free-tier",
        "no-card",
        "closed-source",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.2,
        "grade": "C",
        "agentReady": false,
        "rank": 411,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 73,
          "payments": 30,
          "reliability": 64,
          "schema": 75,
          "security": 54,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.",
        "bestFor": "Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.",
        "strengths": [
          "REST API v3, webhooks and the MCP server are listed on every plan, Free (up to 10 users) among them, and the 14-day trial needs no card",
          "Swagger 2.0 and OpenAPI 3.0 files for v3 (143 operations) are downloadable, with enums, string limits and required fields",
          "The hosted MCP server uses OAuth with PKCE, dynamic client registration and the scopes read, write, story-write, comment-write and admin",
          "API tokens can be read-only or read-write since 20 January 2026, and Observers' tokens can read but not change data",
          "status.shortcut.com has separate API and Shortcut MCP components with incident history back to 2023"
        ],
        "weaknesses": [
          "The v3 docs still allow the API token as a `token` query parameter, marked deprecated with no removal date",
          "No idempotency keys, Retry-After header or backoff guidance found. The docs state only 200 requests a minute and a 429",
          "No API changelog or deprecation policy found. API changes appear as lines in the product release notes",
          "The open-source MCP server is archived at v0.25.0, and the hosted server's tool list can't be read without a Shortcut account",
          "One official SDK, `@shortcut/client` for JavaScript and TypeScript, and no vendor entry in the official MCP registry"
        ],
        "agentNotes": [
          "Send the v3 token in the `Shortcut-Token` header. v4 (alpha) takes `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens, and v3 tokens don't work there.",
          "Create a story with `name` and `workflow_state_id`. Sending both `workflow_state_id` and `project_id`, or neither, is rejected.",
          "Use `GET /api/v3/search/stories` with `detail=slim`, `page_size` (1 to 250) and the `next` token. Many other v3 list endpoints return every record at once.",
          "Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.",
          "For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as `read` or `story-write`."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.2
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 73,
          "payments": 30,
          "reliability": 64,
          "schema": 75,
          "security": 54,
          "transparency": 57
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "npm install @shortcut/client",
        "http": "curl -X GET -H \"Content-Type: application/json\" -H \"Shortcut-Token: $SHORTCUT_API_TOKEN\" -L \"https://api.app.shortcut.com/api/v3/categories\"",
        "claudeCode": "claude mcp add --transport http shortcut https://mcp.shortcut.com/mcp",
        "config": {
          "mcpServers": {
            "shortcut": {
              "url": "https://mcp.shortcut.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/tasks.create",
        "tool": "https://letme.dev/shortcut"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Free (API, webhooks and MCP server included)",
          "unit": "seat-month",
          "usd": 0,
          "note": "up to 10 users, 5 GB of storage"
        },
        {
          "item": "Team, billed yearly",
          "unit": "seat-month",
          "usd": 8.5,
          "note": "$10 billed monthly, as shown on 2026-10-08"
        },
        {
          "item": "Business, billed yearly",
          "unit": "seat-month",
          "usd": 12,
          "note": "$16 billed monthly, as shown on 2026-10-08"
        }
      ],
      "provenance": {
        "legalEntity": "Shortcut Software Company",
        "domain": "shortcut.com",
        "domainRegistered": "1997-08-01",
        "endpointOnVendorDomain": true,
        "terms": "https://www.shortcut.com/terms/",
        "privacy": "https://www.shortcut.com/privacy/",
        "statusPage": "https://status.shortcut.com",
