{
  "fixes": {
    "slug": "phrase",
    "name": "Phrase",
    "listing": "https://www.anchorterminal.com/tools/phrase",
    "markdown": "# Fix list: Phrase\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/phrase, the October 2026 research run, assessed 8 October 2026. Grade B, 64.2 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Phrase: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Reliability, 55 out of 100, up to 9 more on the total\n\nWhy it scored 55: Hosted reading, for the public APIs and the hosted MCP server. status.phrase.com on Statuspage, with components for Strings, TMS and the Language AI API in the EU and the US (20). Its feed lists 14 incidents between 10 July and 8 October 2026, two marked critical, ten major and two minor. Most were degraded performance in one component, such as TMS project management for about three and a half hours on 31 August and Strings branching for about 19 hours on 6 and 7 August, and none is titled as a full API outage. Larger ones have post-mortems (5 of 30). Strings publishes 1,000 requests in 5 minutes and 4 concurrent, TMS 6,000 a minute and 100 concurrent, and no figure was found for Language AI (12 of 15). 429 responses carry `X-Rate-Limit-Reset` and `X-Rate-Limit-Reason` on Strings and `Ratelimit-Remaining` on TMS. No `Retry-After`, backoff guidance or idempotency keys were found in the reviewed documentation (8 of 15). No SLA in the public terms, which disclaim uninterrupted availability (0). The APIs and the MCP server are generally available (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 2. Payments \u0026 pricing, 30 out of 100, up to 8.8 more on the total\n\nWhy it scored 30: No x402, MPP or L402 (0). Plan prices are public, $27, $525 and $1,245 a month billed annually, with included capacities and the MTU conversion published. Top-up prices and the Business and Enterprise plans are quoted by sales, so plan-only credit (10). A 14-day trial whose signup form asks for an email address and a password, with no automatic charge afterwards (20). A person signs up in a browser, and the MCP server needs a Phrase account login (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 3. Security \u0026 auth, 58 out of 100, up to 7.4 more on the total\n\nWhy it scored 58: The hosted MCP server uses OAuth with PKCE, dynamic client registration and three scopes. Service accounts use the client credentials grant limited by product and scope, and platform tokens are exchanged for JWTs that last about four hours (30). Less 10 because the Strings docs give an `access_token` query parameter as an option, and still document Basic authentication with email and password (20 of 30). View, create and delete consents on MCP, revocable under the Consents tab, with role permissions still applied. No confirmation step for destructive calls was found (15 of 20). Tools return customer strings, comments and translations, and no prompt-injection guidance was found (3 of 15). Each user sees their login history, while audit logs are held by Phrase engineers and supplied on request (6 of 15). ISO 27001 certificate, SOC 2 Type I with Type II expected in 2026, annual third-party penetration tests and a disclosure address at security@phrase.com. No security.txt and no bug bounty found (14 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 4. Agent ergonomics, 70 out of 100, up to 4.9 more on the total\n\nWhy it scored 70: API reading of the checklist, with the hosted MCP server noted where its behaviour is documented. Strings lists return 25 items by default with `per_page` up to 100, and locale downloads support ETag. The hosted MCP server's tool list isn't published, and the deprecated local server listed 145 tools (17 of 25). `page` and `per_page` with `Link` headers, and filters on list endpoints (18 of 20). Strings returns a message on 400 and field-level errors on 422, and names the limit hit on 429. Language AI error bodies are undocumented (14 of 20). No idempotency keys. Conditional GETs are safe to repeat, and the MCP consent separates view, create, and modify and delete (8 of 20). Language AI needs three fields, six official Strings clients and a CLI exist, but a missing `User-Agent` header earns a 400 and the clients cover Strings alone (13 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 5. Transparency \u0026 trust, 74 out of 100, up to 2.3 more on the total\n\nMade of editorial 65, provenance 82.