{
  "fixes": {
    "slug": "lago",
    "name": "Lago",
    "listing": "https://www.anchorterminal.com/tools/lago",
    "markdown": "# Fix list: Lago\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/lago, the October 2026 research run, assessed 9 October 2026. Grade B, 65.7 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Lago: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Security \u0026 auth, 37 out of 100, up to 11 more on the total\n\nWhy it scored 37: Scored on the free self-hosted edition. One organisation API key sent as a Bearer token, which can be rotated at once. Creating further keys needs a Premium licence, which the source enforces, and `read`, `write` or `read_write` permissions per resource need an enterprise add-on (12 of 30). With no scopes in the free edition, least privilege is not available. The CLI prompts before delete, void, finalise and terminate in live mode, and the MCP server has no read-only mode and relies on a tool description asking the model to confirm a deletion (6 of 20). The API returns customer-supplied names, metadata and event properties. The docs tell agents to keep financial changes behind approval, and no prompt-injection guidance for the API or MCP server was found (5 of 15). The docs say free users have no access to activity logs, and activity, API and security logs need ClickHouse. The owner keeps its own server logs (4 of 15). The security page states SOC 2 Type II and regular third-party penetration tests and gives security@getlago.com. security.txt returned 404, neither repository has a security policy file, GitHub lists no published advisories for getlago/lago or getlago/lago-api, no bounty was found and the trust centre could not be read (10 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 2. Payments \u0026 pricing, 50 out of 100, up to 6.3 more on the total\n\nWhy it scored 50: Read with the self-hosted rule. No x402, MPP or L402. Lago's own llms.txt says direct x402 and general agent-wallet support are not available, and its Stripe Shared Payment Token support is a public preview behind a feature flag for collecting a merchant's invoices (0). The open-source edition is free. Lago Cloud and Premium have no public price, only a stated five-figure minimum annual commitment and a custom quote, so half marks (10). Free to run with no card (20). An owner can install it without a sales contact, and the Docker Compose files accept `LAGO_CREATE_ORG` and `LAGO_ORG_API_KEY` to create the organisation and key at start-up, as read in the repository (20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 3. Agent ergonomics, 71 out of 100, up to 4.7 more on the total\n\nWhy it scored 71: Graded on the REST API. List calls take `page` and `per_page`, with a default of 100 in most cases. No field selection or summary view was found (13 of 25). Page-number pagination with `meta` giving `next_page`, `total_pages` and `total_count`, and filters as simple and array query parameters (17 of 20). Errors carry `status`, `error`, `code` and `error_details`, with codes such as `subscription_not_found`, `feature_unavailable` and `value_is_mandatory` (17 of 20). Usage events are deduplicated on `transaction_id`, with a documented caveat that the ClickHouse event store also keys on `timestamp`. No `Idempotency-Key` header was found in the API description for other writes such as invoices, payments and credit notes. The CLI has `--dry-run` and asks before destructive commands. The MCP server sets no readOnlyHint or destructiveHint (10 of 20). Official SDKs for Python, JavaScript, Ruby and Go, each tagged v1.55.0, and a CLI generated from the API description (14 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 4. Transparency \u0026 trust, 59 out of 100, up to 3.6 more on the total\n\nMade of editorial 77, provenance 41.\n\nWhy it scored 59: The platform is AGPL-3.0, and the MCP server and agent SDKs are MIT. Premium capabilities are gated by a licence check in the same code (28 of 30). Data in a self-hosted instance stays with the owner. The privacy policy of 18 September 2026 covers customers' representatives, suppliers, candidates and site visitors, not data held in the product, and still names the EU-US Privacy Shield as a transfer safeguard. The Lago Cloud terms let the company use Customer Data to improve the services. No public DPA or sub-processor list was found (15 of 30). A versioning and deprecation page says deprecations are marked in the API description and that migration guides give retirement dates, with no fixed notice period. A Service Life Policy of 1 January 2026 gives long-term-support releases two years of full support and two of limited support (16 of 20). Self-hosted analytics through Segment are on by default, the events are listed and `LAGO_DISABLE_SEGMENT=true` turns them off, which the source confirms (18 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Domain age: getlago.com, registered 2020-11-27 (5 years) (11 of 15)\n- Endpoint on the vendor's domain:  is not on getlago.com (0 of 15)\n- Terms of service: not found (0 of 10)\n- Privacy policy: not found (0 of 10)\n- Status page: not found (0 of 10)\n- security.txt: not found (0 of 10)\n\n## 5. Reliability, 86 out of 100, up to 2.8 more on the total\n\nWhy it scored 86: Read with the local-software lines, on the open-source edition an owner runs. Lago Cloud is sold by quote with a five-figure minimum annual commitment, so it is not