EasyPost

by Simpler Postage, Inc. (d/b/a EasyPost) HTTP API in Shipping & fulfilment

Hosted

Simpler Postage, Inc. · easypost.com since 1998 · status page · who's behind it

EasyPost is a multi-carrier shipping API from Simpler Postage, Inc. Its REST API quotes carrier rates, buys labels, verifies addresses, tracks parcels and files refunds and insurance claims, with a hosted read-only MCP server in early release.

Good for An agent that quotes rates across carriers, buys a label, verifies an address, follows tracking by webhook and requests a refund from one merchant account, mainly on US carriers.

Is this your product? Claim this listing or verify it

Assessment. Docs written for agents (llms.txt, a Markdown copy of each page, a JSON page index), seven official SDKs and free test keys make the REST API easy to start on. No OpenAPI spec or idempotency keys were found, every key has full account access, and the status page shows a connectivity outage on 23 July 2026 that affected all operations.

Facts

Transport
HTTP
Endpoint
https://api.easypost.com/v2
Auth
API key
Pricing
Freemium · $0.02 / call
x402
No
Licence
Proprietary service under the EasyPost Master Customer Agreement. The official client libraries on GitHub are MIT, with the Go library under ISC
Packages
npm @easypost/api
pypi easypost
go github.com/EasyPost/easypost-go/v5
llms.txt
published
Last release
GitHub stars
149
npm / week
100k
PyPI / week
42k
API
REST at https://api.easypost.com/v2 over TLS 1.2, JSON. Shipments, rates, addresses, trackers, refunds, insurance, claims, pickups, batches, orders, customs, scan forms, reports, webhooks, events, users, API keys and billing. Some newer calls sit under /beta, such as POST /beta/rates
Credentials
API key as the HTTP Basic username with an empty password. Test and production keys. Keys can be created, disabled, enabled and deleted through /api_keys with a production key. Every key has full account access. Child users have their own keys
Getting access
Self-serve signup at app.easypost.com. The docs say a wallet and a ship-from address must be set up before API keys can be seen or generated
Test mode
A test key buys no postage and contacts no carrier. Test tracking codes return fixed statuses and fire webhooks. Negotiated rates appear only in production
MCP server
Hosted at https://app-api.easypost.com/mcp, Streamable HTTP, Bearer production API key, early release. 11 read-only tools (whoami, list_shipments, get_shipment, list_trackers, get_tracker, list_carrier_accounts, carrier_metadata, pickups, refunds, insurances, claims). Test keys aren't supported
Rate limits
A load-based limiter on buying and rating, with no number published, and a fixed limit on index endpoints, given as five requests a second. 429 on excess. At most 60 carrier accounts are rated in one request
Lists
page_size up to 100 (most endpoints default to 20), before_id and after_id, start_datetime and end_datetime, and a has_more flag. Support varies by endpoint
Errors
JSON error object with code, message and errors (field, message, suggestion). errors can be an array of objects or of strings. 13 general codes in the errors guide, such as PAYMENT_REQUIRED and MODE.UNAUTHORIZED
Webhooks
Up to 30 endpoints, X-Hmac-Signature from a webhook_secret, an X-Easypost-Event-Type header, up to three custom headers, a seven-second response window and six retries
Refunds
POST /refunds by carrier and tracking code. USPS labels within 30 days if never scanned, with at least 15 days of processing. UPS and FedEx within 90 days
Address verification
verify, verify_strict and verify_carrier (UPS or FedEx) on address creation. The docs say more than 240 countries and territories are covered, at levels that vary by country
Fees in the API Addendum
Each label bought includes one tracker call, one address verification call and three rating calls. Beyond that, $0.02 a tracker, $0.02 a US address verification, $0.06 an international one, $0.02 a rating call, $0.03 a SmartRate call, $0.15 a Pay-On-Delivery return label, and a 3 per cent surcharge on labels bought on the customer's own USPS rate card with PC Postage (version 4.2, effective 21 August 2026)
SDKs
easypost-csharp 7.10.0 (27 July 2026), easypost-go 5.10.1 (29 September), easypost-java 8.8.0 (25 June), @easypost/api 8.9.0 (25 June, with 9.0.0-rc.1 on 8 September), easypost-php 8.8.3 (8 September), easypost 10.7.0 on PyPI (25 June), easypost-ruby 7.7.0 (25 June). MIT, with Go under ISC
Status
www.easypoststatus.com on Statuspage, 44 components covering the API, webhooks, tracking, address verification, label purchases and each carrier, with incident history
Support
support@easypost.com and a help centre. The Support Services Addendum sets a four-hour response target on the Base tier and 30 minutes for a critical outage

Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • llms.txt, a Markdown copy of almost every docs page and a JSON page index with a note on when to read each page
  • Test API keys run the rate, buy, track and webhook flow at no cost, with no postage bought and no carrier contacted
  • Seven official SDKs (C#, Go, Java, Node, PHP, Python, Ruby), with Go 5.10.1 on 29 September 2026 and PHP 8.8.3 on 8 September
  • Dated release notes almost every week, 10 entries between 12 July and 28 September 2026
  • The data processing addendum names 12 subprocessors with purpose and country, and the legal centre keeps every past version of each agreement

Weaknesses

  • No OpenAPI spec was found in the docs or in the EasyPost GitHub organisation. The reference is prose and tables, with a Postman workspace
  • No idempotency keys were found, and reference on a shipment isn't unique, so a retried buy can purchase a second label
  • API keys allow full account access. Test and production modes and child users are the only separation, with no read-only or scoped key
  • An outage on 23 July 2026 at the hosting provider affected all operations for about four and a half hours. Two carrier-side incidents were marked major in the same 90 days
  • The Master Customer Agreement supplies the service as is, with no uptime commitment, and the per-label fee after 3,000 free labels isn't on the pricing page

Before you call it notes for agents

  1. Use a test API key while building. It buys no postage and contacts no carrier, and test tracking codes simulate each tracking status
  2. Don't blind-retry POST /shipments/:id/buy after a timeout. Retrieve the shipment first and check for postage_label, since no idempotency key exists
  3. Send the API key as the HTTP Basic username with an empty password on the REST API, and as a Bearer token on the MCP server
  4. Handle errors as either an array of objects or an array of strings. The docs say both shapes occur
  5. Pass a scoped carrier_accounts list when rating. Only the first 60 accounts are rated and the call doesn't fail when more are enabled

Who's behind it provenance 87/100

  • Legal entity namedSimpler Postage, Inc. (d/b/a EasyPost)20/20
  • Domain ageeasypost.com, registered 1998-01-18 (28 years)15/15
  • Endpoint on the vendor's domainapi.easypost.com15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagewww.easypoststatus.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2026-08-25, states 6 of 7, 2 to know

TL;DR Dated 2026-08-25. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on benchmarking and arbitration or a class action waiver.

Restricts benchmarking or competitive usecosts points
Access for any competitive purposes (including to build an application or product that is competitive with the EasyPost Products and Services).

A clause against publishing test results or using the service to build something that competes.

Requires arbitration or waives class actions
Any dispute or claim arising out of or relating to this Agreement or breach thereof, shall be settled by confidential binding arbitration in Salt Lake City, Utah, under the Rules of Arbitration of the International Chamber of Commerce by one arbitrator appointed in accordance with said rules.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2026-08-25
Effective August 25th 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of Utah
This Agreement shall be governed by the laws of the State of Utah, exclusive of its rules governing conflicts of laws.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at US$50
NOTWITHSTANDING ANYTHING ELSE IN THIS AGREEMENT, EASYPOST PROVIDES NO WARRANTY, INDEMNITY, SUPPORT FOR BETA FEATURES, AND ITS LIABILITY FOR BETA FEATURES WILL NOT EXCEED US$50.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
Termination of this Agreement will terminate all Order Form Terms then-in effect unless otherwise specified on the applicable Order Form.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives 30 days of notice before a change
Updated Master Terms will be effective upon the earlier of: (a) renewal, including auto renewal, of an Order Form (provided that the updated Master Terms were posted at least 30 days prior to such renewal) and (b) Customer entering into a new Order Form after such updated Master Terms have been posted.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
IF YOU DO NOT HAVE SUCH AUTHORITY, OR IF YOU DO NOT AGREE WITH THIS AGREEMENT, YOU MUST NOT ACCEPT THIS AGREEMENT AND MAY NOT USE ANY PRODUCT OR RECEIVE ANY PROFESSIONAL SERVICES.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

The document · read 2026-10-08 · 97,752 words

Privacy policy dated 2026-08-25, states 8 of 8

TL;DR Dated 2026-08-25. States all 8 things a reader expects. The rules found no clause to flag.

