{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/late.json",
        "name": "Zernio (formerly Late) API + MCP",
        "score": 67.5,
        "shared": [
          "social.post",
          "social.schedule",
          "social.analytics",
          "social.comments",
          "social.media-upload"
        ],
        "slug": "late"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/upload-post.json",
        "name": "Upload-Post API + MCP",
        "score": 58.7,
        "shared": [
          "social.post",
          "social.schedule",
          "social.analytics",
          "social.comments",
          "social.media-upload"
        ],
        "slug": "upload-post"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/ayrshare.json",
        "name": "Ayrshare API + MCP",
        "score": 57.2,
        "shared": [
          "social.post",
          "social.schedule",
          "social.analytics",
          "social.comments",
          "social.media-upload"
        ],
        "slug": "ayrshare"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/blotato.json",
        "name": "Blotato",
        "score": 46.1,
        "shared": [
          "social.post",
          "social.schedule",
          "social.analytics",
          "social.comments",
          "social.media-upload"
        ],
        "slug": "blotato"
      },
      {
        "grade": "F",
        "json": "https://www.anchorterminal.com/tools/oneup.json",
        "name": "OneUp API + MCP",
        "score": 24.4,
        "shared": [
          "social.post",
          "social.schedule",
          "social.analytics",
          "social.comments",
          "social.media-upload"
        ],
        "slug": "oneup"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/postiz.json",
        "name": "Postiz API + MCP",
        "score": 59.3,
        "shared": [
          "social.post",
          "social.schedule",
          "social.analytics",
          "social.media-upload"
        ],
        "slug": "postiz"
      }
    ],
    "tool": {
      "slug": "bundle-social",
      "name": "bundle.social",
      "vendor": "BUNDLE SP. Z O.O.",
      "vendorUrl": "https://bundle.social",
      "kind": "http-api",
      "category": "social-media",
      "summary": "bundle.social is a hosted REST API from BUNDLE SP. Z O.O. in Warsaw for publishing, scheduling, commenting and reading analytics across 15 social networks. It also ships a TypeScript SDK, a CLI and a local MCP server.",
      "url": "https://www.anchorterminal.com/tools/bundle-social",
      "markdownUrl": "https://www.anchorterminal.com/tools/bundle-social.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bundle-social.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bundle-social.json",
      "repo": "https://github.com/bundleglobal/bundlesocial-node",
      "license": "Proprietary hosted service under bundle.social's terms of service. The TypeScript SDK, the CLI and the MCP server on GitHub are MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.bundle.social/api/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "bundlesocial"
        },
        {
          "registry": "npm",
          "name": "bundlesocial-mcp"
        },
        {
          "registry": "npm",
          "name": "bundlesocial-cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve organisation API key sent in the `x-api-key` header, created and rolled in the dashboard after a browser sign-up, up to 50 keys an organisation. Keys carry no scopes and reach every team. Connecting a social account needs a person to complete that network's OAuth consent through a hosted connect link.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 20 posts a month, three teams and API access, no payment details needed. Pro is $100 a month for 10,000 posts and Business $400 for 100,000, both with unlimited connected accounts. Enterprise is quoted. X actions are charged from prepaid credit at X's rates (https://bundle.social/pricing.md).",
      "priceSummary": "$100 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in llms.txt, pricing.md, the docs index or the OpenAPI description in the SDK repository (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": 68,
      "popularity": {
        "githubStars": 2,
        "npmWeekly": 4095,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://info.bundle.social",
      "llmsTxt": "https://bundle.social/llms.txt",
      "openapi": "https://api.bundle.social/swagger-json",
      "capabilities": [
        "social.post",
        "social.schedule",
        "social.analytics",
        "social.comments",
        "social.media-upload"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "api-key",
        "openapi",
        "llms-txt",
        "mcp",
        "cli",
        "typescript",
        "webhooks",
        "status-page"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.1,
        "grade": "C",
        "agentReady": false,
        "rank": 530,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 78,
          "payments": 35,
          "reliability": 63,
          "schema": 86,
          "security": 34,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 63,
            "points": 12.6,
            "reason": "Graded as a hosted API. Better Stack status page with two components and 90 days of history (20). One incident in 90 days, on 31 August 2026, with the API down for 4 hours 3 minutes and 99.793 per cent uptime shown (10). Rate limits published as 100 a second, 500 per 10 seconds and 2,000 a minute, plus daily caps per network (15). The docs ask for exponential backoff on 429 and flag platform errors with `isTransient`, but no Retry-After header or idempotency key was found (8). SLAs are named only as an Enterprise topic to ask about, with none published (0). The core API is generally available, with DMs and automations in beta (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 86,
            "points": 13.98,
            "reason": "OpenAPI 3.0.2 with 145 paths and 194 operations, linked from the docs and read from the copy in the SDK repository (25). llms.txt, llms-full.txt, pricing.md and a Markdown copy of each docs page (10). Every operation has a description and many say when to call it (15). 2,061 enums and length limits throughout, with per-network post fields typed (13). Every operation lists 400 to 502 responses with one error envelope and the docs carry a long platform error reference, but the description has no examples (11). Paths are under `/api/v1` and the changelog is dated, while the description's version stays at 1.0.0 (12)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 66,
            "points": 10.73,
            "reason": "Graded on the REST API. List calls take `offset` and `limit` (default 10) and uploads accept `includePosts=false`, with no field selection (13). Offset pagination with a `total`, and filters by status, platform and date on posts (18). Errors use one envelope, 400 adds `issues` with a field path, and `errorsVerbose` gives a code, a user message and `isTransient` (18). No idempotency key. `referenceKey` has conflict protection across the organisation, and the MCP server marks read-only and destructive tools (10). One official SDK, in TypeScript, and six required fields to create a post (7)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 34,
            "points": 5.95,
            "reason": "Organisation API keys in the `x-api-key` header, up to 50 an organisation, created and rolled in the dashboard, with no scopes (20). No read-only key or approval step found. The MCP server sets destructiveHint on 8 tools and posts can be created as drafts (4). Comments, reviews and DMs return text written by strangers and no prompt-injection guidance was found (0). Webhook deliveries can be inspected and API logs are kept 7 days internally, with no customer audit log found (2). security.txt is valid until 7 April 2027 and the docs publish a disclosure policy with response times and a no-action promise. No bug bounty, SOC 2 or ISO 27001 was found (8)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 35,