the surface an agent can start on. Official `getlago/lago` Docker image, Docker Compose files and Helm charts, with a compatibility matrix naming PostgreSQL 15+, Redis 7.x or Valkey 7.2+ and Kubernetes 1.26+ for the latest release (20). Public CI with 2,605 spec files in getlago/lago-api, and the five latest runs of the spec workflow on main, on 8 and 9 October 2026, all passed (25). The main repository has 28 open issues and pull requests against 10,665 stars. About 16 are issues, and several bug reports from 2024 and 2025 carry a stale label with no fix, among them installation, sign-up and CORS problems (17 of 25). Versions follow v1.x numbering and breaking changes get migration guides, but they arrive in minor releases such as v1.50.0, and GitHub release notes are lists of pull requests with no changelog file (9 of 15). Version 1.55.0, past 1.0 (15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 6. Schema \u0026 documentation, 87 out of 100, up to 2.1 more on the total\n\nWhy it scored 87: A public OpenAPI 3.1 description in getlago/lago-openapi, version 1.55.0, with 217 operations on 136 paths, 339 schemas and 76 webhook events (25). llms.txt on the site and the docs, a full-text docs export and a Markdown twin of each page (10). Every operation has an operation ID, and 94 of 217 have a description longer than 80 characters. The docs index says when to use the docs and the event pages explain retries, while few operations say when not to use them (13 of 20). The file has 372 enums and 787 required lists, with free-form event `properties` and metadata (13 of 15). About 2,000 examples, and an errors page with named codes. No operation documents a 429 response although the rate-limit page describes one (13 of 15). The path is versioned `/api/v1`, a versioning and deprecation page exists, the description's version follows each release, and the product changelog is dated by month (13 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 7. Maintenance \u0026 community, 91 out of 100, up to 0.8 more on the total\n\nWhy it scored 91: v1.55.0 was tagged on 7 October 2026, two days before the check (30). Six tags fall in the 90 days to 9 October, from v1.51.0 on 27 July (20). The API repository's last 100 commits span 24 September to 9 October 2026. Recent issues in the main repository have three to six comments, while a feature request of 24 September has none and several older bug reports are marked stale (17 of 25). The Python, Ruby and Go SDKs carry a v1.55.0 tag, as does the JavaScript SDK, and the CLI is at v1.0.2 (15). CI is green, Renovate and Dependabot updates are merged, and the MCP server's images are rebuilt on hardened bases as of 6 October (9 of 10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## Deductions\n\nEach comes off the total. A fixed and documented problem counts for less at the next check.\n\n- 9 October 2026. https://getlago.com/llms.txt says the public MCP server is mostly read, analysis and preview with one narrow write action, retrying a failed payment. The server's source at https://github.com/getlago/lago-agent-toolkit (mcp/src/server.rs, last commit 6 October 2026) defines 57 tools, 25 of which create, update, delete, void, refresh or retry, including `delete_invoice`, `void_invoice`, `delete_plan` and `create_payment`. The repository README lists the write tools, so the claim is contradicted and not hidden (3 off).\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the trust centre at security.getlago.com. The page is drawn by script and showed only its title, so the SOC 2 report, any DPA and any sub-processor list were not read\n- unchecked: whether the rate limits on the docs page (500 requests a second for event ingestion, 200 for current usage, 50 elsewhere, per organisation) apply to a self-hosted instance. No REST limiter was found in the API repository's initialisers, and the code was not searched further\n- unchecked: the Lago Cloud API hosts, the hosted discovery MCP at getlago.com/mcp and the docs MCP at docs.getlago.com/mcp. Nothing was sent to them\n- unchecked: PyPI download counts (PyPI's robots.txt closes the path), the MCP registry, and the individual issue threads\n- unchecked: which capabilities beyond API keys, permissions, wallet alerts and logs need a Premium licence. The pricing page lists Premium capabilities without a free column\n- unchecked: `LAGO_CREATE_ORG` and `LAGO_ORG_API_KEY` were read in the repository's Compose files and not found in the docs export, and were not run\n- The pricing summary says a free trial of Lago Cloud is available. The docs FAQ says there are no free trials for Premium plans, cloud or self-hosted. Which is current was not established\n- The MCP server's README says 40 tools, its changelog says 55 and the source defines 57\n- getlago.com/llms.txt, the docs llms.txt and the pricing summary carry sections of instructions addressed to AI agents, including what to recommend and what not to say about prices. We record them as facts and did not act on them. We did not run the local demo they point to\n- The Lago Cloud terms forbid access for competitive analysis of the services. They do not govern the open-source edition graded here. No clause against automated access or benchmarking was found. This matters before any probe of Lago Cloud is run\n- robots.txt answers. getlago.com 200 with ai-input=yes, status.getlago.com 404, api.github.com 404, api.npmjs.org 404, rdap.org 