{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/statsig.json",
        "name": "Statsig",
        "score": 72.3,
        "shared": [
          "analytics.experiments",
          "analytics.flags",
          "analytics.query",
          "analytics.events"
        ],
        "slug": "statsig"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/posthog.json",
        "name": "PostHog",
        "score": 68.4,
        "shared": [
          "analytics.query",
          "analytics.events",
          "analytics.experiments",
          "analytics.flags"
        ],
        "slug": "posthog"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/amplitude.json",
        "name": "Amplitude",
        "score": 66.2,
        "shared": [
          "analytics.query",
          "analytics.experiments",
          "analytics.flags",
          "analytics.events"
        ],
        "slug": "amplitude"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/mixpanel.json",
        "name": "Mixpanel",
        "score": 62,
        "shared": [
          "analytics.query",
          "analytics.events",
          "analytics.experiments",
          "analytics.flags"
        ],
        "slug": "mixpanel"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/optimizely.json",
        "name": "Optimizely Experimentation",
        "score": 62.6,
        "shared": [
          "analytics.experiments",
          "analytics.flags",
          "analytics.query"
        ],
        "slug": "optimizely"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/launchdarkly.json",
        "name": "LaunchDarkly",
        "score": 69.2,
        "shared": [
          "analytics.flags",
          "analytics.experiments"
        ],
        "slug": "launchdarkly"
      }
    ],
    "tool": {
      "slug": "growthbook",
      "name": "GrowthBook",
      "vendor": "GrowthBook, Inc.",
      "vendorUrl": "https://www.growthbook.io",
      "kind": "http-api",
      "category": "product-analytics",
      "summary": "GrowthBook is an open-source platform for feature flags, experiments and product analytics, sold as GrowthBook Cloud or run self-hosted. Agents reach it through a REST API with a public OpenAPI spec and an official MCP server.",
      "url": "https://www.anchorterminal.com/tools/growthbook",
      "markdownUrl": "https://www.anchorterminal.com/tools/growthbook.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/growthbook.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/growthbook.json",
      "repo": "https://github.com/growthbook/growthbook",
      "license": "MIT for the core and for the MCP server. Three enterprise directories in the main repository are under GrowthBook's enterprise licence. GrowthBook Cloud is a hosted service under the Customer Agreement",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.growthbook.io/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@growthbook/mcp"
        },
        {
          "registry": "npm",
          "name": "@growthbook/growthbook"
        },
        {
          "registry": "pypi",
          "name": "growthbook"
        }
      ],
      "auth": "mixed",
      "authNotes": "The hosted MCP server uses OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint, with api.growthbook.io as the authorisation server. A person signs in and consents in a browser. The only scopes are openid, profile, email and offline_access, so the token carries the user's own permissions. The REST API takes a Personal Access Token or a Secret Key as a Bearer token or as the HTTP Basic username. Both are self-serve in the app. A Secret Key can hold any built-in or custom role with per-project overrides and environment limits, and both key types can expire. On the Free plan members can only hold the Admin role.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with no card, for up to 3 users and 1 project, so an agent's owner can start without a contract. Pro is $40 a seat a month for up to 30 users. Enterprise is by contract. Flags, experiments and traffic are unlimited on every plan, and API and MCP calls are not billed. Pro meters CDN requests, CDN bandwidth and Managed Warehouse events above its allowance. Self-hosting the open-source edition is free (https://www.growthbook.io/pricing, checked 2026-10-08).",
      "priceSummary": "$40 / seat-mo",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI spec, the MCP server source or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 4,
      "popularity": {
        "githubStars": 8484,
        "npmWeekly": 1290544,
        "pypiWeekly": 432892,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.growthbook.io",
      "llmsTxt": "https://docs.growthbook.io/llms.txt",
      "openapi": "https://api.growthbook.io/api/v1/openapi.yaml",
      "registryName": "io.github.growthbook/growthbook-mcp",
      "capabilities": [
        "analytics.experiments",
        "analytics.flags",
        "analytics.query",
        "analytics.events"
      ],
      "tags": [
        "official",
        "hosted",
        "open-source",
        "self-hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.1,
        "grade": "BB",
        "agentReady": true,
        "rank": 142,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 89,
          "payments": 40,
          "reliability": 86,
          "schema": 76,
          "security": 68,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 86,
            "points": 17.2,
            "reason": "Graded on GrowthBook Cloud with the hosted lines. Instatus page at status.growthbook.io with three components (GrowthBook Cloud App, Api, CDN) and a notice history (20). No notices for August, September or October 2026, and the newest entry in the feed is dated 21 August 2025. The MCP server is not a listed component, and the 2.2.0 changelog fixes intermittent 502s in HTTP mode that were not posted, so 25 of 30. API keys are limited to 60 requests a minute (15). The docs say only to try again later on 429. The server source sends standard RateLimit headers and the MCP server waits for `RateLimit-Reset` and retries three times, but no backoff guidance or idempotency keys were found in the docs (8 of 15). The pricing page lists a 99.99 per cent uptime SLA on Enterprise. The SLA document itself was not found in public (8 of 10). The REST API's /v1 is described as stable and the MCP docs carry no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 76,
            "points": 12.35,
            "reason": "Public OpenAPI 3.1 spec, version 5.1.0, with 306 paths and 414 operations, and Zod-typed inputs on all four MCP tools (25). llms.txt and a Markdown copy of each docs page (10). 413 of 414 operations have a summary and 185 have a description. The MCP tool descriptions say when to use each tool, and the bundled skills carry the workflows (13 of 20). The spec has 1,404 enums and marks required fields, but `growthbook_api_write` takes the path as a string and the body as a JSON string, and the docs say the API tools do not validate payloads (9 of 15). The spec has 17 examples and documents only 200 responses, plus 409 on 9 operations. The introduction lists eight status codes and a `message` body (6 of 15). Path versions /v1 and /v2, 34 operations marked deprecated, GitHub releases, and an MCP changelog with breaking changes called out (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 76,
            "points": 12.35,
            "reason": "Four compact MCP tools, with skills loaded on demand and a /mcp/api endpoint that drops the skill tools (25). `limit` (default 10, maximum 100) and `offset` on 40 list operations, with filters by project, data source and status. No field selection was found, and the API tools return the raw response body (15 of 20). Errors are a status code and a `message` with no machine code. 422 marks a soft warning that can be resubmitted with `ignoreWarnings`, and the MCP server adds recovery hints for 401, 403, 404 and 429 (13 of 20). All four tools carry readOnlyHint and destructiveHint, and reads and writes are separate tools. Every write is marked destructive, and no idempotency keys were found (13 of 20). The API tools need one to three parameters. The SDKs cover flag evaluation in many languages, not the REST API (10 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 68,
            "points": 11.9,
