# Fix list: Vercel Connect From Anchor Terminal's listing at https://www.anchorterminal.com/tools/vercel-connect, the October 2026 research run, assessed 8 October 2026. Grade B, 68.8 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Vercel Connect: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 40 out of 100, up to 7.5 more on the total Why it scored 40: No x402, MPP or L402 (0). Unit prices are public without a login, $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on Pro (20). Hobby includes 500 token requests and 1,000 triggers a month at no charge, for non-commercial use, and the Hobby plan page names no card (20). A person signs up in a browser, and connectors and user consent also pass through a browser (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Reliability, 63 out of 100, up to 7.4 more on the total Why it scored 63: Graded on the hosted lines. Connect is a component on www.vercel-status.com with an incident feed (20). The feed has elevated error rates on Connect and Passport for 1 hour 34 minutes on 10 September 2026, marked major, and elevated KMS and Connect errors posted for 18 September, which we read as one major (10). Rate limits published with numbers, 200 reads and 50 writes a minute per team and 6,000 a minute on the OAuth gateway and trigger endpoints (15). A 429 is documented with a one-minute wait and token requests are safe to repeat, but we found no Retry-After header or idempotency keys for writes (8). Vercel's SLA says it does not apply to the APIs or CLI (0). Generally available since 25 August 2026, with Salesforce and Linq connectors still beta (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 3. Agent ergonomics, 75 out of 100, up to 4.1 more on the total Why it scored 75: A token call returns one token with its expiry and identifiers, so there is little to size (22). Listing connectors takes `limit`, `cursor`, `search`, `projectId` and `type` (18). Errors are typed and each maps to a next step, such as starting consent or attaching the project, but the 429 carries no documented wait header (17). Token requests are cached and safe to repeat, and we found no idempotency keys for create, attach or revoke (10). Only the connector and subject are required and scopes default to the connector's own, but the one official SDK is TypeScript, with a CLI and plain HTTP for everything else (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Security & auth, 83 out of 100, up to 3 more on the total Why it scored 83: Callers present a project-bound OIDC token or a Vercel access token, provider tokens are short-lived and scoped per request, refresh tokens stay with Vercel, and grants can be revoked from the SDK, CLI or dashboard (28). Project links limit which environments may ask, requests can narrow scopes and resources, and Pro and Enterprise can restrict who manages connectors. There is no approval step before a token is issued, omitted scopes default to `['*']`, and revocation depends on the provider (14). The API returns tokens, not untrusted content (10). Token requests, authorisations and revocations are logged with correlation IDs, kept 12 hours on Hobby, 3 days on Pro and 30 days on Enterprise, with drains on paid plans (13). Valid security.txt, HackerOne, SOC 2 Type 2 and ISO 27001:2022 as Vercel states them, and a public bulletin for the April 2026 incident (18). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 5. Schema & documentation, 84 out of 100, up to 2.6 more on the total Why it scored 84: Vercel's public OpenAPI 3.0.3 document has 13 Connect paths, the token and authorise calls among them (25). Docs are served as Markdown on request and vercel.com/llms.txt exists (10). The docs say when to use Connect and when a Vercel Integration fits better, and give a use-when line for each subject type (16). The token body types the subject as a union with enums, but most variants allow extra properties, `authorizationDetails` is open and scopes are provider strings (10). Examples are plentiful and six SDK error classes are documented with fixes, while the OpenAPI error responses for the token call have empty descriptions (11). Paths are versioned and the SDK follows semver with a dated product changelog, though the package changelog in the public repository stops at 2.0.2 (12). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Transparency & trust, 77 out of 100, up to 2 more on the total Made of editorial 55, provenance 99. Why it scored 77: Closed service under the Terms of Service of 1 June 2026 plus short Connect product terms, with an Apache-2.0 SDK and CLI (20). A privacy notice and a DPA exist, and the docs say refresh tokens are stored on Vercel's infrastructure and give event retention by plan. We found no retention period or encryption statement for stored provider credentials, and the DPA covers Pro and Enterprise only (18). No deprecation policy found. The product terms let Vercel remove third-party platforms without notice, though the beta price change was announced with a date of 25 September 2026 (5). The DPA points to a subprocessor list on security.vercel.com and says primary processing is in the United States. We saw the list's page but could not read its entries (12). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10) ## 7. Maintenance & community, 81 out of 100, up to 1.7 more on the total Why it scored 81: `@vercel/connect` 2.4.1 was published on 6 October 2026 (30). npm shows 30 versions since 2 July 2026, and the changelog has Connect entries on 11 and 25 August and 11 and 21 September (20). Closed service with a dated public changelog. The public copy of the SDK in vercel/vercel was last synced on 8 September 2026 and stops at 2.0.2, and we didn't read issue replies (10). One current official SDK, with 738,165 npm downloads in the week to 4 October 2026 (15). One runtime dependency and 13 test files in the package. We didn't confirm CI status on the default branch (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - April 2026. Vercel's security bulletin says an attacker took over an employee's account through a compromised third-party AI tool, reached internal systems and decrypted non-sensitive environment variables of a limited subset of customers. It predates Connect's general availability on 25 August 2026 and is documented with remediation, so 3 of a possible 15 is taken, because Connect now keeps customers' provider refresh tokens on the same platform (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the entries of the subprocessor list on security.vercel.com, which is drawn by script. We saw only that the page has a Subprocessors section. - unchecked: whether Hobby signup asks for a card. The Hobby plan page names none, and we did not open the signup flow. - unchecked: CI status for packages/connect on the default branch of vercel/vercel, and issue replies there. - Whether failed or cached token requests are billed. The pricing page defines a token request as a call that returns a provider token. - How stored provider refresh tokens and API keys are encrypted and how long they are kept after a connector is deleted. Not found in the reviewed documentation. - Whether a REST path for revocation is public. The docs say tokens can be revoked through the REST API, and the OpenAPI document has no Connect revoke path. - The deduction of 3 for the April 2026 incident is a judgement call. The existing vercel-sandbox listing took none for the same bulletin. - The 18 September 2026 status entry for KMS and Connect errors has no duration, so its length is unknown. - The count of 1,083 catalogue services is ours, from the Markdown of /connect/browse. Vercel's own figure at launch was 100+ preset connectors. ## Weaknesses - Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment - Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page - Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise - Revocation depends on the provider. Without a revocation endpoint the provider credential can work until it expires - The SDK is TypeScript only, and the public repository's copy stops at 2.0.2 while npm has 2.4.1 ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry - Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes - Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser - Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user - On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.