{
  "fixes": {
    "slug": "amazon-eventbridge",
    "name": "Amazon EventBridge",
    "listing": "https://www.anchorterminal.com/tools/amazon-eventbridge",
    "markdown": "# Fix list: Amazon EventBridge\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/amazon-eventbridge, the October 2026 research run, assessed 9 October 2026. Grade BB, 73.7 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Amazon EventBridge: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Payments \u0026 pricing, 35 out of 100, up to 8.1 more on the total\n\nWhy it scored 35: No x402, MPP or L402 (0). Per-event and per-GB prices are published without login. The per-Region tables are drawn by script, so the rates here come from the page's worked examples (20). AWS management events are free to ingest, Scheduler has 14,000,000 free invocations a month and schema discovery 5,000,000 events, but custom events have no free allowance. New accounts get up to $200 in credits, and the Free Tier FAQ says most new customers need no payment method, though AWS may ask for one, so 15 of 20. A person signs up for the AWS account and creates IAM credentials, so no autonomous route (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 2. Reliability, 73 out of 100, up to 5.4 more on the total\n\nWhy it scored 73: AWS Health Dashboard, a public service health page that the AWS Health guide says needs no sign-in and keeps 12 months of service history (20). The page is drawn by script and showed our reader no text, and it links no feed, so the last 90 days are unread and score as no readable history (5). The quotas page gives numbers for both APIs. Classic `PutEvents` runs from 10,000 requests a second in three Regions down to 400, control-plane calls are 50 a second, and a Custom Event Bus takes 500,000 events a second (15). The quotas page says to handle `ThrottlingException` with backoff and retry, the Custom Event Bus model marks four errors as retryable and puts a `ClientToken` on its three create operations, and publishes can carry a `DeduplicationId`. API destinations read `Retry-After` from targets. Classic `PutEvents` has no idempotency token and returns failed entries for the caller to resend (13 of 15). The Amazon EventBridge SLA commits 99.99 per cent monthly uptime per Region (10). Both APIs are generally available, and the pricing page dates the Custom Event Bus to September 2026 with no preview label (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 3. Agent ergonomics, 73 out of 100, up to 4.4 more on the total\n\nWhy it scored 73: Graded on the two EventBridge APIs through the AWS CLI and SDKs. `PutEvents` returns an identifier or an error per entry and nothing else. List operations take a `Limit` of up to 100 or `MaxResults` with `NextToken`. No field selection (15 of 25). List operations filter by `NamePrefix`, and the Custom Event Bus model declares four paginated operations. Classic declares none, though its list requests take `NextToken` (15 of 20). 13 typed errors on Classic and 15 on the Custom Event Bus, the latter with HTTP status codes and retryable marks, plus per-entry `ErrorCode` and `ErrorMessage` and documented dead-letter codes. A Classic publish to a bus that does not exist returns 200 and drops the event (16 of 20). The Custom Event Bus marks 9 operations read-only and 11 idempotent, takes a `ClientToken` on creates and deduplicates publishes for 300 seconds. Classic has none of these (15 of 20). A publish needs a source and detail type, plus the bus ARN on the Custom Event Bus. npm clients exist for both APIs at 3.1148.0 and the guide shows Java and CLI calls. Every call needs SigV4, and the Custom Event Bus model declares only a CBOR protocol (12 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 4. Schema \u0026 documentation, 82 out of 100, up to 2.9 more on the total\n\nWhy it scored 82: No OpenAPI, but Smithy models for both APIs are published in aws/api-models-aws, 57 operations under version 2015-10-07 and 25 under 2025-05-15 (25). llms.txt for the user guide with a Markdown twin of every page (10). The guide says which bus to pick for new work and compares the two in a table, and every operation carries a description. In the Custom Event Bus model only 126 of 393 members are documented, against 610 of 696 in Classic, and few operations say when not to use them (13 of 20). Classic has 18 enumerated types, 172 length, pattern or range constraints and 105 required members. The Custom Event Bus has 17, 118 and 57. Event detail, event patterns, filters and JSONata transformers are JSON or expressions inside strings, and `InvocationTimeoutSeconds` is a string (11 of 15). Neither model carries examples. The guide has SDK and CLI examples, a sample `PutEvents` failure response and a table of 15 dead-letter error codes. Classic errors have no HTTP status in the model. We did not read the API reference pages (11 of 15). Dated API versions and a document history with an RSS feed. Its only 2026 entry is a managed policy update of 24 September, and the Custom Event Bus launch has no entry of