            "points": 4.38,
            "reason": "No x402, MPP or L402 (0). Prices are public and machine-readable in pricing.md. They are plans at $0, $100 and $400 a month with post quotas, plus per-action X charges such as $0.015 a post, so we scored between plan-only and per-unit (15). The free plan has 20 posts a month and needs no payment details (20). A person creates the organisation and first key in the dashboard (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 78,
            "points": 6.83,
            "reason": "The `bundlesocial` SDK reached 2.66.0 on 6 October 2026 and the changelog's newest entry is 30 September 2026 (30). 17 SDK tags and four changelog entries since 11 July 2026 (20). Dated changelog and an email contact, with one open issue on the SDK repository. No community channel was verified (8). The TypeScript SDK is regenerated from the OpenAPI description. The MCP server was not found in the official registry and its server.json still says 1.0.0 against package 1.2.0 (12). Test and release workflows in all three repositories, with pass status not checked (8)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 65,
            "points": 5.69,
            "note": "editorial 44, provenance 86",
            "reason": "Closed service under terms dated 14 July 2026 that name the API. The SDK, CLI and MCP server are MIT (15). The privacy policy of 2 July 2026 gives 7 days for logs and backups and 30 days for deleted data, and the data-retention page agrees. Customer content is not used to train third-party AI models. The DPA is on request only (18). No deprecation policy. The changelog dated the move to prepaid X billing (announced 20 July, live 16 August 2026), and the terms promise notice where reasonably possible (7). No sub-processor list. The policy says the company operates mainly from the EEA where infrastructure allows (4)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. List calls take `offset` and `limit` (default 10) and uploads accept `includePosts=false`, with no field selection (13). Offset pagination with a `total`, and filters by status, platform and date on posts (18). Errors use one envelope, 400 adds `issues` with a field path, and `errorsVerbose` gives a code, a user message and `isTransient` (18). No idempotency key. `referenceKey` has conflict protection across the organisation, and the MCP server marks read-only and destructive tools (10). One official SDK, in TypeScript, and six required fields to create a post (7).",
            "maintenance": "The `bundlesocial` SDK reached 2.66.0 on 6 October 2026 and the changelog's newest entry is 30 September 2026 (30). 17 SDK tags and four changelog entries since 11 July 2026 (20). Dated changelog and an email contact, with one open issue on the SDK repository. No community channel was verified (8). The TypeScript SDK is regenerated from the OpenAPI description. The MCP server was not found in the official registry and its server.json still says 1.0.0 against package 1.2.0 (12). Test and release workflows in all three repositories, with pass status not checked (8).",
            "payments": "No x402, MPP or L402 (0). Prices are public and machine-readable in pricing.md. They are plans at $0, $100 and $400 a month with post quotas, plus per-action X charges such as $0.015 a post, so we scored between plan-only and per-unit (15). The free plan has 20 posts a month and needs no payment details (20). A person creates the organisation and first key in the dashboard (0).",
            "reliability": "Graded as a hosted API. Better Stack status page with two components and 90 days of history (20). One incident in 90 days, on 31 August 2026, with the API down for 4 hours 3 minutes and 99.793 per cent uptime shown (10). Rate limits published as 100 a second, 500 per 10 seconds and 2,000 a minute, plus daily caps per network (15). The docs ask for exponential backoff on 429 and flag platform errors with `isTransient`, but no Retry-After header or idempotency key was found (8). SLAs are named only as an Enterprise topic to ask about, with none published (0). The core API is generally available, with DMs and automations in beta (10).",
            "schema": "OpenAPI 3.0.2 with 145 paths and 194 operations, linked from the docs and read from the copy in the SDK repository (25). llms.txt, llms-full.txt, pricing.md and a Markdown copy of each docs page (10). Every operation has a description and many say when to call it (15). 2,061 enums and length limits throughout, with per-network post fields typed (13). Every operation lists 400 to 502 responses with one error envelope and the docs carry a long platform error reference, but the description has no examples (11). Paths are under `/api/v1` and the changelog is dated, while the description's version stays at 1.0.0 (12).",
            "security": "Organisation API keys in the `x-api-key` header, up to 50 an organisation, created and rolled in the dashboard, with no scopes (20). No read-only key or approval step found. The MCP server sets destructiveHint on 8 tools and posts can be created as drafts (4). Comments, reviews and DMs return text written by strangers and no prompt-injection guidance was found (0). Webhook deliveries can be inspected and API logs are kept 7 days internally, with no customer audit log found (2). security.txt is valid until 7 April 2027 and the docs publish a disclosure policy with response times and a no-action promise. No bug bounty, SOC 2 or ISO 27001 was found (8).",
            "transparency": "Closed service under terms dated 14 July 2026 that name the API. The SDK, CLI and MCP server are MIT (15). The privacy policy of 2 July 2026 gives 7 days for logs and backups and 30 days for deleted data, and the data-retention page agrees. Customer content is not used to train third-party AI models. The DPA is on request only (18). No deprecation policy. The changelog dated the move to prepaid X billing (announced 20 July, live 16 August 2026), and the terms promise notice where reasonably possible (7). No sub-processor list. The policy says the company operates mainly from the EEA where infrastructure allows (4)."
          },
          "sources": [
            {
              "what": "llms.txt",
              "url": "https://bundle.social/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "llms-full.txt",
              "url": "https://bundle.social/llms-full.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing, quotas and X rates",
              "url": "https://bundle.social/pricing.md",
              "seen": "2026-10-09"
            },
            {
              "what": "terms of service",
              "url": "https://bundle.social/terms",
              "seen": "2026-10-09"
            },
            {
              "what": "privacy policy",
              "url": "https://bundle.social/privacy",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt",
              "url": "https://bundle.social/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "API catalogue",
              "url": "https://bundle.social/.well-known/api-catalog",
              "seen": "2026-10-09"
            },
            {
              "what": "status page",
              "url": "https://bundlesocial.betteruptime.com/",
              "seen": "2026-10-09"
            },
            {
              "what": "docs index",
              "url": "https://info.bundle.social/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "rate limits",
              "url": "https://info.bundle.social/api-reference/rate-limits.md",
              "seen": "2026-10-09"
            },
            {
              "what": "errors",
              "url": "https://info.bundle.social/api-reference/errors.md",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server docs",
              "url": "https://info.bundle.social/api-reference/mcp.md",
