Karrio
by Karrio, Inc. HTTP API in Shipping & fulfilment
Karrio, Inc. · karrio.io since 2022 · who's behind it
Karrio is an open-source multi-carrier shipping server from Karrio, Inc. Its REST API quotes rates, buys labels, tracks parcels and books pickups through the owner's own carrier accounts, self-hosted with Docker or run by Karrio as a paid platform.
Good for A team that wants to host its own multi-carrier API with its own carrier contracts and can maintain a Django and PostgreSQL stack.
Is this your product? Claim this listing or verify it
Assessment. A current OpenAPI 3.0.3 contract with 65 paths, a free LGPL-3.0 server and 30 carrier connectors suit a team that hosts it. The last release was 23 June 2026, the @karrio/mcp package the docs install is absent from npm, and api.karrio.io didn't resolve on 8 October 2026.
Facts
- Transport
- HTTP
- Auth
- API key
- Pricing
- Freemium · $499 / mo
- x402
- No
- Licence
- LGPL-3.0 for the server, SDK and modules. Code under `ee/` is under the Karrio Enterprise licence and needs a subscription for production use. The MCP package in `packages/mcp` is Apache-2.0
- Packages
pypikarriopypikarrio-serverocikarrio/server- llms.txt
- not found
- Last release
- GitHub stars
- 799
- PyPI / week
- 338
- Graded surface
- The open-source server its owner hosts, REST under
/v1with a GraphQL API beside it. The managed platform wasn't reachable for grading on 8 October 2026 - API
- OpenAPI 3.0.3, version 2026.1.32, 65 paths. Shipments, rates, trackers, pickups, manifests, orders, addresses, parcels, products, documents, webhooks, carrier connections, batches, plus
/v1/proxy/*calls that pass straight to a carrier without storing a record - Carriers
- 30 connectors in
modules/connectors, among them UPS, FedEx, USPS, DHL Express, DHL Parcel DE, Canada Post, Purolator, DPD, GLS, La Poste, Chronopost, Australia Post and Sendle. More sit in a community submodule we didn't count. The owner supplies the carrier accounts - Credentials
- Private API keys (
key_...) with a label, bound to test or live mode, sent as the HTTP Basic username orAuthorization: Token. JWT pairs fromPOST /api/tokenwith email and password. Short-lived resource tokens fromPOST /api/tokensfor document links, five minutes by default and one hour at most - Getting access
- Self-hosted,
docker compose upindocker/, API on port 5002 and dashboard on 3002, default loginadmin@example.comwith passworddemo. The managed platform is by demo booking - Test mode
- Keys are bound to test or live mode, and JWT requests choose with the
x-test-modeheader. Test mode calls the carriers' sandbox hosts with the owner's sandbox credentials - Rate limits
- Defaults in
settings/base.py. 60 a minute anonymous, 600 a minute per user, 300 a minute on carrier requests, each set by environment variable (ANON_RATE_LIMIT,USER_RATE_LIMIT,CARRIER_REQUEST_RATE_LIMIT) - Pagination
limitfrom 1 to 100 andoffset, withcount,nextandpreviousin the response. Shipment lists filter by carrier, status, dates, keyword, metadata key and value,is_returnand more- MCP server
packages/mcpin the repository, Apache-2.0, version 1.0.0, 12 tools and two carrier resources, stdio or Streamable HTTP on port 3100. Not on npm on 8 October 2026 and not in the official MCP registry- Packages
- PyPI
karrio2026.1.32 (Python 3.11 or later),karrio-server2026.1.32 andkarrio-cli, all uploaded 23 June 2026. Docker Hubkarrio/server, about 27,000 pulls. The npm clientkarriois at 2023.1.0 - Licence
- LGPL-3.0 for the server, SDK and modules.