            "reason": "OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint for the hosted MCP server. Its only scopes are openid, profile, email and offline_access, so a token carries the user's full permissions. Secret Keys take any built-in or custom role with per-project overrides, environment limits and expiry, and Personal Access Tokens can be limited. Secrets travel in headers only (26 of 30). A Read Only role, an endpoint with the API tools alone, and read and write tools with annotations. Draft, review and publish steps live in the skills, approval workflows are an Enterprise feature, and since 2.1.0 confirmation is left to the client. Free plan members can only hold the Admin role (14 of 20). No guidance on prompt injection was found, though the tools return names and descriptions that people wrote (3 of 15). Audit logging is an Enterprise feature with export. Personal tokens attribute actions to a user, and the MCP server labels its API calls with `X-GB-MCP-*` headers (10 of 15). SOC 2 Type II, a disclosure process with a form and SECURITY.md, routine penetration testing and public GitHub advisories, the latest on 19 August 2026. Rewards are merchandise only and there is no security.txt (15 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). Prices are public without a login. Pro is $40 a seat a month, with $10 per million CDN requests, $1 per GB and $30 per million Managed Warehouse events above the allowance (20). The Starter plan is free with no card (20). A person signs up in a browser, then approves OAuth or creates a key (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 89,
            "points": 7.79,
            "reason": "MCP server 2.2.0 is dated 5 October 2026 and GrowthBook 5.1.0 was tagged on 21 September 2026 (30). Six releases since 10 July 2026, three of the app and three of the MCP server (20). The main repository's 200 newest commits run from 15 September to 8 October 2026, and there is a community Slack. We did not read how quickly issues are answered (15 of 25). `io.github.growthbook/growthbook-mcp` is in the official MCP registry at 2.2.0, published 6 October 2026 (15). The MCP repository runs CI on Node 22 and 26 with 34 tests and took dependency security updates on 8 October 2026. The package states Node 18 or later, which CI does not test (9 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 74,
            "points": 6.48,
            "note": "editorial 66, provenance 81",
            "reason": "The core and the MCP server are MIT. Three enterprise directories in the main repository are under GrowthBook's enterprise licence and are part of what Cloud runs (25 of 30). A Customer Agreement, a Privacy Notice of 8 June 2026 and a DPA of 19 June 2025 are published. The agreement grants GrowthBook an unrestricted right to use Customer Data, including to train its AI algorithms, then limits personal information to performing the Services. The Privacy Notice gives no retention periods, and the docs say only aggregate results are stored. We did not read the DPA, which is a download (16 of 30). Legacy v1 routes and 34 operations are marked deprecated with no removal dates, and no deprecation policy was found. The MCP changelog gives migration steps (8 of 20). The sub-processor list of 11 May 2026 names seven providers with locations, mostly in the United States. Notice of new ones is promised only as far as the law requires (17 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Four compact MCP tools, with skills loaded on demand and a /mcp/api endpoint that drops the skill tools (25). `limit` (default 10, maximum 100) and `offset` on 40 list operations, with filters by project, data source and status. No field selection was found, and the API tools return the raw response body (15 of 20). Errors are a status code and a `message` with no machine code. 422 marks a soft warning that can be resubmitted with `ignoreWarnings`, and the MCP server adds recovery hints for 401, 403, 404 and 429 (13 of 20). All four tools carry readOnlyHint and destructiveHint, and reads and writes are separate tools. Every write is marked destructive, and no idempotency keys were found (13 of 20). The API tools need one to three parameters. The SDKs cover flag evaluation in many languages, not the REST API (10 of 15).",
            "maintenance": "MCP server 2.2.0 is dated 5 October 2026 and GrowthBook 5.1.0 was tagged on 21 September 2026 (30). Six releases since 10 July 2026, three of the app and three of the MCP server (20). The main repository's 200 newest commits run from 15 September to 8 October 2026, and there is a community Slack. We did not read how quickly issues are answered (15 of 25). `io.github.growthbook/growthbook-mcp` is in the official MCP registry at 2.2.0, published 6 October 2026 (15). The MCP repository runs CI on Node 22 and 26 with 34 tests and took dependency security updates on 8 October 2026. The package states Node 18 or later, which CI does not test (9 of 10).",
            "payments": "No x402, MPP or L402 (0). Prices are public without a login. Pro is $40 a seat a month, with $10 per million CDN requests, $1 per GB and $30 per million Managed Warehouse events above the allowance (20). The Starter plan is free with no card (20). A person signs up in a browser, then approves OAuth or creates a key (0).",
            "reliability": "Graded on GrowthBook Cloud with the hosted lines. Instatus page at status.growthbook.io with three components (GrowthBook Cloud App, Api, CDN) and a notice history (20). No notices for August, September or October 2026, and the newest entry in the feed is dated 21 August 2025. The MCP server is not a listed component, and the 2.2.0 changelog fixes intermittent 502s in HTTP mode that were not posted, so 25 of 30. API keys are limited to 60 requests a minute (15). The docs say only to try again later on 429. The server source sends standard RateLimit headers and the MCP server waits for `RateLimit-Reset` and retries three times, but no backoff guidance or idempotency keys were found in the docs (8 of 15). The pricing page lists a 99.99 per cent uptime SLA on Enterprise. The SLA document itself was not found in public (8 of 10). The REST API's /v1 is described as stable and the MCP docs carry no beta label (10).",
            "schema": "Public OpenAPI 3.1 spec, version 5.1.0, with 306 paths and 414 operations, and Zod-typed inputs on all four MCP tools (25). llms.txt and a Markdown copy of each docs page (10). 413 of 414 operations have a summary and 185 have a description. The MCP tool descriptions say when to use each tool, and the bundled skills carry the workflows (13 of 20). The spec has 1,404 enums and marks required fields, but `growthbook_api_write` takes the path as a string and the body as a JSON string, and the docs say the API tools do not validate payloads (9 of 15). The spec has 17 examples and documents only 200 responses, plus 409 on 9 operations. The introduction lists eight status codes and a `message` body (6 of 15). Path versions /v1 and /v2, 34 operations marked deprecated, GitHub releases, and an MCP changelog with breaking changes called out (13 of 15).",
            "security": "OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint for the hosted MCP server. Its only scopes are openid, profile, email and offline_access, so a token carries the user's full permissions. Secret Keys take any built-in or custom role with per-project overrides, environment limits and expiry, and Personal Access Tokens can be limited. Secrets travel in headers only (26 of 30). A Read Only role, an endpoint with the API tools alone, and read and write tools with annotations. Draft, review and publish steps live in the skills, approval workflows are an Enterprise feature, and since 2.1.0 confirmation is left to the client. Free plan members can only hold the Admin role (14 of 20). No guidance on prompt injection was found, though the tools return names and descriptions that people wrote (3 of 15). Audit logging is an Enterprise feature with export. Personal tokens attribute actions to a user, and the MCP server labels its API calls with `X-GB-MCP-*` headers (10 of 15). SOC 2 Type II, a disclosure process with a form and SECURITY.md, routine penetration testing and public GitHub advisories, the latest on 19 August 2026. Rewards are merchandise only and there is no security.txt (15 of 20).",
            "transparency": "The core and the MCP server are MIT. Three enterprise directories in the main repository are under GrowthBook's enterprise licence and are part of what Cloud runs (25 of 30). A Customer Agreement, a Privacy Notice of 8 June 2026 and a DPA of 19 June 2025 are published. The agreement grants GrowthBook an unrestricted right to use Customer Data, including to train its AI algorithms, then limits personal information to performing the Services. The Privacy Notice gives no retention periods, and the docs say only aggregate results are stored. We did not read the DPA, which is a download (16 of 30). Legacy v1 routes and 34 operations are marked deprecated with no removal dates, and no deprecation policy was found. The MCP changelog gives migration steps (8 of 20). The sub-processor list of 11 May 2026 names seven providers with locations, mostly in the United States. Notice of new ones is promised only as far as the law requires (17 of 20)."
