{
  "data": {
    "similar": [
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/tally.json",
        "name": "Tally",
        "score": 60.6,
        "shared": [
          "forms.responses",
          "forms.webhooks",
          "forms.surveys",
          "forms.embed"
        ],
        "slug": "tally"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/typeform.json",
        "name": "Typeform",
        "score": 58.4,
        "shared": [
          "forms.responses",
          "forms.webhooks",
          "forms.surveys",
          "forms.embed"
        ],
        "slug": "typeform"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/surveymonkey.json",
        "name": "SurveyMonkey",
        "score": 55.3,
        "shared": [
          "forms.surveys",
          "forms.responses",
          "forms.webhooks",
          "forms.embed"
        ],
        "slug": "surveymonkey"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/jotform.json",
        "name": "Jotform",
        "score": 52.9,
        "shared": [
          "forms.responses",
          "forms.webhooks",
          "forms.surveys"
        ],
        "slug": "jotform"
      }
    ],
    "tool": {
      "slug": "fillout",
      "name": "Fillout",
      "vendor": "Restly, Inc. (trading as Zite)",
      "vendorUrl": "https://www.fillout.com",
      "kind": "http-api",
      "category": "forms",
      "summary": "Fillout is a form, survey and quiz builder from Restly, Inc., which trades as Zite. Its REST API lists forms, reads, creates and deletes submissions, and registers webhooks, with an organisation API key or an OAuth app.",
      "url": "https://www.anchorterminal.com/tools/fillout",
      "markdownUrl": "https://www.anchorterminal.com/tools/fillout.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/fillout.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/fillout.json",
      "repo": "https://github.com/fillout/api-client",
      "license": "Proprietary service under Fillout's terms of service. The TypeScript API client on GitHub is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.fillout.com/v1/api",
      "packages": [
        {
          "registry": "npm",
          "name": "@fillout/api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. An organisation API key from the Developer tab of account settings goes in `Authorization: Bearer \u003ckey\u003e`, and can be regenerated or revoked there. There is one key per organisation and the docs describe no scopes. Third-party apps use an OAuth authorisation code flow (authorise at `app.zite.com/authorize/oauth`, exchange at `server.fillout.com/public/oauth/accessToken`), with no scopes, expiry or refresh token documented. Fillout says public or partner OAuth apps may need its review before other users can connect (https://fillout.com/help/oauth-applications).",
      "pricing": "freemium",
      "pricingNotes": "Free plan with REST API access, 1,000 responses a month, unlimited forms and seats, so an agent's owner can start without a contract. Paid plans are flat monthly fees by response quota. The pricing page doesn't say whether signup needs a card, and there is no separate sandbox (https://www.fillout.com/pricing, checked 2026-10-08).",
      "priceSummary": "$15 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the REST API docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 1785,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.fillout.com/help/fillout-rest-api",
      "llmsTxt": "https://www.fillout.com/help/llms.txt",
      "openapi": "https://www.fillout.com/help/openapi.json",
      "capabilities": [
        "forms.responses",
        "forms.webhooks",
        "forms.surveys",
        "forms.embed"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "api-key",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "free-tier",
        "typescript",
        "status-page",
        "soc2",
        "eu-hosting"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 52.2,
        "grade": "D",
        "agentReady": false,
        "rank": 496,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 46,
          "payments": 30,
          "reliability": 70,
          "schema": 63,
          "security": 37,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 70,
            "points": 14,
            "reason": "Graded on the hosted lines for the REST API. Statuspage site at fillout.statuspage.io with seven components, one of them Developer API (20). Eight incidents between 10 July and 8 October 2026, none naming the Developer API. One was labelled major (29 August, 18 minutes, editor and dashboard), and the longest was 8 hours 50 minutes of slow custom domains on Zite Apps on 22 July (20). 5 requests a second per key (15). The docs say nothing about 429s or retries, and writes have no idempotency key, but live responses carry `ratelimit-limit`, `ratelimit-remaining` and `ratelimit-reset` headers (5). Enterprise lists custom agreements and SLAs, with no published SLA (0). The API is v1 with no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 63,
            "points": 10.24,
            "reason": "Public OpenAPI 3.0.1 spec with 8 operations and 31 schemas (25). llms.txt and a Markdown copy of each help page (10). Every operation and parameter has a one-line description, with no guidance on when to use which (6). Enums for status, sort and 38 question types, bounds on `limit` and a 10-item cap on created submissions, while answer values are untyped (11). The spec has no examples and documents only 200 responses (3). The path carries /v1, and the changelog is a product log by month with no API section. The last API item we found in it is from 2025 (8)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 47,
            "points": 7.64,
            "reason": "Eight operations, so the surface is small. Submissions can be capped at 1 to 150 a page, with no field selection (12). `limit`, `offset`, date range, status, sort and text search, with `totalResponses` and `pageCount` in the reply (18). Errors are undocumented. Live errors are JSON with `statusCode`, `error` and a specific `message`, and a missing key answered 400 where 401 is usual (6). No idempotency key on created submissions. Deleting by ID is safe to repeat (3). Few required parameters, and one official SDK in TypeScript only (8)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 37,
            "points": 6.48,
            "reason": "One API key per organisation, revocable and regenerable, with no scopes. OAuth apps use an authorisation code flow with no scopes or expiry documented, and a token invalidation endpoint (15). No read-only key and no confirmation before a submission is deleted. Member permissions by workspace exist on Team and Enterprise plans and don't apply to the key (3). Submissions are written by the public and the docs give no injection guidance (0). Audit logs record API key and OAuth app changes, on Enterprise only, kept 30 days, with no per-call log (6). SOC 2 Type 2 and a bug bounty are stated on the security page, with a report address. No security.txt and no public advisories found (13)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 (0). Plan prices are public with response quotas per plan, and nothing is priced per call (10). The free plan includes REST API access and 1,000 responses a month. The pricing page doesn't mention a card, and we didn't walk the signup (20). A person has to sign up in a browser and copy the key from Developer settings (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 46,
            "points": 4.03,
            "reason": "The changelog's newest entry is labelled October 2026, and the newest tagged Forms is August 2026, inside 90 days (20). Nine entries from August to October 2026, one of them tagged Forms, so half credit for the forms product (10). Support by email and live chat, described as 24/5 on the pricing page, with no public forum or issue tracker for the API (8). The one official SDK, `@fillout/api` 1.5.0, was last published on 5 May 2025 (5). Its repository has a release workflow and no tests that we saw (3)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 69,
            "points": 6.04,
            "note": "editorial 53, provenance 85",