Gives the date it was last updated Last updated 2026-08-25
Effective August 25th 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
(d/b/a EasyPost) (“Company”, “we”, “us” “our”) describes how we collect, use and disclose information about users of our website (www.easypost.com) and our mobile and desktop applications and platform, services, tools and features, including when interacting with us in the context of an application for employment or i…

The basic statement a privacy policy exists to make.

Says how long data is kept
We retain your information for as long as is reasonably necessary for the purposes specified in this Privacy Policy.

Says when data sent to the service is deleted.

Says who else receives the data
Customer’s use of Third-Party Offerings is subject to Customer’s agreement with the relevant provider governing Customer’s access to and receipt or use of such Third-Party Offerings (“Third-Party Provider Agreements”) and not this Agreement.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
We do not “sell” or “share” personal information (as those terms are defined in applicable law), including sensitive personal information, nor have we done so in the preceding 12 months.

A plain statement either way.

Says what rights people have over their data
not share with Company any Personal Data of any Data Subject who has exercised a right to opt-out that Customer has committed to honoring;

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@easypost.com
Should you have any questions about our privacy practices or this Privacy Policy, please email us at privacy@easypost.com or contact us at Simpler Postage, Inc.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
“EU Standard Contractual Clauses” means the contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council s…

The countries data goes to and the safeguard used.

The document · read 2026-10-08 · 97,752 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Master Customer Agreement (version 6.1, effective 25 August 2026) names Simpler Postage, Inc. (d/b/a EasyPost), 2600 N. Ashton Blvd., Suite 300A, Lehi, UT 84043.

www.easypost.com/.well-known/security.txt and api.easypost.com/.well-known/security.txt return 404. The legal centre carries a Responsible Disclosure Policy with the contact security-abuse@easypost.com.

The privacy policy and the Data Protection Addendum are both version 1.0, effective 18 August 2025. The addendum's Annex D lists 12 subprocessors, all in the USA.

The MCP server is on app-api.easypost.com and the REST API on api.easypost.com. The status page is on a separate domain, easypoststatus.com.

trust.easypost.com answered 403 to our reader, so certifications are taken only from the addendum, which refers to a SOC 2 Type 2 report.

Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 16:44 UTC

Right nowUpHTTP 404 · 747 ms · 5 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h615 msget
p95 24h747 msopen endpoint

Probed every five minutes at https://api.easypost.com/v2. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page minor, Partially Degraded Service · 10 minutes ago
  • github EasyPost/easypost-node v8.9.0, released 2026-06-25
  • npm @easypost/api 8.9.0
  • pypi easypost 10.7.0, released 2026-06-25
  • GitHub stars 149
  • npm downloads a week 100k
  • PyPI downloads a week 43k
  • security.txt none · 1 hour ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/easypost.json