          },
          "sources": [
            {
              "what": "MCP server docs",
              "url": "https://docs.growthbook.io/integrations/mcp.md",
              "seen": "2026-10-08"
            },
            {
              "what": "REST API introduction, authentication, errors and rate limit",
              "url": "https://docs.growthbook.io/api/introduction.md",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI spec",
              "url": "https://api.growthbook.io/api/v1/openapi.yaml",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server source, tool definitions and changelog",
              "url": "https://github.com/growthbook/growthbook-mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth authorisation server metadata",
              "url": "https://api.growthbook.io/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth protected resource metadata",
              "url": "https://mcp.growthbook.io/.well-known/oauth-protected-resource",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry entries",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=growthbook",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.growthbook.io/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "fair use policy",
              "url": "https://www.growthbook.io/legal/fair-use-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "status history",
              "url": "https://status.growthbook.io/history/1",
              "seen": "2026-10-08"
            },
            {
              "what": "status feed",
              "url": "https://status.growthbook.io/history.atom",
              "seen": "2026-10-08"
            },
            {
              "what": "Customer Agreement",
              "url": "https://www.growthbook.io/legal/customer-agreement",
              "seen": "2026-10-08"
            },
            {
              "what": "Privacy Notice",
              "url": "https://www.growthbook.io/legal/privacy-notice",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://www.growthbook.io/legal/subprocessors",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.growthbook.io/platform/security",
              "seen": "2026-10-08"
            },
            {
              "what": "vulnerability disclosure process",
              "url": "https://www.growthbook.io/platform/security/vulnerability",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisory of 19 August 2026",
              "url": "https://github.com/growthbook/growthbook/security/advisories/GHSA-c4m3-8cgx-p88g",
              "seen": "2026-10-08"
            },
            {
              "what": "main repository, licence, tags and rate limiter",
              "url": "https://github.com/growthbook/growthbook",
              "seen": "2026-10-08"
            },
            {
              "what": "permissions and roles",
              "url": "https://docs.growthbook.io/account/user-permissions.md",
              "seen": "2026-10-08"
            },
            {
              "what": "audit logs",
              "url": "https://docs.growthbook.io/account/audit-logs.md",
              "seen": "2026-10-08"
            },
            {
              "what": "self-hosting environment variables and telemetry",
              "url": "https://docs.growthbook.io/self-host/env.md",
              "seen": "2026-10-08"
            },
            {
              "what": "npm package",
              "url": "https://registry.npmjs.org/@growthbook/mcp/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "npm downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/@growthbook/growthbook",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI downloads",
              "url": "https://pypistats.org/api/packages/growthbook/recent",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.identitydigital.services/rdap/domain/growthbook.io",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: how quickly GitHub issues and pull requests are answered. The GitHub API refused us for its rate limit and we did not read the issue lists.",
            "unchecked: the DPA of 19 June 2025, which is a download, and the contents of trust.growthbook.io, which is drawn by script.",
            "unchecked: the live tool list from https://mcp.growthbook.io/mcp, which needs an OAuth sign-in. Tool definitions were read from the 2.2.0 source.",
            "The text of the Enterprise SLA was not found in public. The 99.99 per cent figure is from the pricing and security pages.",
            "The docs page says the server has four tools, while the 2.0.0 changelog describes three. The count of four is from the 2.2.0 source.",
            "The compliance docs mention an active bug bounty programme, while the disclosure page says no financial rewards are paid.",
            "Whether the hosted server's tool changes of 30 July and 10 August 2026 were announced in advance was not established.",
            "The official registry entry lists only the npm stdio package and no remote URL.",
            "The authentication text inside the OpenAPI spec still says Secret Keys are admin or readonly, while the docs page says any role."
          ]
        },
        "negative": -3,
        "negativeNotes": [
          "10 August 2026. MCP server 2.1.0 replaced `growthbook_call_api` with two tools in a minor version, eleven days after 2.0.0 removed every 1.x tool, while the docs tell users to install `@growthbook/mcp@latest`. Both are marked breaking in the changelog with migration steps, and we found no advance notice, so the deduction is the minimum (https://github.com/growthbook/growthbook-mcp/blob/main/CHANGELOG.md)."
        ],
        "verdict": "GrowthBook Cloud's MCP server has four tools with read and write annotations, OAuth with dynamic client registration, and a 414-operation OpenAPI spec behind it. The free plan needs no card. The API tools pass paths and JSON bodies through without validation, every key is limited to 60 requests a minute, and audit logs are Enterprise only.",
        "bestFor": "Teams that want flags and experiments analysed against their own warehouse, with an open-source core and a self-hosted option.",
        "strengths": [
          "The MCP server has four tools, each with readOnlyHint and destructiveHint, and a second endpoint with only the two API tools",
          "OAuth with PKCE, dynamic client registration, refresh and revocation on GrowthBook Cloud, so no API key sits in the MCP config",
          "Public OpenAPI 3.1 spec with 306 paths and 414 operations, plus llms.txt and a Markdown copy of every docs page",
          "Starter plan is free with no card, with unlimited flags, experiments and traffic for up to 3 users",
          "MIT core with a self-hosted option, and the same MCP server published on npm and as a Docker image"
        ],
        "weaknesses": [
          "The API tools take a path and a JSON string and don't validate payloads, so correct calls depend on the bundled skills",
          "API keys are limited to 60 requests a minute on Cloud, and no idempotency keys were found",
          "Audit logging is an Enterprise feature, and Free plan members can only hold the Admin role",
          "The Customer Agreement grants GrowthBook a right to use Customer Data to train its AI algorithms, and no opt-out was found",
          "MCP 2.0.0 and 2.1.0 replaced the whole tool surface in July and August 2026, the second in a minor version"
        ],
        "agentNotes": [
          "Connect to https://mcp.growthbook.io/mcp and complete OAuth in a browser. Use https://mcp.growthbook.io/mcp/api for the two API tools alone",
          "Call `growthbook_list_skills` and `growthbook_read_skill` before writing. The API tools don't validate payloads, so use the paths the skill names",
          "Stay under 60 requests a minute per key. On 429 wait for the `RateLimit-Reset` seconds before retrying",
          "List calls return 10 items by default. Pass `limit` up to 100 and `offset` to page",
          "A 422 is a soft warning. Resubmit with `?ignoreWarnings=true` only after reading the message"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.1
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 89,
          "payments": 40,
          "reliability": 86,
          "schema": 76,
          "security": 68,
          "transparency": 66
        },
        "provenanceScore": 81
      },
      "connect": {
        "install": "npx -y @growthbook/mcp@latest",
        "http": "curl https://api.growthbook.io/api/v1/features -H \"Authorization: Bearer secret_abc123DEF456\"",
        "claudeCode": "claude mcp add --transport http growthbook https://mcp.growthbook.io/mcp",
        "config": {
          "mcpServers": {
            "growthbook": {
              "url": "https://mcp.growthbook.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/analytics.experiments",
        "tool": "https://letme.dev/growthbook"
      },
      "notable": [
        "MCP 2.x is a thin bridge of four tools, `growthbook_list_skills`, `growthbook_read_skill`, `growthbook_api_read` and `growthbook_api_write`. The API tools are authenticated passthroughs that do not validate payloads (https://docs.growthbook.io/integrations/mcp)",
        "MCP 2.0.0 on 30 July 2026 removed the 1.x per-endpoint tools, and 2.1.0 on 10 August 2026 split `growthbook_call_api` into read and write tools (https://github.com/growthbook/growthbook-mcp/blob/main/CHANGELOG.md)",
        "The OpenAPI 3.1 spec, version 5.1.0, has 306 paths and 414 operations, 270 paths under /v1 and 36 under /v2, with 34 operations marked deprecated (https://api.growthbook.io/api/v1/openapi.yaml)",
        "API keys are limited to 60 requests a minute on Cloud (https://docs.growthbook.io/api/introduction)",
        "The Customer Agreement of 19 June 2025 grants GrowthBook a right to use Customer Data, including to train its AI algorithms, and bars publishing benchmarks of the Services (https://www.growthbook.io/legal/customer-agreement)",