\n\nWhy it scored 74: Closed service with published terms, and the CLI, clients and local MCP server under MIT (15). The privacy notice of 6 October 2026, the Data Processing Addendum and the AI statement agree on processor status, a 60-day deletion period and which products train on customer content. The terms still permit training non-text models, and any model for internal research, on customer content without approval (22 of 30). Deprecations are announced in the changelog with dates, such as the Quality Evaluator v1 and v2 endpoints on 2 July 2026, but without removal dates, and no written notice period was found (10 of 20). A sub-processor list with locations and transfer mechanisms, a choice of EU or US data centre, and hosting on AWS and Google Cloud disclosed (18 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Terms of service: read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points (4.3 of 10)\n- Privacy policy: read, states 8 of the 8 things a reader expects, and has 1 clause that costs points (8 of 10)\n- security.txt: not found (0 of 10)\n\n## 6. Schema \u0026 documentation, 87 out of 100, up to 2.1 more on the total\n\nWhy it scored 87: OpenAPI 3 specs for all nine APIs at developers.phrase.com/openapi, among them Strings with 301 operations and TMS with 547 (25). llms.txt and a Markdown copy of every docs page (10). Every Strings and Language AI operation has a description, 390 of 547 TMS operations do, and a page titled Choose the right API says which API fits which job. Few operations say when not to use them (14 of 20). Language AI inputs carry length limits, item counts and enums. The Strings spec has 49 enums across 301 operations (11 of 15). Strings documents 400, 401, 403, 404 and 429 on nearly every operation with 896 examples, while the Language AI error responses have no body schema (12 of 15). Versioned paths, four TMS versions to pin, and a dated changelog (15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 7. Maintenance \u0026 community, 83 out of 100, up to 1.5 more on the total\n\nWhy it scored 83: The changelog's latest entry is 6 October 2026, and the CLI's latest release is 2.69.1 of 23 September (30). 21 dated changelog entries since 10 July 2026 (20). A public changelog, a help centre and written support around the clock on paid plans. We didn't read the GitHub issues (11 of 15). The hosted MCP server is in the official MCP registry as `io.github.phrase/mcp`, and `phrase-js` 3.27.0 is current (15). The CLI has release and vulnerability workflows. The local MCP server was deprecated on 7 August 2026, under six months after its first tag (7 of 10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the hosted MCP server's tool list, schemas and annotations, which need a signed-in Phrase account. `toolCount` is left empty.\n- unchecked: trust.phrase.com, which renders only in a browser, so the SOC 2 and ISO 27001 details come from phrase.com/security.\n- unchecked: GitHub issues on phrase/phrase-cli and phrase/phrase-mcp-server, beyond the open counts of 4 and 12.\n- No rate limit figure for the Language AI API and no public SLA were found in the reviewed documentation.\n- Whether the Strings API's default limit is 1,000 requests in 5 minutes on every plan is unclear. The pricing page lists 500 for Software UI/UX and Team and 1,000 for Business without a unit.\n- The lead was right about the interfaces. It didn't say that the local npm MCP server is deprecated since 7 August 2026, which leaves the hosted server as the MCP surface.\n- Anthropic, whose models wrote this grade, is one of Phrase's listed LLM sub-processors. No score depends on that.\n\n## Weaknesses\n\n- status.phrase.com lists 14 incidents between 10 July and 8 October 2026, two marked critical and ten major, most confined to one component\n- The terms of 4 October 2026 let Phrase train non-text models on customer content without approval, and prohibit use for benchmarking\n- The Strings API still documents email and password Basic authentication and an `access_token` query parameter\n- No idempotency keys, no `Retry-After` header in the docs and no published rate limit for the Language AI API\n- The hosted MCP server's tool list isn't published, and the local npm server was deprecated on 7 August 2026, under six months after its first release\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Exchange a Phrase Platform API token at `https://eu.phrase.com/idm/oauth/token` (or `us.phrase.com`) for a Bearer JWT, which lasts about four hours, and refresh it before it expires\n- Send a `User-Agent` header naming your application on every Strings and TMS call. The Strings API answers 400 without one\n- Keep Strings calls under 1,000 in five minutes and four in parallel, and read `X-Rate-Limit-Reset` and `X-Rate-Limit-Reason` on a 429\n- Send at most six texts of 2,000 characters to `/v2/textTranslations`, with `consumerId` and `targetLang`. Term bases and translation memories work only with an AI translation agent profile\n- Use the MCP URL for the account's region, `https://mcp.eu.phrase.com` or `https://mcp.us.phrase.com`, and ask the user for the view consent alone unless the task writes\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "B",