        "changelog": "https://www.shortcut.com/release-notes/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (effective 18 September 2025) name Shortcut Software Company, govern the Service on shortcut.com and korey.ai, and are under New York law. The GDPR notice gives the address 201 Allen St, Unit #10004, New York, NY 10002.",
          "The privacy policy (effective 11 July 2025) covers the websites, the app and the platform.",
          "The API answers at api.app.shortcut.com and the MCP server at mcp.shortcut.com.",
          "www.shortcut.com/.well-known/security.txt returns 404. Reports go to security@shortcut.com under the disclosure policy at shortcut.com/disclosure.",
          "The changelog link is the product release notes. No separate API changelog was found.",
          "RDAP for shortcut.com gives a registration date of 1997-08-01. Shortcut was named Clubhouse until September 2021 per its llms.txt."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shortcut.json",
      "live": {
        "slug": "shortcut",
        "probe": {
          "target": "https://api.app.shortcut.com",
          "method": "get",
          "lastAt": "2026-10-08T21:12:21.490163068Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 247,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 252,
          "p95ms24h": 306,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shortcut.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:25.985770991Z"
        },
        "updatedAt": "2026-10-08T21:12:21.490163068Z"
      }
    },
    "answer": "Shortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "youtrack",
      "name": "YouTrack",
      "vendor": "JetBrains s.r.o.",
      "vendorUrl": "https://www.jetbrains.com/youtrack/",
      "kind": "http-api",
      "category": "project-management",
      "summary": "YouTrack is JetBrains' issue tracker and project management tool, with a knowledge base, helpdesk and time tracking. Agents reach each YouTrack Cloud or Server instance through its REST API and a built-in remote MCP server at `/mcp`.",
      "url": "https://www.anchorterminal.com/tools/youtrack",
      "markdownUrl": "https://www.anchorterminal.com/tools/youtrack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/youtrack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/youtrack.json",
      "license": "Proprietary service under the JetBrains YouTrack Cloud Terms of Service. YouTrack Server is licensed separately for self-hosting",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve. Each user creates a permanent token in their profile (Account Security) and sends it as a Bearer token. Tokens never expire, can be deleted, and carry one or both of two scopes, YouTrack and YouTrack Administration. OAuth 2.0 comes from the built-in Hub service, with authorisation code and PKCE (S256), client credentials and a deprecated implicit flow. From YouTrack 2026.2 a system administrator registers OAuth clients or enables automatic registration through Client ID Metadata Documents (off by default). Dynamic Client Registration is not supported. Every call acts with the authorising user's permissions. No app review or partner approval is described.",
      "pricing": "freemium",
      "pricingNotes": "The free plan covers up to ten users and three helpdesk agents, with 30 GB of storage, and the REST API is always enabled, so an agent can start without a contract. Paid Cloud subscriptions are priced per user on a sliding scale. JetBrains announced USD 5.40 a user a month on monthly billing and USD 4.50 on annual billing from 1 October 2025, and USD 6 or USD 5.50 per helpdesk agent beyond three. The pricing page served pounds to our network on 2026-10-08 (GBP 4.30 monthly, GBP 43 a year). API and MCP calls are not priced. A 14-day trial covers up to 100 users. No separate sandbox was found (https://www.jetbrains.com/youtrack/buy/, checked 2026-10-08).",
      "priceSummary": "$4.50 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer portal, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 23,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.jetbrains.com/help/youtrack/devportal/youtrack-rest-api.html",
      "llmsTxt": "https://www.jetbrains.com/help/youtrack/devportal/llms.txt",
      "openapi": "https://youtrack.jetbrains.com/api/openapi.json",
      "capabilities": [
        "tasks.create",
        "tasks.update",
        "projects.manage",
        "tasks.comments",
        "work.issues",
        "work.docs"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "freemium",
        "free-tier",
        "status-page",