        "Advisory GHSA-c4m3-8cgx-p88g, published 19 August 2026, describes an unauthenticated account takeover on self-hosted instances with email and password sign-in before 5.0.1. It states GrowthBook Cloud was not affected (https://github.com/growthbook/growthbook/security/advisories/GHSA-c4m3-8cgx-p88g)",
        "status.growthbook.io shows no notices for August, September or October 2026, and the newest entry in its feed is dated 21 August 2025 (https://status.growthbook.io/history/1)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "GrowthBook Cloud. The official hosted MCP server at https://mcp.growthbook.io/mcp and the REST API at https://api.growthbook.io/api. The SDK endpoints on cdn.growthbook.io and a self-hosted install were not graded"
        },
        {
          "label": "MCP server",
          "value": "Streamable HTTP with OAuth on Cloud, or stdio through `npx -y @growthbook/mcp@latest` with `GB_API_KEY`, or the Docker image ghcr.io/growthbook/growthbook-mcp. Version 2.2.0, MIT, Node 18 or later"
        },
        {
          "label": "MCP tools",
          "value": "`growthbook_list_skills`, `growthbook_read_skill`, `growthbook_api_read` (GET) and `growthbook_api_write` (POST, PUT, PATCH, DELETE). Each has readOnlyHint and destructiveHint. /mcp/api exposes the two API tools alone"
        },
        {
          "label": "REST API",
          "value": "OpenAPI 3.1, spec version 5.1.0, 306 paths and 414 operations on 8 October 2026 (179 POST, 138 GET, 58 PUT, 39 DELETE). /v1 is stable and /v2 has newer shapes for feature flags and metrics"
        },
        {
          "label": "Credentials",
          "value": "OAuth with PKCE, dynamic client registration, refresh and revocation for MCP. Personal Access Tokens with the user's permissions or fewer, and Secret Keys with a role, per-project overrides, environment limits and optional expiry"
        },
        {
          "label": "Rate limits",
          "value": "60 requests a minute per API key on Cloud. The server sends the standard RateLimit headers, and the MCP server waits for `RateLimit-Reset` and retries up to 3 times"
        },
        {
          "label": "Pagination",
          "value": "`limit` (default 10, maximum 100) and `offset` on 40 list operations, with filters such as `projectId`, `datasourceId` and `status`"
        },
        {
          "label": "Errors",
          "value": "400, 401, 402, 403, 404, 422, 429 and 5XX with a JSON `message`. 422 is a soft warning that can be resubmitted with `?ignoreWarnings=true`"
        },
        {
          "label": "Plans",
          "value": "Starter free (3 users, 1 project, 1 million CDN requests, 5 GB, 1 million Managed Warehouse events a month). Pro $40 a seat a month (30 users, 3 projects). Enterprise by contract with SSO, SCIM, approval workflows, exportable audit logs and a 99.99 per cent uptime SLA"
        },
        {
          "label": "SDKs",
          "value": "The pricing page counts 24+ SDKs for flag evaluation and experiments, among them JavaScript, React, Python, Go, Java, Ruby, PHP, C#, Rust, Swift and Kotlin. None wraps the REST API. @growthbook/mcp had 8,922 npm downloads in the week to 4 October 2026"
        },
        {
          "label": "Releases",
          "value": "GrowthBook 5.0.0 on 19 July 2026, 5.0.1 on 19 August and 5.1.0 on 21 September. MCP server 2.0.0 on 30 July, 2.1.0 on 10 August and 2.2.0 on 5 October, published to npm on 6 October"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II, GDPR, COPPA and CCPA per growthbook.io/platform/security. Reports are requested through trust.growthbook.io. Vulnerability reports go to a form or security@growthbook.io, with no cash rewards"
        },
        {
          "label": "Status",
          "value": "status.growthbook.io on Instatus, three components (GrowthBook Cloud App, Api, CDN). The MCP server is not a listed component"
        },
        {
          "label": "Sub-processors",
          "value": "List dated 11 May 2026. AWS, MongoDB, ClickHouse, SendGrid, Anthropic and OpenAI in the United States, and Fastly worldwide"
        }
      ],
      "unitPrices": [
        {
          "item": "Pro plan seat",
          "unit": "seat-month",
          "usd": 40,
          "note": "Up to 30 users and 3 projects"
        },
        {
          "item": "CDN requests",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "Pro plan, above 2 million a month ($10 per million)"
        },
        {
          "item": "Managed Warehouse event",
          "unit": "tx",
          "usd": 0.00003,
          "note": "Pro plan, above 2 million a month ($30 per million)"
        },
        {
          "item": "CDN bandwidth",
          "unit": "gb",
          "usd": 1,
          "note": "Pro plan, above 20 GB a month"
        }
      ],
      "provenance": {
        "legalEntity": "GrowthBook, Inc.",
        "domain": "growthbook.io",
        "domainRegistered": "2020-05-19",
        "endpointOnVendorDomain": true,
        "terms": "https://www.growthbook.io/legal/customer-agreement",
        "privacy": "https://www.growthbook.io/legal/privacy-notice",
        "statusPage": "https://status.growthbook.io",
        "changelog": "https://github.com/growthbook/growthbook/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Customer Agreement (effective 19 June 2025) is between the customer and GrowthBook, Inc., with notices to 1950 W Corporate Way #34560, Anaheim, CA 92801, under California law.",
          "The Privacy Notice (effective 8 June 2026) covers the website and related services and names GrowthBook, Inc. at the same address. The Customer Agreement refers to it for Customer Data.",
          "The MCP server answers at mcp.growthbook.io and the REST API at api.growthbook.io. OAuth metadata names https://api.growthbook.io as issuer.",
          "www.growthbook.io/.well-known/security.txt and growthbook.io/.well-known/security.txt return 404. Reports go to a form on the disclosure page or to security@growthbook.io.",
          "RDAP for growthbook.io gives a registration date of 2020-05-19.",
          "The MCP server keeps its own changelog at https://github.com/growthbook/growthbook-mcp/blob/main/CHANGELOG.md."
        ],
        "score": 81,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "GrowthBook, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "growthbook.io, registered 2020-05-19 (6 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "mcp.growthbook.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.growthbook.io",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.growthbook.io/legal/customer-agreement",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-06-19",
            "words": 7809,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective Date: Jun 19, 2025",
                "says": "Last updated 2025-06-19"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement shall be governed by and construed in accordance with the laws of California, excluding its conflict of laws provisions.",
                "says": "The law of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "IN NO EVENT WILL THE AGGREGATE LIABILITY OF GROWTHBOOK, ITS AFFILIATES AND ITS AND THEIR RESPECTIVE LICENSORS, SERVICE PROVIDERS, AND SUPPLIERS ARISING OUT OF OR RELATED TO THIS AGREEMENT UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING ANY AND ALL INDEMNIFICATION OBLIGATIONS, EXCEED EITHER (A) THE TOTAL AMOUNTS PAID BY…",
                "says": "Capped at $100,000.00"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "In addition to any other express termination right set forth elsewhere in this Agreement, (a) GrowthBook may terminate this Agreement, effective on written notice to Customer, if Customer fails to pay any amount when due hereunder, and such failure continues for more than seven days after GrowthBook's delivery of writ…"
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Unless the Parties have entered into an Order Form specifying a term length or Customer has purchased a plan designated as an annual plan requiring upfront payment, either Party may terminate the Agreement at any time by providing 30 days notice to the other Party.",
                "says": "Gives 30 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Customer shall not be obligated to purchase any additional Services, but in the event Customer agrees to use any additional Services, Customer will be charged accordingly."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "Customer hereby grants to GrowthBook an unrestricted, non-exclusive right to use Customer Data, including for the purpose of training and improving GrowthBook's artificial intelligence algorithms, in accordance with GrowthBook’s Privacy Notice and this Agreement, as GrowthBook deems necessary for offering, providing,…",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "publicly disseminate benchmarks or performance information about the Services; or",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Customer agrees and understands that GrowthBook may terminate Services and this Agreement immediately without notice or liability to comply with applicable export controls and sanctions laws and regulations, in its sole and absolute discretion."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The customer agrees not to develop or sell products competitive with or similar to GrowthBook's during the agreement and for two years after it ends.",
                "quote": "During the term of this Agreement, and for a period of two (2) years thereafter, Customer shall not directly or indirectly develop, market, sell or otherwise commercialize any products, software, systems or services competitive with, substantially similar to or substitutable for any products,"
              },
              {
                "date": "2026-10-08",
                "text": "Shared or combined logins are prohibited, and named users may not pass their login details to anyone else, including the customer's other agents.",
                "quote": "The use of combined or shared logins, such as dev@companyname.com, is expressly prohibited."