ee/(multi-tenancy, workflows, audit logging, SSO) under the Karrio Enterprise licence, which needs a subscription for production use. MCP package Apache-2.0 - Support
- GitHub Discussions and Discord for the open-source edition. The platform page lists email and Slack support for Scale customers and an SLA for enterprise and commercial licence customers
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- OpenAPI 3.0.3 contract in the repository at version 2026.1.32, with 65 paths covering rates, shipments, trackers, pickups, manifests, orders, documents and webhooks
- The core server and SDK are LGPL-3.0 and run on the owner's infrastructure with Docker Compose, with no fee to Karrio
- 30 carrier connectors in
modules/connectors, among them UPS, FedEx, USPS, DHL Express, Canada Post, DPD and Australia Post, used with the owner's own carrier accounts - API keys are bound to test or live mode, and test mode runs rates, labels, trackers and pickups against carrier sandboxes
- Default throttles are in the settings file with numbers (600 requests a minute per user, 300 for carrier calls) and can be changed by environment variable
Weaknesses
- No release since 2026.1.32 on 23 June 2026, 107 days before this check, and fix pull requests opened in September 2026 were still open
- Neither
@karrio/mcpnorkarrio-mcpexists on npm, though the README and the MCP guide givenpxcommands for them api.karrio.iodidn't resolve andapp.karrio.ioanswered 503 with a paused deployment on 8 October 2026, and the managed platform starts with a demo booking- Versions 2026.1.22 to 2026.1.31 stored passwords as MD5 hashes in production, fixed in 2026.1.32 with a changelog line and no published advisory
- No idempotency keys were found, and a private API key can perform any request. Team permissions and audit logging sit in the paid
ee/code
Before you call it notes for agents
- Run your own instance with Docker Compose and call it at
http://localhost:5002. Don't rely onapi.karrio.io, which didn't resolve on 8 October 2026 - Don't run
npx karrio-mcpornpx -y @karrio/mcp. Neither name is published on npm, so build the server frompackages/mcpin the repository - Change the default
admin@example.comanddemologin before the instance is reachable, and upgrade to 2026.1.32 or later so passwords aren't stored as MD5 - Don't blind-retry
POST /v1/shipmentswith aserviceset orPOST /v1/shipments/{id}/purchase. Fetch the shipment and check its status first, since no idempotency key exists - Use a test-mode API key while building. Send it as the HTTP Basic username or as
Authorization: Token key_...
Who's behind it provenance 53/100
- Legal entity namedKarrio, Inc.20/20
- Domain agekarrio.io, registered 2022-01-20 (4 years)7/15
- Endpoint on the vendor's domain is not on karrio.io0/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 1 clause that costs points6.3/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2025-04-08, states 5 of 7, 1 to know
TL;DR Dated 2025-04-08. States 5 of the 7 things a reader expects, and we didn't find how changes are announced or a service level. To know before relying on it, limits on benchmarking.
Restricts benchmarking or competitive usecosts points
(vi) access or use any Karrio IP for purposes of competitive analysis of Karrio or the Services, the development, provision, or use of a competing software service or product, or any other purpose that is to Karrio’s detriment or commercial disadvantage
A clause against publishing test results or using the service to build something that competes.
Gives the date it was last updated Last updated 2025-04-08
Last Modified: 08 April 2025
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
This Agreement is governed by and construed in accordance with the internal laws of the State of California without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the State of California.
Says where a dispute would be heard and under whose law.
States a limit on its liability
event will either party’s aggregate liability arising out of or related to this
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Notwithstanding anything to the contrary in this Agreement, Karrio may temporarily suspend Customer’s and any Authorized User’s access to any portion or all of the Services if: (i) Karrio reasonably determines that (A) there is a threat or attack on any of the Karrio IP;
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced
Not found in the text.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Customer shall not use the Services for any purposes beyond the scope of the access granted in this Agreement.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Karrio may name the customer and use its name, logo and trademarks in its customer list, press releases, blog posts, advertisements and website.
Karrio may identify Customer as a user of the Services and may use Customer’s name, logo, and other trademarks in Karrio’s customer list, press releases, blog posts, advertisements, and website
Noted by a second reader on 2026-10-08.
Karrio may make aggregated data compiled from customer data available to third parties, including its other customers.