    "score": 64.2,
    "assessed": "2026-10-08",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 55,
        "maxGain": 9,
        "reason": "Hosted reading, for the public APIs and the hosted MCP server. status.phrase.com on Statuspage, with components for Strings, TMS and the Language AI API in the EU and the US (20). Its feed lists 14 incidents between 10 July and 8 October 2026, two marked critical, ten major and two minor. Most were degraded performance in one component, such as TMS project management for about three and a half hours on 31 August and Strings branching for about 19 hours on 6 and 7 August, and none is titled as a full API outage. Larger ones have post-mortems (5 of 30). Strings publishes 1,000 requests in 5 minutes and 4 concurrent, TMS 6,000 a minute and 100 concurrent, and no figure was found for Language AI (12 of 15). 429 responses carry `X-Rate-Limit-Reset` and `X-Rate-Limit-Reason` on Strings and `Ratelimit-Remaining` on TMS. No `Retry-After`, backoff guidance or idempotency keys were found in the reviewed documentation (8 of 15). No SLA in the public terms, which disclaim uninterrupted availability (0). The APIs and the MCP server are generally available (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 30,
        "maxGain": 8.8,
        "reason": "No x402, MPP or L402 (0). Plan prices are public, $27, $525 and $1,245 a month billed annually, with included capacities and the MTU conversion published. Top-up prices and the Business and Enterprise plans are quoted by sales, so plan-only credit (10). A 14-day trial whose signup form asks for an email address and a password, with no automatic charge afterwards (20). A person signs up in a browser, and the MCP server needs a Phrase account login (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 58,
        "maxGain": 7.4,
        "reason": "The hosted MCP server uses OAuth with PKCE, dynamic client registration and three scopes. Service accounts use the client credentials grant limited by product and scope, and platform tokens are exchanged for JWTs that last about four hours (30). Less 10 because the Strings docs give an `access_token` query parameter as an option, and still document Basic authentication with email and password (20 of 30). View, create and delete consents on MCP, revocable under the Consents tab, with role permissions still applied. No confirmation step for destructive calls was found (15 of 20). Tools return customer strings, comments and translations, and no prompt-injection guidance was found (3 of 15). Each user sees their login history, while audit logs are held by Phrase engineers and supplied on request (6 of 15). ISO 27001 certificate, SOC 2 Type I with Type II expected in 2026, annual third-party penetration tests and a disclosure address at security@phrase.com. No security.txt and no bug bounty found (14 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 70,
        "maxGain": 4.9,
        "reason": "API reading of the checklist, with the hosted MCP server noted where its behaviour is documented. Strings lists return 25 items by default with `per_page` up to 100, and locale downloads support ETag. The hosted MCP server's tool list isn't published, and the deprecated local server listed 145 tools (17 of 25). `page` and `per_page` with `Link` headers, and filters on list endpoints (18 of 20). Strings returns a message on 400 and field-level errors on 422, and names the limit hit on 429. Language AI error bodies are undocumented (14 of 20). No idempotency keys. Conditional GETs are safe to repeat, and the MCP consent separates view, create, and modify and delete (8 of 20). Language AI needs three fields, six official Strings clients and a CLI exist, but a missing `User-Agent` header earns a 400 and the clients cover Strings alone (13 of 15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 74,
        "maxGain": 2.3,
        "reason": "Closed service with published terms, and the CLI, clients and local MCP server under MIT (15). The privacy notice of 6 October 2026, the Data Processing Addendum and the AI statement agree on processor status, a 60-day deletion period and which products train on customer content. The terms still permit training non-text models, and any model for internal research, on customer content without approval (22 of 30). Deprecations are announced in the changelog with dates, such as the Quality Evaluator v1 and v2 endpoints on 2 July 2026, but without removal dates, and no written notice period was found (10 of 20). A sub-processor list with locations and transfer mechanisms, a choice of EU or US data centre, and hosting on AWS and Google Cloud disclosed (18 of 20).",