        "soc2",
        "project-management",
        "issue-tracker"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 49.9,
        "grade": "D",
        "agentReady": false,
        "rank": 601,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 30,
          "reliability": 30,
          "schema": 72,
          "security": 67,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-04-17. CVE-2026-33392, a sandbox bypass allowing code execution by an administrator, reported in March 2026. JetBrains says the impact was greatest in YouTrack Cloud, where it could bypass cross-tenant isolation on shared hardware, that Cloud was mitigated within 48 hours, and that it found no evidence of exploitation. Fixed and disclosed, so 3 of a possible 15 (https://blog.jetbrains.com/youtrack/2026/04/security-issue-in-youtrack-cve-2026-33392/)",
          "2026-06-19. CVE-2026-56141 (admin account takeover through authentication token forgery) and CVE-2026-56142 (email verification bypass), found in May 2026, affected YouTrack Cloud, and CVE-2026-50242 affected Server. JetBrains says Cloud was patched before the post and that it found no evidence of exploitation outside testing. Fixed and disclosed, so 2 points (https://blog.jetbrains.com/youtrack/2026/06/youtrack-security-update-youtrack-server-upgrade-required/)"
        ],
        "verdict": "Every instance serves an OpenAPI 3.0 document, a 23-tool MCP server with OAuth and PKCE, and field selection on each REST call, and the free plan covers ten users. No rate limits, 429 handling, error reference or SLA were found, and JetBrains disclosed two sets of critical vulnerabilities affecting YouTrack Cloud in 2026, both patched.",
        "bestFor": "Software teams that already run YouTrack and want an agent to search, file and update issues, comment, log time and maintain knowledge base articles under each user's permissions.",
        "strengths": [
          "OpenAPI 3.0.1 document at `/api/openapi.json` on every instance, with 281 operations on 157 paths, plus llms.txt and a Markdown copy of each docs page",
          "Built-in remote MCP server at `/mcp` with 23 predefined tools, and `tools` and `ignoreTools` URL parameters that trim the tool list",
          "OAuth 2.0 authorisation code flow with PKCE (S256) and Client ID Metadata Documents, or revocable permanent tokens with two scopes",
          "Free plan for up to ten users and three helpdesk agents, with the REST API always enabled",
          "19 Server builds published between 15 July and 5 October 2026, and a REST API changelog by version"
        ],
        "weaknesses": [
          "No rate limits, 429 handling, idempotency keys or error reference found in the reviewed documentation",
          "The status page shows availability percentages by region for 24 hours and 30 days, with no incident history, and no SLA was found",
          "Two security disclosures in 2026 affected YouTrack Cloud, a cross-tenant isolation bypass (CVE-2026-33392) and an admin account takeover (CVE-2026-56141). Both were patched",
          "Permanent tokens never expire and carry only two coarse scopes, YouTrack and YouTrack Administration",
          "No current official SDK. YouTrackSharp for .NET covers a subset of the API and was last published on 31 March 2023"
        ],
        "agentNotes": [
          "Send `fields` on every REST request. Without it the server returns only the database ID and `$type` of each entity",
          "Page collections with `$top` and `$skip`. Most resources return 42 items by default",
          "Call `get_issue_fields_schema` before `create_issue` or `update_issue`, because required custom fields differ by project",
          "Connect MCP clients to `https://\u003cinstance\u003e.youtrack.cloud/mcp`. OAuth needs an administrator to enable CIMD or register the client, since Dynamic Client Registration is not supported",
          "Create permanent tokens with the YouTrack scope only, and add `?tools=` to the MCP URL to limit the tools listed"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 49.9
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 30,
          "reliability": 30,
          "schema": 72,
          "security": 67,
          "transparency": 65
        },
        "provenanceScore": 98
      },
      "connect": {
        "http": "curl 'https://example.youtrack.cloud/api/users/me?fields=id,login,name' -H 'Accept: application/json' -H \"Authorization: Bearer $YOUTRACK_TOKEN\"",