Customer agrees that Karrio may (i) make Aggregated Data available to third parties including its other customers in compliance with applicable law, and (ii) use Aggregated Data to the extent and in the manner permitted under applicable law.
Noted by a second reader on 2026-10-08.
Storing payment cardholder information through the service needs Karrio's prior written approval.
Customer may not store any payment cardholder information using the Services without Karrio’s prior written approval.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,676 words
Privacy policy dated 2025-04-08, states 8 of 8
TL;DR Dated 2025-04-08. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2025-04-08
Last modified: 08 April 2025
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We collect personal information in connection with your visits to and use of the Service.
The basic statement a privacy policy exists to make.
Says how long data is kept
We will usually store the personal information we collect about you for no longer than necessary for the purposes set out in Annex 1 and Annex 2, in accordance with our legal obligations and legitimate business interests.
Says when data sent to the service is deleted.
Says who else receives the data
California - Your California Privacy Rights: If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
Note we do not sell your personal information within the meaning of Chapter 603A.
A plain statement either way.
Says what rights people have over their data
In these instances, and if you have provided consent, you have the right to withdraw your consent.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@karrio.io
If you believe that we might have collected information from a child under 13, please contact us at privacy@karrio.io.
An address or officer to send a request to.
Says where data is transferred or stored
The personal information we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third party service providers have operations.
The countries data goes to and the safeguard used.
The notice does not cover customer data that Karrio processes on a customer's behalf, and it refers readers to that customer's own privacy notice.
This Privacy Notice does not apply to such processing and we recommend you read the Privacy Notice of the respective customer, if their processing concerns your personal information.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 7,526 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Customer Terms and Conditions (last modified 8 April 2025) name Karrio, Inc., a Delaware corporation at 760 Chemin Marie-Le Ber, Verdun, Quebec, Canada, and govern the hosted platform. The self-hosted open-source edition is governed by LGPL-3.0, and LICENSE_EE points ee/ users to the subscription terms at docs.karrio.io/product/resources/terms, an older copy dated 19 April 2022.
The privacy policy (last modified 8 April 2025) covers karrio.io and associated services and excludes customer data processed on a customer's behalf. No data processing addendum was found.
The graded surface is an instance on the owner's own host, so the endpoint isn't on the vendor's domain. api.karrio.io didn't resolve and app.karrio.io returned 503 on 8 October 2026.
No status page was found. status.karrio.io didn't resolve and the site links none.
www.karrio.io/.well-known/security.txt returns 404. SECURITY.md in the repository sends reports to hello@karrio.io.
The changelog page on www.karrio.io stops at 2024.12.6. CHANGELOG.md in the repository is current to 2026.1.32.
RDAP for karrio.io gives a registration date of 2022-01-20.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Notable
- The repository's default branch and newest tag are both at 2026.1.32, dated 23 June 2026, with 33 dated 2026 entries in
CHANGELOG.mdbefore it source - The README configures the MCP server with
npx karrio-mcpand the MCP guide withnpx -y @karrio/mcp. The npm registry answered 404 for both names on 8 October 2026 source packages/mcpholds 12 tools in source, each withreadOnlyHintanddestructiveHintannotations, over stdio or Streamable HTTP sourceapi.karrio.io, the base URL in the docs' examples, didn't resolve in DNS on 8 October 2026, andapp.karrio.ioreturned 503 with Vercel'sDEPLOYMENT_PAUSEDerror source- The platform page says self-hosting is free, the managed Scale platform starts at $499 a month with pay-as-you-go pricing, and a commercial licence for embedding starts at $50,000 a year source
- The 2026.1.32 changelog says the MD5
PASSWORD_HASHERSoverride is now scoped to the test runner so production no longer stores MD5 password hashes. The override arrived in a commit of 12 March 2026 source - GitHub Issues is switched off and questions go to Discussions, where 10 of the 15 newest threads showed no maintainer reply on 8 October 2026 source