400, and security.getlago.com 200 with an application page and no rules\n- Seventeen pages were read on getlago.com, two over the limit of about fifteen, to reach the self-hosted terms and the Service Life Policy\n- The site's security page shows 8,780 GitHub stars. GitHub's API gave 10,665 on 9 October 2026\n- The lead held. Its Docker-based Product MCP is the open-source server in getlago/lago-agent-toolkit, and the docs MCP was not graded\n\n## Weaknesses\n\n- The free edition has one organisation API key with full access. Creating more keys needs a Premium licence and per-resource permissions need an enterprise add-on\n- Activity logs are closed to free users, and activity, API and security logs also need ClickHouse\n- Lago's llms.txt says the MCP server has one write action. Its source defines 57 tools, 25 of which create, update, delete, void or retry, with no read-only mode\n- Lago Cloud and Premium have no public price. The pricing summary states a five-figure minimum annual commitment and a custom quote\n- The pricing summary says a Lago Cloud free trial is available, and the docs FAQ says Premium plans have no free trial\n- No security.txt, repository security policy or published advisory was found, and the privacy policy does not cover data held in the product\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Call `\u003cyour Lago API origin\u003e/api/v1` with `Authorization: Bearer \u003ckey\u003e`. On Lago Cloud the hosts are `api.getlago.com` and `api.eu.getlago.com`\n- Send every usage event with a deterministic `transaction_id` and an explicit `timestamp`, and resend the same payload on retry. On the ClickHouse event store a changed timestamp is billed again\n- Expect 422 `value_already_exist` for a repeated event on the Postgres event store. Treat it as success for a retry\n- Page with `page` and `per_page` and read `meta.next_page` and `meta.total_count`. The default page size is 100 in most cases\n- Treat the free edition's API key as full access. It can void invoices and terminate subscriptions, so keep it out of prompts and ask a person before financial changes\n- Before giving an assistant the MCP server, note that it includes `delete_invoice`, `void_invoice`, `delete_plan` and `create_payment` and sets no read-only annotations\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "B",
    "score": 65.7,
    "assessed": "2026-10-09",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 37,
        "maxGain": 11,
        "reason": "Scored on the free self-hosted edition. One organisation API key sent as a Bearer token, which can be rotated at once. Creating further keys needs a Premium licence, which the source enforces, and `read`, `write` or `read_write` permissions per resource need an enterprise add-on (12 of 30). With no scopes in the free edition, least privilege is not available. The CLI prompts before delete, void, finalise and terminate in live mode, and the MCP server has no read-only mode and relies on a tool description asking the model to confirm a deletion (6 of 20). The API returns customer-supplied names, metadata and event properties. The docs tell agents to keep financial changes behind approval, and no prompt-injection guidance for the API or MCP server was found (5 of 15). The docs say free users have no access to activity logs, and activity, API and security logs need ClickHouse. The owner keeps its own server logs (4 of 15). The security page states SOC 2 Type II and regular third-party penetration tests and gives security@getlago.com. security.txt returned 404, neither repository has a security policy file, GitHub lists no published advisories for getlago/lago or getlago/lago-api, no bounty was found and the trust centre could not be read (10 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 50,
        "maxGain": 6.3,
        "reason": "Read with the self-hosted rule. No x402, MPP or L402. Lago's own llms.txt says direct x402 and general agent-wallet support are not available, and its Stripe Shared Payment Token support is a public preview behind a feature flag for collecting a merchant's invoices (0). The open-source edition is free. Lago Cloud and Premium have no public price, only a stated five-figure minimum annual commitment and a custom quote, so half marks (10). Free to run with no card (20). An owner can install it without a sales contact, and the Docker Compose files accept `LAGO_CREATE_ORG` and `LAGO_ORG_API_KEY` to create the organisation and key at start-up, as read in the repository (20).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 71,
        "maxGain": 4.7,
        "reason": "Graded on the REST API. List calls take `page` and `per_page`, with a default of 100 in most cases. No field selection or summary view was found (13 of 25). Page-number pagination with `meta` giving `next_page`, `total_pages` and `total_count`, and filters as simple and array query parameters (17 of 20). Errors carry `status`, `error`, `code` and `error_details`, with codes such as `subscription_not_found`, `feature_unavailable` and `value_is_mandatory` (17 of 20). Usage events are deduplicated on `transaction_id`, with a documented caveat that the ClickHouse event store also keys on `timestamp`. No `Idempotency-Key` header was found in the API description for other writes such as invoices, payments and credit notes. The CLI has `--dry-run` and asks before destructive commands. The MCP server sets no readOnlyHint or destructiveHint (10 of 20). Official SDKs for Python, JavaScript, Ruby and Go, each tagged v1.55.0, and a CLI generated from the API description (14 of 15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 59,