            "reason": "Closed service with public terms dated 2 July 2022, and an MIT client (15). Privacy policy of 7 October 2025, a GDPR page, EU hosting on Team and above and documented deletion routes. Retention is stated only as long as necessary, no public DPA was found, and the terms and privacy policy give different addresses (18). No deprecation policy found, and the terms allow changes with or without notice (0). Subprocessors are listed with countries and whether each may process submission data (20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Eight operations, so the surface is small. Submissions can be capped at 1 to 150 a page, with no field selection (12). `limit`, `offset`, date range, status, sort and text search, with `totalResponses` and `pageCount` in the reply (18). Errors are undocumented. Live errors are JSON with `statusCode`, `error` and a specific `message`, and a missing key answered 400 where 401 is usual (6). No idempotency key on created submissions. Deleting by ID is safe to repeat (3). Few required parameters, and one official SDK in TypeScript only (8).",
            "maintenance": "The changelog's newest entry is labelled October 2026, and the newest tagged Forms is August 2026, inside 90 days (20). Nine entries from August to October 2026, one of them tagged Forms, so half credit for the forms product (10). Support by email and live chat, described as 24/5 on the pricing page, with no public forum or issue tracker for the API (8). The one official SDK, `@fillout/api` 1.5.0, was last published on 5 May 2025 (5). Its repository has a release workflow and no tests that we saw (3).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public with response quotas per plan, and nothing is priced per call (10). The free plan includes REST API access and 1,000 responses a month. The pricing page doesn't mention a card, and we didn't walk the signup (20). A person has to sign up in a browser and copy the key from Developer settings (0).",
            "reliability": "Graded on the hosted lines for the REST API. Statuspage site at fillout.statuspage.io with seven components, one of them Developer API (20). Eight incidents between 10 July and 8 October 2026, none naming the Developer API. One was labelled major (29 August, 18 minutes, editor and dashboard), and the longest was 8 hours 50 minutes of slow custom domains on Zite Apps on 22 July (20). 5 requests a second per key (15). The docs say nothing about 429s or retries, and writes have no idempotency key, but live responses carry `ratelimit-limit`, `ratelimit-remaining` and `ratelimit-reset` headers (5). Enterprise lists custom agreements and SLAs, with no published SLA (0). The API is v1 with no beta label (10).",
            "schema": "Public OpenAPI 3.0.1 spec with 8 operations and 31 schemas (25). llms.txt and a Markdown copy of each help page (10). Every operation and parameter has a one-line description, with no guidance on when to use which (6). Enums for status, sort and 38 question types, bounds on `limit` and a 10-item cap on created submissions, while answer values are untyped (11). The spec has no examples and documents only 200 responses (3). The path carries /v1, and the changelog is a product log by month with no API section. The last API item we found in it is from 2025 (8).",
            "security": "One API key per organisation, revocable and regenerable, with no scopes. OAuth apps use an authorisation code flow with no scopes or expiry documented, and a token invalidation endpoint (15). No read-only key and no confirmation before a submission is deleted. Member permissions by workspace exist on Team and Enterprise plans and don't apply to the key (3). Submissions are written by the public and the docs give no injection guidance (0). Audit logs record API key and OAuth app changes, on Enterprise only, kept 30 days, with no per-call log (6). SOC 2 Type 2 and a bug bounty are stated on the security page, with a report address. No security.txt and no public advisories found (13).",
            "transparency": "Closed service with public terms dated 2 July 2022, and an MIT client (15). Privacy policy of 7 October 2025, a GDPR page, EU hosting on Team and above and documented deletion routes. Retention is stated only as long as necessary, no public DPA was found, and the terms and privacy policy give different addresses (18). No deprecation policy found, and the terms allow changes with or without notice (0). Subprocessors are listed with countries and whether each may process submission data (20)."
          },
          "sources": [
            {
              "what": "REST API overview, authentication and rate limit",
              "url": "https://fillout.com/help/fillout-rest-api.md",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI 3.0.1 spec",
              "url": "https://www.fillout.com/help/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt index",
              "url": "https://www.fillout.com/help/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth apps",
              "url": "https://fillout.com/help/oauth-applications.md",
              "seen": "2026-10-08"
            },
            {
              "what": "create a webhook reference",
              "url": "https://fillout.com/help/api-reference/create-a-webhook.md",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.fillout.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "Team plan",
              "url": "https://fillout.com/help/team-plan.md",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents",
              "url": "https://fillout.statuspage.io/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://fillout.com/help/security.md",
              "seen": "2026-10-08"
            },
            {
              "what": "audit logs",
              "url": "https://fillout.com/help/audit-logs.md",
              "seen": "2026-10-08"
            },
            {
              "what": "subprocessors",
              "url": "https://fillout.com/help/subprocessors.md",
              "seen": "2026-10-08"
            },
            {
              "what": "GDPR page",
              "url": "https://fillout.com/help/gdpr.md",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.fillout.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.fillout.com/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://zite.com/help/whats-new.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Zite MCP overview",
              "url": "https://zite.com/help/database/mcp/mcp-overview.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Zite MCP connection guide",
              "url": "https://zite.com/help/database/mcp/connection-overview.md",
              "seen": "2026-10-08"
            },
            {
              "what": "npm package @fillout/api",
              "url": "https://registry.npmjs.org/@fillout/api",
              "seen": "2026-10-08"
            },
            {
              "what": "API client repository",
              "url": "https://github.com/fillout/api-client",
              "seen": "2026-10-08"
            },
            {
              "what": "unauthenticated API response and rate-limit headers",
              "url": "https://api.fillout.com/v1/api/forms",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (404)",
              "url": "https://www.fillout.com/.well-known/security.txt",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: whether signing up for the free plan needs a card. The pricing page doesn't say and we didn't create an account.",
            "unchecked: how the API answers a real 429, and whether it sends Retry-After. We saw only the rate-limit headers on a 400.",
            "unchecked: webhook signing, retries and delivery timeouts. Nothing in the reviewed docs covers them.",
            "unchecked: OAuth token lifetime and scopes. The OAuth page documents neither.",
            "unchecked: the day of the latest changelog entry. Entries are labelled by month, so `lastRelease` is left empty.",
            "unchecked: the bug bounty's scope and platform. The security page states one exists and links to no programme page.",
            "unchecked: GitHub stars for fillout/api-client.",
            "The official MCP registry has no Fillout or Zite entry under a vendor namespace. A search for fillout returned one third-party server, io.usefulapi/fillout."