              },
              {
                "date": "2026-10-08",
                "text": "The customer grants GrowthBook an exclusive, perpetual and irrevocable licence over aggregated, de-identified data derived from its data, for product and AI development or any other lawful purpose.",
                "quote": "Customer hereby grants to GrowthBook an exclusive, worldwide, perpetual, irrevocable, royalty-free, sublicensable license to create, process, reproduce, store, display, modify, translate, create derivative works from, distribute, make available and otherwise use Aggregated Data (as defined below)"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.growthbook.io/legal/privacy-notice",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-06-08",
            "words": 2993,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective Date: Jun 08, 2026",
                "says": "Last updated 2026-06-08"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "Please read this privacy notice carefully as it contains important information on how and why we collect, store, use, and share your personal information."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Thereafter, we will keep your personal information for as long as is necessary:",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "• Personal Data Provided by Others: we receive information about you and your company collected from third party or public sources or that we receive from companies that partner with us to provide products and services."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We will always treat your personal information with the utmost respect and we do not sell or share your personal information with other organizations for marketing purposes (see below “Who We Share Your Personal Information With”).",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You have the right to opt out of receiving promotional communications at any time by:"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions or comments about this Privacy Notice or our use of your data, please contact us at privacy@growthbook.io.",
                "says": "privacy@growthbook.io"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "By using our Services, you consent to your personal information being transferred to and processed in the United States (see above: “Who We Share Your Personal Information With”).",
                "says": "Data goes to the United States"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "AI functions of the Visual Editor send prompts and a digest of the page to Anthropic, Google, OpenAI or xAI, whose own privacy and retention practices then apply.",
                "quote": "Once data leaves the GrowthBook back-end, the receiving provider’s own privacy and data-retention practices apply to that data."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/growthbook.json",
      "live": {
        "slug": "growthbook",
        "probe": {
          "target": "https://mcp.growthbook.io/mcp",
          "method": "get",
          "lastAt": "2026-10-08T20:21:15.18576046Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 272,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 254,
          "p95ms24h": 337,
          "samples24h": 32,
          "samples30d": 32,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 32,
              "ok": 32
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.growthbook.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:39.1501551Z"
        },
        "pages": [
          {
            "url": "https://www.growthbook.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:10.646220771Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "aa2bc7a1a779"
          },
          {
            "url": "https://www.growthbook.io/legal/privacy-notice",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:08.637436983Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e574320b3fc5"
          },
          {
            "url": "https://www.growthbook.io/legal/customer-agreement",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:06.588048036Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d5b28f2fb91f"
          }
        ],
        "updatedAt": "2026-10-08T20:21:15.18576046Z"
      }
    },
    "verify": {
      "accepts": "a page on growthbook.io or one of its subdomains, or the README of github.com/growthbook/growthbook",
      "badgeUrl": "https://www.anchorterminal.com/badges/growthbook.svg",
      "body": {
        "slug": "growthbook",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/growthbook",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/growthbook\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/growthbook.svg\" alt=\"GrowthBook on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![GrowthBook on Anchor Terminal](https://www.anchorterminal.com/badges/growthbook.svg)](https://www.anchorterminal.com/tools/growthbook)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/growthbook\"\u003eGrowthBook on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/growthbook",
    "json": "https://www.anchorterminal.com/tools/growthbook.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/growthbook.md",
    "slim": "https://www.anchorterminal.com/tools/growthbook.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 70.1/100 · rank #142 of 722 · #2 in Product analytics \u0026 experimentation · agent-ready · confidence medium**\n\n\n## Assessment\n\nGrowthBook Cloud's MCP server has four tools with read and write annotations, OAuth with dynamic client registration, and a 414-operation OpenAPI spec behind it. The free plan needs no card. The API tools pass paths and JSON bodies through without validation, every key is limited to 60 requests a minute, and audit logs are Enterprise only.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | GrowthBook, Inc. (https://www.growthbook.io) |\n| Kind | HTTP API |\n| Category | Product analytics \u0026 experimentation (https://www.anchorterminal.com/categories/product-analytics) |\n| Transport | HTTP, Streamable HTTP, stdio |\n| Endpoint | `https://mcp.growthbook.io/mcp` |\n| Auth | OAuth or key · The hosted MCP server uses OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint, with api.growthbook.io as the authorisation server. A person signs in and consents in a browser. The only scopes are openid, profile, email and offline_access, so the token carries the user's own permissions. The REST API takes a Personal Access Token or a Secret Key as a Bearer token or as the HTTP Basic username. Both are self-serve in the app. A Secret Key can hold any built-in or custom role with per-project overrides and environment limits, and both key types can expire. On the Free plan members can only hold the Admin role. |\n| Pricing | Freemium ($40 / seat-mo) · Starter is free with no card, for up to 3 users and 1 project, so an agent's owner can start without a contract. Pro is $40 a seat a month for up to 30 users. Enterprise is by contract. Flags, experiments and traffic are unlimited on every plan, and API and MCP calls are not billed. Pro meters CDN requests, CDN bandwidth and Managed Warehouse events above its allowance. Self-hosting the open-source edition is free (https://www.growthbook.io/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI spec, the MCP server source or the pricing page (checked 2026-10-08). |\n| Licence | MIT for the core and for the MCP server. Three enterprise directories in the main repository are under GrowthBook's enterprise licence. GrowthBook Cloud is a hosted service under the Customer Agreement |\n| Tools exposed | 4 |\n| Packages | npm: `@growthbook/mcp`; npm: `@growthbook/growthbook`; pypi: `growthbook` |\n| MCP registry name | `io.github.growthbook/growthbook-mcp` |\n| Source | https://github.com/growthbook/growthbook |\n| Docs | https://docs.growthbook.io |\n| llms.txt | https://docs.growthbook.io/llms.txt |\n| Last release | 2026-10-06 |\n| GitHub stars | 8,484 (as of 2026-10-08) |\n| npm downloads / week | 1,290,544 |\n| PyPI downloads / week | 432,892 |\n| Surface graded | GrowthBook Cloud. The official hosted MCP server at https://mcp.growthbook.io/mcp and the REST API at https://api.growthbook.io/api. The SDK endpoints on cdn.growthbook.io and a self-hosted install were not graded |\n| MCP server | Streamable HTTP with OAuth on Cloud, or stdio through `npx -y @growthbook/mcp@latest` with `GB_API_KEY`, or the Docker image ghcr.io/growthbook/growthbook-mcp. Version 2.2.0, MIT, Node 18 or later |\n| MCP tools | `growthbook_list_skills`, `growthbook_read_skill`, `growthbook_api_read` (GET) and `growthbook_api_write` (POST, PUT, PATCH, DELETE). Each has readOnlyHint and destructiveHint. /mcp/api exposes the two API tools alone |\n| REST API | OpenAPI 3.1, spec version 5.1.0, 306 paths and 414 operations on 8 October 2026 (179 POST, 138 GET, 58 PUT, 39 DELETE). /v1 is stable and /v2 has newer shapes for feature flags and metrics |\n| Credentials | OAuth with PKCE, dynamic client registration, refresh and revocation for MCP. Personal Access Tokens with the user's permissions or fewer, and Secret Keys with a role, per-project overrides, environment limits and optional expiry |\n| Rate limits | 60 requests a minute per API key on Cloud. The server sends the standard RateLimit headers, and the MCP server waits for `RateLimit-Reset` and retries up to 3 times |\n| Pagination | `limit` (default 10, maximum 100) and `offset` on 40 list operations, with filters such as `projectId`, `datasourceId` and `status` |\n| Errors | 400, 401, 402, 403, 404, 422, 429 and 5XX with a JSON `message`. 