              "seen": "2026-10-09"
            },
            {
              "what": "CLI docs",
              "url": "https://info.bundle.social/api-reference/cli.md",
              "seen": "2026-10-09"
            },
            {
              "what": "webhooks",
              "url": "https://info.bundle.social/api-reference/webhooks.md",
              "seen": "2026-10-09"
            },
            {
              "what": "data retention",
              "url": "https://info.bundle.social/api-reference/data-retention.md",
              "seen": "2026-10-09"
            },
            {
              "what": "changelog",
              "url": "https://info.bundle.social/changelog.md",
              "seen": "2026-10-09"
            },
            {
              "what": "security policy",
              "url": "https://info.bundle.social/SECURITY.md",
              "seen": "2026-10-09"
            },
            {
              "what": "SDK source, OpenAPI copy, tags and CI",
              "url": "https://github.com/bundleglobal/bundlesocial-node",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server source and tool definitions",
              "url": "https://github.com/bundleglobal/bundlesocial-mcp",
              "seen": "2026-10-09"
            },
            {
              "what": "CLI source and skill file",
              "url": "https://github.com/bundleglobal/bundlesocial-cli",
              "seen": "2026-10-09"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/bundlesocial",
              "seen": "2026-10-09"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=bundlesocial",
              "seen": "2026-10-09"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.org/domain/bundle.social",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: bundle.social's HTML pages other than the terms and privacy policy (pricing, MCP, CLI, AI agents, about and per-network pages). The terms say customers must not scrape the Service, which includes the website, so we kept to the published agent files after reading them",
            "unchecked: the live OpenAPI description and Swagger UI on api.bundle.social, whose robots.txt disallows every path. We read the copy in the SDK repository, last regenerated on 6 October 2026",
            "unchecked: incident detail beyond the status front page, which shows one API incident on 31 August 2026",
            "Whether API keys can be limited by team or permission. The docs list an `/api-key` group that the public description does not include",
            "Whether 429 responses carry a Retry-After header. None is described",
            "Whether the CI on the three repositories passes. Workflow files were read, run results were not",
            "The lead named the SDK `@bundleglobal/sdk`, which npm does not have. The package is `bundlesocial`",
            "llms.txt, llms-full.txt and pricing.md carry instructions addressed to AI models (a 'Do not assume' list and how to attribute review ratings). We treated them as data"
          ]
        },
        "negative": 0,
        "verdict": "The REST API has a public OpenAPI 3.0 description of 194 operations, Markdown docs and published rate limits, and the free plan needs no card. Organisation API keys carry no scopes, there is no idempotency key, and the status page shows one API outage of 4 hours 3 minutes on 31 August 2026.",
        "bestFor": "A SaaS product or agent that manages many accounts for many customers, since paid plans do not charge per connected account and teams separate tenants.",
        "strengths": [
          "OpenAPI 3.0.2 description with 194 operations, each with a description, plus llms.txt, llms-full.txt and Markdown copies of every docs page",
          "Paid plans are priced per organisation with no fee per connected account. The free plan covers 20 posts a month and needs no payment details",
          "Rate limits are published as three windows (100 a second, 500 per 10 seconds, 2,000 a minute), counted per endpoint for API keys",
          "Platform errors come back with a stable `code`, a `userFacingMessage` and an `isTransient` flag in `errorsVerbose`",
          "Valid security.txt and a disclosure policy that promises acknowledgement within 3 business days"
        ],
        "weaknesses": [
          "API keys are organisation-wide with no scopes or read-only mode found, so one key reaches every team and connected account",
          "No idempotency key on `POST /api/v1/post`. A `referenceKey` with conflict protection is the nearest safeguard",
          "The status page records the API down for 4 hours 3 minutes on 31 August 2026",
          "The DPA is sent on request only, and no sub-processor list or certification was found",
          "One official SDK (TypeScript). The MCP server is local stdio only, with 68 tools and no toolsets"
        ],
        "agentNotes": [
          "Send the key in the `x-api-key` header to `https://api.bundle.social/api/v1`. A missing key returns 401 and a bad key 403",
          "Pass `teamId` on most calls. Set `BUNDLESOCIAL_TEAM_ID` for the MCP server or CLI when the organisation has more than one team",
          "Set a `referenceKey` on each post and look it up with the reference-key endpoint before retrying a create, because there is no idempotency key",
          "Check `GET /api/v1/organization/usage/daily-limits` before bulk scheduling. Failed and deleted posts still count against the monthly quota",
          "A person must complete each network's OAuth consent in a browser. Keep prepaid credit for X, where a post costs $0.015 or $0.20 with a link"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.1
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 78,
          "payments": 35,
          "reliability": 63,
          "schema": 86,
          "security": 34,
          "transparency": 44
        },
        "provenanceScore": 86
      },
      "connect": {
        "install": "npm install bundlesocial",
        "http": "curl \"https://api.bundle.social/api/v1/team\" -H \"x-api-key: $BUNDLE_SOCIAL_API_KEY\"",
        "claudeCode": "claude mcp add bundlesocial --env BUNDLESOCIAL_API_KEY=sk_live_... -- npx -y bundlesocial-mcp",
        "config": {
          "mcpServers": {
            "bundlesocial": {
              "args": [
                "-y",
                "bundlesocial-mcp"
              ],
              "command": "npx",
              "env": {
                "BUNDLESOCIAL_API_KEY": "sk_live_..."
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/social.post",
        "tool": "https://letme.dev/bundle-social"
      },
      "notable": [
        "Paid plans are billed per organisation with no fee per seat or connected account. A team holds one account per network, and paid plans do not cap teams (https://bundle.social/pricing.md)",
        "X posting and reads moved to prepaid credit on 16 August 2026, passed through at X's rates, $0.015 a post and $0.20 a post with a link (https://bundle.social/pricing.md)",
        "The MCP server `bundlesocial-mcp` is a local stdio server with 68 tools. The docs say a hosted server at mcp.bundle.social is on the roadmap (https://info.bundle.social/api-reference/mcp.md)",
        "The status page shows the API down for 4 hours 3 minutes on 31 August 2026 and 99.793 per cent uptime over 90 days (https://bundlesocial.betteruptime.com/)",
        "Analytics are kept 30 days, webhook events 7 days and unused uploads 14 days (https://info.bundle.social/api-reference/data-retention.md)",
        "The terms say customer content and OAuth data are not used to train third-party AI models, and that customers must not scrape the Service (https://bundle.social/terms)",
        "llms.txt, llms-full.txt and pricing.md carry a list of instructions addressed to AI models, about what not to assume and how to attribute review ratings (https://bundle.social/llms.txt)",
        "api.bundle.social's robots.txt disallows every path, including the OpenAPI description the docs link (https://api.bundle.social/robots.txt)"