          ]
        },
        "negative": 0,
        "verdict": "Fillout's REST API is on every plan, the free one included, with a public OpenAPI 3.0.1 spec, llms.txt and submission filters by date, status and text. It has eight operations and none creates or edits a form. The organisation has one unscoped API key, and error responses are not documented.",
        "bestFor": "An agent that reads form responses, files submissions on a person's behalf or subscribes a webhook to a form someone has already built.",
        "strengths": [
          "REST API access is included on the free plan, which allows 1,000 responses a month with unlimited forms and seats",
          "Public OpenAPI 3.0.1 spec at fillout.com/help/openapi.json, plus llms.txt and a Markdown copy of every help page",
          "Submissions can be filtered by date range, status and search text, sorted, and paged with `limit` (1 to 150) and `offset`",
          "The spec types 38 question kinds as an enum, so each answer arrives with its field type",
          "Subprocessor list with countries and a column showing which ones may process submission data"
        ],
        "weaknesses": [
          "No operation creates or edits a form. Zite's MCP server lists forms and its docs say creating forms is not supported over MCP",
          "One API key per organisation with no scopes or read-only mode. Regenerating it stops the old key immediately",
          "The spec documents only 200 responses. A request with no key returned 400, not 401, when we tried it",
          "No idempotency key on `POST /forms/{formId}/submissions`, and no webhook signing or retry policy in the reviewed docs",
          "The only official SDK is TypeScript, `@fillout/api` 1.5.0, last published on 5 May 2025"
        ],
        "agentNotes": [
          "Build the form in the Fillout editor first. The API reads forms and writes submissions but can't create a form or change its questions",
          "Read the base URL from the Developer settings page. EU-hosted accounts use https://eu-api.fillout.com/v1/api",
          "Stay under 5 requests a second per key and read the `ratelimit-remaining` and `ratelimit-reset` response headers",
          "Page submissions with `limit` (at most 150) and `offset`, and stop at `pageCount`. `status=in_progress` returns unfinished ones",
          "Send at most 10 submissions per create call and don't retry blindly, because the call has no idempotency key"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 52.2
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 46,
          "payments": 30,
          "reliability": 70,
          "schema": 63,
          "security": 37,
          "transparency": 53
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "npm install @fillout/api",
        "http": "curl \"https://api.fillout.com/v1/api/forms\" \\\n  -H \"Authorization: Bearer $FILLOUT_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/forms.responses",
        "tool": "https://letme.dev/fillout"
      },
      "notable": [
        "The REST API has eight operations. List forms, get form metadata, list, get, create and delete submissions, create and remove a webhook (https://www.fillout.com/help/openapi.json)",
        "No operation creates or edits a form. Zite's MCP server at https://mcp.zite.com/mcp lists the Fillout forms in a workspace, and its overview says creating forms is not supported over MCP (https://zite.com/help/database/mcp/mcp-overview)",
        "REST API access is listed as included on the Free, Starter, Pro and Business plans (https://www.fillout.com/pricing)",
        "All endpoints are limited to 5 calls a second per account or API key (https://www.fillout.com/help/fillout-rest-api). An unauthenticated request on 2026-10-08 returned `ratelimit-limit: 5` and `ratelimit-policy: 5;w=1` headers",
        "Webhooks registered through the API receive each submission in the same format as the `responses` entries of the submissions endpoint (https://fillout.com/help/api-reference/create-a-webhook)",
        "The status page has a Developer API component. Eight incidents were posted between 10 July and 8 October 2026 and none named that component (https://fillout.statuspage.io/history)",
        "Fillout is operated by Restly, Inc., which now trades as Zite. The privacy policy, security page and status page carry the Zite name (https://www.fillout.com/privacy)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "Fillout REST API v1 at https://api.fillout.com/v1/api (EU accounts https://eu-api.fillout.com/v1/api), eight operations, OpenAPI 3.0.1"
        },
        {
          "label": "Operations",
          "value": "GET /forms, GET /forms/{formId}, GET, POST /forms/{formId}/submissions, GET, DELETE /forms/{formId}/submissions/{submissionId}, POST /webhook/create, POST /webhook/delete"
        },
        {
          "label": "Form creation",
          "value": "Not available through the API. Forms are built in the Fillout editor or by its in-product Form Agent"
        },
        {
          "label": "MCP",
          "value": "No Fillout MCP server. Zite's server at https://mcp.zite.com/mcp (streamable HTTP, OAuth) lists a workspace's Fillout forms and can't create them, per its overview"
        },
        {
          "label": "Credentials",
          "value": "One API key per organisation, regenerated or revoked in Developer settings, or an OAuth app token. No scopes documented"
        },
        {
          "label": "Rate limits",
          "value": "5 requests a second per account or API key, with `ratelimit-limit`, `ratelimit-remaining` and `ratelimit-reset` response headers"
        },
        {
          "label": "Pagination",
          "value": "`limit` 1 to 150 (default 50), `offset`, `afterDate`, `beforeDate`, `status`, `sort`, `search`. Responses carry `totalResponses` and `pageCount`"
        },
        {
          "label": "Writes",
          "value": "Create up to 10 submissions per call, delete a submission by ID, create and remove webhooks. No idempotency key"
        },
        {
          "label": "Free tier",
          "value": "Free plan with REST API access, 1,000 responses a month, unlimited forms and seats"
        },
        {
          "label": "SDK",
          "value": "TypeScript `@fillout/api` 1.5.0 (5 May 2025), MIT, with a `region: \"eu\"` option. No other official language found"
        },
        {
          "label": "Audit",
