{
  "fixes": {
    "slug": "easypost",
    "name": "EasyPost",
    "listing": "https://www.anchorterminal.com/tools/easypost",
    "markdown": "# Fix list: EasyPost\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/easypost, the October 2026 research run, assessed 7 October 2026. Grade C, 54.3 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on EasyPost: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Payments \u0026 pricing, 22 out of 100, up to 9.8 more on the total\n\nWhy it scored 22: Read with the hosted rubric. No x402, MPP or L402 (0). The API Addendum publishes unit fees without a login ($0.02 for each extra tracker, US address verification or rating call, $0.06 for an international verification, $0.03 a SmartRate call), and the pricing page lists tracking at $0.01 to $0.03 a shipment and insurance at 1 per cent. The per-label fee after 3,000 free labels isn't stated, and Forge, GlobalShip and Luma are priced by sales (12 of 20). Up to 3,000 labels carry no EasyPost fee and test keys cost nothing, but postage is always paid, and the docs say a wallet must be set up before keys are issued. Whether that needs a card wasn't established (10 of 20). A person signs up in a browser. Keys can be created by API only with an existing production key (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 2. Reliability, 53 out of 100, up to 9.4 more on the total\n\nWhy it scored 53: Read with the hosted lines and scored on the REST API at api.easypost.com/v2, the surface an agent would use to rate, buy and track. The hosted MCP server only reads and is an early release. www.easypoststatus.com on Statuspage lists 44 components with incident history (20). In the 90 days to 7 October 2026 it shows seven incidents. A connectivity fault at the hosting provider on 23 July affected all operations from 07:57 to about 12:21 Pacific time, and two carrier-side incidents were marked major (UPS accounts supplied by EasyPost on 22 July for 3 h 29 min, USPS Ship on 20 September for 5 h 24 min). Two short API degradations lasted 10 and 14 minutes. One core outage and two upstream majors (7 of 30). The rate-limiting guide gives five requests a second on index endpoints and a 60-account cap on rating, but the load-based limiter on buying and rating has no published number (8 of 15). The guide describes 429 handling with retry and backoff and a code sample. No Retry-After header and no idempotency keys were found, and the sample retries only GET and DELETE (8 of 15). The Master Customer Agreement supplies the service as is and as available, and the support addendum sets response targets only (0). The v2 API is generally available (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 3. Security \u0026 auth, 47 out of 100, up to 9.3 more on the total\n\nWhy it scored 47: API keys go in the HTTP Basic username over TLS 1.2. Keys can be created, disabled, enabled and deleted through the API or the dashboard, and the docs say a key allows full account access. Plain revocable keys, with no secret in a query string (20 of 30). Test keys buy no postage, child users hold separate keys, and the MCP server has read tools only and omits carrier credentials, wallet balances and payment methods. The REST API has no read-only or scoped key and no confirmation step before a purchase (8 of 20). Responses carry addresses and carrier tracking text. The MCP guide advises connecting only to trusted clients and servers, and no injection guidance was found (4 of 15). Events and their payloads can be retrieved and each shipment lists its fees, but no audit log of API calls or key use was found in the reviewed documentation (5 of 15). A Responsible Disclosure Policy with a safe-harbour commitment and the contact security-abuse@easypost.com, HMAC-signed webhooks, and a SOC 2 Type 2 report referred to in the data processing addendum. No security.txt and no bug bounty were found, and trust.easypost.com refused our reader (10 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 4. Schema \u0026 documentation, 55 out of 100, up to 7.3 more on the total\n\nWhy it scored 55: No OpenAPI or similar spec was found in the docs, llms.txt, the page index or the 56 public repositories of the EasyPost GitHub organisation. A Postman workspace is listed, which we didn't read (0 of 25). llms.txt, a Markdown copy of almost every page and doc-index.json with audience and usage notes for each page (10). Each object has a property table with a type and description, and the index says when each page applies. Endpoint pages are mostly examples, with little on when not to use a call (12 of 20). Types and allowed values are given in prose tables, such as the ten tracker statuses, with no schema to validate against, and the Markdown copies omit some parameter lists that the HTML pages render (8 of 15). Every endpoint has examples in cURL and seven SDK languages, plus an error object and 13 general error codes. The full error code list is on a part of the page the Markdown copy omits (13 of 15). The path carries v2 and the releases page has dated notes almost every week. No written versioning policy was found, and some calls sit under /beta (12 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 5. Agent ergonomics, 63 out of 100, up to 6 more on the total\n\nWhy it scored 63: List calls take `page_size` up to 100 with a default of 20 on most endpoints. No field selection was found, and a shipment response nests addresses, parcel, rates and tracker (12 of 25). Cursor pagination by `before_id` and `after_id`, date ranges and a `has_more` flag, with support that varies by endpoint (16 of 20). Errors carry a machine-readable `code`, a message and per-field entries with an occasional suggestion. The `errors` array arrives as objects or as strings, so a client has to handle both (15 of 20). No idempotency keys were found. Trackers are deduplicated by tracking code and carrier for three months, but `reference` on a shipment isn't unique and nothing guards a repeated buy. The MCP tools only read, though we couldn't list them without a key to see annotations (5 of 20). One-call buy creates and purchases in one request, addresses and parcels can be nested or reused by id, and official SDKs cover seven languages (15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 6. Transparency \u0026 trust, 70 out of 100, up to 2.6 more on the total\n\nMade of editorial 53, provenance 87.