Notable

  • The docs are published for agents. llms.txt, a Markdown copy of almost every page under /markdown, and doc-index.json with a note on when each page is the right one to read source
  • EasyPost MCP is a hosted server at https://app-api.easypost.com/mcp with 11 tools that only read. The guide calls it an early release and says it needs a production API key source
  • No vendor entry was found in the official MCP registry. The two EasyPost entries there, io.github.pipeworx-io/easypost and io.usefulapi/easypost, are third-party source
  • The pricing page lists the Suite as free for up to 3,000 labels on wallet carriers, postage not included, and $20 a month plus a per-label fee for customers who bring their own carrier accounts source
  • The API Addendum publishes overage fees, $0.02 for each extra tracker, US address verification or rating call and $0.06 for an international address verification source
  • Trackers are deduplicated. The same tracking code and carrier from the same user within three months returns the original tracker source
  • A return label is a shipment created with is_return set to true, which swaps the two addresses source
  • The status page records an outage on 23 July 2026, a connectivity fault at the hosting provider that affected all operations from 07:57 to about 12:21 Pacific time source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 10.6
Read with the hosted lines and scored on the REST API at api.easypost.com/v2, the surface an agent would use to rate, buy and track. The hosted MCP server only reads and is an early release. www.easypoststatus.com on Statuspage lists 44 components with incident history (20). In the 90 days to 7 October 2026 it shows seven incidents. A connectivity fault at the hosting provider on 23 July affected all operations from 07:57 to about 12:21 Pacific time, and two carrier-side incidents were marked major (UPS accounts supplied by EasyPost on 22 July for 3 h 29 min, USPS Ship on 20 September for 5 h 24 min). Two short API degradations lasted 10 and 14 minutes. One core outage and two upstream majors (7 of 30). The rate-limiting guide gives five requests a second on index endpoints and a 60-account cap on rating, but the load-based limiter on buying and rating has no published number (8 of 15). The guide describes 429 handling with retry and backoff and a code sample. No Retry-After header and no idempotency keys were found, and the sample retries only GET and DELETE (8 of 15). The Master Customer Agreement supplies the service as is and as available, and the support addendum sets response targets only (0). The v2 API is generally available (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 8.9
No OpenAPI or similar spec was found in the docs, llms.txt, the page index or the 56 public repositories of the EasyPost GitHub organisation. A Postman workspace is listed, which we didn't read (0 of 25). llms.txt, a Markdown copy of almost every page and doc-index.json with audience and usage notes for each page (10). Each object has a property table with a type and description, and the index says when each page applies. Endpoint pages are mostly examples, with little on when not to use a call (12 of 20). Types and allowed values are given in prose tables, such as the ten tracker statuses, with no schema to validate against, and the Markdown copies omit some parameter lists that the HTML pages render (8 of 15). Every endpoint has examples in cURL and seven SDK languages, plus an error object and 13 general error codes. The full error code list is on a part of the page the Markdown copy omits (13 of 15). The path carries v2 and the releases page has dated notes almost every week. No written versioning policy was found, and some calls sit under /beta (12 of 15).
Agent ergonomics 13%16.2 10.2
List calls take page_size up to 100 with a default of 20 on most endpoints. No field selection was found, and a shipment response nests addresses, parcel, rates and tracker (12 of 25). Cursor pagination by before_id and after_id, date ranges and a has_more flag, with support that varies by endpoint (16 of 20). Errors carry a machine-readable code, a message and per-field entries with an occasional suggestion. The errors array arrives as objects or as strings, so a client has to handle both (15 of 20). No idempotency keys were found. Trackers are deduplicated by tracking code and carrier for three months, but reference on a shipment isn't unique and nothing guards a repeated buy. The MCP tools only read, though we couldn't list them without a key to see annotations (5 of 20). One-call buy creates and purchases in one request, addresses and parcels can be nested or reused by id, and official SDKs cover seven languages (15).
Security & auth 14%17.5 8.2
API keys go in the HTTP Basic username over TLS 1.2. Keys can be created, disabled, enabled and deleted through the API or the dashboard, and the docs say a key allows full account access. Plain revocable keys, with no secret in a query string (20 of 30). Test keys buy no postage, child users hold separate keys, and the MCP server has read tools only and omits carrier credentials, wallet balances and payment methods. The REST API has no read-only or scoped key and no confirmation step before a purchase (8 of 20). Responses carry addresses and carrier tracking text. The MCP guide advises connecting only to trusted clients and servers, and no injection guidance was found (4 of 15). Events and their payloads can be retrieved and each shipment lists its fees, but no audit log of API calls or key use was found in the reviewed documentation (5 of 15). A Responsible Disclosure Policy with a safe-harbour commitment and the contact security-abuse@easypost.com, HMAC-signed webhooks, and a SOC 2 Type 2 report referred to in the data processing addendum. No security.txt and no bug bounty were found, and trust.easypost.com refused our reader (10 of 20).
Payments & pricing 10%12.5 2.8
Read with the hosted rubric. No x402, MPP or L402 (0). The API Addendum publishes unit fees without a login ($0.02 for each extra tracker, US address verification or rating call, $0.06 for an international verification, $0.03 a SmartRate call), and the pricing page lists tracking at $0.01 to $0.03 a shipment and insurance at 1 per cent. The per-label fee after 3,000 free labels isn't stated, and Forge, GlobalShip and Luma are priced by sales (12 of 20). Up to 3,000 labels carry no EasyPost fee and test keys cost nothing, but postage is always paid, and the docs say a wallet must be set up before keys are issued. Whether that needs a card wasn't established (10 of 20). A person signs up in a browser. Keys can be created by API only with an existing production key (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.4
The releases page has an entry dated 28 September 2026, nine days before the check, and easypost-go 5.10.1 was tagged on 29 September (30). Ten dated release notes between 12 July and 28 September 2026 (20). A closed service with public release notes, support@easypost.com, a help centre, a dedicated ai@easypost.com address for the MCP server and a published four-hour response target on the Base support tier. We didn't read GitHub issues or test response times (11 of 15). Seven official SDKs, all pushed between 24 September and 3 October 2026, though the Java, Python, Ruby and Node stable releases date from 25 June (15). The Python library's CI lints and runs tests on Python 3.9 to 3.13, and the Node library has a 9.0.0 release candidate that moves to TypeScript and fetch (9 of 10).
Transparency & trusteditorial 53, provenance 87 7%8.8 6.1
The service is closed, under a Master Customer Agreement (version 6.1, effective 25 August 2026) and seven addenda in a legal centre that keeps every past version. The SDKs are MIT or ISC (15). The privacy policy (18 August 2025) gives no retention period. The agreement points to a Data Retention Policy in the help centre, which refused our reader, and it grants EasyPost a licence to use customer data to improve its services and develop new products during and after the term. A data processing addendum with EU and UK standard clauses is public (15 of 30). The agreement says EasyPost will use reasonable efforts to notify customers before API changes that aren't backwards compatible, with no notice period, and allows termination with a refund within 15 days if functionality is materially reduced. No deprecation policy with dates was found (6 of 20). Annex D of the addendum lists 12 subprocessors with purpose and country, all in the USA, and customers have 10 days to object to a new one (17 of 20).
Negative events≤15None recorded0
Total54.3 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 20 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on EasyPost, or have the agent fetch /fixes/easypost.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: EasyPost

