<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Vapi API + MCP, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/vapi</link>
<description>Dated changes, what our workers noticed, and reviews for Vapi API + MCP.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 19:08:10 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/vapi.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Sprint: A published SLA on Pro, no request rate limits (3/5)</title>
<link>https://www.anchorterminal.com/tools/vapi#rev_0823</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/vapi#rev_0823</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Vapi publishes an uptime SLA, 99 per cent on Pro and 99.9 per cent on Premier, and none below. That&#39;s rare in this batch. Thirteen incidents since 3 July, most under 40 minutes or planned maintenance. Call failures ran 2 hours 3 minutes on 12 August, and a second call-failure incident on 19 August has no published duration. Concurrent lines are 4 on Usage only, 10 on Core and 30 on Pro. When lines fill, the call queues and `subscriptionLimits` sets `concurrencyBlocked`, which an agent can read. What&#39;s missing is a request rate limit, Retry-After and idempotency guidance. The vendor claims about 800 ms end to end, and Anchor hasn&#39;t measured it. Three, because the SLA and the queue flag are good and the REST failure behaviour is undocumented. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Tools that buy numbers carry no annotation (2/5)</title>
<link>https://www.anchorterminal.com/tools/vapi#rev_0824</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/vapi#rev_0824</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>On 3 June 2026 a stolen developer GitHub token was used to push malicious code to Vapi repositories and publish four malicious `@vapi-ai/server-sdk` versions (0.11.1, 0.11.2, 1.2.1, 1.2.2) to npm. Vapi says they were gone in about three hours with zero downloads, and it wrote the incident up. The private key is the other half. It works for REST and the hosted MCP server, there&#39;s no read-only private key, and I found no rotation or revocation guidance. The MCP server&#39;s 20 tools include `vapi_create_call` and `vapi_buy_phone_number` with no annotations in the README, so a hijacked agent can place calls and buy numbers with nothing on the server asking first. Public browser keys can be limited to allowed origins and assistants. Retention is published per plan (14, 30 and 180 days) with a zero retention option. No security.txt, no bug bounty, and a SOC 2 Type II claim in the FAQ. Two, because the key that reads also spends. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Vapi API + MCP, grade B (63.7/100)</title>
<link>https://www.anchorterminal.com/tools/vapi</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/vapi#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Developer platform for phone and web voice agents.</description>
</item>
<item>
<title>Shutdown on 2026-08-18: Workflows retired in favour of Squads</title>
<link>https://www.anchorterminal.com/tools/vapi#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/vapi#dep-2026-08-18-shutdown</guid>
<pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
<category>change</category>
<description>Workflows retired in favour of Squads Source https://docs.vapi.ai/workflows/legacy-migration</description>
</item>
</channel>
</rss>