- The Compose files pull images through
karrio.docker.scarf.sh, a Scarf gateway, and Sentry and PostHog reporting run only when the operator setsSENTRY_DSNorPOSTHOG_KEYsource
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 15.2 | |
Read with the local-software lines, since the graded surface is the open-source server its owner hosts. The managed platform has no status page we could find, and its hosts didn't answer on 8 October 2026. Docker images on Docker Hub and PyPI packages at 2026.1.32, with Python 3.11 or later stated for karrio, though karrio-server still declares 3.7 or later (18 of 20). A public tests workflow runs SDK type checks, SDK tests and server tests on PostgreSQL, and the last five runs on main, all on 23 June 2026, passed (25). GitHub Issues is switched off, so bug reports go to Discussions. Reports from July and August 2026 on FedEx dimensions and a GraphQL crash had no reply, and a June report that migration 0093 deleted tracker history was fixed in 2026.1.32 (10 of 25). Versions are calendar-based, not semver, and the breaking rename of the purchased status shipped in 2026.1.20 with a banner in the changelog (8 of 15). Releases are past 1.0 and numbered for production use (15). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 11.1 | |
schemas/openapi.yml is OpenAPI 3.0.3 at version 2026.1.32, with 65 paths, and the docs site renders a reference from it. GraphQL schemas sit beside it (25). No llms.txt on www.karrio.io or docs.karrio.io, both 404 (0). The spec carries about 1,200 description lines and the guides cover authentication, pagination, shipments, trackers and webhooks, with little on when not to use a call, such as the stored /v1/shipments against the pass-through /v1/proxy/shipping (12 of 20). Units, statuses and label types are enums and required fields are marked, but carrier options and connection credentials are open objects whose keys differ by carrier (10 of 15). The guides have cURL and JavaScript examples and the spec has an ErrorResponse schema, while the error guide is a table of HTTP statuses only (9 of 15). Versions are dated and CHANGELOG.md is current, but the changelog page on the website stops at 2024.12.6 (12 of 15). | |||
| Agent ergonomics | 13%16.2 | 9.3 | |
List calls take limit from 1 to 100 with offset. No field selection was found, and a shipment response nests addresses, parcels, rates and documents. The MCP server in source has 12 compact tools but isn't published (13 of 25). Offset pagination with count, next and previous, and filters on carrier, status, dates, keyword and metadata (17 of 20). Errors come back as an errors array with a code, message and details, and carrier messages pass through. The published guide lists HTTP statuses, not codes (12 of 20). No idempotency keys were found in the server or the spec. A cancel on an already cancelled shipment returns 202, and the MCP tools in source carry readOnlyHint and destructiveHint (8 of 20). A shipment created with a service buys the label in one call and addresses can be nested. The Python SDK is current, while the npm client karrio is at 2023.1.0 (7 of 15). | |||
| Security & auth | 14%17.5 | 7.7 | |
Private API keys with a label, bound to test or live mode, sent as the Basic username or in the Authorization header. The docs say a private key can perform any request without restriction. Short-lived resource tokens for document links can travel in a ?token= query string, which we didn't count against the score because they expire in five minutes by default and open one resource (20 of 30). Test-mode keys keep building away from live carriers. Team permissions are in the paid ee/ code, and the MCP guide asks the agent to confirm with the user before create_shipment (7 of 20). Responses carry carrier tracking text and addresses, and no injection guidance was found (3 of 15). API logs, tracing records and events are stored and readable in the open-source edition, and audit logging is listed as an enterprise feature (10 of 15). SECURITY.md gives an email address only. No security.txt, bug bounty or certification was found, and GitHub lists no published advisories although 2026.1.32 fixed MD5 password storage (4 of 20). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). Self-hosting is free, and the platform page gives starting prices only, $499 a month for the managed Scale platform with pay-as-you-go usage and $50,000 a year for a commercial licence, with no unit price (10 of 20). The open-source edition needs no card or account (20). Install is scriptable with Docker Compose and POST /api/token issues a JWT for an email and password, but carrier accounts and the API key are set up by a person, so half (10 of 20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 2.5 | |