        "claudeCode": "claude mcp add --header \"Authorization: Bearer \u003ctoken\u003e\" --transport http youtrack \u003cyoutrack-mcp-endpoint-url\u003e"
      },
      "letme": {
        "capability": "https://letme.dev/tasks.create",
        "tool": "https://letme.dev/youtrack"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Free plan (up to 10 users, 3 helpdesk agents)",
          "unit": "seat-month",
          "usd": 0,
          "note": "30 GB storage; REST API and MCP server included"
        },
        {
          "item": "Cloud user, annual billing",
          "unit": "seat-month",
          "usd": 4.5,
          "note": "starting price as announced for 1 October 2025; falls as users are added. Pricing page served GBP on 2026-10-08"
        },
        {
          "item": "Cloud user, monthly billing",
          "unit": "seat-month",
          "usd": 5.4,
          "note": "starting price as announced for 1 October 2025; pricing page showed GBP 4.30 on 2026-10-08"
        },
        {
          "item": "Helpdesk agent beyond three, monthly billing",
          "unit": "seat-month",
          "usd": 6,
          "note": "USD 5.50 on annual billing, as announced for 1 October 2025"
        }
      ],
      "provenance": {
        "legalEntity": "JetBrains s.r.o.",
        "domain": "jetbrains.com",
        "domainRegistered": "2001-11-09",
        "endpointOnVendorDomain": true,
        "terms": "https://www.jetbrains.com/legal/docs/youtrack/youtrack_cloud/",
        "privacy": "https://www.jetbrains.com/legal/docs/privacy/privacy/",
        "statusPage": "https://www.jetbrains.com/youtrack/cloud/status/",
        "changelog": "https://www.jetbrains.com/help/youtrack/devportal/api-changelog.html",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The YouTrack Cloud Terms of Service (version 2.0, effective 14 August 2024) name JetBrains s.r.o., Na Hřebenech II 1718/8, Prague, 14000, Czech Republic, ID No. 265 02 275, and are governed by Czech law.",
          "The JetBrains Privacy Notice (version 3.2, last updated 12 June 2026) covers JetBrains websites, products and services, and the Cloud terms point to it. Customer personal data is processed under the Data Processing Addendum (version 1.3, 27 April 2022).",
          "Cloud instances answer at \u003cinstance\u003e.youtrack.cloud, or \u003cinstance\u003e.myjetbrains.com/youtrack for instances registered before 2 November 2021. RDAP gives youtrack.cloud a registration date of 2021-04-30 through MarkMonitor, and the docs describe both domains as JetBrains'.",
          "www.jetbrains.com/.well-known/security.txt has a Contact line (security@jetbrains.com) and a Policy line pointing to the Coordinated Disclosure Policy, and no Expires field, which RFC 9116 requires.",
          "The status page draws its figures by script from myjetbrains.com/youtrack/youtrack-hosted-master/rest/stat, which we read directly.",
          "RDAP for jetbrains.com gives a registration date of 2001-11-09 and Network Solutions, LLC as registrar."
        ],
        "score": 98
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/youtrack.json",
      "live": {
        "slug": "youtrack",
        "vendorStatus": {
          "page": "https://www.jetbrains.com/youtrack/cloud/status",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:21.794121817Z"
        },
        "updatedAt": "2026-10-08T19:39:21.794121817Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Shortcut Software Company",
        "b": "JetBrains s.r.o.",
        "name": "Vendor"
      },
      {
        "a": "https://api.app.shortcut.com",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT",
        "b": "Proprietary service under the JetBrains YouTrack Cloud Terms of Service. YouTrack Server is licensed separately for self-hosting",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "23",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "2025-09-18",
        "b": "2024-08-14",
        "name": "Terms last updated"
      },
      {
        "a": "2025-07-11",
        "b": "2026-06-12",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "142 stars, 103k npm/wk",
        "b": "none",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Shortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Shortcut or YouTrack?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Shortcut and YouTrack need an API key?"