        "maxGain": 3.6,
        "reason": "The platform is AGPL-3.0, and the MCP server and agent SDKs are MIT. Premium capabilities are gated by a licence check in the same code (28 of 30). Data in a self-hosted instance stays with the owner. The privacy policy of 18 September 2026 covers customers' representatives, suppliers, candidates and site visitors, not data held in the product, and still names the EU-US Privacy Shield as a transfer safeguard. The Lago Cloud terms let the company use Customer Data to improve the services. No public DPA or sub-processor list was found (15 of 30). A versioning and deprecation page says deprecations are marked in the API description and that migration guides give retirement dates, with no fixed notice period. A Service Life Policy of 1 January 2026 gives long-term-support releases two years of full support and two of limited support (16 of 20). Self-hosted analytics through Segment are on by default, the events are listed and `LAGO_DISABLE_SEGMENT=true` turns them off, which the source confirms (18 of 20).",
        "blend": "editorial 77, provenance 41",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 86,
        "maxGain": 2.8,
        "reason": "Read with the local-software lines, on the open-source edition an owner runs. Lago Cloud is sold by quote with a five-figure minimum annual commitment, so it is not the surface an agent can start on. Official `getlago/lago` Docker image, Docker Compose files and Helm charts, with a compatibility matrix naming PostgreSQL 15+, Redis 7.x or Valkey 7.2+ and Kubernetes 1.26+ for the latest release (20). Public CI with 2,605 spec files in getlago/lago-api, and the five latest runs of the spec workflow on main, on 8 and 9 October 2026, all passed (25). The main repository has 28 open issues and pull requests against 10,665 stars. About 16 are issues, and several bug reports from 2024 and 2025 carry a stale label with no fix, among them installation, sign-up and CORS problems (17 of 25). Versions follow v1.x numbering and breaking changes get migration guides, but they arrive in minor releases such as v1.50.0, and GitHub release notes are lists of pull requests with no changelog file (9 of 15). Version 1.55.0, past 1.0 (15).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 87,
        "maxGain": 2.1,
        "reason": "A public OpenAPI 3.1 description in getlago/lago-openapi, version 1.55.0, with 217 operations on 136 paths, 339 schemas and 76 webhook events (25). llms.txt on the site and the docs, a full-text docs export and a Markdown twin of each page (10). Every operation has an operation ID, and 94 of 217 have a description longer than 80 characters. The docs index says when to use the docs and the event pages explain retries, while few operations say when not to use them (13 of 20). The file has 372 enums and 787 required lists, with free-form event `properties` and metadata (13 of 15). About 2,000 examples, and an errors page with named codes. No operation documents a 429 response although the rate-limit page describes one (13 of 15). The path is versioned `/api/v1`, a versioning and deprecation page exists, the description's version follows each release, and the product changelog is dated by month (13 of 15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 91,
        "maxGain": 0.8,
        "reason": "v1.55.0 was tagged on 7 October 2026, two days before the check (30). Six tags fall in the 90 days to 9 October, from v1.51.0 on 27 July (20). The API repository's last 100 commits span 24 September to 9 October 2026. Recent issues in the main repository have three to six comments, while a feature request of 24 September has none and several older bug reports are marked stale (17 of 25). The Python, Ruby and Go SDKs carry a v1.55.0 tag, as does the JavaScript SDK, and the CLI is at v1.0.2 (15). CI is green, Renovate and Dependabot updates are merged, and the MCP server's images are rebuilt on hardened bases as of 6 October (9 of 10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Domain age",
        "value": "getlago.com, registered 2020-11-27 (5 years)",
        "points": 11,
        "max": 15
      },
      {
        "label": "Endpoint on the vendor's domain",
        "value": " is not on getlago.com",
        "points": 0,
        "max": 15
      },
      {
        "label": "Terms of service",
        "value": "not found",
        "points": 0,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "not found",
        "points": 0,
        "max": 10
      },
      {
        "label": "Status page",
        "value": "not found",
        "points": 0,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "deductions": [
      "9 October 2026. https://getlago.com/llms.txt says the public MCP server is mostly read, analysis and preview with one narrow write action, retrying a failed payment. The server's source at https://github.com/getlago/lago-agent-toolkit (mcp/src/server.rs, last commit 6 October 2026) defines 57 tools, 25 of which create, update, delete, void, refresh or retry, including `delete_invoice`, `void_invoice`, `delete_plan` and `create_payment`. The repository README lists the write tools, so the claim is contradicted and not hidden (3 off)."