| The newest release, 2026.1.32, is dated 23 June 2026, 107 days before the check, and nothing has landed on main since (10 of 30). No release between 10 July and 8 October 2026 (0 of 20). Of the 15 newest Discussions threads, 10 showed no maintainer reply, and fix pull requests opened between 23 September and 2 October 2026 each had one or two comments and were unmerged, among 83 open pull requests (8 of 25). No entry in the official MCP registry and no MCP package on npm. The PyPI packages match the last release and the npm client is at 2023.1.0 (5 of 15). CI passed on the last commit and the changelog records pinning axios away from compromised versions, while dependency pull requests from April and June 2026 remain open (6 of 10). | |||
| Transparency & trusteditorial 59, provenance 53 | 7%8.8 | 4.9 | |
The server, SDK and modules are LGPL-3.0, an OSI licence. ee/ is under a proprietary licence in the same repository, and the PyPI metadata for karrio leaves the licence field empty (26 of 30). On a self-hosted instance the data stays with the owner. The privacy policy (8 April 2025) covers the website and associated services, excludes customer data, gives no retention periods and names 12 service providers. No data processing addendum was found (14 of 30). Breaking changes are flagged in the changelog and the spec says a new dated version marks an incompatible change. No deprecation policy with notice periods was found (7 of 20). Sentry and PostHog reporting are documented and stay off unless the operator sets their keys. The Compose files pull images through a Scarf gateway and the README carries a Scarf pixel, neither described in the docs we read (12 of 20). | |||
| Negative events | ≤15 |
| -7 |
| Total | 48.7 · D | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Karrio, or have the agent fetch /fixes/karrio.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Karrio
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/karrio, the October 2026 research run, assessed 8 October 2026. Grade D, 48.7 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Karrio: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Security & auth, 44 out of 100, up to 9.8 more on the total
Why it scored 44: Private API keys with a label, bound to test or live mode, sent as the Basic username or in the `Authorization` header. The docs say a private key can perform any request without restriction. Short-lived resource tokens for document links can travel in a `?token=` query string, which we didn't count against the score because they expire in five minutes by default and open one resource (20 of 30). Test-mode keys keep building away from live carriers. Team permissions are in the paid `ee/` code, and the MCP guide asks the agent to confirm with the user before `create_shipment` (7 of 20). Responses carry carrier tracking text and addresses, and no injection guidance was found (3 of 15). API logs, tracing records and events are stored and readable in the open-source edition, and audit logging is listed as an enterprise feature (10 of 15). `SECURITY.md` gives an email address only. No security.txt, bug bounty or certification was found, and GitHub lists no published advisories although 2026.1.32 fixed MD5 password storage (4 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 2. Payments & pricing, 40 out of 100, up to 7.5 more on the total
Why it scored 40: Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). Self-hosting is free, and the platform page gives starting prices only, $499 a month for the managed Scale platform with pay-as-you-go usage and $50,000 a year for a commercial licence, with no unit price (10 of 20). The open-source edition needs no card or account (20). Install is scriptable with Docker Compose and `POST /api/token` issues a JWT for an email and password, but carrier accounts and the API key are set up by a person, so half (10 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 3. Agent ergonomics, 57 out of 100, up to 7 more on the total
Why it scored 57: List calls take `limit` from 1 to 100 with `offset`. No field selection was found, and a shipment response nests addresses, parcels, rates and documents. The MCP server in source has 12 compact tools but isn't published (13 of 25). Offset pagination with `count`, `next` and `previous`, and filters on carrier, status, dates, keyword and metadata (17 of 20). Errors come back as an `errors` array with a code, message and details, and carrier messages pass through. The published guide lists HTTP statuses, not codes (12 of 20). No idempotency keys were found in the server or the spec. A cancel on an already cancelled shipment returns 202, and the MCP tools in source carry `readOnlyHint` and `destructiveHint` (8 of 20). A shipment created with a `service` buys the label in one call and addresses can be nested. The Python SDK is current, while the npm client `karrio` is at 2023.1.0 (7 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 4. Maintenance & community, 29 out of 100, up to 6.2 more on the total
