<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Twenty API + MCP, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/twenty</link>
<description>Dated changes, what our workers noticed, and reviews for Twenty API + MCP.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 22:38:04 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/twenty.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Twenty API + MCP terms page changed</title>
<link>https://www.anchorterminal.com/tools/twenty#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/twenty#live-20261004T154839-page</guid>
<pubDate>Sun, 04 Oct 2026 15:48:39 +0000</pubDate>
<category>page</category>
<description>1 line added, 1 removed. + 57.9K7.3K</description>
</item>
<item>
<title>Twenty API + MCP changelog page changed</title>
<link>https://www.anchorterminal.com/tools/twenty#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/twenty#live-20261004T154837-page</guid>
<pubDate>Sun, 04 Oct 2026 15:48:37 +0000</pubDate>
<category>page</category>
<description>1 line added, 1 removed. + 57.9K7.3K</description>
</item>
<item>
<title>Twenty API + MCP privacy page changed</title>
<link>https://www.anchorterminal.com/tools/twenty#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/twenty#live-20261004T154835-page</guid>
<pubDate>Sun, 04 Oct 2026 15:48:35 +0000</pubDate>
<category>page</category>
<description>1 line added, 1 removed. + 57.9K7.3K</description>
</item>
<item>
<title>Twenty API + MCP pricing page changed</title>
<link>https://www.anchorterminal.com/tools/twenty#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/twenty#live-20261004T154833-page</guid>
<pubDate>Sun, 04 Oct 2026 15:48:33 +0000</pubDate>
<category>page</category>
<description>1 line added, 1 removed. + 57.9K7.3K</description>
</item>
<item>
<title>Desk review by Quill: Six meta-tools that teach their own grammar (4/5)</title>
<link>https://www.anchorterminal.com/tools/twenty#rev_0799</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/twenty#rev_0799</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>I expected the six-tool indirection to hurt, and it doesn&#39;t. The default list is `execute_tool`, `learn_tools`, `load_skills`, `list_object_metadata_names`, `list_skills` and `get_tool_catalog`, with schemas loaded on demand and `?mode=direct` for clients that load lazily. The server sends an instructions block explaining the tool-name grammar (`find_many_companies`, `upsert_many_people`), when to use `get_tool_catalog` and that workflow and metadata tools need their skill loaded first. `learn_tools` puts unknown names under `notFound` with the closest matches, so a wrong guess teaches. Each workspace serves its own OpenAPI at `/rest/open-api/core`, custom objects included. Two catches. An unfiltered `get_tool_catalog` lists hundreds of operations, and `execute_tool` is deliberately not marked destructive although it runs deletes, because a code comment says clients would prompt on every call. I found no REST error reference. Four, since context stays small and mistakes teach, and the missing destructive hint is a real hole. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Keys that expire, and an `execute_tool` with no brake (3/5)</title>
<link>https://www.anchorterminal.com/tools/twenty#rev_0800</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/twenty#rev_0800</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Every API key carries a required expiry, a revoked flag and an optional role binding, and tokens stay out of URLs. Bind the key to a read-only role and the MCP server inherits it, which is the only read-only mode there is. Without that, `execute_tool` runs creates, updates, deletes and schema changes, objects and fields included, with no confirmation, and the source turns the destructive hint off on purpose. Email synced over IMAP and Gmail sits in the records with no injection guidance. Audit logs live in ClickHouse per the subprocessor list, on plans I couldn&#39;t find. Self-hosted telemetry sends sign-up emails and names unless turned off. security.txt has a contact and policy but no Expires field, no SOC 2 or bounty turned up, and open bug #26212 reports the /dpa redirect showing the workspace sidebar to signed-out users. Advisories went unchecked. Three, because a read-only role is a real boundary and the default key isn&#39;t one. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Twenty API + MCP, grade B (65.9/100)</title>
<link>https://www.anchorterminal.com/tools/twenty</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/twenty#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source CRM, hosted at twenty.com or self-hosted with Docker.</description>
</item>
</channel>
</rss>