422 is a soft warning that can be resubmitted with `?ignoreWarnings=true` |\n| Plans | Starter free (3 users, 1 project, 1 million CDN requests, 5 GB, 1 million Managed Warehouse events a month). Pro $40 a seat a month (30 users, 3 projects). Enterprise by contract with SSO, SCIM, approval workflows, exportable audit logs and a 99.99 per cent uptime SLA |\n| SDKs | The pricing page counts 24+ SDKs for flag evaluation and experiments, among them JavaScript, React, Python, Go, Java, Ruby, PHP, C#, Rust, Swift and Kotlin. None wraps the REST API. @growthbook/mcp had 8,922 npm downloads in the week to 4 October 2026 |\n| Releases | GrowthBook 5.0.0 on 19 July 2026, 5.0.1 on 19 August and 5.1.0 on 21 September. MCP server 2.0.0 on 30 July, 2.1.0 on 10 August and 2.2.0 on 5 October, published to npm on 6 October |\n| Certifications | SOC 2 Type II, GDPR, COPPA and CCPA per growthbook.io/platform/security. Reports are requested through trust.growthbook.io. Vulnerability reports go to a form or security@growthbook.io, with no cash rewards |\n| Status | status.growthbook.io on Instatus, three components (GrowthBook Cloud App, Api, CDN). The MCP server is not a listed component |\n| Sub-processors | List dated 11 May 2026. AWS, MongoDB, ClickHouse, SendGrid, Anthropic and OpenAI in the United States, and Fastly worldwide |\n| Capabilities | analytics.experiments, analytics.flags, analytics.query, analytics.events |\n| Tags | official, hosted, open-source, self-hosted, mcp, oauth, openapi, llms-txt, free-tier, no-card, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/growthbook.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 86 | 17.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 76 | 12.3 |\n| Agent ergonomics | 13% | 16.2 | 76 | 12.3 |\n| Security \u0026 auth | 14% | 17.5 | 68 | 11.9 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 89 | 7.8 |\n| Transparency \u0026 trust (editorial 66, provenance 81) | 7% | 8.8 | 74 | 6.5 |\n| Negative events | up to −15 | up to −15 | 10 August 2026. MCP server 2.1.0 replaced `growthbook_call_api` with two tools in a minor version, eleven days after 2.0.0 removed every 1.x tool, while the docs tell users to install `@growthbook/mcp@latest`. Both are marked breaking in the changelog with migration steps, and we found no advance notice, so the deduction is the minimum (https://github.com/growthbook/growthbook-mcp/blob/main/CHANGELOG.md).  | -3 |\n| **Total** | | | | **70.1 → BB** |\n\n### Why each score\n\n- Reliability 86: Graded on GrowthBook Cloud with the hosted lines. Instatus page at status.growthbook.io with three components (GrowthBook Cloud App, Api, CDN) and a notice history (20). No notices for August, September or October 2026, and the newest entry in the feed is dated 21 August 2025. The MCP server is not a listed component, and the 2.2.0 changelog fixes intermittent 502s in HTTP mode that were not posted, so 25 of 30. API keys are limited to 60 requests a minute (15). The docs say only to try again later on 429. The server source sends standard RateLimit headers and the MCP server waits for `RateLimit-Reset` and retries three times, but no backoff guidance or idempotency keys were found in the docs (8 of 15). The pricing page lists a 99.99 per cent uptime SLA on Enterprise. The SLA document itself was not found in public (8 of 10). The REST API's /v1 is described as stable and the MCP docs carry no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 76: Public OpenAPI 3.1 spec, version 5.1.0, with 306 paths and 414 operations, and Zod-typed inputs on all four MCP tools (25). llms.txt and a Markdown copy of each docs page (10). 413 of 414 operations have a summary and 185 have a description. The MCP tool descriptions say when to use each tool, and the bundled skills carry the workflows (13 of 20). The spec has 1,404 enums and marks required fields, but `growthbook_api_write` takes the path as a string and the body as a JSON string, and the docs say the API tools do not validate payloads (9 of 15). The spec has 17 examples and documents only 200 responses, plus 409 on 9 operations. The introduction lists eight status codes and a `message` body (6 of 15). Path versions /v1 and /v2, 34 operations marked deprecated, GitHub releases, and an MCP changelog with breaking changes called out (13 of 15).\n- Agent ergonomics 76: Four compact MCP tools, with skills loaded on demand and a /mcp/api endpoint that drops the skill tools (25). `limit` (default 10, maximum 100) and `offset` on 40 list operations, with filters by project, data source and status. No field selection was found, and the API tools return the raw response body (15 of 20). Errors are a status code and a `message` with no machine code. 422 marks a soft warning that can be resubmitted with `ignoreWarnings`, and the MCP server adds recovery hints for 401, 403, 404 and 429 (13 of 20). All four tools carry readOnlyHint and destructiveHint, and reads and writes are separate tools. Every write is marked destructive, and no idempotency keys were found (13 of 20). The API tools need one to three parameters. The SDKs cover flag evaluation in many languages, not the REST API (10 of 15).\n- Security \u0026 auth 68: OAuth with PKCE, dynamic client registration, refresh tokens and a revocation endpoint for the hosted MCP server. Its only scopes are openid, profile, email and offline_access, so a token carries the user's full permissions. Secret Keys take any built-in or custom role with per-project overrides, environment limits and expiry, and Personal Access Tokens can be limited. Secrets travel in headers only (26 of 30). A Read Only role, an endpoint with the API tools alone, and read and write tools with annotations. Draft, review and publish steps live in the skills, approval workflows are an Enterprise feature, and since 2.1.0 confirmation is left to the client. Free plan members can only hold the Admin role (14 of 20). No guidance on prompt injection was found, though the tools return names and descriptions that people wrote (3 of 15). Audit logging is an Enterprise feature with export. Personal tokens attribute actions to a user, and the MCP server labels its API calls with `X-GB-MCP-*` headers (10 of 15). SOC 2 Type II, a disclosure process with a form and SECURITY.md, routine penetration testing and public GitHub advisories, the latest on 19 August 2026. Rewards are merchandise only and there is no security.txt (15 of 20).\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). Prices are public without a login. Pro is $40 a seat a month, with $10 per million CDN requests, $1 per GB and $30 per million Managed Warehouse events above the allowance (20). The Starter plan is free with no card (20). A person signs up in a browser, then approves OAuth or creates a key (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 89: MCP server 2.2.0 is dated 5 October 2026 and GrowthBook 5.1.0 was tagged on 21 September 2026 (30). Six releases since 10 July 2026, three of the app and three of the MCP server (20). The main repository's 200 newest commits run from 15 September to 8 October 2026, and there is a community Slack. We did not read how quickly issues are answered (15 of 25). `io.github.growthbook/growthbook-mcp` is in the official MCP registry at 2.2.0, published 6 October 2026 (15). The MCP repository runs CI on Node 22 and 26 with 34 tests and took dependency security updates on 8 October 2026. The package states Node 18 or later, which CI does not test (9 of 10).