      ],
      "area": "communication",
      "details": [
        {
          "label": "Networks",
          "value": "TikTok, YouTube, Instagram, Facebook, X, Threads, LinkedIn, Pinterest, Reddit, Mastodon, Discord, Slack, Bluesky, Google Business Profile and Snapchat. Comments are not supported on X, Pinterest or Google Business Profile"
        },
        {
          "label": "Approval and accounts",
          "value": "Uses bundle.social's own network apps through a hosted connect link, so no developer app is needed. A person completes each network's OAuth consent in a browser"
        },
        {
          "label": "API",
          "value": "REST at https://api.bundle.social/api/v1, OpenAPI 3.0.2 with 145 paths and 194 operations (copy in the SDK repository dated 6 October 2026)"
        },
        {
          "label": "MCP server",
          "value": "`bundlesocial-mcp` 1.2.0, local stdio through npx, 68 tools with read-only and destructive annotations, Node.js 20 or later"
        },
        {
          "label": "SDK and CLI",
          "value": "`bundlesocial` 2.66.0 (TypeScript, 6 October 2026) and `bundlesocial-cli` 1.2.0, which prints JSON and ships a skill file"
        },
        {
          "label": "Plans",
          "value": "Free $0 (20 posts, 50 comments, 200 uploads a month, 3 teams, no analytics). Pro $100 (10,000 posts). Business $400 (100,000 posts). Yearly billing is $90 and $360 a month"
        },
        {
          "label": "X charges",
          "value": "Post $0.015, post with link $0.20, post read $0.005, account read $0.01, delete $0.01, repost $0.015, from prepaid credit"
        },
        {
          "label": "Rate limits",
          "value": "100 requests a second, 500 per 10 seconds and 2,000 a minute, per endpoint for API keys. Daily caps per network and plan, for example 10 TikTok posts a day per account on Pro"
        },
        {
          "label": "Errors",
          "value": "`{ statusCode, message }`, with `issues` on 400. Platform failures in `errorsVerbose` with `code`, `userFacingMessage` and `isTransient`"
        },
        {
          "label": "Webhooks",
          "value": "Up to 5 an organisation, signed with HMAC-SHA256 in `x-signature`, three delivery attempts, disabled after 7 days without a success"
        },
        {
          "label": "Media",
          "value": "Multipart upload, upload from URL and chunked uploads up to 5 GB. Unused uploads are removed after 14 days"
        },
        {
          "label": "Retention",
          "value": "Analytics 30 days, webhook events 7 days, application and API logs 7 days, backups 7 days, deleted customer data within 30 days"
        },
        {
          "label": "Status",
          "value": "Better Stack page with components for api.bundle.social and bundle.social, 90 days of history"
        }
      ],
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 100,
          "note": "10,000 posts a month, unlimited connected accounts"
        },
        {
          "item": "Business plan",
          "unit": "month",
          "usd": 400,
          "note": "100,000 posts a month"
        },
        {
          "item": "X post",
          "unit": "tx",
          "usd": 0.015,
          "note": "X's charge passed through, from prepaid credit"
        },
        {
          "item": "X post with a link",
          "unit": "tx",
          "usd": 0.2,
          "note": "X's charge passed through"
        }
      ],
      "provenance": {
        "legalEntity": "BUNDLE SP. Z O.O.",
        "domain": "bundle.social",
        "domainRegistered": "2023-09-17",
        "endpointOnVendorDomain": true,
        "terms": "https://bundle.social/terms",
        "privacy": "https://bundle.social/privacy",
        "statusPage": "https://bundlesocial.betteruptime.com/",
        "changelog": "https://info.bundle.social/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "The terms (last updated 14 July 2026) name BUNDLE SP. Z O.O., ul. Hoża 86 / 410, 00-682 Warsaw, KRS 0001103308, and say they govern the website, dashboard and API. Polish law applies.",
          "The privacy policy (last updated 2 July 2026) covers the same Service and says the company is a processor for customer content and connected account data.",
          "security.txt at bundle.social/.well-known/security.txt expires on 7 April 2027 and gives a contact address and the contact page.",
          "RDAP gives a registration date of 2023-09-17 for bundle.social.",
          "The status page is on Better Stack's betteruptime.com domain. The API answers at api.bundle.social and the docs at info.bundle.social."
        ],
        "score": 86,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "BUNDLE SP. Z O.O.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "bundle.social, registered 2023-09-17 (3 years)",
            "points": 7,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.bundle.social",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "bundlesocial.betteruptime.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://bundle.social/terms",
            "state": "read",
            "readAt": "2026-10-09",
            "statedDate": "2026-07-14",
            "words": 3450,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: July 14, 2026",
                "says": "Last updated 2026-07-14"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These Terms are governed by the laws of Poland, without regard to its conflict of law principles.",
                "says": "The law of Poland"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "To the maximum extent permitted by law, our total aggregate liability arising out of or relating to the Service or these Terms will not exceed the amount paid by you to us for the Service during the six months before the event giving rise to the claim.",
                "says": "Capped at the fees paid in the 6 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "In such cases we may remove, refuse to publish, quarantine, delete, disable access to, demote, or otherwise restrict content, and we may suspend, limit, or terminate accounts, organizations, teams, connected social accounts, or API keys."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "For non-material updates, clarifications, formatting changes, or updates that better describe existing practices, the updated Terms will be effective when posted, unless stated otherwise.",
                "says": "Changes are posted, with no other notice named"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you do not agree, you must not use the Service."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "You must not attempt to bypass limits, abuse the API, overload the Service, scrape the Service, or use the Service in a way that harms stability, security, third-party platforms, or other customers.",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We may make changes without advance notice where needed for security, legal compliance, platform API changes, abuse prevention, emergency maintenance, infrastructure reliability, or third-party platform requirements.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The terms say customer content, uploaded media, social account data and OAuth data are not used to train third-party AI models.",
                "quote": "We do not use customer content, uploaded media, social account data, or OAuth data to train third-party AI models."
              },
              {
                "date": "2026-10-08",
                "text": "Total liability is capped at the amount paid for the Service in the six months before the event giving rise to the claim.",
                "quote": "To the maximum extent permitted by law, our total aggregate liability arising out of or relating to the Service or these Terms will not exceed the amount paid by you to us for the Service during the six months before the event giving rise to the claim."