\n\nWhy it scored 70: The service is closed, under a Master Customer Agreement (version 6.1, effective 25 August 2026) and seven addenda in a legal centre that keeps every past version. The SDKs are MIT or ISC (15). The privacy policy (18 August 2025) gives no retention period. The agreement points to a Data Retention Policy in the help centre, which refused our reader, and it grants EasyPost a licence to use customer data to improve its services and develop new products during and after the term. A data processing addendum with EU and UK standard clauses is public (15 of 30). The agreement says EasyPost will use reasonable efforts to notify customers before API changes that aren't backwards compatible, with no notice period, and allows termination with a refund within 15 days if functionality is materially reduced. No deprecation policy with dates was found (6 of 20). Annex D of the addendum lists 12 subprocessors with purpose and country, all in the USA, and customers have 10 days to object to a new one (17 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10)\n- security.txt: not found (0 of 10)\n\n## 7. Maintenance \u0026 community, 85 out of 100, up to 1.3 more on the total\n\nWhy it scored 85: The releases page has an entry dated 28 September 2026, nine days before the check, and easypost-go 5.10.1 was tagged on 29 September (30). Ten dated release notes between 12 July and 28 September 2026 (20). A closed service with public release notes, support@easypost.com, a help centre, a dedicated ai@easypost.com address for the MCP server and a published four-hour response target on the Base support tier. We didn't read GitHub issues or test response times (11 of 15). Seven official SDKs, all pushed between 24 September and 3 October 2026, though the Java, Python, Ruby and Node stable releases date from 25 June (15). The Python library's CI lints and runs tests on Python 3.9 to 3.13, and the Node library has a 9.0.0 release candidate that moves to TypeScript and fetch (9 of 10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: trust.easypost.com and www.easypost.com/security answered 403 to our reader, so certifications beyond the SOC 2 Type 2 report named in the data processing addendum are unconfirmed.\n- unchecked: the Data Retention Policy at support.easypost.com, which answered 403, so retention periods for shipment data are unknown.\n- unchecked: the MCP server's tool schemas and annotations. tools/list answers 401 without a production key, so the 11 tools are taken from the guide.\n- unchecked: the Postman workspace at www.postman.com/easypost-api, which may hold a machine-readable collection.\n- unchecked: GitHub issues and response times on the SDK repositories.\n- www.easypost.com/pricing answered a Cloudflare block to curl and loaded through WebFetch. Prices here come from that one read and from the API Addendum.\n- The per-label fee after 3,000 free labels, and whether the 3,000 are counted by month or year, aren't stated on the pricing page.\n- Whether setting up the wallet needed for API keys requires a card or a deposit wasn't established. We didn't sign up.\n- The rate-limiting guide gives five requests a second on index endpoints as an example. Limits on buying and rating are load-based with no number.\n- The 23 July 2026 outage has its Statuspage impact field left at none, although the updates say all operations were affected. We scored it as a major outage.\n- No date was found for the MCP server's launch. It isn't in the release notes we read.\n\n## Weaknesses\n\n- No OpenAPI spec was found in the docs or in the EasyPost GitHub organisation. The reference is prose and tables, with a Postman workspace\n- No idempotency keys were found, and `reference` on a shipment isn't unique, so a retried buy can purchase a second label\n- API keys allow full account access. Test and production modes and child users are the only separation, with no read-only or scoped key\n- An outage on 23 July 2026 at the hosting provider affected all operations for about four and a half hours. Two carrier-side incidents were marked major in the same 90 days\n- The Master Customer Agreement supplies the service as is, with no uptime commitment, and the per-label fee after 3,000 free labels isn't on the pricing page\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Use a test API key while building. It buys no postage and contacts no carrier, and test tracking codes simulate each tracking status\n- Don't blind-retry `POST /shipments/:id/buy` after a timeout. Retrieve the shipment first and check for `postage_label`, since no idempotency key exists\n- Send the API key as the HTTP Basic username with an empty password on the REST API, and as a Bearer token on the MCP server\n- Handle `errors` as either an array of objects or an array of strings. The docs say both shapes occur\n- Pass a scoped `carrier_accounts` list when rating. Only the first 60 accounts are rated and the call doesn't fail when more are enabled\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "C",