      },
      {
        "answer": "Shortcut has a hosted endpoint at https://api.app.shortcut.com. No hosted endpoint is listed for YouTrack.",
        "question": "Can an agent call Shortcut and YouTrack without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 64 against 30",
          "Maintenance \u0026 community, 73 against 64"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card",
          "No incidents deducted, where YouTrack loses 5 points for them"
        ],
        "goodFor": "Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.",
        "slug": "shortcut",
        "watchFor": "The v3 docs still allow the API token as a `token` query parameter, marked deprecated with no removal date"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 67 against 54",
          "Transparency \u0026 trust, 82 against 73"
        ],
        "also": null,
        "goodFor": "Software teams that already run YouTrack and want an agent to search, file and update issues, comment, log time and maintain knowledge base articles under each user's permissions.",
        "slug": "youtrack",
        "watchFor": "No rate limits, 429 handling, idempotency keys or error reference found in the reviewed documentation"
      }
    ],
    "job": {
      "capability": "tasks.create",
      "name": "Tasks create"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/asana-vs-shortcut.json",
        "title": "Asana vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/asana-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/asana-vs-youtrack.json",
        "title": "Asana vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/asana-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/basecamp-vs-shortcut.json",
        "title": "Basecamp vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/basecamp-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/basecamp-vs-youtrack.json",
        "title": "Basecamp vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/basecamp-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickup-vs-shortcut.json",
        "title": "ClickUp vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/clickup-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickup-vs-youtrack.json",
        "title": "ClickUp vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/clickup-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-shortcut.json",
        "title": "monday.com vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/monday-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-youtrack.json",
        "title": "monday.com vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/monday-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plane-vs-shortcut.json",
        "title": "Plane vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/plane-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/plane-vs-youtrack.json",
        "title": "Plane vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/plane-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/roma-vs-shortcut.json",
        "title": "Roma vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/roma-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/roma-vs-youtrack.json",
        "title": "Roma vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/roma-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shortcut-vs-teamwork.json",
        "title": "Shortcut vs Teamwork.com",
        "url": "https://www.anchorterminal.com/compare/shortcut-vs-teamwork"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shortcut-vs-todoist.json",
        "title": "Shortcut vs Todoist",
        "url": "https://www.anchorterminal.com/compare/shortcut-vs-todoist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shortcut-vs-trello.json",
        "title": "Shortcut vs Trello",
        "url": "https://www.anchorterminal.com/compare/shortcut-vs-trello"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shortcut-vs-wrike.json",
        "title": "Shortcut vs Wrike",
        "url": "https://www.anchorterminal.com/compare/shortcut-vs-wrike"
      },
      {
        "json": "https://www.anchorterminal.com/compare/teamwork-vs-youtrack.json",
        "title": "Teamwork.com vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/teamwork-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/todoist-vs-youtrack.json",
        "title": "Todoist vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/todoist-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/trello-vs-youtrack.json",
        "title": "Trello vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/trello-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/wrike-vs-youtrack.json",
        "title": "Wrike vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/wrike-vs-youtrack"
      }
    ],
    "scores": [
      {
        "by": 34,
        "edge": "shortcut",
        "key": "reliability",
        "name": "Reliability",
        "shortcut": 64,
        "weight": 16,