              },
              {
                "date": "2026-10-08",
                "text": "Prepaid credits are non-refundable and non-transferable and carry no cash value, except where the law requires otherwise.",
                "quote": "Prepaid credits are non-refundable and non-transferable, carry no cash value, and cannot be redeemed for cash, except where required by law."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://bundle.social/privacy",
            "state": "read",
            "readAt": "2026-10-09",
            "statedDate": "2026-07-02",
            "words": 2531,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: July 2, 2026",
                "says": "Last updated 2026-07-02"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": false
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Application logs and API logs are retained for 7 days, unless longer retention is required for security, abuse prevention, debugging, legal, billing, or dispute reasons.",
                "says": "Names a period of 7 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "You may create an account or log in to the Service using third-party authentication providers, such as Google or GitHub, where available."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We may share personal data with trusted service providers where necessary to provide, secure, support, improve, or bill for the Service."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Depending on where you are located and subject to applicable law, you may have the right to access, correct, delete, restrict, object to the processing of, or request portability of your personal data."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "To delete data already stored by bundle.social, use the in-app deletion controls for your account, organization, team, connected social account, posts, or media, or request deletion by contacting us at [email protected].",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, Data Privacy Framework certification where applicable, or another lawful transfer mechanism under GDPR.",
                "says": "Relies on standard contractual clauses and the Data Privacy Framework"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Revoking access at a third-party platform may not delete data already stored in bundle.social, and deletion of stored data needs a separate request.",
                "quote": "Revoking access from a third-party platform may stop future access to that platform, but it may not automatically delete data already stored in bundle.social."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/bundle-social.json",
      "live": {
        "slug": "bundle-social",
        "probe": {
          "target": "https://api.bundle.social/api/v1",
          "method": "get",
          "lastAt": "2026-10-10T02:07:04.364399785Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 87,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 125,
          "p95ms24h": 336,
          "samples24h": 107,
          "samples30d": 107,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://bundlesocial.betteruptime.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:11.659944209Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "bundleglobal/bundlesocial-node",
            "version": "v2.66.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-09T16:44:11.330353144Z"
          },
          {
            "registry": "npm",
            "name": "bundlesocial",
            "version": "2.66.0",
            "seenAt": "2026-10-09T16:44:07.124149089Z"
          },
          {
            "registry": "npm",
            "name": "bundlesocial-cli",
            "version": "1.2.0",
            "seenAt": "2026-10-09T16:44:09.336926914Z"
          },
          {
            "registry": "npm",
            "name": "bundlesocial-mcp",
            "version": "1.2.0",
            "seenAt": "2026-10-09T16:44:08.016971776Z"
          }
        ],
        "githubStars": 2,
        "npmWeekly": 4095,
        "pages": [
          {
            "url": "https://info.bundle.social/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:30.493711689Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3cc1075e6da1"
          },
          {
            "url": "https://bundle.social/pricing.md",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:33:26.088434635Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a06b56dc1904"
          },
          {
            "url": "https://bundle.social/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:33:28.243797522Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "873c63ca40f1"
          },
          {
            "url": "https://bundle.social/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:33:30.268270502Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cfd8eeb305a0"
          }
        ],
        "updatedAt": "2026-10-10T02:07:04.364399785Z"
      }
    },
    "verify": {
      "accepts": "a page on bundle.social or one of its subdomains, or the README of github.com/bundleglobal/bundlesocial-node",
      "badgeUrl": "https://www.anchorterminal.com/badges/bundle-social.svg",
      "body": {
        "slug": "bundle-social",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/bundle-social",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/bundle-social\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/bundle-social.svg\" alt=\"bundle.social on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![bundle.social on Anchor Terminal](https://www.anchorterminal.com/badges/bundle-social.svg)](https://www.anchorterminal.com/tools/bundle-social)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/bundle-social\"\u003ebundle.social on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/bundle-social",
    "json": "https://www.anchorterminal.com/tools/bundle-social.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/bundle-social.md",
    "slim": "https://www.anchorterminal.com/tools/bundle-social.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 60.1/100 · rank #530 of 950 · #3 in Social media posting APIs · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe REST API has a public OpenAPI 3.0 description of 194 operations, Markdown docs and published rate limits, and the free plan needs no card. Organisation API keys carry no scopes, there is no idempotency key, and the status page shows one API outage of 4 hours 3 minutes on 31 August 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | BUNDLE SP. Z O.O. (https://bundle.social) |\n| Kind | HTTP API |\n| Category | Social media posting APIs (https://www.anchorterminal.com/categories/social-media) |\n| Transport | HTTP, stdio |\n| Endpoint | `https://api.bundle.social/api/v1` |\n| Auth | API key · Self-serve organisation API key sent in the `x-api-key` header, created and rolled in the dashboard after a browser sign-up, up to 50 keys an organisation. Keys carry no scopes and reach every team. Connecting a social account needs a person to complete that network's OAuth consent through a hosted connect link. |\n| Pricing | Freemium ($100 / mo) · Free plan at $0 with 20 posts a month, three teams and API access, no payment details needed. Pro is $100 a month for 10,000 posts and Business $400 for 100,000, both with unlimited connected accounts. Enterprise is quoted. X actions are charged from prepaid credit at X's rates (https://bundle.social/pricing.md). |\n| x402 | No · No x402, MPP or L402 in llms.txt, pricing.md, the docs index or the OpenAPI description in the SDK repository (checked 2026-10-09). |\n| Licence | Proprietary hosted service under bundle.social's terms of service. The TypeScript SDK, the CLI and the MCP server on GitHub are MIT |\n| Tools exposed | 68 |\n| Packages | npm: `bundlesocial`; npm: `bundlesocial-mcp`; npm: `bundlesocial-cli` |\n| Source | https://github.com/bundleglobal/bundlesocial-node |\n| Docs | https://info.bundle.social |\n| llms.txt | https://bundle.social/llms.txt |\n| Last release | 2026-10-06 |\n| GitHub stars | 2 (as of 2026-10-09) |\n| npm downloads / week | 4,095 |\n| Networks | TikTok, YouTube, Instagram, Facebook, X, Threads, LinkedIn, Pinterest, Reddit, Mastodon, Discord, Slack, Bluesky, Google