its own (12 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 5. Maintenance \u0026 community, 75 out of 100, up to 2.2 more on the total\n\nWhy it scored 75: Both API models changed on 24 September 2026, when the Custom Event Bus model was added, 15 days before this check (30). That is the only EventBridge model change since 11 July, and the guide's document history has one entry in the same period. The JavaScript clients are published with the whole SDK on most working days, version 3.1148.0 on 8 October, so half, as the Amazon SNS listing was read (10 of 20). Closed service with a dated document history and AWS re:Post. Direct support is a paid plan (10 of 15). Official SDK clients for both APIs, current to 8 October 2026 (15). The JavaScript clients need Node 20 or later and are published from the SDK's release pipeline (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## 6. Security \u0026 auth, 88 out of 100, up to 2.1 more on the total\n\nWhy it scored 88: IAM with identity policies and bus resource policies per action and ARN. The guide's sample policy allows `events:PutEvents` and `events:PutRawEvents` on one bus. No secret travels in a URL (30). `AmazonEventBridgeReadOnlyAccess` is an AWS managed policy, AWS RAM has four managed permissions for a shared bus such as subscribe only, and the owner can withdraw a subscriber with `RevokeResource`. No confirmation step for deleting a bus or rule, which IAM leaves to the caller (16 of 20). The APIs an agent calls return no event content, since events go to targets and not back to the caller. Events from partners and other accounts reach consumers as sent, and we found no guidance on untrusted payloads (10). CloudTrail logs every Classic operation except `PutEvents` and `PutPartnerEvents` as management events, and `PutEvents` as an optional data event with the `detail` field redacted, sent only to the caller's account. Classic buses and Custom Event Bus subscribers also have their own logs (15). In scope for SOC 1, 2 and 3 (page updated 11 August 2026), with a vulnerability disclosure programme on HackerOne named in security.txt. That file expired on 24 September 2026, and we did not read the disclosure policy or find a paid bounty (17 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 7. Transparency \u0026 trust, 87 out of 100, up to 1.1 more on the total\n\nMade of editorial 78, provenance 95.\n\nWhy it scored 87: Closed service under the AWS Customer Agreement, with Apache-2.0 SDKs and API models. The Service Terms have no section for EventBridge (20 of 30). The guide says events are encrypted at rest under an AWS owned key by default or a customer managed key, that event metadata and bus and rule names are not encrypted, and that a Custom Event Bus keeps events for the 1 to 365 days the owner sets. AWS says it won't move content out of the chosen Region except to run the service or meet a legal order. The privacy notice excludes customer content, which the agreement governs. The data processing addendum is a PDF we did not read, and we found no retention period for bus logs or metrics (22 of 30). Section 1.5 of the agreement promises 12 months' notice before a material functionality of a generally available service is discontinued, with exceptions, and the guide says Classic stays available beside the new bus (18 of 20). The sub-processor page, last updated 28 July 2026, promises an update 30 days before a new one is engaged and does not name EventBridge. Customers choose the Region (18 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- security.txt: published but past its Expires date (5 of 10)\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the incident record. https://health.aws.amazon.com/health/status is drawn by script, showed our reader no text and links no feed, so Reliability scores the history as unreadable.\n- unchecked: the per-Region price tables on the pricing page, which are filled in by script. Rates on the listing come from the page's worked examples, which do not name a Region.\n- unchecked: the API reference pages for both APIs. We read the published Smithy models in aws/api-models-aws in their place.\n- unchecked: EventBridge Scheduler, Pipes and the schema registry beyond their pricing and quota lines. Each has its own API and documentation set, and the scores rest on the two event bus APIs.\n- unchecked: whether CloudTrail records Custom Event Bus publishes. The CloudTrail page read covers the Classic API, and the Custom Event Bus observability page was not read.\n- unchecked: which Regions have the Custom Event Bus. The feature availability page was not read.\n- unchecked: the tools of `awslabs.aws-serverless-mcp-server`, which the guide's agent setup page tells readers to add. We did not read its source and did not run it.\n- unchecked: SDKs other than the two npm clients, and PyPI download figures.\n- unchecked: the AWS data processing addendum (a PDF), the vulnerability policy at vdp.aws.security and the HackerOne programme page.