        "youtrack": 30
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "shortcut",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shortcut": 75,
        "weight": 13,
        "youtrack": 72
      },
      {
        "by": 2,
        "edge": "shortcut",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shortcut": 57,
        "weight": 13,
        "youtrack": 55
      },
      {
        "by": 13,
        "edge": "youtrack",
        "key": "security",
        "name": "Security \u0026 auth",
        "shortcut": 54,
        "weight": 14,
        "youtrack": 67
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shortcut": 30,
        "weight": 10,
        "youtrack": 30
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "shortcut",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shortcut": 73,
        "weight": 7,
        "youtrack": 64
      },
      {
        "by": 9,
        "edge": "youtrack",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shortcut": 73,
        "weight": 7,
        "youtrack": 82
      }
    ],
    "summary": "Shortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security \u0026 auth and transparency \u0026 trust. Both do tasks create.",
    "verdicts": {
      "shortcut": "REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.",
      "youtrack": "Every instance serves an OpenAPI 3.0 document, a 23-tool MCP server with OAuth and PKCE, and field selection on each REST call, and the free plan covers ten users. No rate limits, 429 handling, error reference or SLA were found, and JetBrains disclosed two sets of critical vulnerabilities affecting YouTrack Cloud in 2026, both patched."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/shortcut-vs-youtrack",
    "json": "https://www.anchorterminal.com/compare/shortcut-vs-youtrack.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/shortcut-vs-youtrack.md",
    "slim": "https://www.anchorterminal.com/compare/shortcut-vs-youtrack.min.md"
  },
  "markdown": "Shortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security \u0026 auth and transparency \u0026 trust. Both do tasks create.\n\n- Shortcut: grade C, 60.2/100, rank #411 of 722. Markdown https://www.anchorterminal.com/tools/shortcut.md · JSON https://www.anchorterminal.com/api/v1/tools/shortcut.json\n- YouTrack: grade D, 49.9/100, rank #601 of 722. Markdown https://www.anchorterminal.com/tools/youtrack.md · JSON https://www.anchorterminal.com/api/v1/tools/youtrack.json\n\n## Which one, for what\n\n### Shortcut (C)\n\nGood for: Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.\n\nAhead on:\n- Reliability, 64 against 30\n- Maintenance \u0026 community, 73 against 64\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n- No incidents deducted, where YouTrack loses 5 points for them\n\nWatch for: The v3 docs still allow the API token as a `token` query parameter, marked deprecated with no removal date\n\n### YouTrack (D)\n\nGood for: Software teams that already run YouTrack and want an agent to search, file and update issues, comment, log time and maintain knowledge base articles under each user's permissions.\n\nAhead on:\n- Security \u0026 auth, 67 against 54\n- Transparency \u0026 trust, 82 against 73\n\nWatch for: No rate limits, 429 handling, idempotency keys or error reference found in the reviewed documentation\n\n\n## Score by category\n\n| Category | Weight | Shortcut | YouTrack | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 64 | 30 | Shortcut +34 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 75 | 72 | Shortcut +3 |\n| Agent ergonomics | 13% (16.2 this run) | 57 | 55 | Shortcut +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 54 | 67 | YouTrack +13 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 30 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 73 | 64 | Shortcut +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 82 | YouTrack +9 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **60.2 · C** | **49.9 · D** | |\n\n## Facts side by side\n\n| Fact | Shortcut | YouTrack |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Shortcut Software Company | JetBrains s.r.o. |\n| Hosted endpoint | `https://api.app.shortcut.com` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT | Proprietary service under the JetBrains YouTrack Cloud Terms of Service. YouTrack Server is licensed separately for self-hosting |\n| Tools exposed | none | 23 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-22 | 2026-10-05 |\n| Terms last updated | 2025-09-18 | 2024-08-14 |\n| Privacy policy last updated | 2025-07-11 | 2026-06-12 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 142 stars, 103k npm/wk | none |\n\n## Verdicts\n\n**Shortcut.** REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.\n\n**YouTrack.** Every instance serves an OpenAPI 3.0 document, a 23-tool MCP server with OAuth and PKCE, and field selection on each REST call, and the free plan covers ten users. No rate limits, 429 handling, error reference or SLA were found, and JetBrains disclosed two sets of critical vulnerabilities affecting YouTrack Cloud in 2026, both patched.