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/easypost, the October 2026 research run, assessed 7 October 2026. Grade C, 54.3 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on EasyPost: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 22 out of 100, up to 9.8 more on the total

Why it scored 22: Read with the hosted rubric. No x402, MPP or L402 (0). The API Addendum publishes unit fees without a login ($0.02 for each extra tracker, US address verification or rating call, $0.06 for an international verification, $0.03 a SmartRate call), and the pricing page lists tracking at $0.01 to $0.03 a shipment and insurance at 1 per cent. The per-label fee after 3,000 free labels isn't stated, and Forge, GlobalShip and Luma are priced by sales (12 of 20). Up to 3,000 labels carry no EasyPost fee and test keys cost nothing, but postage is always paid, and the docs say a wallet must be set up before keys are issued. Whether that needs a card wasn't established (10 of 20). A person signs up in a browser. Keys can be created by API only with an existing production key (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Reliability, 53 out of 100, up to 9.4 more on the total

Why it scored 53: Read with the hosted lines and scored on the REST API at api.easypost.com/v2, the surface an agent would use to rate, buy and track. The hosted MCP server only reads and is an early release. www.easypoststatus.com on Statuspage lists 44 components with incident history (20). In the 90 days to 7 October 2026 it shows seven incidents. A connectivity fault at the hosting provider on 23 July affected all operations from 07:57 to about 12:21 Pacific time, and two carrier-side incidents were marked major (UPS accounts supplied by EasyPost on 22 July for 3 h 29 min, USPS Ship on 20 September for 5 h 24 min). Two short API degradations lasted 10 and 14 minutes. One core outage and two upstream majors (7 of 30). The rate-limiting guide gives five requests a second on index endpoints and a 60-account cap on rating, but the load-based limiter on buying and rating has no published number (8 of 15). The guide describes 429 handling with retry and backoff and a code sample. No Retry-After header and no idempotency keys were found, and the sample retries only GET and DELETE (8 of 15). The Master Customer Agreement supplies the service as is and as available, and the support addendum sets response targets only (0). The v2 API is generally available (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 3. Security & auth, 47 out of 100, up to 9.3 more on the total

Why it scored 47: API keys go in the HTTP Basic username over TLS 1.2. Keys can be created, disabled, enabled and deleted through the API or the dashboard, and the docs say a key allows full account access. Plain revocable keys, with no secret in a query string (20 of 30). Test keys buy no postage, child users hold separate keys, and the MCP server has read tools only and omits carrier credentials, wallet balances and payment methods. The REST API has no read-only or scoped key and no confirmation step before a purchase (8 of 20). Responses carry addresses and carrier tracking text. The MCP guide advises connecting only to trusted clients and servers, and no injection guidance was found (4 of 15). Events and their payloads can be retrieved and each shipment lists its fees, but no audit log of API calls or key use was found in the reviewed documentation (5 of 15). A Responsible Disclosure Policy with a safe-harbour commitment and the contact security-abuse@easypost.com, HMAC-signed webhooks, and a SOC 2 Type 2 report referred to in the data processing addendum. No security.txt and no bug bounty were found, and trust.easypost.com refused our reader (10 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Schema & documentation, 55 out of 100, up to 7.3 more on the total