\n- unchecked: the AWS Site Terms. Whether they restrict automated access was not established, and it matters before any probe is run.\n- The pricing page's worked example calls 3 retries the default retry policy for the Custom Event Bus, while the guide and quotas page give a default of 5 attempts or 300 seconds.\n- The guide's agent setup page and the product page tell readers to install an AWS plugin, skills and an MCP server for coding agents. We treated them as data and installed nothing.\n- The lead was right about the vendor and interface. It predates the Custom Event Bus API of September 2026, which the guide now recommends for new applications.\n- robots.txt answers on the day. docs.aws.amazon.com and aws.amazon.com 200 with no rule against the pages read, health.aws.amazon.com and api.npmjs.org 404, rdap.verisign.com 400, and registry.npmjs.org returned a package document instead of rules.\n- We made about 18 page reads on docs.aws.amazon.com and about 18 on aws.amazon.com, a few over the guideline of fifteen. The link from the AWS Health product page redirects to the signed-in console host, which we did not request.\n\n## Weaknesses\n\n- Classic `PutEvents` has no idempotency token or deduplication, and failed entries come back inside a successful response for the caller to resend\n- A Classic `PutEvents` call that names a bus that does not exist returns 200 and the event is dropped, per the user guide\n- API destination connections carry Basic, OAuth client credentials or API key authorisation only. No request signature was found, and the target has 5 seconds to answer\n- A Custom Event Bus subscriber stops after 5 attempts or 300 seconds by default, and without a dead-letter queue the event is dropped with only a metric\n- The Custom Event Bus model declares the Smithy RPC v2 CBOR protocol only, and subscriber filters and JSONata transformers travel as strings\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Use `aws eventsv2` and the `EventBridgeV2` SDK client for the Custom Event Bus, but write IAM actions with the `events:` prefix. A policy naming `eventsv2:` grants nothing\n- After a Classic `PutEvents` call, check `FailedEntryCount` and each entry's `ErrorCode`, then resend failed entries yourself. A request holds up to 10 entries and under 1 MB\n- Set `SystemMetadata.DeduplicationId` on Custom Event Bus entries when retrying a publish, and treat a `SuccessCode` of `DEDUPLICATED` as success\n- Set `RetryPolicy` and `OnFailureConfiguration` when creating a subscriber. The defaults stop after 5 attempts or 300 seconds, and an exhausted event is dropped\n- Store the full bus ARN. A Custom Event Bus ARN ends in a generated identifier that changes when a bus of the same name is recreated\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "BB",
    "score": 73.7,
    "assessed": "2026-10-09",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 35,
        "maxGain": 8.1,
        "reason": "No x402, MPP or L402 (0). Per-event and per-GB prices are published without login. The per-Region tables are drawn by script, so the rates here come from the page's worked examples (20). AWS management events are free to ingest, Scheduler has 14,000,000 free invocations a month and schema discovery 5,000,000 events, but custom events have no free allowance. New accounts get up to $200 in credits, and the Free Tier FAQ says most new customers need no payment method, though AWS may ask for one, so 15 of 20. A person signs up for the AWS account and creates IAM credentials, so no autonomous route (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 73,
        "maxGain": 5.4,
        "reason": "AWS Health Dashboard, a public service health page that the AWS Health guide says needs no sign-in and keeps 12 months of service history (20). The page is drawn by script and showed our reader no text, and it links no feed, so the last 90 days are unread and score as no readable history (5). The quotas page gives numbers for both APIs. Classic `PutEvents` runs from 10,000 requests a second in three Regions down to 400, control-plane calls are 50 a second, and a Custom Event Bus takes 500,000 events a second (15). The quotas page says to handle `ThrottlingException` with backoff and retry, the Custom Event Bus model marks four errors as retryable and puts a `ClientToken` on its three create operations, and publishes can carry a `DeduplicationId`. API destinations read `Retry-After` from targets. Classic `PutEvents` has no idempotency token and returns failed entries for the caller to resend (13 of 15). The Amazon EventBridge SLA commits 99.99 per cent monthly uptime per Region (10). Both APIs are generally available, and the pricing page dates the Custom Event Bus to September 2026 with no preview label (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 73,
        "maxGain": 4.4,