    "score": 54.3,
    "assessed": "2026-10-07",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 22,
        "maxGain": 9.8,
        "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). The API Addendum publishes unit fees without a login ($0.02 for each extra tracker, US address verification or rating call, $0.06 for an international verification, $0.03 a SmartRate call), and the pricing page lists tracking at $0.01 to $0.03 a shipment and insurance at 1 per cent. The per-label fee after 3,000 free labels isn't stated, and Forge, GlobalShip and Luma are priced by sales (12 of 20). Up to 3,000 labels carry no EasyPost fee and test keys cost nothing, but postage is always paid, and the docs say a wallet must be set up before keys are issued. Whether that needs a card wasn't established (10 of 20). A person signs up in a browser. Keys can be created by API only with an existing production key (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 53,
        "maxGain": 9.4,
        "reason": "Read with the hosted lines and scored on the REST API at api.easypost.com/v2, the surface an agent would use to rate, buy and track. The hosted MCP server only reads and is an early release. www.easypoststatus.com on Statuspage lists 44 components with incident history (20). In the 90 days to 7 October 2026 it shows seven incidents. A connectivity fault at the hosting provider on 23 July affected all operations from 07:57 to about 12:21 Pacific time, and two carrier-side incidents were marked major (UPS accounts supplied by EasyPost on 22 July for 3 h 29 min, USPS Ship on 20 September for 5 h 24 min). Two short API degradations lasted 10 and 14 minutes. One core outage and two upstream majors (7 of 30). The rate-limiting guide gives five requests a second on index endpoints and a 60-account cap on rating, but the load-based limiter on buying and rating has no published number (8 of 15). The guide describes 429 handling with retry and backoff and a code sample. No Retry-After header and no idempotency keys were found, and the sample retries only GET and DELETE (8 of 15). The Master Customer Agreement supplies the service as is and as available, and the support addendum sets response targets only (0). The v2 API is generally available (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 47,
        "maxGain": 9.3,
        "reason": "API keys go in the HTTP Basic username over TLS 1.2. Keys can be created, disabled, enabled and deleted through the API or the dashboard, and the docs say a key allows full account access. Plain revocable keys, with no secret in a query string (20 of 30). Test keys buy no postage, child users hold separate keys, and the MCP server has read tools only and omits carrier credentials, wallet balances and payment methods. The REST API has no read-only or scoped key and no confirmation step before a purchase (8 of 20). Responses carry addresses and carrier tracking text. The MCP guide advises connecting only to trusted clients and servers, and no injection guidance was found (4 of 15). Events and their payloads can be retrieved and each shipment lists its fees, but no audit log of API calls or key use was found in the reviewed documentation (5 of 15). A Responsible Disclosure Policy with a safe-harbour commitment and the contact security-abuse@easypost.com, HMAC-signed webhooks, and a SOC 2 Type 2 report referred to in the data processing addendum. No security.txt and no bug bounty were found, and trust.easypost.com refused our reader (10 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 55,
        "maxGain": 7.3,
        "reason": "No OpenAPI or similar spec was found in the docs, llms.txt, the page index or the 56 public repositories of the EasyPost GitHub organisation. A Postman workspace is listed, which we didn't read (0 of 25). llms.txt, a Markdown copy of almost every page and doc-index.json with audience and usage notes for each page (10). Each object has a property table with a type and description, and the index says when each page applies. Endpoint pages are mostly examples, with little on when not to use a call (12 of 20). Types and allowed values are given in prose tables, such as the ten tracker statuses, with no schema to validate against, and the Markdown copies omit some parameter lists that the HTML pages render (8 of 15). Every endpoint has examples in cURL and seven SDK languages, plus an error object and 13 general error codes. The full error code list is on a part of the page the Markdown copy omits (13 of 15). The path carries v2 and the releases page has dated notes almost every week. No written versioning policy was found, and some calls sit under /beta (12 of 15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 63,
        "maxGain": 6,
        "reason": "List calls take `page_size` up to 100 with a default of 20 on most endpoints. No field selection was found, and a shipment response nests addresses, parcel, rates and tracker (12 of 25). Cursor pagination by `before_id` and `after_id`, date ranges and a `has_more` flag, with support that varies by endpoint (16 of 20). Errors carry a machine-readable `code`, a message and per-field entries with an occasional suggestion. The `errors` array arrives as objects or as strings, so a client has to handle both (15 of 20). No idempotency keys were found. Trackers are deduplicated by tracking code and carrier for three months, but `reference` on a shipment isn't unique and nothing guards a repeated buy. The MCP tools only read, though we couldn't list them without a key to see annotations (5 of 20). One-call buy creates and purchases in one request, addresses and parcels can be nested or reused by id, and official SDKs cover seven languages (15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 70,