          "value": "Audit logs on Enterprise plans, kept 30 days, covering logins, API key changes and OAuth apps, with an API Keys actor type"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2 per the security page, which also says a bug bounty programme is in place. Reports go to security@fillout.com"
        },
        {
          "label": "Hosting",
          "value": "AWS through Render in the United States. EU hosting of submissions on the Team plan and above"
        },
        {
          "label": "Status",
          "value": "https://fillout.statuspage.io (also status.zite.com) on Statuspage, seven components including Developer API"
        }
      ],
      "unitPrices": [
        {
          "item": "Starter (2,000 responses a month)",
          "unit": "month",
          "usd": 15,
          "note": "billed annually at $180"
        },
        {
          "item": "Pro (5,000 responses a month)",
          "unit": "month",
          "usd": 40,
          "note": "billed annually at $480"
        },
        {
          "item": "Business (unlimited responses)",
          "unit": "month",
          "usd": 75,
          "note": "billed annually at $900"
        },
        {
          "item": "Team bundle (forms, Zite apps and databases)",
          "unit": "month",
          "usd": 300,
          "note": "or $3,000 a year"
        }
      ],
      "provenance": {
        "legalEntity": "Restly, Inc.",
        "domain": "fillout.com",
        "domainRegistered": "2001-05-31",
        "endpointOnVendorDomain": true,
        "terms": "https://www.fillout.com/terms",
        "privacy": "https://www.fillout.com/privacy",
        "statusPage": "https://fillout.statuspage.io",
        "changelog": "https://zite.com/help/whats-new",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms (effective 2 July 2022) say Fillout is operated by Restly, Inc., a Delaware corporation, with a contact address at 1210 S Indiana Ave, Chicago, IL 60605, and Illinois governing law.",
          "The privacy policy (last modified 7 October 2025) names Restly, Inc., d.b.a. Zite, at 9450 SW Gemini Dr, PMB 39088, Beaverton, Oregon 97008.",
          "The API answers at api.fillout.com and eu-api.fillout.com. OAuth authorisation starts at app.zite.com and the token exchange is at server.fillout.com.",
          "www.fillout.com/.well-known/security.txt and fillout.com/security.txt return 404. The security page gives security@fillout.com for reports.",
          "The status page at fillout.statuspage.io is titled Zite and names status.zite.com as its address.",
          "The changelog lives on zite.com and labels entries by month. Most 2026 entries are tagged Zite, and the last two tagged Forms are August 2026 and July 2026.",
          "RDAP for fillout.com gives a registration date of 2001-05-31."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Restly, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "fillout.com, registered 2001-05-31 (25 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.fillout.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "fillout.statuspage.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.fillout.com/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-07-02",
            "words": 6817,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective Date: July 2, 2022",
                "says": "Last updated 2022-07-02"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The Terms and the relationship between you and Fillout shall be governed by the laws of the State of Illinois without regard to conflict of law provisions",
                "says": "The law of the State of Illinois"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "EXCEPT AS OTHERWISE SPECIFICALLY PROVIDED IN NO EVENT SHALL FILLOUT, NOR ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AFFILIATES, PARTNERS, SUPPLIERS, CONTRACTORS, OR CONTENT PROVIDERS, BE LIABLE UNDER CONTRACT, TORT, STRICT LIABILITY, NEGLIGENCE, OR ANY OTHER LEGAL OR EQUITABLE THEORY WITH RESPECT TO THE SERVICE (I) F…",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If your payment fails or if your payment information expires, you will be notified by Fillout and access to the Services will be suspended until payment is received."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If changes to the Terms or Privacy Policy occur, we will notify you by posting the updated terms on the Site, or by email to the email affiliated with your account.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "As a condition of use, you agree not to use the Services for any purpose that is prohibited by the Terms or law."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "You shall not use the Services for purposes of competitive analysis, the development of a competing product or service, or any other purpose that is to our commercial disadvantage;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We reserve the right to modify, suspend or discontinue all or any aspect of the Services with or without notice to you, including the suspension or takedown of any Form.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may suspend or cancel your Account without notice to you if you violate this Agreement, or for any reason at all."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "The parties further agree that any arbitration shall be conducted in their individual capacities only and not as a class action or other representative action, and the parties expressly waive their right to file a class action or seek relief on a class basis."
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Effective Date: July 2, 2022"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Paid subscriptions renew automatically unless written notice of cancellation is given at least 30 days before the next billing period.",
                "quote": "unless you notify us in writing of your intent to cancel your paid subscription at least 30 days prior to your next subscription billing period."
              },
              {
                "date": "2026-10-08",
                "text": "When an account is cancelled, Fillout may remove the account information and settings from its servers without liability or notice.",
                "quote": "If your Account is cancelled, we reserve the right to remove your account information along with any account settings from our servers with NO liability or notice to you."
