# ClickUp > ClickUp is a work management platform for tasks, docs, chat and time tracking. Agents reach it through a hosted MCP server at mcp.clickup.com and a public REST API (v2 and v3), both available on every plan. - Canonical: https://www.anchorterminal.com/tools/clickup - Markdown: https://www.anchorterminal.com/tools/clickup.md (~7,800 tokens) - Slim: https://www.anchorterminal.com/tools/clickup.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/clickup.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade C · 60.9/100 · rank #336 of 629 · #5 in Project & task management · not agent-ready · confidence medium** ## Assessment The hosted MCP server uses OAuth 2.1 with PKCE, dynamic client registration and read and write scopes, and works on the Free Forever plan. Without the Everything AI add-on, MCP calls are capped at 100 to 25,000 per rolling 24 hours by plan. No API changelog, deprecation policy, official SDK or SLA was found. ## Facts | Field | Value | | --- | --- | | Vendor | Mango Technologies, Inc. DBA ClickUp (https://clickup.com) | | Kind | HTTP API | | Category | Project & task management (https://www.anchorterminal.com/categories/project-management) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://api.clickup.com` | | Auth | OAuth or key · Access is self-serve. The MCP server at https://mcp.clickup.com/mcp accepts only OAuth 2.1 with PKCE, with dynamic client registration and read and write scopes, and refuses API keys. The REST API takes a personal token (`pk_`, generated under Settings, Apps) or an OAuth 2.0 authorisation code token from an app that a Workspace owner or admin creates. Neither REST token expires or carries scopes. Users choose the Workspaces they authorise, and calls act with that user's permissions. No app review or partner approval is described. | | Pricing | Freemium ($7 / seat-mo) · Free Forever includes the API and the MCP server, so an agent can start without a contract. Unlimited is $7 a seat a month billed yearly or $10 monthly, Business $12 or $19, Enterprise through sales. API calls are not priced. Without the Everything AI add-on ($28 a seat a month as shown) MCP is capped per rolling 24 hours, from 100 calls on Free Forever to 25,000 on Enterprise Plus. No separate sandbox was found (https://clickup.com/pricing, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under ClickUp's Terms of Service and Developer Terms. The clickup-plugin repository on GitHub is MIT | | Tools exposed | 48 | | Source | https://github.com/clickup/clickup-plugin | | Docs | https://developer.clickup.com | | llms.txt | https://developer.clickup.com/llms.txt | | Last release | 2026-09-18 | | Surfaces graded | Hosted MCP server at https://mcp.clickup.com/mcp and the public REST API at https://api.clickup.com (v2 with 138 operations, v3 with 35) | | MCP tools | 48 documented. Search (3), tasks (5), bulk tasks (2), attachments (1), comments (3), tags (2), links and dependencies (4), moving tasks (2), time tracking (6), hierarchy (8), members (3), Chat (2), Docs (5), time in status (2) | | MCP authentication | OAuth 2.1 only, authorisation code with PKCE (S256), dynamic client registration, scopes read and write, resource indicators. No API keys | | API authentication | Personal token (`pk_`) in the Authorization header, or OAuth 2.0 authorisation code tokens per user. Neither expires. No scopes. Users choose which Workspaces to authorise | | API rate limits | Per token per minute. Free Forever, Unlimited and Business 100, Business Plus 1,000, Enterprise and Enterprise Plus 10,000. 429 with `X-RateLimit-Limit`, `X-RateLimit-Remaining`, `X-RateLimit-Reset` | | MCP rate limits | Without the Everything AI add-on, calls per rolling 24 hours per Workspace and client. Free Forever 100, Core or Unlimited 300, Business 1,000, Business Plus 2,500, Enterprise 5,000, Enterprise Plus 25,000. With the add-on, the API limits apply | | Pagination | API v2 uses `page` at 100 tasks a page. API v3 uses `limit` with `cursor` and `next_cursor` | | Webhooks | Created through the API per Workspace, Space, Folder, List or task, signed with HMAC SHA-256 in `X-Signature`. Five delivery attempts per event, suspension at 100 failures, failed events not resent | | Enterprise-only API | User and guest management endpoints, the Workspace audit log endpoint, and `admin_can_manage` on Update Space | | SDKs and plugins | No official SDK found. Official clickup-plugin repository (MIT, version 1.1.0) for Claude Code, Cursor and Agent Plugins clients, with three skills | | Certifications | SOC 1 Type 2, SOC 2 Type 2, SOC 3, ISO 27001, 27017, 27018, 27701 and 42001 per clickup.com/security. Reports on request from sales | | Status | status.clickup.com on incident.io, 22 components including Public API, Tasks, Search and Docs | | Sub-processors | List updated 28 September 2026 with purposes and locations. Hosting on AWS in the USA, Ireland, Germany, Australia and Singapore | | Capabilities | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, work.docs, work.chat | | Tags | official, hosted, mcp, oauth, openapi, llms-txt, freemium, free-tier, webhooks, status-page, soc2, project-management | | JSON | https://www.anchorterminal.com/api/v1/tools/clickup.