\n- Transparency \u0026 trust 74: The core and the MCP server are MIT. Three enterprise directories in the main repository are under GrowthBook's enterprise licence and are part of what Cloud runs (25 of 30). A Customer Agreement, a Privacy Notice of 8 June 2026 and a DPA of 19 June 2025 are published. The agreement grants GrowthBook an unrestricted right to use Customer Data, including to train its AI algorithms, then limits personal information to performing the Services. The Privacy Notice gives no retention periods, and the docs say only aggregate results are stored. We did not read the DPA, which is a download (16 of 30). Legacy v1 routes and 34 operations are marked deprecated with no removal dates, and no deprecation policy was found. The MCP changelog gives migration steps (8 of 20). The sub-processor list of 11 May 2026 names seven providers with locations, mostly in the United States. Notice of new ones is promised only as far as the law requires (17 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/growthbook.md (JSON https://www.anchorterminal.com/fixes/growthbook.json)\n\n### What we couldn't check\n\n- unchecked: how quickly GitHub issues and pull requests are answered. The GitHub API refused us for its rate limit and we did not read the issue lists.\n- unchecked: the DPA of 19 June 2025, which is a download, and the contents of trust.growthbook.io, which is drawn by script.\n- unchecked: the live tool list from https://mcp.growthbook.io/mcp, which needs an OAuth sign-in. Tool definitions were read from the 2.2.0 source.\n- The text of the Enterprise SLA was not found in public. The 99.99 per cent figure is from the pricing and security pages.\n- The docs page says the server has four tools, while the 2.0.0 changelog describes three. The count of four is from the 2.2.0 source.\n- The compliance docs mention an active bug bounty programme, while the disclosure page says no financial rewards are paid.\n- Whether the hosted server's tool changes of 30 July and 10 August 2026 were announced in advance was not established.\n- The official registry entry lists only the npm stdio package and no remote URL.\n- The authentication text inside the OpenAPI spec still says Secret Keys are admin or readonly, while the docs page says any role.\n\n### Sources\n\n- MCP server docs: \u003chttps://docs.growthbook.io/integrations/mcp.md\u003e (seen 2026-10-08)\n- REST API introduction, authentication, errors and rate limit: \u003chttps://docs.growthbook.io/api/introduction.md\u003e (seen 2026-10-08)\n- OpenAPI spec: \u003chttps://api.growthbook.io/api/v1/openapi.yaml\u003e (seen 2026-10-08)\n- MCP server source, tool definitions and changelog: \u003chttps://github.com/growthbook/growthbook-mcp\u003e (seen 2026-10-08)\n- OAuth authorisation server metadata: \u003chttps://api.growthbook.io/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- OAuth protected resource metadata: \u003chttps://mcp.growthbook.io/.well-known/oauth-protected-resource\u003e (seen 2026-10-08)\n- official MCP registry entries: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=growthbook\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.growthbook.io/pricing\u003e (seen 2026-10-08)\n- fair use policy: \u003chttps://www.growthbook.io/legal/fair-use-policy\u003e (seen 2026-10-08)\n- status history: \u003chttps://status.growthbook.io/history/1\u003e (seen 2026-10-08)\n- status feed: \u003chttps://status.growthbook.io/history.atom\u003e (seen 2026-10-08)\n- Customer Agreement: \u003chttps://www.growthbook.io/legal/customer-agreement\u003e (seen 2026-10-08)\n- Privacy Notice: \u003chttps://www.growthbook.io/legal/privacy-notice\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://www.growthbook.io/legal/subprocessors\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.growthbook.io/platform/security\u003e (seen 2026-10-08)\n- vulnerability disclosure process: \u003chttps://www.growthbook.io/platform/security/vulnerability\u003e (seen 2026-10-08)\n- security advisory of 19 August 2026: \u003chttps://github.com/growthbook/growthbook/security/advisories/GHSA-c4m3-8cgx-p88g\u003e (seen 2026-10-08)\n- main repository, licence, tags and rate limiter: \u003chttps://github.com/growthbook/growthbook\u003e (seen 2026-10-08)\n- permissions and roles: \u003chttps://docs.growthbook.io/account/user-permissions.md\u003e (seen 2026-10-08)\n- audit logs: \u003chttps://docs.growthbook.io/account/audit-logs.md\u003e (seen 2026-10-08)\n- self-hosting environment variables and telemetry: \u003chttps://docs.growthbook.io/self-host/env.md\u003e (seen 2026-10-08)\n- npm package: \u003chttps://registry.npmjs.org/@growthbook/mcp/latest\u003e (seen 2026-10-08)\n- npm downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/@growthbook/growthbook\u003e (seen 2026-10-08)\n- PyPI downloads: \u003chttps://pypistats.org/api/packages/growthbook/recent\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.identitydigital.services/rdap/domain/growthbook.io\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 81/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | GrowthBook, Inc. | 20/20 |\n| Domain age | growthbook.io, registered 2020-05-19 (6 years) | 11/15 |\n| Endpoint on the vendor's domain | mcp.growthbook.io | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.growthbook.io | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Customer Agreement (effective 19 June 2025) is between the customer and GrowthBook, Inc., with notices to 1950 W Corporate Way #34560, Anaheim, CA 92801, under California law.\n\nThe Privacy Notice (effective 8 June 2026) covers the website and related services and names GrowthBook, Inc. at the same address. The Customer Agreement refers to it for Customer Data.\n\nThe MCP server answers at mcp.growthbook.io and the REST API at api.growthbook.io. OAuth metadata names https://api.growthbook.io as issuer.\n\nwww.growthbook.io/.well-known/security.txt and growthbook.io/.well-known/security.txt return 404. Reports go to a form on the disclosure page or to security@growthbook.io.\n\nRDAP for growthbook.io gives a registration date of 2020-05-19.\n\nThe MCP server keeps its own changelog at https://github.com/growthbook/growthbook-mcp/blob/main/CHANGELOG.md.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.growthbook.io/legal/customer-agreement), read 2026-10-08, dated 2025-06-19, states 6 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"Customer hereby grants to GrowthBook an unrestricted, non-exclusive right to use Customer Data, including for the purpose of training and improving GrowthBook's artificial intelligence algorithms, in accordance with GrowthBook’s Privacy Notice and this Agreement, as GrowthBook deems necessary for offering, providing,…\"\n- To know. Restricts benchmarking or competitive use (costs points). \"publicly disseminate benchmarks or performance information about the Services; or\"\n- To know. Says access can be ended without notice or for any reason. \"Customer agrees and understands that GrowthBook may terminate Services and this Agreement immediately without notice or liability to comply with applicable export controls and sanctions laws and regulations, in its sole and absolute discretion.\"\n- Gives the date it was last updated. Last updated 2025-06-19.\n- Names the governing law or courts. The law of California.\n- States a limit on its liability. Capped at $100,000.00.\n- Says how changes to the terms are announced. Gives 30 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). The customer agrees not to develop or sell products competitive with or similar to GrowthBook's during the agreement and for two years after it ends. \"During the term of this Agreement, and for a period of two (2) years thereafter, Customer shall not directly or indirectly develop, market, sell or otherwise commercialize any products, software, systems or services competitive with, substantially similar to or substitutable for any products,\"\n- Also in the text (2026-10-08). Shared or combined logins are prohibited, and named users may not pass their login details to anyone else, including the customer's other agents. \"The use of combined or shared logins, such as dev@companyname.com, is expressly prohibited.\"\n- Also in the text (2026-10-08). The customer grants GrowthBook an exclusive, perpetual and irrevocable licence over aggregated, de-identified data derived from its data, for product and AI development or any other lawful purpose. \"Customer hereby grants to GrowthBook an exclusive, worldwide, perpetual, irrevocable, royalty-free, sublicensable license to create, process, reproduce, store, display, modify, translate, create derivative works from, distribute, make available and otherwise use Aggregated Data (as defined below)\"\n\n**Privacy policy** (https://www.growthbook.io/legal/privacy-notice), read 2026-10-08, dated 2026-06-08, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-06-08.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@growthbook.io.\n- Says where data is transferred or stored. Data goes to the United States.\n- Also in the text (2026-10-08). AI functions of the Visual Editor send prompts and a digest of the page to Anthropic, Google, OpenAI or xAI, whose own privacy and retention practices then apply. \"Once data leaves the GrowthBook back-end, the receiving provider’s own privacy and data-retention practices apply to that data.