        "maxGain": 2.6,
        "reason": "The service is closed, under a Master Customer Agreement (version 6.1, effective 25 August 2026) and seven addenda in a legal centre that keeps every past version. The SDKs are MIT or ISC (15). The privacy policy (18 August 2025) gives no retention period. The agreement points to a Data Retention Policy in the help centre, which refused our reader, and it grants EasyPost a licence to use customer data to improve its services and develop new products during and after the term. A data processing addendum with EU and UK standard clauses is public (15 of 30). The agreement says EasyPost will use reasonable efforts to notify customers before API changes that aren't backwards compatible, with no notice period, and allows termination with a refund within 15 days if functionality is materially reduced. No deprecation policy with dates was found (6 of 20). Annex D of the addendum lists 12 subprocessors with purpose and country, all in the USA, and customers have 10 days to object to a new one (17 of 20).",
        "blend": "editorial 53, provenance 87",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 85,
        "maxGain": 1.3,
        "reason": "The releases page has an entry dated 28 September 2026, nine days before the check, and easypost-go 5.10.1 was tagged on 29 September (30). Ten dated release notes between 12 July and 28 September 2026 (20). A closed service with public release notes, support@easypost.com, a help centre, a dedicated ai@easypost.com address for the MCP server and a published four-hour response target on the Base support tier. We didn't read GitHub issues or test response times (11 of 15). Seven official SDKs, all pushed between 24 September and 3 October 2026, though the Java, Python, Ruby and Node stable releases date from 25 June (15). The Python library's CI lints and runs tests on Python 3.9 to 3.13, and the Node library has a 9.0.0 release candidate that moves to TypeScript and fetch (9 of 10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Terms of service",
        "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
        "points": 7.1,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "unchecked": [
      "unchecked: trust.easypost.com and www.easypost.com/security answered 403 to our reader, so certifications beyond the SOC 2 Type 2 report named in the data processing addendum are unconfirmed.",
      "unchecked: the Data Retention Policy at support.easypost.com, which answered 403, so retention periods for shipment data are unknown.",
      "unchecked: the MCP server's tool schemas and annotations. tools/list answers 401 without a production key, so the 11 tools are taken from the guide.",
      "unchecked: the Postman workspace at www.postman.com/easypost-api, which may hold a machine-readable collection.",
      "unchecked: GitHub issues and response times on the SDK repositories.",
      "www.easypost.com/pricing answered a Cloudflare block to curl and loaded through WebFetch. Prices here come from that one read and from the API Addendum.",
      "The per-label fee after 3,000 free labels, and whether the 3,000 are counted by month or year, aren't stated on the pricing page.",
      "Whether setting up the wallet needed for API keys requires a card or a deposit wasn't established. We didn't sign up.",
      "The rate-limiting guide gives five requests a second on index endpoints as an example. Limits on buying and rating are load-based with no number.",
      "The 23 July 2026 outage has its Statuspage impact field left at none, although the updates say all operations were affected. We scored it as a major outage.",
      "No date was found for the MCP server's launch. It isn't in the release notes we read."
    ],
    "weaknesses": [
      "No OpenAPI spec was found in the docs or in the EasyPost GitHub organisation. The reference is prose and tables, with a Postman workspace",
      "No idempotency keys were found, and `reference` on a shipment isn't unique, so a retried buy can purchase a second label",
      "API keys allow full account access. Test and production modes and child users are the only separation, with no read-only or scoped key",
      "An outage on 23 July 2026 at the hosting provider affected all operations for about four and a half hours. Two carrier-side incidents were marked major in the same 90 days",
      "The Master Customer Agreement supplies the service as is, with no uptime commitment, and the per-label fee after 3,000 free labels isn't on the pricing page"
    ],
    "agentNotes": [
      "Use a test API key while building. It buys no postage and contacts no carrier, and test tracking codes simulate each tracking status",
      "Don't blind-retry `POST /shipments/:id/buy` after a timeout. Retrieve the shipment first and check for `postage_label`, since no idempotency key exists",
      "Send the API key as the HTTP Basic username with an empty password on the REST API, and as a Bearer token on the MCP server",
      "Handle `errors` as either an array of objects or an array of strings. The docs say both shapes occur",
      "Pass a scoped `carrier_accounts` list when rating. Only the first 60 accounts are rated and the call doesn't fail when more are enabled"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