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 74 | 14.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 74 | 12.0 | | Agent ergonomics | 13% | 16.2 | 48 | 7.8 | | Security & auth | 14% | 17.5 | 64 | 11.2 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 54 | 4.7 | | Transparency & trust (editorial 52, provenance 97) | 7% | 8.8 | 75 | 6.6 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **60.9 → C** | ### Why each score - Reliability 74: Graded on the hosted MCP server and the public REST API, with the hosted lines. Status page at status.clickup.com on incident.io with 22 components, Public API among them (20). The incident feed shows one incident since 20 July 2026, degraded Search for some US users on 27 July for about 2 h 35 min, marked minor, and two completed maintenance windows on 19 and 24 September. The page holds imported records and its calendar loads in the browser, so 10 to 20 July could not be read (20). API limits published per plan, 100 requests a minute per token on Free Forever, Unlimited and Business, 1,000 on Business Plus and 10,000 on Enterprise, and MCP caps of 100 to 25,000 calls per rolling 24 hours (15). 429s carry `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`, and MCP returns `RATE_LIMIT_EXCEEDED` with `retryAfter`. No backoff guidance and no idempotency keys found (9 of 15). No SLA found in the reviewed pages (0). Neither surface is marked beta, though the MCP docs say limits may change (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 74: OpenAPI 3.1 spec for API v2 with 138 operations and an OpenAPI 3.0 spec for v3 with 35, both public (25). The MCP tool schemas need an OAuth session and were not read. llms.txt and a Markdown copy of every docs page (10). 137 of 138 v2 operations carry a description, and the MCP tools page gives each tool one line and an example prompt. It lists Delete task while the MCP FAQ says no deletion tools exist (13 of 20). Required fields are marked, but v2 has 6 enums, dates are Unix milliseconds and `custom_fields` filters travel as JSON in a query string. v3 has 62 enums (10 of 15). Every v2 operation has a response example. Error responses are specified on few (400 on 6, 401 on 3), and the Common Errors page covers OAuth codes only (9 of 15). Versions sit in the path (v2, v3). No API changelog was found, developer.clickup.com/changelog returns 404, and the product changelog rarely covers the API (7 of 15). - Agent ergonomics 48: 48 documented MCP tools (5). The OAuth metadata advertises separate read and write scopes and `clickup_get_task` takes an `include` list, per ClickUp's plugin skills (3 more, 8 of 25). Get Tasks filters by status, assignee, tag, dates and Custom Fields at 100 tasks a page, v3 uses `limit` and `next_cursor`, and MCP has a Workspace search tool. No field selection on v2 (16 of 20). Errors carry `err` and an `ECODE`, and v3 adds `status`, `message` and `trace_id`. Only the OAuth codes are explained (12 of 20). No idempotency keys in either spec. `readOnlyHint` and `destructiveHint` could not be checked without an OAuth session. MCP rate errors return `retryAfter` (5 of 20). Create Task needs only `name`. No official SDK found on npm or in the ClickUp GitHub organisation. The official plugin adds three skills that preview a plan before writing (7 of 15). - Security & auth 64: The MCP server takes only OAuth 2.1 with PKCE (S256), dynamic client registration and resource indicators, with two scopes, read and write. The REST API takes a personal token (`pk_`) or an OAuth 2.0 token, neither of which expires or carries scopes (24 of 30). The read scope, the user's choice of Workspaces at authorisation and ClickUp's permission model limit reach. The MCP FAQ says deletion tools are withheld as a safety measure, while the tools page lists Delete task. No server-side confirmation step is documented (12 of 20). Tools return task, comment, Doc and Chat text written by other people, and no injection guidance was found (3 of 15). Audit Log is an Enterprise feature with a v3 endpoint, and MCP responses carry `X-Correlation-ID`. Whether MCP calls are logged per tool was not established (8 of 15). security.txt valid until 1 September 2027, a disclosure policy with safe harbour, SOC 1 and SOC 2 Type 2, ISO 27001, 27017, 27018, 27701 and 42001 stated, third-party penetration tests. No paid bounty found (17 of 20). - Payments & pricing 30: No x402, MPP or L402 (0). Plan prices are public, Free Forever, Unlimited at $7 a seat a month billed yearly or $10 monthly, Business at $12 or $19, Enterprise through sales. API and MCP calls are not priced per call, and the MCP daily caps lift with the Everything AI add-on at $28 a seat a month (10). Free Forever includes the API and the MCP server at 100 MCP calls per rolling 24 hours. We did not go through signup to confirm no card is asked for (20). Dynamic client registration lets an MCP client register itself, but a person signs in and authorises the Workspace in a browser (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 54: The MCP docs page was updated on 7 October 2026 and product Release Notes 4.08 are dated 18 September 2026 (30). The product changelog has three dated entries in the last 90 days (18 August, 25 August, 18 September), none about the public API, and docs pages changed on 10 August, 14 August, 17 September and 7 October (12 of 20). Public product changelog and feedback board, and 24/7 support stated on the pricing page. No API changelog, and response times were not checked (8 of 15). No entry under a ClickUp namespace among 13 ClickUp results in the official MCP registry, and no official SDK (0). The official clickup-plugin repository is MIT, at version 1.1.0, with six commits between 1 April and 7 September 2026 (4 of 10). - Transparency & trust 75: Closed service under Terms of Service effective 27 June 2025 and Developer Terms last updated 16 July 2024, naming Mango Technologies, Inc. DBA ClickUp. Clause 4.13(e) of the terms excludes API access with an unauthorised or third-party client, without defining it. The plugin repository is MIT (13 of 30). Privacy policy effective 2 June 2026 and a public DPA. Retention is stated as long as reasonably required, with no periods, and deletion at the end of term as soon as reasonably practicable. The security page says AI partners may not train on or retain customer data (18 of 30). No deprecation policy or dated notices found, and the Developer Terms state no obligation to maintain or support the API (3 of 20). Sub-processor list updated 28 September 2026 with purposes and locations, and Enterprise data residency in the US, Europe and Asia Pacific (18 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/clickup.md (JSON https://www.anchorterminal.com/fixes/clickup.json) ### What we couldn't check - unchecked: the MCP tool definitions (input schemas, descriptions, readOnlyHint and destructiveHint), since tools/list needs an OAuth session. The tool count of 48 comes from the docs page - unchecked: help.clickup.com, which answered with a bot check, so MCP admin controls, audit log contents and the add-on articles were not read - unchecked: status history for 10 to 20 July 2026. The feed returns 25 records, most of them imported from 2018 and 2019, and the page calendar loads in the browser - Whether the MCP server has a delete tool. The tools page lists Delete task and the MCP FAQ says no deletion tools exist - Whether Free Forever signup asks for a card. We did not go through signup - Whether any tier carries an uptime SLA. /terms/sla returned ClickUp's error page and none was found in the terms - What clause 4.13(e) of the terms (no API access with an unauthorised or third-party client) means for agents using a personal token - The MCP docs name Core, Business Plus and Enterprise Plus plans that the pricing page did not show on 8 October 2026 - Whether the read scope removes write tools from tools/list ### Sources - MCP server overview, limits and FAQ: (seen 2026-10-08) - MCP supported tools: (seen 2026-10-08) - MCP setup instructions: (seen 2026-10-08) - MCP OAuth authorisation server metadata: (seen 2026-10-08) - API rate limits: (seen 2026-10-08) - API authentication: (seen 2026-10-08) - OpenAPI spec, API v2: (seen 2026-10-08) - OpenAPI spec, API v3: (seen 2026-10-08) - docs index for agents: (seen 2026-10-08) - common errors: (seen 2026-10-08) - API availability by plan: (seen 2026-10-08) - webhook health and retries: (seen 2026-10-08) - status incident feed: (seen 2026-10-08) - status page and RSS feed: (seen 2026-10-08) - pricing: (seen 2026-10-08) - security page: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - vulnerability disclosure policy: (seen 2026-10-08) - terms of service: (seen 2026-10-08) - developer terms: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - data processing addendum: (seen 2026-10-08) - sub-processors: (seen 2026-10-08) - product changelog: (seen 2026-10-08) - official plugin repository: (seen 2026-10-08) - MCP registry search: (seen 2026-10-08) - domain registration (RDAP): (seen 2026-10-08) ## Who's behind it (provenance 97/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Mango Technologies, Inc. DBA ClickUp | 20/20 | | Domain age | clickup.com, registered 2001-07-05 (25 years) | 15/15 | | Endpoint on the vendor's domain | api.clickup.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.clickup.