Business Profile and Snapchat. Comments are not supported on X, Pinterest or Google Business Profile |\n| Approval and accounts | Uses bundle.social's own network apps through a hosted connect link, so no developer app is needed. A person completes each network's OAuth consent in a browser |\n| API | REST at https://api.bundle.social/api/v1, OpenAPI 3.0.2 with 145 paths and 194 operations (copy in the SDK repository dated 6 October 2026) |\n| MCP server | `bundlesocial-mcp` 1.2.0, local stdio through npx, 68 tools with read-only and destructive annotations, Node.js 20 or later |\n| SDK and CLI | `bundlesocial` 2.66.0 (TypeScript, 6 October 2026) and `bundlesocial-cli` 1.2.0, which prints JSON and ships a skill file |\n| Plans | Free $0 (20 posts, 50 comments, 200 uploads a month, 3 teams, no analytics). Pro $100 (10,000 posts). Business $400 (100,000 posts). Yearly billing is $90 and $360 a month |\n| X charges | Post $0.015, post with link $0.20, post read $0.005, account read $0.01, delete $0.01, repost $0.015, from prepaid credit |\n| Rate limits | 100 requests a second, 500 per 10 seconds and 2,000 a minute, per endpoint for API keys. Daily caps per network and plan, for example 10 TikTok posts a day per account on Pro |\n| Errors | `{ statusCode, message }`, with `issues` on 400. Platform failures in `errorsVerbose` with `code`, `userFacingMessage` and `isTransient` |\n| Webhooks | Up to 5 an organisation, signed with HMAC-SHA256 in `x-signature`, three delivery attempts, disabled after 7 days without a success |\n| Media | Multipart upload, upload from URL and chunked uploads up to 5 GB. Unused uploads are removed after 14 days |\n| Retention | Analytics 30 days, webhook events 7 days, application and API logs 7 days, backups 7 days, deleted customer data within 30 days |\n| Status | Better Stack page with components for api.bundle.social and bundle.social, 90 days of history |\n| Capabilities | social.post, social.schedule, social.analytics, social.comments, social.media-upload |\n| Tags | hosted, freemium, free-tier, no-card, api-key, openapi, llms-txt, mcp, cli, typescript, webhooks, status-page |\n| JSON | https://www.anchorterminal.com/api/v1/tools/bundle-social.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 63 | 12.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 86 | 14.0 |\n| Agent ergonomics | 13% | 16.2 | 66 | 10.7 |\n| Security \u0026 auth | 14% | 17.5 | 34 | 6.0 |\n| Payments \u0026 pricing | 10% | 12.5 | 35 | 4.4 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 78 | 6.8 |\n| Transparency \u0026 trust (editorial 44, provenance 86) | 7% | 8.8 | 65 | 5.7 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **60.1 → C** |\n\n### Why each score\n\n- Reliability 63: Graded as a hosted API. Better Stack status page with two components and 90 days of history (20). One incident in 90 days, on 31 August 2026, with the API down for 4 hours 3 minutes and 99.793 per cent uptime shown (10). Rate limits published as 100 a second, 500 per 10 seconds and 2,000 a minute, plus daily caps per network (15). The docs ask for exponential backoff on 429 and flag platform errors with `isTransient`, but no Retry-After header or idempotency key was found (8). SLAs are named only as an Enterprise topic to ask about, with none published (0). The core API is generally available, with DMs and automations in beta (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 86: OpenAPI 3.0.2 with 145 paths and 194 operations, linked from the docs and read from the copy in the SDK repository (25). llms.txt, llms-full.txt, pricing.md and a Markdown copy of each docs page (10). Every operation has a description and many say when to call it (15). 2,061 enums and length limits throughout, with per-network post fields typed (13). Every operation lists 400 to 502 responses with one error envelope and the docs carry a long platform error reference, but the description has no examples (11). Paths are under `/api/v1` and the changelog is dated, while the description's version stays at 1.0.0 (12).\n- Agent ergonomics 66: Graded on the REST API. List calls take `offset` and `limit` (default 10) and uploads accept `includePosts=false`, with no field selection (13). Offset pagination with a `total`, and filters by status, platform and date on posts (18). Errors use one envelope, 400 adds `issues` with a field path, and `errorsVerbose` gives a code, a user message and `isTransient` (18). No idempotency key. `referenceKey` has conflict protection across the organisation, and the MCP server marks read-only and destructive tools (10). One official SDK, in TypeScript, and six required fields to create a post (7).\n- Security \u0026 auth 34: Organisation API keys in the `x-api-key` header, up to 50 an organisation, created and rolled in the dashboard, with no scopes (20). No read-only key or approval step found. The MCP server sets destructiveHint on 8 tools and posts can be created as drafts (4). Comments, reviews and DMs return text written by strangers and no prompt-injection guidance was found (0). Webhook deliveries can be inspected and API logs are kept 7 days internally, with no customer audit log found (2). security.txt is valid until 7 April 2027 and the docs publish a disclosure policy with response times and a no-action promise. No bug bounty, SOC 2 or ISO 27001 was found (8).\n- Payments \u0026 pricing 35: No x402, MPP or L402 (0). Prices are public and machine-readable in pricing.md. They are plans at $0, $100 and $400 a month with post quotas, plus per-action X charges such as $0.015 a post, so we scored between plan-only and per-unit (15). The free plan has 20 posts a month and needs no payment details (20). A person creates the organisation and first key in the dashboard (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 78: The `bundlesocial` SDK reached 2.66.0 on 6 October 2026 and the changelog's newest entry is 30 September 2026 (30). 17 SDK tags and four changelog entries since 11 July 2026 (20). Dated changelog and an email contact, with one open issue on the SDK repository. No community channel was verified (8). The TypeScript SDK is regenerated from the OpenAPI description. The MCP server was not found in the official registry and its server.json still says 1.0.0 against package 1.2.0 (12). Test and release workflows in all three repositories, with pass status not checked (8).\n- Transparency \u0026 trust 65: Closed service under terms dated 14 July 2026 that name the API. The SDK, CLI and MCP server are MIT (15). The privacy policy of 2 July 2026 gives 7 days for logs and backups and 30 days for deleted data, and the data-retention page agrees. Customer content is not used to train third-party AI models. The DPA is on request only (18). No deprecation policy. The changelog dated the move to prepaid X billing (announced 20 July, live 16 August 2026), and the terms promise notice where reasonably possible (7). No sub-processor list. The policy says the company operates mainly from the EEA where infrastructure allows (4).