Why it scored 55: No OpenAPI or similar spec was found in the docs, llms.txt, the page index or the 56 public repositories of the EasyPost GitHub organisation. A Postman workspace is listed, which we didn't read (0 of 25). llms.txt, a Markdown copy of almost every page and doc-index.json with audience and usage notes for each page (10). Each object has a property table with a type and description, and the index says when each page applies. Endpoint pages are mostly examples, with little on when not to use a call (12 of 20). Types and allowed values are given in prose tables, such as the ten tracker statuses, with no schema to validate against, and the Markdown copies omit some parameter lists that the HTML pages render (8 of 15). Every endpoint has examples in cURL and seven SDK languages, plus an error object and 13 general error codes. The full error code list is on a part of the page the Markdown copy omits (13 of 15). The path carries v2 and the releases page has dated notes almost every week. No written versioning policy was found, and some calls sit under /beta (12 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 5. Agent ergonomics, 63 out of 100, up to 6 more on the total

Why it scored 63: List calls take `page_size` up to 100 with a default of 20 on most endpoints. No field selection was found, and a shipment response nests addresses, parcel, rates and tracker (12 of 25). Cursor pagination by `before_id` and `after_id`, date ranges and a `has_more` flag, with support that varies by endpoint (16 of 20). Errors carry a machine-readable `code`, a message and per-field entries with an occasional suggestion. The `errors` array arrives as objects or as strings, so a client has to handle both (15 of 20). No idempotency keys were found. Trackers are deduplicated by tracking code and carrier for three months, but `reference` on a shipment isn't unique and nothing guards a repeated buy. The MCP tools only read, though we couldn't list them without a key to see annotations (5 of 20). One-call buy creates and purchases in one request, addresses and parcels can be nested or reused by id, and official SDKs cover seven languages (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 6. Transparency & trust, 70 out of 100, up to 2.6 more on the total

Made of editorial 53, provenance 87.

Why it scored 70: The service is closed, under a Master Customer Agreement (version 6.1, effective 25 August 2026) and seven addenda in a legal centre that keeps every past version. The SDKs are MIT or ISC (15). The privacy policy (18 August 2025) gives no retention period. The agreement points to a Data Retention Policy in the help centre, which refused our reader, and it grants EasyPost a licence to use customer data to improve its services and develop new products during and after the term. A data processing addendum with EU and UK standard clauses is public (15 of 30). The agreement says EasyPost will use reasonable efforts to notify customers before API changes that aren't backwards compatible, with no notice period, and allows termination with a refund within 15 days if functionality is materially reduced. No deprecation policy with dates was found (6 of 20). Annex D of the addendum lists 12 subprocessors with purpose and country, all in the USA, and customers have 10 days to object to a new one (17 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10)
- security.txt: not found (0 of 10)

## 7. Maintenance & community, 85 out of 100, up to 1.3 more on the total

Why it scored 85: The releases page has an entry dated 28 September 2026, nine days before the check, and easypost-go 5.10.1 was tagged on 29 September (30). Ten dated release notes between 12 July and 28 September 2026 (20). A closed service with public release notes, support@easypost.com, a help centre, a dedicated ai@easypost.com address for the MCP server and a published four-hour response target on the Base support tier. We didn't read GitHub issues or test response times (11 of 15). Seven official SDKs, all pushed between 24 September and 3 October 2026, though the Java, Python, Ruby and Node stable releases date from 25 June (15). The Python library's CI lints and runs tests on Python 3.9 to 3.13, and the Node library has a 9.0.0 release candidate that moves to TypeScript and fetch (9 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: trust.easypost.com and www.easypost.com/security answered 403 to our reader, so certifications beyond the SOC 2 Type 2 report named in the data processing addendum are unconfirmed.
- unchecked: the Data Retention Policy at support.easypost.com, which answered 403, so retention periods for shipment data are unknown.
- unchecked: the MCP server's tool schemas and annotations. tools/list answers 401 without a production key, so the 11 tools are taken from the guide.
- unchecked: the Postman workspace at www.postman.com/easypost-api, which may hold a machine-readable collection.
- unchecked: GitHub issues and response times on the SDK repositories.
- www.easypost.com/pricing answered a Cloudflare block to curl and loaded through WebFetch. Prices here come from that one read and from the API Addendum.
- The per-label fee after 3,000 free labels, and whether the 3,000 are counted by month or year, aren't stated on the pricing page.
- Whether setting up the wallet needed for API keys requires a card or a deposit wasn't established. We didn't sign up.
- The rate-limiting guide gives five requests a second on index endpoints as an example. Limits on buying and rating are load-based with no number.
- The 23 July 2026 outage has its Statuspage impact field left at none, although the updates say all operations were affected. We scored it as a major outage.
- No date was found for the MCP server's launch. It isn't in the release notes we read.