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The Terms of Service (effective 27 June 2025) and the privacy policy (effective 2 June 2026) name Mango Technologies, Inc. DBA ClickUp, 350 Tenth Ave, 5th floor, San Diego, CA 92101. The API answers at api.clickup.com and the MCP server at mcp.clickup.com, both clickup.com subdomains. clickup.com/.well-known/security.txt lists security@clickup.com and expires on 1 September 2027. It is not signed. The changelog link is the product changelog. No API changelog was found, and developer.clickup.com/changelog returns 404. RDAP for clickup.com gives a registration date of 2001-07-05. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://clickup.com/terms), read 2026-10-08, dated 2025-06-27, states 6 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "We prohibit crawling, scraping, caching or otherwise accessing any content on the Service via automated means (except as may be the result of standard search engine protocols or technologies used by a search engine with our express consent)." - To know. Says access can be ended without notice or for any reason. "We reserve the right to refuse access to the Service to anyone for any reason at any time." - To know. Requires arbitration or waives class actions. "…use of the Service, and/or rights of privacy and/or publicity, will be resolved by binding, individual arbitration under the American Arbitration Association's rules for arbitration of consumer-related disputes and you and we hereby expressly waive trial by jury." - Gives the date it was last updated. Last updated 2025-06-27. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Capped at $100.00. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Total liability to a customer is capped at 100 US dollars. "IN NO EVENT WILL THE CLICKUP PARTIES TOTAL LIABILITY TO YOU FOR ALL DAMAGES, LOSSES OR CAUSES OR ACTION EXCEED ONE HUNDRED UNITED STATES DOLLARS ($100.00)." - Also in the text (2026-10-08). Customer content carries no obligation of confidence on ClickUp's part, and ClickUp accepts no liability for its use or disclosure. "None of your Content will be subject to any obligation of confidence on our part, and we will not be liable for any use or disclosure of any Content you provide." - Also in the text (2026-10-08). Accounts renew automatically by default, and ClickUp may charge for the renewal unless the service has been cancelled. "By default, customer accounts are set to automatically renew and we may automatically charge you for such renewal on or after the renewal date associated with your account unless you have cancelled the Service." **Privacy policy** (https://clickup.com/terms/privacy), read 2026-10-08, dated 2026-06-02, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-06-02. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Says where data is transferred or stored. Data goes to the United States. - Also in the text (2026-10-08). Where the law imposes a duty to protect personal information that cannot be disclaimed, the user agrees that intentional misconduct is the standard for measuring ClickUp's compliance. "If applicable law imposes any non-disclaimable duty to protect your personally identifiable information, you agree that intentional misconduct will be the standards used to measure our compliance with that duty." - Also in the text (2026-10-08). ClickUp says a team's project and task data is never transferred to third parties, except as its Data Protection Addendum sets out. "Except as otherwise provided in our Data Protection Addendum, your team's project and task data will never be transferred to third parties." ## Live (updated 2026-10-08 19:08 UTC) - Right now: up, HTTP 404, 115 ms, checked 2026-10-08 19:08 UTC (get on `https://api.clickup.com`) - Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 39 ms · p95 63 ms - Vendor status page: none, All Systems Operational - security.txt: valid, expires 2027-09-01T00:00:00.000Z - Watching changelog - Watching pricing - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/clickup.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Free Forever (API and MCP included) | free | per seat per month | 100 MCP calls per rolling 24 hours | | Unlimited | $7 | per seat per month | billed yearly; $10 billed monthly | | Business | $12 | per seat per month | billed yearly; $19 billed monthly | | Everything AI add-on | $28 | per seat per month | as shown on 2026-10-08; lifts the MCP daily caps to the API limits | | AI Super Credits | $0.001 | per credit | $10 per 10,000; MCP calls do not use them | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Hosted MCP server at mcp.clickup.com/mcp with OAuth 2.1, PKCE (S256), dynamic client registration and read and write scopes - Public OpenAPI specs for API v2 (138 operations) and v3 (35), plus llms.txt and a Markdown copy of every docs page - API and MCP server available on every plan, including