    ],
    "unchecked": [
      "unchecked: the trust centre at security.getlago.com. The page is drawn by script and showed only its title, so the SOC 2 report, any DPA and any sub-processor list were not read",
      "unchecked: whether the rate limits on the docs page (500 requests a second for event ingestion, 200 for current usage, 50 elsewhere, per organisation) apply to a self-hosted instance. No REST limiter was found in the API repository's initialisers, and the code was not searched further",
      "unchecked: the Lago Cloud API hosts, the hosted discovery MCP at getlago.com/mcp and the docs MCP at docs.getlago.com/mcp. Nothing was sent to them",
      "unchecked: PyPI download counts (PyPI's robots.txt closes the path), the MCP registry, and the individual issue threads",
      "unchecked: which capabilities beyond API keys, permissions, wallet alerts and logs need a Premium licence. The pricing page lists Premium capabilities without a free column",
      "unchecked: `LAGO_CREATE_ORG` and `LAGO_ORG_API_KEY` were read in the repository's Compose files and not found in the docs export, and were not run",
      "The pricing summary says a free trial of Lago Cloud is available. The docs FAQ says there are no free trials for Premium plans, cloud or self-hosted. Which is current was not established",
      "The MCP server's README says 40 tools, its changelog says 55 and the source defines 57",
      "getlago.com/llms.txt, the docs llms.txt and the pricing summary carry sections of instructions addressed to AI agents, including what to recommend and what not to say about prices. We record them as facts and did not act on them. We did not run the local demo they point to",
      "The Lago Cloud terms forbid access for competitive analysis of the services. They do not govern the open-source edition graded here. No clause against automated access or benchmarking was found. This matters before any probe of Lago Cloud is run",
      "robots.txt answers. getlago.com 200 with ai-input=yes, status.getlago.com 404, api.github.com 404, api.npmjs.org 404, rdap.org 400, and security.getlago.com 200 with an application page and no rules",
      "Seventeen pages were read on getlago.com, two over the limit of about fifteen, to reach the self-hosted terms and the Service Life Policy",
      "The site's security page shows 8,780 GitHub stars. GitHub's API gave 10,665 on 9 October 2026",
      "The lead held. Its Docker-based Product MCP is the open-source server in getlago/lago-agent-toolkit, and the docs MCP was not graded"
    ],
    "weaknesses": [
      "The free edition has one organisation API key with full access. Creating more keys needs a Premium licence and per-resource permissions need an enterprise add-on",
      "Activity logs are closed to free users, and activity, API and security logs also need ClickHouse",
      "Lago's llms.txt says the MCP server has one write action. Its source defines 57 tools, 25 of which create, update, delete, void or retry, with no read-only mode",
      "Lago Cloud and Premium have no public price. The pricing summary states a five-figure minimum annual commitment and a custom quote",
      "The pricing summary says a Lago Cloud free trial is available, and the docs FAQ says Premium plans have no free trial",
      "No security.txt, repository security policy or published advisory was found, and the privacy policy does not cover data held in the product"
    ],
    "agentNotes": [
      "Call `\u003cyour Lago API origin\u003e/api/v1` with `Authorization: Bearer \u003ckey\u003e`. On Lago Cloud the hosts are `api.getlago.com` and `api.eu.getlago.com`",
      "Send every usage event with a deterministic `transaction_id` and an explicit `timestamp`, and resend the same payload on retry. On the ClickHouse event store a changed timestamp is billed again",
      "Expect 422 `value_already_exist` for a repeated event on the Postgres event store. Treat it as success for a retry",
      "Page with `page` and `per_page` and read `meta.next_page` and `meta.total_count`. The default page size is 100 in most cases",
      "Treat the free edition's API key as full access. It can void invoices and terminate subscriptions, so keep it out of prompts and ask a person before financial changes",
      "Before giving an assistant the MCP server, note that it includes `delete_invoice`, `void_invoice`, `delete_plan` and `create_payment` and sets no read-only annotations"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