Why it scored 29: The newest release, 2026.1.32, is dated 23 June 2026, 107 days before the check, and nothing has landed on main since (10 of 30). No release between 10 July and 8 October 2026 (0 of 20). Of the 15 newest Discussions threads, 10 showed no maintainer reply, and fix pull requests opened between 23 September and 2 October 2026 each had one or two comments and were unmerged, among 83 open pull requests (8 of 25). No entry in the official MCP registry and no MCP package on npm. The PyPI packages match the last release and the npm client is at 2023.1.0 (5 of 15). CI passed on the last commit and the changelog records pinning axios away from compromised versions, while dependency pull requests from April and June 2026 remain open (6 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## 5. Schema & documentation, 68 out of 100, up to 5.2 more on the total
Why it scored 68: `schemas/openapi.yml` is OpenAPI 3.0.3 at version 2026.1.32, with 65 paths, and the docs site renders a reference from it. GraphQL schemas sit beside it (25). No llms.txt on www.karrio.io or docs.karrio.io, both 404 (0). The spec carries about 1,200 description lines and the guides cover authentication, pagination, shipments, trackers and webhooks, with little on when not to use a call, such as the stored `/v1/shipments` against the pass-through `/v1/proxy/shipping` (12 of 20). Units, statuses and label types are enums and required fields are marked, but carrier `options` and connection `credentials` are open objects whose keys differ by carrier (10 of 15). The guides have cURL and JavaScript examples and the spec has an `ErrorResponse` schema, while the error guide is a table of HTTP statuses only (9 of 15). Versions are dated and `CHANGELOG.md` is current, but the changelog page on the website stops at 2024.12.6 (12 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 6. Reliability, 76 out of 100, up to 4.8 more on the total
Why it scored 76: Read with the local-software lines, since the graded surface is the open-source server its owner hosts. The managed platform has no status page we could find, and its hosts didn't answer on 8 October 2026. Docker images on Docker Hub and PyPI packages at 2026.1.32, with Python 3.11 or later stated for `karrio`, though `karrio-server` still declares 3.7 or later (18 of 20). A public tests workflow runs SDK type checks, SDK tests and server tests on PostgreSQL, and the last five runs on main, all on 23 June 2026, passed (25). GitHub Issues is switched off, so bug reports go to Discussions. Reports from July and August 2026 on FedEx dimensions and a GraphQL crash had no reply, and a June report that migration 0093 deleted tracker history was fixed in 2026.1.32 (10 of 25). Versions are calendar-based, not semver, and the breaking rename of the `purchased` status shipped in 2026.1.20 with a banner in the changelog (8 of 15). Releases are past 1.0 and numbered for production use (15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 7. Transparency & trust, 56 out of 100, up to 3.9 more on the total
Made of editorial 59, provenance 53.
Why it scored 56: The server, SDK and modules are LGPL-3.0, an OSI licence. `ee/` is under a proprietary licence in the same repository, and the PyPI metadata for `karrio` leaves the licence field empty (26 of 30). On a self-hosted instance the data stays with the owner. The privacy policy (8 April 2025) covers the website and associated services, excludes customer data, gives no retention periods and names 12 service providers. No data processing addendum was found (14 of 30). Breaking changes are flagged in the changelog and the spec says a new dated version marks an incompatible change. No deprecation policy with notice periods was found (7 of 20). Sentry and PostHog reporting are documented and stay off unless the operator sets their keys. The Compose files pull images through a Scarf gateway and the README carries a Scarf pixel, neither described in the docs we read (12 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Domain age: karrio.io, registered 2022-01-20 (4 years) (7 of 15)
- Endpoint on the vendor's domain: is not on karrio.io (0 of 15)
- Terms of service: read, states 5 of the 7 things a reader expects, and has 1 clause that costs points (6.3 of 10)
- Status page: not found (0 of 10)
- security.txt: not found (0 of 10)
## Deductions
Each comes off the total. A fixed and documented problem counts for less at the next check.