Free Forever - Rate limits published per plan for the API (100 to 10,000 requests a minute per token) and for MCP - security.txt valid until 1 September 2027, a disclosure policy with safe harbour, SOC 2 Type 2 and ISO 27001 stated ## Weaknesses - MCP calls are capped per rolling 24 hours without the Everything AI add-on, 100 on Free Forever and 300 on Unlimited, per Workspace and client - Personal API tokens and REST OAuth tokens never expire and carry no scopes - No API changelog or deprecation policy found, and the Developer Terms state no obligation to maintain the API - No official SDK and no idempotency keys found, and no entry under a ClickUp namespace in the official MCP registry - 48 documented MCP tools, and the tools page lists Delete task while the MCP FAQ says no deletion tools exist ## Before you call it (notes for agents) 1. Connect to https://mcp.clickup.com/mcp with OAuth 2.1 and PKCE. API keys and REST OAuth tokens are refused on the MCP server 2. Pass `workspace_id` on every MCP call when the user belongs to more than one Workspace, as ClickUp's own skills instruct 3. Budget MCP calls. Each tool call counts against the rolling 24-hour cap, and `RATE_LIMIT_EXCEEDED` returns `retryAfter` 4. On the REST API read `X-RateLimit-Remaining` and `X-RateLimit-Reset`, and page Get Tasks with `page` at 100 tasks a page 5. Treat `team_id` in API v2 as the Workspace ID, and send dates as Unix milliseconds ## Connect First request: ```bash curl https://api.clickup.com/api/v2/team -H "Authorization: $CLICKUP_API_TOKEN" ``` Claude Code: ```bash claude mcp add --transport http clickup https://mcp.clickup.com/mcp ``` MCP client configuration: ```json { "mcpServers": { "clickup": { "url": "https://mcp.clickup.com/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/clickup (letme picks it for work.chat, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | monday.com | BB | 76.4 | 32 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, work.docs | no | https://www.anchorterminal.com/tools/monday.md | | Asana | BB | 70.1 | 134 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/asana.md | | Todoist | B | 66.9 | 206 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/todoist.md | | Wrike | C | 60.1 | 364 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/wrike.md | | Trello | C | 61.1 | 333 | tasks.create, tasks.update, projects.manage, tasks.comments | no | https://www.anchorterminal.com/tools/trello.md | | Roma | D | 51.1 | 509 | tasks.create, tasks.update, projects.manage | no | https://www.anchorterminal.com/tools/roma.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The MCP server URL is https://mcp.clickup.com/mcp, available on all plans, and authenticates only with OAuth (source: ) - OAuth metadata lists authorisation code with PKCE S256, a registration endpoint and the scopes read and write (source: ) - Without the Everything AI add-on, MCP calls are capped per rolling 24 hours per Workspace and client, 100 on Free Forever, 300 on Unlimited, 1,000 on Business (source: ) - The API allows 100 requests a minute per token on Free Forever, Unlimited and Business, 1,000 on Business Plus and 10,000 on Enterprise (source: ) - Personal tokens never expire, and OAuth access tokens currently do not expire (source: ) - OpenAPI specs are published for API v2 and v3 (source: ) - The tools page lists Delete task, while the MCP FAQ says no deletion tools have been added as a safety measure (source: ) - The official plugin for Claude Code and Cursor wraps the hosted MCP server and adds three skills (source: ) ## Compare - [Asana vs ClickUp](https://www.anchorterminal.com/compare/asana-vs-clickup.md): BB 70.1 vs C 60.9 - [ClickUp vs monday.com](https://www.anchorterminal.com/compare/clickup-vs-monday.md): C 60.9 vs BB 76.4 - [ClickUp vs Roma](https://www.anchorterminal.com/compare/clickup-vs-roma.md): C 60.9 vs D 51.1 - [ClickUp vs Todoist](https://www.anchorterminal.com/compare/clickup-vs-todoist.md): C 60.9 vs B 66.9 - [ClickUp vs Trello](https://www.anchorterminal.com/compare/clickup-vs-trello.md): C 60.9 vs C 61.1 - [ClickUp vs Wrike](https://www.anchorterminal.com/compare/clickup-vs-wrike.md): C 60.9 vs C 60.1 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on clickup.com or one of its subdomains, or the README of github.com/clickup/clickup-plugin. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "clickup", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html ClickUp on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![ClickUp on Anchor Terminal](https://www.anchorterminal.com/badges/clickup.svg)](https://www.anchorterminal.com/tools/clickup) ``` Plain link: ```html ClickUp on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say ClickUp is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/clickup-dark.png - Light: https://www.anchorterminal.com/assets/share/clickup-light.png