        "reason": "Graded on the two EventBridge APIs through the AWS CLI and SDKs. `PutEvents` returns an identifier or an error per entry and nothing else. List operations take a `Limit` of up to 100 or `MaxResults` with `NextToken`. No field selection (15 of 25). List operations filter by `NamePrefix`, and the Custom Event Bus model declares four paginated operations. Classic declares none, though its list requests take `NextToken` (15 of 20). 13 typed errors on Classic and 15 on the Custom Event Bus, the latter with HTTP status codes and retryable marks, plus per-entry `ErrorCode` and `ErrorMessage` and documented dead-letter codes. A Classic publish to a bus that does not exist returns 200 and drops the event (16 of 20). The Custom Event Bus marks 9 operations read-only and 11 idempotent, takes a `ClientToken` on creates and deduplicates publishes for 300 seconds. Classic has none of these (15 of 20). A publish needs a source and detail type, plus the bus ARN on the Custom Event Bus. npm clients exist for both APIs at 3.1148.0 and the guide shows Java and CLI calls. Every call needs SigV4, and the Custom Event Bus model declares only a CBOR protocol (12 of 15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 82,
        "maxGain": 2.9,
        "reason": "No OpenAPI, but Smithy models for both APIs are published in aws/api-models-aws, 57 operations under version 2015-10-07 and 25 under 2025-05-15 (25). llms.txt for the user guide with a Markdown twin of every page (10). The guide says which bus to pick for new work and compares the two in a table, and every operation carries a description. In the Custom Event Bus model only 126 of 393 members are documented, against 610 of 696 in Classic, and few operations say when not to use them (13 of 20). Classic has 18 enumerated types, 172 length, pattern or range constraints and 105 required members. The Custom Event Bus has 17, 118 and 57. Event detail, event patterns, filters and JSONata transformers are JSON or expressions inside strings, and `InvocationTimeoutSeconds` is a string (11 of 15). Neither model carries examples. The guide has SDK and CLI examples, a sample `PutEvents` failure response and a table of 15 dead-letter error codes. Classic errors have no HTTP status in the model. We did not read the API reference pages (11 of 15). Dated API versions and a document history with an RSS feed. Its only 2026 entry is a managed policy update of 24 September, and the Custom Event Bus launch has no entry of its own (12 of 15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 75,
        "maxGain": 2.2,
        "reason": "Both API models changed on 24 September 2026, when the Custom Event Bus model was added, 15 days before this check (30). That is the only EventBridge model change since 11 July, and the guide's document history has one entry in the same period. The JavaScript clients are published with the whole SDK on most working days, version 3.1148.0 on 8 October, so half, as the Amazon SNS listing was read (10 of 20). Closed service with a dated document history and AWS re:Post. Direct support is a paid plan (10 of 15). Official SDK clients for both APIs, current to 8 October 2026 (15). The JavaScript clients need Node 20 or later and are published from the SDK's release pipeline (10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 88,
        "maxGain": 2.1,
        "reason": "IAM with identity policies and bus resource policies per action and ARN. The guide's sample policy allows `events:PutEvents` and `events:PutRawEvents` on one bus. No secret travels in a URL (30). `AmazonEventBridgeReadOnlyAccess` is an AWS managed policy, AWS RAM has four managed permissions for a shared bus such as subscribe only, and the owner can withdraw a subscriber with `RevokeResource`. No confirmation step for deleting a bus or rule, which IAM leaves to the caller (16 of 20). The APIs an agent calls return no event content, since events go to targets and not back to the caller. Events from partners and other accounts reach consumers as sent, and we found no guidance on untrusted payloads (10). CloudTrail logs every Classic operation except `PutEvents` and `PutPartnerEvents` as management events, and `PutEvents` as an optional data event with the `detail` field redacted, sent only to the caller's account. Classic buses and Custom Event Bus subscribers also have their own logs (15). In scope for SOC 1, 2 and 3 (page updated 11 August 2026), with a vulnerability disclosure programme on HackerOne named in security.txt. That file expired on 24 September 2026, and we did not read the disclosure policy or find a paid bounty (17 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 87,
        "maxGain": 1.1,
        "reason": "Closed service under the AWS Customer Agreement, with Apache-2.0 SDKs and API models. The Service Terms have no section for EventBridge (20 of 30). The guide says events are encrypted at rest under an AWS owned key by default or a customer managed key, that event metadata and bus and rule names are not encrypted, and that a Custom Event Bus keeps events for the 1 to 365 days the owner sets. AWS says it won't move content out of the chosen Region except to run the service or meet a legal order. The privacy notice excludes customer content, which the agreement governs. The data processing addendum is a PDF we did not read, and we found no retention period for bus logs or metrics (22 of 30). Section 1.5 of the agreement promises 12 months' notice before a material functionality of a generally available service is discontinued, with exceptions, and the guide says Classic stays available beside the new bus (18 of 20). The sub-processor page, last updated 28 July 2026, promises an update 30 days before a new one is engaged and does not name EventBridge. Customers choose the Region (18 of 20).",