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/bundle-social.md (JSON https://www.anchorterminal.com/fixes/bundle-social.json)\n\n### What we couldn't check\n\n- unchecked: bundle.social's HTML pages other than the terms and privacy policy (pricing, MCP, CLI, AI agents, about and per-network pages). The terms say customers must not scrape the Service, which includes the website, so we kept to the published agent files after reading them\n- unchecked: the live OpenAPI description and Swagger UI on api.bundle.social, whose robots.txt disallows every path. We read the copy in the SDK repository, last regenerated on 6 October 2026\n- unchecked: incident detail beyond the status front page, which shows one API incident on 31 August 2026\n- Whether API keys can be limited by team or permission. The docs list an `/api-key` group that the public description does not include\n- Whether 429 responses carry a Retry-After header. None is described\n- Whether the CI on the three repositories passes. Workflow files were read, run results were not\n- The lead named the SDK `@bundleglobal/sdk`, which npm does not have. The package is `bundlesocial`\n- llms.txt, llms-full.txt and pricing.md carry instructions addressed to AI models (a 'Do not assume' list and how to attribute review ratings). We treated them as data\n\n### Sources\n\n- llms.txt: \u003chttps://bundle.social/llms.txt\u003e (seen 2026-10-09)\n- llms-full.txt: \u003chttps://bundle.social/llms-full.txt\u003e (seen 2026-10-09)\n- pricing, quotas and X rates: \u003chttps://bundle.social/pricing.md\u003e (seen 2026-10-09)\n- terms of service: \u003chttps://bundle.social/terms\u003e (seen 2026-10-09)\n- privacy policy: \u003chttps://bundle.social/privacy\u003e (seen 2026-10-09)\n- security.txt: \u003chttps://bundle.social/.well-known/security.txt\u003e (seen 2026-10-09)\n- API catalogue: \u003chttps://bundle.social/.well-known/api-catalog\u003e (seen 2026-10-09)\n- status page: \u003chttps://bundlesocial.betteruptime.com/\u003e (seen 2026-10-09)\n- docs index: \u003chttps://info.bundle.social/llms.txt\u003e (seen 2026-10-09)\n- rate limits: \u003chttps://info.bundle.social/api-reference/rate-limits.md\u003e (seen 2026-10-09)\n- errors: \u003chttps://info.bundle.social/api-reference/errors.md\u003e (seen 2026-10-09)\n- MCP server docs: \u003chttps://info.bundle.social/api-reference/mcp.md\u003e (seen 2026-10-09)\n- CLI docs: \u003chttps://info.bundle.social/api-reference/cli.md\u003e (seen 2026-10-09)\n- webhooks: \u003chttps://info.bundle.social/api-reference/webhooks.md\u003e (seen 2026-10-09)\n- data retention: \u003chttps://info.bundle.social/api-reference/data-retention.md\u003e (seen 2026-10-09)\n- changelog: \u003chttps://info.bundle.social/changelog.md\u003e (seen 2026-10-09)\n- security policy: \u003chttps://info.bundle.social/SECURITY.md\u003e (seen 2026-10-09)\n- SDK source, OpenAPI copy, tags and CI: \u003chttps://github.com/bundleglobal/bundlesocial-node\u003e (seen 2026-10-09)\n- MCP server source and tool definitions: \u003chttps://github.com/bundleglobal/bundlesocial-mcp\u003e (seen 2026-10-09)\n- CLI source and skill file: \u003chttps://github.com/bundleglobal/bundlesocial-cli\u003e (seen 2026-10-09)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/bundlesocial\u003e (seen 2026-10-09)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=bundlesocial\u003e (seen 2026-10-09)\n- domain registration: \u003chttps://rdap.org/domain/bundle.social\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 86/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | BUNDLE SP. Z O.O. | 20/20 |\n| Domain age | bundle.social, registered 2023-09-17 (3 years) | 7/15 |\n| Endpoint on the vendor's domain | api.bundle.social | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | bundlesocial.betteruptime.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe terms (last updated 14 July 2026) name BUNDLE SP. Z O.O., ul. Hoża 86 / 410, 00-682 Warsaw, KRS 0001103308, and say they govern the website, dashboard and API. Polish law applies.\n\nThe privacy policy (last updated 2 July 2026) covers the same Service and says the company is a processor for customer content and connected account data.\n\nsecurity.txt at bundle.social/.well-known/security.txt expires on 7 April 2027 and gives a contact address and the contact page.\n\nRDAP gives a registration date of 2023-09-17 for bundle.social.\n\nThe status page is on Better Stack's betteruptime.com domain. The API answers at api.bundle.social and the docs at info.bundle.social.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://bundle.social/terms), read 2026-10-09, dated 2026-07-14, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"You must not attempt to bypass limits, abuse the API, overload the Service, scrape the Service, or use the Service in a way that harms stability, security, third-party platforms, or other customers.\"\n- To know. Says the terms or the service can change without notice (costs points). \"We may make changes without advance notice where needed for security, legal compliance, platform API changes, abuse prevention, emergency maintenance, infrastructure reliability, or third-party platform requirements.\"\n- Gives the date it was last updated. Last updated 2026-07-14.\n- Names the governing law or courts. The law of Poland.\n- States a limit on its liability. Capped at the fees paid in the 6 months before the claim.\n- Says how changes to the terms are announced. Changes are posted, with no other notice named.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). The terms say customer content, uploaded media, social account data and OAuth data are not used to train third-party AI models. \"We do not use customer content, uploaded media, social account data, or OAuth data to train third-party AI models.\"\n- Also in the text (2026-10-08). Total liability is capped at the amount paid for the Service in the six months before the event giving rise to the claim. \"To the maximum extent permitted by law, our total aggregate liability arising out of or relating to the Service or these Terms will not exceed the amount paid by you to us for the Service during the six months before the event giving rise to the claim.\"\n- Also in the text (2026-10-08). Prepaid credits are non-refundable and non-transferable and carry no cash value, except where the law requires otherwise. \"Prepaid credits are non-refundable and non-transferable, carry no cash value, and cannot be redeemed for cash, except where required by law.\"\n\n**Privacy policy** (https://bundle.social/privacy), read 2026-10-09, dated 2026-07-02, states 7 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-07-02.\n- Not found in the text. Says what personal data is collected.\n- Says how long data is kept. Names a period of 7 days.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Says where data is transferred or stored. Relies on standard contractual clauses and the Data Privacy Framework.\n- Also in the text (2026-10-08). Revoking access at a third-party platform may not delete data already stored in bundle.social, and deletion of stored data needs a separate request. \"Revoking access from a third-party platform may stop future access to that platform, but it may not automatically delete data already stored in bundle.social.\"\n\n## Live (updated 2026-10-10 02:07 UTC)\n\n- Right now: up, HTTP 200, 87 ms, checked 2026-10-10 02:07 UTC (get on `https://api.bundle.social/api/v1`)\n- Uptime 24h 100.0% (107 probes) · 30 days 100.0% (107 probes) · p50 125 ms · p95 336 ms\n- Vendor status page: unknown, no machine-readable status found\n- github `bundleglobal/bundlesocial-node` v2.66.0, released 2026-10-06\n- npm `bundlesocial` 2.66.0\n- npm `bundlesocial-cli` 1.2.0\n- npm `bundlesocial-mcp` 1.2.0\n- Watching changelog \u003chttps://info.bundle.social/changelog\u003e\n- Watching pricing \u003chttps://bundle.social/pricing.md\u003e\n- Watching privacy \u003chttps://bundle.social/privacy\u003e\n- Watching terms \u003chttps://bundle.social/terms\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/bundle-social.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Pro plan | $100 | per month (plan) | 10,000 posts a month, unlimited connected accounts |\n| Business plan | $400 | per month (plan) | 100,000 posts a month |\n| X post | $0.015 | per transaction | X's charge passed through, from prepaid credit |\n| X post with a link | $0.20 | per transaction | X's charge passed through |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- OpenAPI 3.0.2 description with 194 operations, each with a description, plus llms.txt, llms-full.txt and Markdown copies of every docs page\n- Paid plans are priced per organisation with no fee per connected account. The free plan covers 20 posts a month and needs no payment details\n- Rate limits are published as three windows (100 a second, 500 per 10 seconds, 2,000 a minute), counted per endpoint for API keys\n- Platform errors come back with a stable `code`, a `userFacingMessage` and an `isTransient` flag in `errorsVerbose`\n- Valid security.txt and a disclosure policy that promises acknowledgement within 3 business days\n\n## Weaknesses\n\n- API keys are organisation-wide with no scopes or read-only mode found, so one key reaches every team and connected account\n- No idempotency key on `POST /api/v1/post`. A `referenceKey` with