- 12 March to 23 June 2026. Versions 2026.1.22 to 2026.1.31 applied an MD5 `PASSWORD_HASHERS` override outside the test runner, so production instances stored MD5 password hashes. Fixed in 2026.1.32 and described in the changelog, with no published advisory, so 4 of a possible 15 (https://github.com/karrioapi/karrio/blob/main/CHANGELOG.md).
- 8 October 2026. The README and the MCP guide tell users to run `npx karrio-mcp` and `npx -y @karrio/mcp`, and the npm registry answers 404 for both. The examples' API host `api.karrio.io` didn't resolve the same day. 3 for a claim the listing can't meet (https://registry.npmjs.org/@karrio%2fmcp, https://www.karrio.io/docs/developing/mcp-server).
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: whether the managed platform is still operating. `api.karrio.io` didn't resolve and `app.karrio.io` and `platform.karrio.io` returned Vercel's paused-deployment error on 8 October 2026, which may be temporary
- unchecked: the community carrier submodule, which we didn't fetch, so the connector count of 30 covers `modules/connectors` only
- unchecked: reply times in Discord, and the sponsorship prices for Insiders, since polar.sh/karrioapi returned 404
- Whether releases have moved to a private or Insiders repository since June 2026 wasn't established
- No address validation endpoint was found in the OpenAPI file, so `shipping.address-validation` is left out. Returns rest on the `is_return` and `return_shipment` fields in the spec, which we didn't exercise
- The lead said REST API and SDKs with a cloud option. The cloud option couldn't be reached, and the listing grades the self-hosted server
## Weaknesses
- No release since 2026.1.32 on 23 June 2026, 107 days before this check, and fix pull requests opened in September 2026 were still open
- Neither `@karrio/mcp` nor `karrio-mcp` exists on npm, though the README and the MCP guide give `npx` commands for them
- `api.karrio.io` didn't resolve and `app.karrio.io` answered 503 with a paused deployment on 8 October 2026, and the managed platform starts with a demo booking
- Versions 2026.1.22 to 2026.1.31 stored passwords as MD5 hashes in production, fixed in 2026.1.32 with a changelog line and no published advisory
- No idempotency keys were found, and a private API key can perform any request. Team permissions and audit logging sit in the paid `ee/` code
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Run your own instance with Docker Compose and call it at `http://localhost:5002`. Don't rely on `api.karrio.io`, which didn't resolve on 8 October 2026
- Don't run `npx karrio-mcp` or `npx -y @karrio/mcp`. Neither name is published on npm, so build the server from `packages/mcp` in the repository
- Change the default `admin@example.com` and `demo` login before the instance is reachable, and upgrade to 2026.1.32 or later so passwords aren't stored as MD5
- Don't blind-retry `POST /v1/shipments` with a `service` set or `POST /v1/shipments/{id}/purchase`. Fetch the shipment and check its status first, since no idempotency key exists
- Use a test-mode API key while building. Send it as the HTTP Basic username or as `Authorization: Token key_...`
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: whether the managed platform is still operating.
api.karrio.iodidn't resolve andapp.karrio.ioandplatform.karrio.ioreturned Vercel's paused-deployment error on 8 October 2026, which may be temporary - unchecked: the community carrier submodule, which we didn't fetch, so the connector count of 30 covers
modules/connectorsonly - unchecked: reply times in Discord, and the sponsorship prices for Insiders, since polar.sh/karrioapi returned 404
- Whether releases have moved to a private or Insiders repository since June 2026 wasn't established
- No address validation endpoint was found in the OpenAPI file, so
shipping.address-validationis left out. Returns rest on theis_returnandreturn_shipmentfields in the spec, which we didn't exercise - The lead said REST API and SDKs with a cloud option. The cloud option couldn't be reached, and the listing grades the self-hosted server
Sources 18
- repository at tag v2026.1.32 (README, licences, changelog, OpenAPI file, settings, MCP package, CI workflows) github.com · seen 2026-10-08
- changelog github.com · seen 2026-10-08
- OpenAPI 3.0.3 file raw.githubusercontent.com · seen 2026-10-08
- MCP package source github.com · seen 2026-10-08
- MCP guide karrio.io · seen 2026-10-08
- npm registry lookup for the MCP package, 404 registry.npmjs.org · seen 2026-10-08
- platform page with prices karrio.io · seen 2026-10-08
- home page karrio.io · seen 2026-10-08
- Customer Terms and Conditions karrio.io · seen 2026-10-08
- privacy policy karrio.io · seen 2026-10-08
- older terms referenced by the enterprise licence docs.karrio.io · seen 2026-10-08
- dashboard host, 503 with a paused deployment app.karrio.io · seen 2026-10-08
- Discussions github.com · seen 2026-10-08
- GitHub API for stars, open pull requests and test runs api.github.com · seen 2026-10-08
- PyPI package pypi.org · seen 2026-10-08
- Docker Hub image hub.docker.com · seen 2026-10-08
- official MCP registry search, no result registry.modelcontextprotocol.io · seen 2026-10-08
- RDAP record for karrio.io rdap.identitydigital.services · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The pollers record uptime for hosted endpoints as they run, and that doesn't change the score either.