              },
              {
                "date": "2026-10-08",
                "text": "A dispute must first be described to Fillout in writing within 30 days of the event that gave rise to it.",
                "quote": "In order to initiate this dispute resolution process, you must first send us a written description of your problem or dispute within thirty (30) days of the occurrence of the event giving rise to the dispute by sending an email to support@fillout.com."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.fillout.com/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-10-07",
            "words": 3826,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last modified: October 7, 2025",
                "says": "Last updated 2025-10-07"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This policy (“Privacy Policy”) describes the types of information we may collect from you and our practices for collecting, using, maintaining, protecting, and disclosing such information."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We will only retain your Personal Data for as long as is necessary to fulfill the purposes for which it is collected, or to comply with our legal obligations.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Right to data portability: You have the right to transfer your information to a third party in a structured, commonly used and machine-readable format, in circumstances where the information is processed with your consent or by automated means."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not sell or otherwise disclose Personal Data specific personal or transactional information to anyone except as described below.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Right to access: You have the right to access (and obtain a copy of, if required) the categories of personal information that we hold about you, including the information's source, purpose and period of processing, and the persons to whom the information is shared."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions or comments about this Privacy Policy, or if you would like to file a request about the data we hold or file a deletion request, please contact our Privacy team by email at privacy@fillout.com or by mail at:",
                "says": "privacy@fillout.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "For End Users that pay for our enterprise-level Services, Personal Data about End Users and Visitors can be stored in the European Union (EU) pursuant to European Commission-approved Standard Contractual Clauses as needed to perform our Services that you have requested from us, or with your consent.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The policy says the Services are intended only for use inside the United States by United States residents aged 18 or over.",
                "quote": "The Services are only intended to be used inside the United States by residents of the United States who are 18 years of age or older."
              },
              {
                "date": "2026-10-08",
                "text": "User data obtained through Google Workspace APIs will not be used to develop, improve or train generalised AI or machine learning models.",
                "quote": "User data obtained through Google Workspace APIs will not be used to develop, improve, or train generalized AI and/or machine learning models."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/fillout.json",
      "live": {
        "slug": "fillout",
        "probe": {
          "target": "https://api.fillout.com/v1/api",
          "method": "get",
          "lastAt": "2026-10-08T18:20:30.250941648Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 238,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 214,
          "p95ms24h": 513,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://fillout.statuspage.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:22:00.758077183Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "fillout/api-client",
            "version": "v1.5.0",
            "released": "2025-05-05",
            "seenAt": "2026-10-08T16:11:45.173327774Z"
          },
          {
            "registry": "npm",
            "name": "@fillout/api",
            "version": "1.5.0",
            "seenAt": "2026-10-08T16:11:41.429140032Z"
          }
        ],
        "githubStars": 0,
        "npmWeekly": 1785,
        "securityTxt": {
          "url": "https://fillout.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:39.813366641Z"
        },
        "updatedAt": "2026-10-08T18:22:00.758077183Z"
      }
    },
    "verify": {
      "accepts": "a page on fillout.com or one of its subdomains, or the README of github.com/fillout/api-client",
      "badgeUrl": "https://www.anchorterminal.com/badges/fillout.svg",
      "body": {
        "slug": "fillout",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/fillout",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/fillout\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/fillout.svg\" alt=\"Fillout on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Fillout on Anchor Terminal](https://www.anchorterminal.com/badges/fillout.svg)](https://www.anchorterminal.com/tools/fillout)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/fillout\"\u003eFillout on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/fillout",
    "json": "https://www.anchorterminal.com/tools/fillout.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/fillout.md",
    "slim": "https://www.anchorterminal.com/tools/fillout.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 52.2/100 · rank #496 of 629 · #5 in Forms, surveys \u0026 structured intake · not agent-ready · confidence medium**\n\n\n## Assessment\n\nFillout's REST API is on every plan, the free one included, with a public OpenAPI 3.0.1 spec, llms.txt and submission filters by date, status and text. It has eight operations and none creates or edits a form. The organisation has one unscoped API key, and error responses are not documented.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Restly, Inc. (trading as Zite) (https://www.fillout.com) |\n| Kind | HTTP API |\n| Category | Forms, surveys \u0026 structured intake (https://www.anchorterminal.com/categories/forms) |\n| Transport | HTTP |\n| Endpoint | `https://api.fillout.com/v1/api` |\n| Auth | OAuth or key · Self-serve. An organisation API key from the Developer tab of account settings goes in `Authorization: Bearer \u003ckey\u003e`, and can be regenerated or revoked there. There is one key per organisation and the docs describe no scopes. Third-party apps use an OAuth authorisation code flow (authorise at `app.zite.com/authorize/oauth`, exchange at `server.fillout.com/public/oauth/accessToken`), with no scopes, expiry or refresh token documented. Fillout says public or partner OAuth apps may need its review before other users can connect (https://fillout.com/help/oauth-applications). |\n| Pricing | Freemium ($15 / mo) · Free plan with REST API access, 1,000 responses a month, unlimited forms and seats, so an agent's owner can start without a contract. Paid plans are flat monthly fees by response quota. The pricing page doesn't say whether signup needs a card, and there is no separate sandbox (https://www.fillout.com/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the REST API docs, the OpenAPI spec or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Fillout's terms of service. The TypeScript API client on GitHub is MIT |\n| Packages | npm: `@fillout/api` |\n| Source | https://github.com/fillout/api-client |\n| Docs | https://www.fillout.com/help/fillout-rest-api |\n| llms.txt | https://www.fillout.com/help/llms.txt |\n| npm downloads / week | 1,785 |\n| Surface graded | Fillout REST API v1 at https://api.fillout.com/v1/api (EU accounts https://eu-api.fillout.com/v1/api), eight operations, OpenAPI 3.0.1 |\n| Operations | GET /forms, GET /forms/{formId}, GET, POST /forms/{formId}/submissions, GET, DELETE /forms/{formId}/submissions/{submissionId}, POST /webhook/create, POST /webhook/delete |\n| Form creation | Not available through the API. Forms are built in the Fillout editor or by its in-product Form Agent |\n| MCP | No Fillout MCP server. Zite's server at https://mcp.zite.com/mcp (streamable HTTP, OAuth) lists a workspace's Fillout forms and can't create them, per its overview |\n| Credentials | One API key per organisation, regenerated or revoked in Developer settings, or an OAuth app token. No scopes documented |\n| Rate limits | 5 requests a second per account or API key, with `ratelimit-limit`, `ratelimit-remaining` and `ratelimit-reset` response headers |\n| Pagination | `limit` 1 to 150 (default 50), `offset`, `afterDate`, `beforeDate`, `status`, `sort`, `search`. Responses carry `totalResponses` and `pageCount` |\n| Writes | Create up to 10 submissions per call, delete a submission by ID, create and remove webhooks. No idempotency key |\n| Free tier | Free plan with REST API access, 1,000 responses a month, unlimited forms and seats |\n| SDK | TypeScript `@fillout/api` 1.5.0 (5 May 2025), MIT, with a `region: \"eu\"` option. No other official language found |\n| Audit | Audit logs on Enterprise plans, kept 30 days, covering logins, API key changes and OAuth apps, with an API Keys actor type |\n| Certifications | SOC 2 Type 2 per the security page, which also says a bug bounty programme is in place. Reports go to security@fillout.com |\n| Hosting | AWS through Render in the United States. EU hosting of submissions on the Team plan and above |\n| Status | https://fillout.statuspage.io (also status.zite.com) on Statuspage, seven components including Developer API |\n| Capabilities | forms.responses, forms.webhooks, forms.surveys, forms.embed |\n| Tags | hosted, closed-source, api-key, oauth, openapi, llms-txt, webhooks, free-tier, typescript, status-page, soc2, eu-hosting |\n| JSON | https://www.anchorterminal.com/api/v1/tools/fillout.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 70 | 14.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 63 | 10.2 |\n| Agent ergonomics | 13% | 16.2 | 47 | 7.6 |\n| Security \u0026 auth | 14% | 17.5 | 37 | 6.5 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 46 | 4.0 |\n| Transparency \u0026 trust (editorial 53, provenance 85) | 7% | 8.8 | 69 | 6.0 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **52.2 → D** |\n\n### Why each score\n\n- Reliability 70: Graded on the hosted lines for the REST API. Statuspage site at fillout.statuspage.io with seven components, one of them Developer API (20). Eight incidents between 10 July and 8 October 2026, none naming the Developer API. One was labelled major (29 August, 18 minutes, editor and dashboard), and the longest was 8 hours 50 minutes of slow custom domains on Zite Apps on 22 July (20). 5 requests a second per key (15). The docs say nothing about 429s or retries, and writes have no idempotency key, but live responses carry `ratelimit-limit`, `ratelimit-remaining` and `ratelimit-reset` headers (5). Enterprise lists custom agreements and SLAs, with no published SLA (0). The API is v1 with no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 63: Public OpenAPI 3.0.1 spec with 8 operations and 31 schemas (25). llms.txt and a Markdown copy of each help page (10). Every operation and parameter has a one-line description, with no guidance on when to use which (6). Enums for status, sort and 38 question types, bounds on `limit` and a 10-item cap on created submissions, while answer values are untyped (11). The spec has no examples and documents only 200 responses (3). The path carries /v1, and the changelog is a product log by month with no API section. The last API item we found in it is from 2025 (8).\n- Agent ergonomics 47: Eight operations, so the surface is small. Submissions can be capped at 1 to 150 a page, with no field selection (12). `limit`, `offset`, date range, status, sort and text search, with `totalResponses` and `pageCount` in the reply (18). Errors are undocumented. Live errors are JSON with `statusCode`, `error` and a specific `message`, and a missing key answered 400 where 401 is usual (6). No idempotency key on created submissions. Deleting by ID is safe to repeat (3). Few required parameters, and one official SDK in TypeScript only (8).\n- Security \u0026 auth 37: One API key per organisation, revocable and regenerable, with no scopes. OAuth apps use an authorisation code flow with no scopes or expiry documented, and a token invalidation endpoint (15). No read-only key and no confirmation before a submission is deleted. Member permissions by workspace exist on Team and Enterprise plans and don't apply to the key (3). Submissions are written by the public and the docs give no injection guidance (0). Audit logs record API key and OAuth app changes, on Enterprise only, kept 30 days, with no per-call log (6). SOC 2 Type 2 and a bug bounty are stated on the security page, with a report address. No security.txt and no public advisories found (13).\n- Payments \u0026 pricing 30: No x402, MPP or L402 (0). Plan prices are public with response quotas per plan, and nothing is priced per call (10). The free plan includes REST API access and 1,000 responses a month. The pricing page doesn't mention a card, and we didn't walk the signup (20). A person has to sign up in a browser and copy the key from Developer settings (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 46: The changelog's newest entry is labelled October 2026, and the newest tagged Forms is August 2026, inside 90 days (20). Nine entries from August to October 2026, one of them tagged Forms, so half credit for the forms product (10). Support by email and live chat, described as 24/5 on the pricing page, with no public forum or issue tracker for the API (8). The one official SDK, `@fillout/api` 1.5.0, was last published on 5 May 2025 (5). Its repository has a release workflow and no tests that we saw (3).\n- Transparency \u0026 trust 69: Closed service with public terms dated 2 July 2022, and an MIT client (15). Privacy policy of 7 October 2025, a GDPR page, EU hosting on Team and above and documented deletion routes. Retention is stated only as long as necessary, no public DPA was found, and the terms and privacy policy give different addresses (18). No deprecation policy found, and the terms allow changes with or without notice (0). Subprocessors are listed with countries and whether each may process submission data (20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/fillout.md (JSON https://www.anchorterminal.com/fixes/fillout.json)\n\n### What we couldn't check\n\n- unchecked: whether signing up for the free plan needs a card. The pricing page doesn't say and we didn't create an account.