        "blend": "editorial 65, provenance 82",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 87,
        "maxGain": 2.1,
        "reason": "OpenAPI 3 specs for all nine APIs at developers.phrase.com/openapi, among them Strings with 301 operations and TMS with 547 (25). llms.txt and a Markdown copy of every docs page (10). Every Strings and Language AI operation has a description, 390 of 547 TMS operations do, and a page titled Choose the right API says which API fits which job. Few operations say when not to use them (14 of 20). Language AI inputs carry length limits, item counts and enums. The Strings spec has 49 enums across 301 operations (11 of 15). Strings documents 400, 401, 403, 404 and 429 on nearly every operation with 896 examples, while the Language AI error responses have no body schema (12 of 15). Versioned paths, four TMS versions to pin, and a dated changelog (15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 83,
        "maxGain": 1.5,
        "reason": "The changelog's latest entry is 6 October 2026, and the CLI's latest release is 2.69.1 of 23 September (30). 21 dated changelog entries since 10 July 2026 (20). A public changelog, a help centre and written support around the clock on paid plans. We didn't read the GitHub issues (11 of 15). The hosted MCP server is in the official MCP registry as `io.github.phrase/mcp`, and `phrase-js` 3.27.0 is current (15). The CLI has release and vulnerability workflows. The local MCP server was deprecated on 7 August 2026, under six months after its first tag (7 of 10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Terms of service",
        "value": "read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points",
        "points": 4.3,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
        "points": 8,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "unchecked": [
      "unchecked: the hosted MCP server's tool list, schemas and annotations, which need a signed-in Phrase account. `toolCount` is left empty.",
      "unchecked: trust.phrase.com, which renders only in a browser, so the SOC 2 and ISO 27001 details come from phrase.com/security.",
      "unchecked: GitHub issues on phrase/phrase-cli and phrase/phrase-mcp-server, beyond the open counts of 4 and 12.",
      "No rate limit figure for the Language AI API and no public SLA were found in the reviewed documentation.",
      "Whether the Strings API's default limit is 1,000 requests in 5 minutes on every plan is unclear. The pricing page lists 500 for Software UI/UX and Team and 1,000 for Business without a unit.",
      "The lead was right about the interfaces. It didn't say that the local npm MCP server is deprecated since 7 August 2026, which leaves the hosted server as the MCP surface.",
      "Anthropic, whose models wrote this grade, is one of Phrase's listed LLM sub-processors. No score depends on that."
    ],
    "weaknesses": [
      "status.phrase.com lists 14 incidents between 10 July and 8 October 2026, two marked critical and ten major, most confined to one component",
      "The terms of 4 October 2026 let Phrase train non-text models on customer content without approval, and prohibit use for benchmarking",
      "The Strings API still documents email and password Basic authentication and an `access_token` query parameter",
      "No idempotency keys, no `Retry-After` header in the docs and no published rate limit for the Language AI API",
      "The hosted MCP server's tool list isn't published, and the local npm server was deprecated on 7 August 2026, under six months after its first release"
    ],
    "agentNotes": [
      "Exchange a Phrase Platform API token at `https://eu.phrase.com/idm/oauth/token` (or `us.phrase.com`) for a Bearer JWT, which lasts about four hours, and refresh it before it expires",
      "Send a `User-Agent` header naming your application on every Strings and TMS call. The Strings API answers 400 without one",
      "Keep Strings calls under 1,000 in five minutes and four in parallel, and read `X-Rate-Limit-Reset` and `X-Rate-Limit-Reason` on a 429",
      "Send at most six texts of 2,000 characters to `/v2/textTranslations`, with `consumerId` and `targetLang`. Term bases and translation memories work only with an AI translation agent profile",
      "Use the MCP URL for the account's region, `https://mcp.eu.phrase.com` or `https://mcp.us.phrase.com`, and ask the user for the view consent alone unless the task writes"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