conflict protection is the nearest safeguard\n- The status page records the API down for 4 hours 3 minutes on 31 August 2026\n- The DPA is sent on request only, and no sub-processor list or certification was found\n- One official SDK (TypeScript). The MCP server is local stdio only, with 68 tools and no toolsets\n\n## Before you call it (notes for agents)\n\n1. Send the key in the `x-api-key` header to `https://api.bundle.social/api/v1`. A missing key returns 401 and a bad key 403\n2. Pass `teamId` on most calls. Set `BUNDLESOCIAL_TEAM_ID` for the MCP server or CLI when the organisation has more than one team\n3. Set a `referenceKey` on each post and look it up with the reference-key endpoint before retrying a create, because there is no idempotency key\n4. Check `GET /api/v1/organization/usage/daily-limits` before bulk scheduling. Failed and deleted posts still count against the monthly quota\n5. A person must complete each network's OAuth consent in a browser. Keep prepaid credit for X, where a post costs $0.015 or $0.20 with a link\n\n## Connect\n\nInstall:\n\n```bash\nnpm install bundlesocial\n```\n\nFirst request:\n\n```bash\ncurl \"https://api.bundle.social/api/v1/team\" -H \"x-api-key: $BUNDLE_SOCIAL_API_KEY\"\n```\n\nClaude Code:\n\n```bash\nclaude mcp add bundlesocial --env BUNDLESOCIAL_API_KEY=sk_live_... -- npx -y bundlesocial-mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"bundlesocial\": {\n      \"args\": [\n        \"-y\",\n        \"bundlesocial-mcp\"\n      ],\n      \"command\": \"npx\",\n      \"env\": {\n        \"BUNDLESOCIAL_API_KEY\": \"sk_live_...\"\n      }\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/bundle-social. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Zernio (formerly Late) API + MCP | B | 67.5 | 251 | social.post, social.schedule, social.analytics, social.comments, social.media-upload | no | https://www.anchorterminal.com/tools/late.md |\n| Upload-Post API + MCP | C | 58.7 | 574 | social.post, social.schedule, social.analytics, social.comments, social.media-upload | no | https://www.anchorterminal.com/tools/upload-post.md |\n| Ayrshare API + MCP | C | 57.2 | 617 | social.post, social.schedule, social.analytics, social.comments, social.media-upload | no | https://www.anchorterminal.com/tools/ayrshare.md |\n| Blotato | D | 46.1 | 856 | social.post, social.schedule, social.analytics, social.comments, social.media-upload | no | https://www.anchorterminal.com/tools/blotato.md |\n| OneUp API + MCP | F | 24.4 | 942 | social.post, social.schedule, social.analytics, social.comments, social.media-upload | no | https://www.anchorterminal.com/tools/oneup.md |\n| Postiz API + MCP | C | 59.3 | 552 | social.post, social.schedule, social.analytics, social.media-upload | no | https://www.anchorterminal.com/tools/postiz.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Paid plans are billed per organisation with no fee per seat or connected account. A team holds one account per network, and paid plans do not cap teams (source: \u003chttps://bundle.social/pricing.md\u003e)\n- X posting and reads moved to prepaid credit on 16 August 2026, passed through at X's rates, $0.015 a post and $0.20 a post with a link (source: \u003chttps://bundle.social/pricing.md\u003e)\n- The MCP server `bundlesocial-mcp` is a local stdio server with 68 tools. The docs say a hosted server at mcp.bundle.social is on the roadmap (source: \u003chttps://info.bundle.social/api-reference/mcp.md\u003e)\n- The status page shows the API down for 4 hours 3 minutes on 31 August 2026 and 99.793 per cent uptime over 90 days (source: \u003chttps://bundlesocial.betteruptime.com/\u003e)\n- Analytics are kept 30 days, webhook events 7 days and unused uploads 14 days (source: \u003chttps://info.bundle.social/api-reference/data-retention.md\u003e)\n- The terms say customer content and OAuth data are not used to train third-party AI models, and that customers must not scrape the Service (source: \u003chttps://bundle.social/terms\u003e)\n- llms.txt, llms-full.txt and pricing.md carry a list of instructions addressed to AI models, about what not to assume and how to attribute review ratings (source: \u003chttps://bundle.social/llms.txt\u003e)\n- api.bundle.social's robots.txt disallows every path, including the OpenAPI description the docs link (source: \u003chttps://api.bundle.social/robots.txt\u003e)\n\n- #3 of 15 in Best social media posting and scheduling APIs for AI agents: https://www.anchorterminal.com/best/social-media/index.md\n- All 103 social comparisons: https://www.anchorterminal.com/compare/social-media/index.md\n\n## Compare\n\n- [Ayrshare API + MCP vs bundle.social](https://www.anchorterminal.com/compare/ayrshare-vs-bundle-social.md): C 57.2 vs C 60.1\n- [Blotato vs bundle.social](https://www.anchorterminal.com/compare/blotato-vs-bundle-social.md): D 46.1 vs C 60.1\n- [Buffer API + MCP vs bundle.social](https://www.anchorterminal.com/compare/buffer-vs-bundle-social.md): B 62 vs C 60.1\n- [bundle.social vs Zernio (formerly Late) API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-late.md): C 60.1 vs B 67.5\n- [bundle.social vs Metricool API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-metricool.md): C 60.1 vs E 38.3\n- [bundle.social vs Mixpost API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-mixpost.md): C 60.1 vs D 49.5\n- [bundle.social vs OneUp API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-oneup.md): C 60.1 vs F 24.4\n- [bundle.social vs Post Bridge API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-post-bridge.md): C 60.1 vs D 48.3\n- [bundle.social vs Postiz API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-postiz.md): C 60.1 vs C 59.3\n- [bundle.social vs Publer API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-publer.md): C 60.1 vs D 46.8\n- [bundle.social vs Typefully](https://www.anchorterminal.com/compare/bundle-social-vs-typefully.md): C 60.1 vs D 49.1\n- [bundle.social vs Upload-Post API + MCP](https://www.anchorterminal.com/compare/bundle-social-vs-upload-post.md): C 60.1 vs C 58.7\n- [bundle.social vs Sprout Social API](https://www.anchorterminal.com/compare/bundle-social-vs-sprout-social.md): C 60.1 vs C 54.7\n- [bundle.social vs X MCP](https://www.anchorterminal.com/compare/bundle-social-vs-x-mcp.md): C 60.1 vs C 55.4\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on bundle.social or one of its subdomains, or the README of github.com/bundleglobal/bundlesocial-node. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"bundle-social\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/bundle-social\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/bundle-social.svg\" alt=\"bundle.social on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![bundle.social on Anchor Terminal](https://www.anchorterminal.com/badges/bundle-social.svg)](https://www.anchorterminal.com/tools/bundle-social)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/bundle-social\"\u003ebundle.social on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say bundle.social is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/bundle-social-dark.png\n- Light: https://www.anchorterminal.com/assets/share/bundle-social-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Social media posting APIs",
        "url": "https://www.anchorterminal.com/categories/social-media"
      },
      {
        "name": "bundle.social",
        "url": ""
      }
    ],
    "description": "bundle.social is a hosted REST API from BUNDLE SP. Z O.O. in Warsaw for publishing, scheduling, commenting and reading analytics across 15 social networks. It also ships a TypeScript SDK, a CLI and a local MCP server.",
    "facts": [
      "rank #530 of 950",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "bundle.social",
    "image": "https://www.anchorterminal.com/assets/og/tools-bundle-social.png",
    "path": "/tools/bundle-social",
    "published": "2026-10-01",
    "section": "tools",
    "title": "bundle.social review (2026): pricing, alternatives and grade C",
    "toc": null,
    "updated": "2026-10-10",
    "url": "https://www.anchorterminal.com/tools/bundle-social"
  },
  "tokens": {
    "markdown": 7450,
    "slim": 1780
  },
  "version": 1
}