Pricing & changes
Freemium $499 / mo Free when self-hosted under LGPL-3.0, with carrier postage billed by the owner's own carrier accounts. The platform page says the managed Scale platform starts at $499 a month with pay-as-you-go pricing and a commercial licence for embedding starts at $50,000 a year, with no unit prices published. An agent can start on a self-hosted instance in test mode with no contract. The managed platform has no self-serve signup, only a demo booking (checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Open-source edition, self-hosted | free | per month (plan) | LGPL-3.0, you pay for your own hosting and carrier postage |
| Scale managed platform, starting price | $499 | per month (plan) | plus pay-as-you-go usage with no published unit price, by demo booking |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/karrio.xml, or this listing's score history at history.json.
Connect
Install
git clone --depth 1 https://github.com/karrioapi/karrio
cd karrio
git submodule update --init community
cd docker
docker compose up
First request
curl http://localhost:5002/v1/shipments \
-u key_xxxxxx:
Through letme picks today, calling later
GET https://letme.dev/karrio
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Easyship BSendcloud BShippo CShipBob CShipStation API CEasyPost C
Head to head EasyPost vs Karrio · Easyship vs Karrio · Karrio vs Sendcloud · Karrio vs ShipBob · Karrio vs Shippo · Karrio vs ShipStation API · Karrio vs Ship24
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Easyship Easyship Inc. | B | 68.8 | shipping.rates shipping.labels shipping.tracking shipping.returns | no |
| Sendcloud Sendcloud B.V. | B | 62 | shipping.rates shipping.labels shipping.tracking shipping.returns | no |
| Shippo Shippo | C | 61.9 | shipping.rates shipping.labels shipping.tracking shipping.returns | no |
| ShipBob ShipBob, Inc. | C | 60.8 | shipping.rates shipping.tracking shipping.returns shipping.labels | no |
| ShipStation API Auctane LLC d/b/a ShipStation | C | 59.3 | shipping.rates shipping.labels shipping.tracking shipping.returns | no |
| EasyPost Simpler Postage, Inc. (d/b/a EasyPost) | C | 54.3 | shipping.rates shipping.labels shipping.tracking shipping.returns | no |
Machine-readable
- JSON
/api/v1/tools/karrio.json· historyhistory.json· badge/badges/karrio.svg· changes feed/feeds/tools/karrio.xml - Markdown
/tools/karrio.md· slim/tools/karrio.min.md(or sendAccept: text/markdown) - Fix list
/fixes/karrio.md·/fixes/karrio.json - From a terminal
anchor tool karrio --md(the CLI) · over MCPget_tool {"slug": "karrio"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/karrio"><img src="https://www.anchorterminal.com/badges/karrio.svg" alt="Karrio on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/karrio)<a href="https://www.anchorterminal.com/tools/karrio">Karrio on Anchor Terminal</a>It counts on a page on karrio.io or one of its subdomains, or the README of github.com/karrioapi/karrio.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "karrio", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