## Weaknesses

- No OpenAPI spec was found in the docs or in the EasyPost GitHub organisation. The reference is prose and tables, with a Postman workspace
- No idempotency keys were found, and `reference` on a shipment isn't unique, so a retried buy can purchase a second label
- API keys allow full account access. Test and production modes and child users are the only separation, with no read-only or scoped key
- An outage on 23 July 2026 at the hosting provider affected all operations for about four and a half hours. Two carrier-side incidents were marked major in the same 90 days
- The Master Customer Agreement supplies the service as is, with no uptime commitment, and the per-label fee after 3,000 free labels isn't on the pricing page

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Use a test API key while building. It buys no postage and contacts no carrier, and test tracking codes simulate each tracking status
- Don't blind-retry `POST /shipments/:id/buy` after a timeout. Retrieve the shipment first and check for `postage_label`, since no idempotency key exists
- Send the API key as the HTTP Basic username with an empty password on the REST API, and as a Bearer token on the MCP server
- Handle `errors` as either an array of objects or an array of strings. The docs say both shapes occur
- Pass a scoped `carrier_accounts` list when rating. Only the first 60 accounts are rated and the call doesn't fail when more are enabled

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: trust.easypost.com and www.easypost.com/security answered 403 to our reader, so certifications beyond the SOC 2 Type 2 report named in the data processing addendum are unconfirmed.
  • unchecked: the Data Retention Policy at support.easypost.com, which answered 403, so retention periods for shipment data are unknown.
  • unchecked: the MCP server's tool schemas and annotations. tools/list answers 401 without a production key, so the 11 tools are taken from the guide.
  • unchecked: the Postman workspace at www.postman.com/easypost-api, which may hold a machine-readable collection.
  • unchecked: GitHub issues and response times on the SDK repositories.
  • www.easypost.com/pricing answered a Cloudflare block to curl and loaded through WebFetch. Prices here come from that one read and from the API Addendum.
  • The per-label fee after 3,000 free labels, and whether the 3,000 are counted by month or year, aren't stated on the pricing page.
  • Whether setting up the wallet needed for API keys requires a card or a deposit wasn't established. We didn't sign up.
  • The rate-limiting guide gives five requests a second on index endpoints as an example. Limits on buying and rating are load-based with no number.
  • The 23 July 2026 outage has its Statuspage impact field left at none, although the updates say all operations were affected. We scored it as a major outage.
  • No date was found for the MCP server's launch. It isn't in the release notes we read.