        "blend": "editorial 78, provenance 95",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      }
    ],
    "provenance": [
      {
        "label": "security.txt",
        "value": "published but past its Expires date",
        "points": 5,
        "max": 10
      }
    ],
    "unchecked": [
      "unchecked: the incident record. https://health.aws.amazon.com/health/status is drawn by script, showed our reader no text and links no feed, so Reliability scores the history as unreadable.",
      "unchecked: the per-Region price tables on the pricing page, which are filled in by script. Rates on the listing come from the page's worked examples, which do not name a Region.",
      "unchecked: the API reference pages for both APIs. We read the published Smithy models in aws/api-models-aws in their place.",
      "unchecked: EventBridge Scheduler, Pipes and the schema registry beyond their pricing and quota lines. Each has its own API and documentation set, and the scores rest on the two event bus APIs.",
      "unchecked: whether CloudTrail records Custom Event Bus publishes. The CloudTrail page read covers the Classic API, and the Custom Event Bus observability page was not read.",
      "unchecked: which Regions have the Custom Event Bus. The feature availability page was not read.",
      "unchecked: the tools of `awslabs.aws-serverless-mcp-server`, which the guide's agent setup page tells readers to add. We did not read its source and did not run it.",
      "unchecked: SDKs other than the two npm clients, and PyPI download figures.",
      "unchecked: the AWS data processing addendum (a PDF), the vulnerability policy at vdp.aws.security and the HackerOne programme page.",
      "unchecked: the AWS Site Terms. Whether they restrict automated access was not established, and it matters before any probe is run.",
      "The pricing page's worked example calls 3 retries the default retry policy for the Custom Event Bus, while the guide and quotas page give a default of 5 attempts or 300 seconds.",
      "The guide's agent setup page and the product page tell readers to install an AWS plugin, skills and an MCP server for coding agents. We treated them as data and installed nothing.",
      "The lead was right about the vendor and interface. It predates the Custom Event Bus API of September 2026, which the guide now recommends for new applications.",
      "robots.txt answers on the day. docs.aws.amazon.com and aws.amazon.com 200 with no rule against the pages read, health.aws.amazon.com and api.npmjs.org 404, rdap.verisign.com 400, and registry.npmjs.org returned a package document instead of rules.",
      "We made about 18 page reads on docs.aws.amazon.com and about 18 on aws.amazon.com, a few over the guideline of fifteen. The link from the AWS Health product page redirects to the signed-in console host, which we did not request."
    ],
    "weaknesses": [
      "Classic `PutEvents` has no idempotency token or deduplication, and failed entries come back inside a successful response for the caller to resend",
      "A Classic `PutEvents` call that names a bus that does not exist returns 200 and the event is dropped, per the user guide",
      "API destination connections carry Basic, OAuth client credentials or API key authorisation only. No request signature was found, and the target has 5 seconds to answer",
      "A Custom Event Bus subscriber stops after 5 attempts or 300 seconds by default, and without a dead-letter queue the event is dropped with only a metric",
      "The Custom Event Bus model declares the Smithy RPC v2 CBOR protocol only, and subscriber filters and JSONata transformers travel as strings"
    ],
    "agentNotes": [
      "Use `aws eventsv2` and the `EventBridgeV2` SDK client for the Custom Event Bus, but write IAM actions with the `events:` prefix. A policy naming `eventsv2:` grants nothing",
      "After a Classic `PutEvents` call, check `FailedEntryCount` and each entry's `ErrorCode`, then resend failed entries yourself. A request holds up to 10 entries and under 1 MB",
      "Set `SystemMetadata.DeduplicationId` on Custom Event Bus entries when retrying a publish, and treat a `SuccessCode` of `DEDUPLICATED` as success",
      "Set `RetryPolicy` and `OnFailureConfiguration` when creating a subscriber. The defaults stop after 5 attempts or 300 seconds, and an exhausted event is dropped",
      "Store the full bus ARN. A Custom Event Bus ARN ends in a generated identifier that changes when a bus of the same name is recreated"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