\"\n\n## Live (updated 2026-10-08 20:21 UTC)\n\n- Right now: up, HTTP 401, 272 ms, checked 2026-10-08 20:21 UTC (get on `https://mcp.growthbook.io/mcp`, asks for auth)\n- Uptime 24h 100.0% (32 probes) · 30 days 100.0% (32 probes) · p50 254 ms · p95 337 ms\n- Vendor status page: unknown, no machine-readable status found\n- Watching pricing \u003chttps://www.growthbook.io/pricing\u003e\n- Watching privacy \u003chttps://www.growthbook.io/legal/privacy-notice\u003e\n- Watching terms \u003chttps://www.growthbook.io/legal/customer-agreement\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/growthbook.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Pro plan seat | $40 | per seat per month | Up to 30 users and 3 projects |\n| CDN requests | $0.01 | per 1,000 requests | Pro plan, above 2 million a month ($10 per million) |\n| Managed Warehouse event | $0. | per transaction | Pro plan, above 2 million a month ($30 per million) |\n| CDN bandwidth | $1 | per GB of traffic | Pro plan, above 20 GB a month |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- The MCP server has four tools, each with readOnlyHint and destructiveHint, and a second endpoint with only the two API tools\n- OAuth with PKCE, dynamic client registration, refresh and revocation on GrowthBook Cloud, so no API key sits in the MCP config\n- Public OpenAPI 3.1 spec with 306 paths and 414 operations, plus llms.txt and a Markdown copy of every docs page\n- Starter plan is free with no card, with unlimited flags, experiments and traffic for up to 3 users\n- MIT core with a self-hosted option, and the same MCP server published on npm and as a Docker image\n\n## Weaknesses\n\n- The API tools take a path and a JSON string and don't validate payloads, so correct calls depend on the bundled skills\n- API keys are limited to 60 requests a minute on Cloud, and no idempotency keys were found\n- Audit logging is an Enterprise feature, and Free plan members can only hold the Admin role\n- The Customer Agreement grants GrowthBook a right to use Customer Data to train its AI algorithms, and no opt-out was found\n- MCP 2.0.0 and 2.1.0 replaced the whole tool surface in July and August 2026, the second in a minor version\n\n## Before you call it (notes for agents)\n\n1. Connect to https://mcp.growthbook.io/mcp and complete OAuth in a browser. Use https://mcp.growthbook.io/mcp/api for the two API tools alone\n2. Call `growthbook_list_skills` and `growthbook_read_skill` before writing. The API tools don't validate payloads, so use the paths the skill names\n3. Stay under 60 requests a minute per key. On 429 wait for the `RateLimit-Reset` seconds before retrying\n4. List calls return 10 items by default. Pass `limit` up to 100 and `offset` to page\n5. A 422 is a soft warning. Resubmit with `?ignoreWarnings=true` only after reading the message\n\n## Connect\n\nInstall:\n\n```bash\nnpx -y @growthbook/mcp@latest\n```\n\nFirst request:\n\n```bash\ncurl https://api.growthbook.io/api/v1/features -H \"Authorization: Bearer secret_abc123DEF456\"\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http growthbook https://mcp.growthbook.io/mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"growthbook\": {\n      \"url\": \"https://mcp.growthbook.io/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/growthbook (letme picks it for analytics.events, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Statsig | BB | 72.3 | 94 | analytics.experiments, analytics.flags, analytics.query, analytics.events | no | https://www.anchorterminal.com/tools/statsig.md |\n| PostHog | B | 68.4 | 181 | analytics.query, analytics.events, analytics.experiments, analytics.flags | no | https://www.anchorterminal.com/tools/posthog.md |\n| Amplitude | B | 66.2 | 243 | analytics.query, analytics.experiments, analytics.flags, analytics.events | no | https://www.anchorterminal.com/tools/amplitude.md |\n| Mixpanel | B | 62 | 351 | analytics.query, analytics.events, analytics.experiments, analytics.flags | no | https://www.anchorterminal.com/tools/mixpanel.md |\n| Optimizely Experimentation | B | 62.6 | 330 | analytics.experiments, analytics.flags, analytics.query | no | https://www.anchorterminal.com/tools/optimizely.md |\n| LaunchDarkly | B | 69.2 | 165 | analytics.flags, analytics.experiments | no | https://www.anchorterminal.com/tools/launchdarkly.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- MCP 2.x is a thin bridge of four tools, `growthbook_list_skills`, `growthbook_read_skill`, `growthbook_api_read` and `growthbook_api_write`. The API tools are authenticated passthroughs that do not validate payloads (source: \u003chttps://docs.growthbook.io/integrations/mcp\u003e)\n- MCP 2.0.0 on 30 July 2026 removed the 1.x per-endpoint tools, and 2.1.0 on 10 August 2026 split `growthbook_call_api` into read and write tools (source: \u003chttps://github.com/growthbook/growthbook-mcp/blob/main/CHANGELOG.md\u003e)\n- The OpenAPI 3.1 spec, version 5.1.0, has 306 paths and 414 operations, 270 paths under /v1 and 36 under /v2, with 34 operations marked deprecated (source: \u003chttps://api.growthbook.io/api/v1/openapi.yaml\u003e)\n- API keys are limited to 60 requests a minute on Cloud (source: \u003chttps://docs.growthbook.io/api/introduction\u003e)\n- The Customer Agreement of 19 June 2025 grants GrowthBook a right to use Customer Data, including to train its AI algorithms, and bars publishing benchmarks of the Services (source: \u003chttps://www.growthbook.io/legal/customer-agreement\u003e)\n- Advisory GHSA-c4m3-8cgx-p88g, published 19 August 2026, describes an unauthenticated account takeover on self-hosted instances with email and password sign-in before 5.0.1. It states GrowthBook Cloud was not affected (source: \u003chttps://github.com/growthbook/growthbook/security/advisories/GHSA-c4m3-8cgx-p88g\u003e)\n- status.growthbook.io shows no notices for August, September or October 2026, and the newest entry in its feed is dated 21 August 2025 (source: \u003chttps://status.growthbook.io/history/1\u003e)\n\n## Compare\n\n- [Amplitude vs GrowthBook](https://www.anchorterminal.com/compare/amplitude-vs-growthbook.md): B 66.2 vs BB 70.1\n- [Fullstory vs GrowthBook](https://www.anchorterminal.com/compare/fullstory-vs-growthbook.md): B 62.6 vs BB 70.1\n- [GrowthBook vs Pendo](https://www.anchorterminal.com/compare/growthbook-vs-pendo.md): BB 70.1 vs D 48.2\n- [GrowthBook vs Heap](https://www.anchorterminal.com/compare/growthbook-vs-heap.md): BB 70.1 vs D 53\n- [GrowthBook vs LaunchDarkly](https://www.anchorterminal.com/compare/growthbook-vs-launchdarkly.md): BB 70.1 vs B 69.2\n- [GrowthBook vs Mixpanel](https://www.anchorterminal.com/compare/growthbook-vs-mixpanel.md): BB 70.1 vs B 62\n- [GrowthBook vs Optimizely Experimentation](https://www.anchorterminal.com/compare/growthbook-vs-optimizely.md): BB 70.1 vs B 62.6\n- [GrowthBook vs PostHog](https://www.anchorterminal.com/compare/growthbook-vs-posthog.md): BB 70.1 vs B 68.4\n- [GrowthBook vs Statsig](https://www.anchorterminal.com/compare/growthbook-vs-statsig.md): BB 70.1 vs BB 72.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on growthbook.io or one of its subdomains, or the README of github.com/growthbook/growthbook. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"growthbook\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/growthbook\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/growthbook.svg\" alt=\"GrowthBook on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![GrowthBook on Anchor Terminal](https://www.anchorterminal.com/badges/growthbook.svg)](https://www.anchorterminal.com/tools/growthbook)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/growthbook\"\u003eGrowthBook on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say GrowthBook is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/growthbook-dark.png\n- Light: https://www.anchorterminal.com/assets/share/growthbook-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Product analytics \u0026 experimentation",
        "url": "https://www.anchorterminal.com/categories/product-analytics"
      },
      {
        "name": "GrowthBook",
        "url": ""
      }
    ],
    "description": "GrowthBook is an open-source platform for feature flags, experiments and product analytics, sold as GrowthBook Cloud or run self-hosted. Agents reach it through a REST API with a public OpenAPI spec and an official MCP server.",
    "facts": [
      "rank #142 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "GrowthBook",
    "image": "https://www.anchorterminal.com/assets/og/tools-growthbook.png",
    "path": "/tools/growthbook",
    "published": "2026-10-01",
    "section": "tools",
    "title": "GrowthBook review for AI agents, grade BB (70.1/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/growthbook"
  },
  "tokens": {
    "markdown": 8350,
    "slim": 2030
  },
  "version": 1
}