\n- unchecked: how the API answers a real 429, and whether it sends Retry-After. We saw only the rate-limit headers on a 400.\n- unchecked: webhook signing, retries and delivery timeouts. Nothing in the reviewed docs covers them.\n- unchecked: OAuth token lifetime and scopes. The OAuth page documents neither.\n- unchecked: the day of the latest changelog entry. Entries are labelled by month, so `lastRelease` is left empty.\n- unchecked: the bug bounty's scope and platform. The security page states one exists and links to no programme page.\n- unchecked: GitHub stars for fillout/api-client.\n- The official MCP registry has no Fillout or Zite entry under a vendor namespace. A search for fillout returned one third-party server, io.usefulapi/fillout.\n\n### Sources\n\n- REST API overview, authentication and rate limit: \u003chttps://fillout.com/help/fillout-rest-api.md\u003e (seen 2026-10-08)\n- OpenAPI 3.0.1 spec: \u003chttps://www.fillout.com/help/openapi.json\u003e (seen 2026-10-08)\n- llms.txt index: \u003chttps://www.fillout.com/help/llms.txt\u003e (seen 2026-10-08)\n- OAuth apps: \u003chttps://fillout.com/help/oauth-applications.md\u003e (seen 2026-10-08)\n- create a webhook reference: \u003chttps://fillout.com/help/api-reference/create-a-webhook.md\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.fillout.com/pricing\u003e (seen 2026-10-08)\n- Team plan: \u003chttps://fillout.com/help/team-plan.md\u003e (seen 2026-10-08)\n- status incidents: \u003chttps://fillout.statuspage.io/api/v2/incidents.json\u003e (seen 2026-10-08)\n- security page: \u003chttps://fillout.com/help/security.md\u003e (seen 2026-10-08)\n- audit logs: \u003chttps://fillout.com/help/audit-logs.md\u003e (seen 2026-10-08)\n- subprocessors: \u003chttps://fillout.com/help/subprocessors.md\u003e (seen 2026-10-08)\n- GDPR page: \u003chttps://fillout.com/help/gdpr.md\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.fillout.com/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.fillout.com/privacy\u003e (seen 2026-10-08)\n- changelog: \u003chttps://zite.com/help/whats-new.md\u003e (seen 2026-10-08)\n- Zite MCP overview: \u003chttps://zite.com/help/database/mcp/mcp-overview.md\u003e (seen 2026-10-08)\n- Zite MCP connection guide: \u003chttps://zite.com/help/database/mcp/connection-overview.md\u003e (seen 2026-10-08)\n- npm package @fillout/api: \u003chttps://registry.npmjs.org/@fillout/api\u003e (seen 2026-10-08)\n- API client repository: \u003chttps://github.com/fillout/api-client\u003e (seen 2026-10-08)\n- unauthenticated API response and rate-limit headers: \u003chttps://api.fillout.com/v1/api/forms\u003e (seen 2026-10-08)\n- security.txt (404): \u003chttps://www.fillout.com/.well-known/security.txt\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 85/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Restly, Inc. | 20/20 |\n| Domain age | fillout.com, registered 2001-05-31 (25 years) | 15/15 |\n| Endpoint on the vendor's domain | api.fillout.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | fillout.statuspage.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe terms (effective 2 July 2022) say Fillout is operated by Restly, Inc., a Delaware corporation, with a contact address at 1210 S Indiana Ave, Chicago, IL 60605, and Illinois governing law.\n\nThe privacy policy (last modified 7 October 2025) names Restly, Inc., d.b.a. Zite, at 9450 SW Gemini Dr, PMB 39088, Beaverton, Oregon 97008.\n\nThe API answers at api.fillout.com and eu-api.fillout.com. OAuth authorisation starts at app.zite.com and the token exchange is at server.fillout.com.\n\nwww.fillout.com/.well-known/security.txt and fillout.com/security.txt return 404. The security page gives security@fillout.com for reports.\n\nThe status page at fillout.statuspage.io is titled Zite and names status.zite.com as its address.\n\nThe changelog lives on zite.com and labels entries by month. Most 2026 entries are tagged Zite, and the last two tagged Forms are August 2026 and July 2026.\n\nRDAP for fillout.com gives a registration date of 2001-05-31.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.fillout.com/terms), read 2026-10-08, dated 2022-07-02, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"You shall not use the Services for purposes of competitive analysis, the development of a competing product or service, or any other purpose that is to our commercial disadvantage;\"\n- To know. Says the terms or the service can change without notice (costs points). \"We reserve the right to modify, suspend or discontinue all or any aspect of the Services with or without notice to you, including the suspension or takedown of any Form.\"\n- To know. Says access can be ended without notice or for any reason. \"We may suspend or cancel your Account without notice to you if you violate this Agreement, or for any reason at all.\"\n- To know. Requires arbitration or waives class actions. \"The parties further agree that any arbitration shall be conducted in their individual capacities only and not as a class action or other representative action, and the parties expressly waive their right to file a class action or seek relief on a class basis.\"\n- To know. Has not been updated for three years or more. \"Effective Date: July 2, 2022\"\n- Gives the date it was last updated. Last updated 2022-07-02.\n- Names the governing law or courts. The law of the State of Illinois.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Paid subscriptions renew automatically unless written notice of cancellation is given at least 30 days before the next billing period. \"unless you notify us in writing of your intent to cancel your paid subscription at least 30 days prior to your next subscription billing period.\"\n- Also in the text (2026-10-08). When an account is cancelled, Fillout may remove the account information and settings from its servers without liability or notice. \"If your Account is cancelled, we reserve the right to remove your account information along with any account settings from our servers with NO liability or notice to you.\"\n- Also in the text (2026-10-08). A dispute must first be described to Fillout in writing within 30 days of the event that gave rise to it. \"In order to initiate this dispute resolution process, you must first send us a written description of your problem or dispute within thirty (30) days of the occurrence of the event giving rise to the dispute by sending an email to support@fillout.com.\"\n\n**Privacy policy** (https://www.fillout.com/privacy), read 2026-10-08, dated 2025-10-07, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2025-10-07.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@fillout.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). The policy says the Services are intended only for use inside the United States by United States residents aged 18 or over. \"The Services are only intended to be used inside the United States by residents of the United States who are 18 years of age or older.\"\n- Also in the text (2026-10-08). User data obtained through Google Workspace APIs will not be used to develop, improve or train generalised AI or machine learning models. \"User data obtained through Google Workspace APIs will not be used to develop, improve, or train generalized AI and/or machine learning models.