\n\n## Before you call either\n\n### Shortcut\n\n1. Send the v3 token in the `Shortcut-Token` header. v4 (alpha) takes `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens, and v3 tokens don't work there.\n2. Create a story with `name` and `workflow_state_id`. Sending both `workflow_state_id` and `project_id`, or neither, is rejected.\n3. Use `GET /api/v3/search/stories` with `detail=slim`, `page_size` (1 to 250) and the `next` token. Many other v3 list endpoints return every record at once.\n4. Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.\n5. For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as `read` or `story-write`.\n\n### YouTrack\n\n1. Send `fields` on every REST request. Without it the server returns only the database ID and `$type` of each entity\n2. Page collections with `$top` and `$skip`. Most resources return 42 items by default\n3. Call `get_issue_fields_schema` before `create_issue` or `update_issue`, because required custom fields differ by project\n4. Connect MCP clients to `https://\u003cinstance\u003e.youtrack.cloud/mcp`. OAuth needs an administrator to enable CIMD or register the client, since Dynamic Client Registration is not supported\n5. Create permanent tokens with the YouTrack scope only, and add `?tools=` to the MCP URL to limit the tools listed\n\n## Questions\n\n### Which is better for AI agents, Shortcut or YouTrack?\n\nShortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security \u0026 auth and transparency \u0026 trust.\n\n### Do Shortcut and YouTrack need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Shortcut and YouTrack without installing anything?\n\nShortcut has a hosted endpoint at https://api.app.shortcut.com. No hosted endpoint is listed for YouTrack.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/shortcut-vs-youtrack.json, and with the fewest tokens: https://www.anchorterminal.com/compare/shortcut-vs-youtrack.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"shortcut\", \"b\": \"youtrack\"}`. From a terminal: `anchor compare shortcut youtrack`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/shortcut.json and https://www.anchorterminal.com/api/v1/tools/youtrack.json\n\n## Other comparisons with Shortcut or YouTrack\n\n- [Asana vs Shortcut](https://www.anchorterminal.com/compare/asana-vs-shortcut.md)\n- [Asana vs YouTrack](https://www.anchorterminal.com/compare/asana-vs-youtrack.md)\n- [Basecamp vs Shortcut](https://www.anchorterminal.com/compare/basecamp-vs-shortcut.md)\n- [Basecamp vs YouTrack](https://www.anchorterminal.com/compare/basecamp-vs-youtrack.md)\n- [ClickUp vs Shortcut](https://www.anchorterminal.com/compare/clickup-vs-shortcut.md)\n- [ClickUp vs YouTrack](https://www.anchorterminal.com/compare/clickup-vs-youtrack.md)\n- [monday.com vs Shortcut](https://www.anchorterminal.com/compare/monday-vs-shortcut.md)\n- [monday.com vs YouTrack](https://www.anchorterminal.com/compare/monday-vs-youtrack.md)\n- [Plane vs Shortcut](https://www.anchorterminal.com/compare/plane-vs-shortcut.md)\n- [Plane vs YouTrack](https://www.anchorterminal.com/compare/plane-vs-youtrack.md)\n- [Roma vs Shortcut](https://www.anchorterminal.com/compare/roma-vs-shortcut.md)\n- [Roma vs YouTrack](https://www.anchorterminal.com/compare/roma-vs-youtrack.md)\n- [Shortcut vs Teamwork.com](https://www.anchorterminal.com/compare/shortcut-vs-teamwork.md)\n- [Shortcut vs Todoist](https://www.anchorterminal.com/compare/shortcut-vs-todoist.md)\n- [Shortcut vs Trello](https://www.anchorterminal.com/compare/shortcut-vs-trello.md)\n- [Shortcut vs Wrike](https://www.anchorterminal.com/compare/shortcut-vs-wrike.md)\n- [Teamwork.com vs YouTrack](https://www.anchorterminal.com/compare/teamwork-vs-youtrack.md)\n- [Todoist vs YouTrack](https://www.anchorterminal.com/compare/todoist-vs-youtrack.md)\n- [Trello vs YouTrack](https://www.anchorterminal.com/compare/trello-vs-youtrack.md)\n- [Wrike vs YouTrack](https://www.anchorterminal.com/compare/wrike-vs-youtrack.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Shortcut vs YouTrack",
        "url": ""
      }
    ],
    "description": "Shortcut scores 60.2 (C) on agent readiness against YouTrack's 49.9 (D), and leads in 4 of 7 scored categories. YouTrack leads on security \u0026 auth and transparency \u0026 trust. Both do tasks create. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Shortcut C 60.2",
      "YouTrack D 49.9",
      "scores"
    ],
    "h1": "Shortcut vs YouTrack",
    "image": "https://www.anchorterminal.com/assets/og/compare-shortcut-vs-youtrack.png",
    "path": "/compare/shortcut-vs-youtrack",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Shortcut vs YouTrack for AI agents, C 60.2 vs D 49.9 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/shortcut-vs-youtrack"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 680
  },
  "version": 1
}