Sources 40

  1. home page easypost.com · seen 2026-10-07
  2. pricing easypost.com · seen 2026-10-07
  3. llms.txt and API basics docs.easypost.com · seen 2026-10-07
  4. docs page index docs.easypost.com · seen 2026-10-07
  5. MCP guide, tools and security notes docs.easypost.com · seen 2026-10-07
  6. MCP endpoint (401 without a key) app-api.easypost.com · seen 2026-10-07
  7. authentication docs.easypost.com · seen 2026-10-07
  8. API keys docs.easypost.com · seen 2026-10-07
  9. rate limiting and backoff guide docs.easypost.com · seen 2026-10-07
  10. errors reference docs.easypost.com · seen 2026-10-07
  11. errors guide and general error codes docs.easypost.com · seen 2026-10-07
  12. pagination docs.easypost.com · seen 2026-10-07
  13. shipments, buy and one-call buy docs.easypost.com · seen 2026-10-07
  14. rates docs.easypost.com · seen 2026-10-07
  15. trackers, test codes and deduplication docs.easypost.com · seen 2026-10-07
  16. addresses and verification docs.easypost.com · seen 2026-10-07
  17. returns docs.easypost.com · seen 2026-10-07
  18. refunds docs.easypost.com · seen 2026-10-07
  19. webhooks guide docs.easypost.com · seen 2026-10-07
  20. getting started docs.easypost.com · seen 2026-10-07
  21. release notes docs.easypost.com · seen 2026-10-07
  22. client libraries docs.easypost.com · seen 2026-10-07
  23. status page summary easypoststatus.com · seen 2026-10-07
  24. status incident history easypoststatus.com · seen 2026-10-07
  25. legal centre, Master Customer Agreement legal.easypost.com · seen 2026-10-07
  26. API Addendum, fees legal.easypost.com · seen 2026-10-07
  27. privacy policy and Responsible Disclosure Policy legal.easypost.com · seen 2026-10-07
  28. Data Protection Addendum and subprocessor annex legal.easypost.com · seen 2026-10-07
  29. Support Services Addendum legal.easypost.com · seen 2026-10-07
  30. security.txt (404) easypost.com · seen 2026-10-07
  31. vendor repositories api.github.com · seen 2026-10-07
  32. Node library, changelog and tags github.com · seen 2026-10-07
  33. Python library, changelog, tags and CI github.com · seen 2026-10-07
  34. Go library tags github.com · seen 2026-10-07
  35. npm package registry.npmjs.org · seen 2026-10-07
  36. npm weekly downloads api.npmjs.org · seen 2026-10-07
  37. PyPI package pypi.org · seen 2026-10-07
  38. PyPI recent downloads pypistats.org · seen 2026-10-07
  39. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-07
  40. domain registration (RDAP) rdap.verisign.com · seen 2026-10-07

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $0.02 / call Free for up to 3,000 labels on wallet carriers, with postage charged separately and a per-label fee after that which the pricing page doesn't state. Bringing your own carrier accounts costs $20 a month plus a per-label fee. Tracking is listed at $0.01 to $0.03 a shipment and insurance at 1 per cent of value, minimum $1.00. Test keys cost nothing, so an agent can build without a contract. Forge, GlobalShip and Luma are priced by sales (checked 2026-10-07).

Prices

ItemPriceUnitNote
Extra tracker call$0.02per callone included with each label bought
Extra US address verification$0.02per callone included with each label bought; $0.06 outside the US
Extra rating call$0.02per callthree included with each label bought
SmartRate call$0.03per call
Bring your own carrier accounts$20per month (plan)plus a per-label fee not stated on the pricing page

Compared across listings on the price index.

Recent changes

  • EasyPost status page: none → minor source
  • Latest release

Follow them as a feed at /feeds/tools/easypost.xml, or this listing's score history at history.json.

Connect

Install

npm install @easypost/api

First request

curl -u "$EASYPOST_API_KEY": https://api.easypost.com/v2/shipments

Claude Code

claude mcp add --scope project --transport http easypost \
  https://app-api.easypost.com/mcp \
  --header 'Authorization: Bearer ${EASYPOST_API_KEY}'

MCP client configuration

{
  "mcpServers": {
    "easypost": {
      "headers": {
        "Authorization": "Bearer ${EASYPOST_API_KEY}"
      },
      "type": "http",
      "url": "https://app-api.easypost.com/mcp"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/easypost

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Easyship Easyship Inc.B68.8shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returnsno
Sendcloud Sendcloud B.V.B62shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returnsno
Shippo ShippoC61.9shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returnsno
ShipStation API Auctane LLC d/b/a ShipStationC59.3shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returnsno
TaxJar TaxJar (Stripe)C57.6shipping.address-validationno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    EasyPost on Anchor Terminal, C, 54.3/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/easypost"><img src="https://www.anchorterminal.com/badges/easypost.svg" alt="EasyPost on Anchor Terminal" height="20"></a>
    [![EasyPost on Anchor Terminal](https://www.anchorterminal.com/badges/easypost.svg)](https://www.anchorterminal.com/tools/easypost)

    It counts on a page on easypost.com or one of its subdomains, or the README of github.com/EasyPost/easypost-node.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "easypost", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.