\"\n\n## Live (updated 2026-10-08 18:22 UTC)\n\n- Right now: up, HTTP 404, 238 ms, checked 2026-10-08 18:20 UTC (get on `https://api.fillout.com/v1/api`)\n- Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 214 ms · p95 513 ms\n- Vendor status page: none, All Systems Operational\n- github `fillout/api-client` v1.5.0, released 2025-05-05\n- npm `@fillout/api` 1.5.0\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/fillout.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Starter (2,000 responses a month) | $15 | per month (plan) | billed annually at $180 |\n| Pro (5,000 responses a month) | $40 | per month (plan) | billed annually at $480 |\n| Business (unlimited responses) | $75 | per month (plan) | billed annually at $900 |\n| Team bundle (forms, Zite apps and databases) | $300 | per month (plan) | or $3,000 a year |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- REST API access is included on the free plan, which allows 1,000 responses a month with unlimited forms and seats\n- Public OpenAPI 3.0.1 spec at fillout.com/help/openapi.json, plus llms.txt and a Markdown copy of every help page\n- Submissions can be filtered by date range, status and search text, sorted, and paged with `limit` (1 to 150) and `offset`\n- The spec types 38 question kinds as an enum, so each answer arrives with its field type\n- Subprocessor list with countries and a column showing which ones may process submission data\n\n## Weaknesses\n\n- No operation creates or edits a form. Zite's MCP server lists forms and its docs say creating forms is not supported over MCP\n- One API key per organisation with no scopes or read-only mode. Regenerating it stops the old key immediately\n- The spec documents only 200 responses. A request with no key returned 400, not 401, when we tried it\n- No idempotency key on `POST /forms/{formId}/submissions`, and no webhook signing or retry policy in the reviewed docs\n- The only official SDK is TypeScript, `@fillout/api` 1.5.0, last published on 5 May 2025\n\n## Before you call it (notes for agents)\n\n1. Build the form in the Fillout editor first. The API reads forms and writes submissions but can't create a form or change its questions\n2. Read the base URL from the Developer settings page. EU-hosted accounts use https://eu-api.fillout.com/v1/api\n3. Stay under 5 requests a second per key and read the `ratelimit-remaining` and `ratelimit-reset` response headers\n4. Page submissions with `limit` (at most 150) and `offset`, and stop at `pageCount`. `status=in_progress` returns unfinished ones\n5. Send at most 10 submissions per create call and don't retry blindly, because the call has no idempotency key\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @fillout/api\n```\n\nFirst request:\n\n```bash\ncurl \"https://api.fillout.com/v1/api/forms\" \\\n  -H \"Authorization: Bearer $FILLOUT_API_KEY\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/fillout. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Tally | C | 60.6 | 348 | forms.responses, forms.webhooks, forms.surveys, forms.embed | no | https://www.anchorterminal.com/tools/tally.md |\n| Typeform | C | 58.4 | 401 | forms.responses, forms.webhooks, forms.surveys, forms.embed | no | https://www.anchorterminal.com/tools/typeform.md |\n| SurveyMonkey | C | 55.3 | 455 | forms.surveys, forms.responses, forms.webhooks, forms.embed | no | https://www.anchorterminal.com/tools/surveymonkey.md |\n| Jotform | D | 52.9 | 489 | forms.responses, forms.webhooks, forms.surveys | no | https://www.anchorterminal.com/tools/jotform.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The REST API has eight operations. List forms, get form metadata, list, get, create and delete submissions, create and remove a webhook (source: \u003chttps://www.fillout.com/help/openapi.json\u003e)\n- No operation creates or edits a form. Zite's MCP server at https://mcp.zite.com/mcp lists the Fillout forms in a workspace, and its overview says creating forms is not supported over MCP (source: \u003chttps://zite.com/help/database/mcp/mcp-overview\u003e)\n- REST API access is listed as included on the Free, Starter, Pro and Business plans (source: \u003chttps://www.fillout.com/pricing\u003e)\n- All endpoints are limited to 5 calls a second per account or API key (https://www.fillout.com/help/fillout-rest-api). An unauthenticated request on 2026-10-08 returned `ratelimit-limit: 5` and `ratelimit-policy: 5;w=1` headers\n- Webhooks registered through the API receive each submission in the same format as the `responses` entries of the submissions endpoint (source: \u003chttps://fillout.com/help/api-reference/create-a-webhook\u003e)\n- The status page has a Developer API component. Eight incidents were posted between 10 July and 8 October 2026 and none named that component (source: \u003chttps://fillout.statuspage.io/history\u003e)\n- Fillout is operated by Restly, Inc., which now trades as Zite. The privacy policy, security page and status page carry the Zite name (source: \u003chttps://www.fillout.com/privacy\u003e)\n\n## Compare\n\n- [Fillout vs Jotform](https://www.anchorterminal.com/compare/fillout-vs-jotform.md): D 52.2 vs D 52.9\n- [Fillout vs SurveyMonkey](https://www.anchorterminal.com/compare/fillout-vs-surveymonkey.md): D 52.2 vs C 55.3\n- [Fillout vs Tally](https://www.anchorterminal.com/compare/fillout-vs-tally.md): D 52.2 vs C 60.6\n- [Fillout vs Typeform](https://www.anchorterminal.com/compare/fillout-vs-typeform.md): D 52.2 vs C 58.4\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on fillout.com or one of its subdomains, or the README of github.com/fillout/api-client. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"fillout\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/fillout\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/fillout.svg\" alt=\"Fillout on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Fillout on Anchor Terminal](https://www.anchorterminal.com/badges/fillout.svg)](https://www.anchorterminal.com/tools/fillout)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/fillout\"\u003eFillout on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Fillout is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/fillout-dark.png\n- Light: https://www.anchorterminal.com/assets/share/fillout-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Forms, surveys \u0026 structured intake",
        "url": "https://www.anchorterminal.com/categories/forms"
      },
      {
        "name": "Fillout",
        "url": ""
      }
    ],
    "description": "Fillout is a form, survey and quiz builder from Restly, Inc., which trades as Zite. Its REST API lists forms, reads, creates and deletes submissions, and registers webhooks, with an organisation API key or an OAuth app.",
    "facts": [
      "rank #496 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Fillout",
    "image": "https://www.anchorterminal.com/assets/og/tools-fillout.png",
    "path": "/tools/fillout",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Fillout review for AI agents, grade D (52.2/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/fillout"
  },
  "tokens": {
    "markdown": 6800,
    "slim": 1630
  },
  "version": 1
}
