# Karrio > Karrio is an open-source multi-carrier shipping server from Karrio, Inc. Its REST API quotes rates, buys labels, tracks parcels and books pickups through the owner's own carrier accounts, self-hosted with Docker or run by Karrio as a paid platform. - Canonical: https://www.anchorterminal.com/tools/karrio - Markdown: https://www.anchorterminal.com/tools/karrio.md (~7,750 tokens) - Slim: https://www.anchorterminal.com/tools/karrio.min.md (~1,980 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/karrio.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade D · 48.7/100 · rank #617 of 722 · #8 in Shipping & fulfilment · not agent-ready · confidence medium** ## Assessment A current OpenAPI 3.0.3 contract with 65 paths, a free LGPL-3.0 server and 30 carrier connectors suit a team that hosts it. The last release was 23 June 2026, the `@karrio/mcp` package the docs install is absent from npm, and `api.karrio.io` didn't resolve on 8 October 2026. ## Facts | Field | Value | | --- | --- | | Vendor | Karrio, Inc. (https://www.karrio.io) | | Kind | HTTP API | | Category | Shipping & fulfilment (https://www.anchorterminal.com/categories/shipping) | | Transport | HTTP | | Auth | API key · A private API key from the instance's dashboard, sent as the HTTP Basic username with no password or as `Authorization: Token key_...`. Keys carry a label and are bound to test or live mode, and the docs say a private key can perform any request without restriction. A JWT pair is also issued by `POST /api/token` for an email and password. On a self-hosted instance the owner creates the first account, so no approval from Karrio is involved. The managed platform is reached through a demo booking. | | Pricing | Freemium ($499 / mo) · Free when self-hosted under LGPL-3.0, with carrier postage billed by the owner's own carrier accounts. The platform page says the managed Scale platform starts at $499 a month with pay-as-you-go pricing and a commercial licence for embedding starts at $50,000 a year, with no unit prices published. An agent can start on a self-hosted instance in test mode with no contract. The managed platform has no self-serve signup, only a demo booking (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the repository, the OpenAPI file, the docs or the platform page (checked 2026-10-08). | | Licence | LGPL-3.0 for the server, SDK and modules. Code under `ee/` is under the Karrio Enterprise licence and needs a subscription for production use. The MCP package in `packages/mcp` is Apache-2.0 | | Packages | pypi: `karrio`; pypi: `karrio-server`; oci: `karrio/server` | | Source | https://github.com/karrioapi/karrio | | Docs | https://www.karrio.io/docs | | llms.txt | not found | | Last release | 2026-06-23 | | GitHub stars | 799 (as of 2026-10-08) | | PyPI downloads / week | 338 | | Graded surface | The open-source server its owner hosts, REST under `/v1` with a GraphQL API beside it. The managed platform wasn't reachable for grading on 8 October 2026 | | API | OpenAPI 3.0.3, version 2026.1.32, 65 paths. Shipments, rates, trackers, pickups, manifests, orders, addresses, parcels, products, documents, webhooks, carrier connections, batches, plus `/v1/proxy/*` calls that pass straight to a carrier without storing a record | | Carriers | 30 connectors in `modules/connectors`, among them UPS, FedEx, USPS, DHL Express, DHL Parcel DE, Canada Post, Purolator, DPD, GLS, La Poste, Chronopost, Australia Post and Sendle. More sit in a community submodule we didn't count. The owner supplies the carrier accounts | | Credentials | Private API keys (`key_...`) with a label, bound to test or live mode, sent as the HTTP Basic username or `Authorization: Token`. JWT pairs from `POST /api/token` with email and password. Short-lived resource tokens from `POST /api/tokens` for document links, five minutes by default and one hour at most | | Getting access | Self-hosted, `docker compose up` in `docker/`, API on port 5002 and dashboard on 3002, default login `admin@example.com` with password `demo`. The managed platform is by demo booking | | Test mode | Keys are bound to test or live mode, and JWT requests choose with the `x-test-mode` header. Test mode calls the carriers' sandbox hosts with the owner's sandbox credentials | | Rate limits | Defaults in `settings/base.py`. 60 a minute anonymous, 600 a minute per user, 300 a minute on carrier requests, each set by environment variable (`ANON_RATE_LIMIT`, `USER_RATE_LIMIT`, `CARRIER_REQUEST_RATE_LIMIT`) | | Pagination | `limit` from 1 to 100 and `offset`, with `count`, `next` and `previous` in the response. Shipment lists filter by carrier, status, dates, keyword, metadata key and value, `is_return` and more | | MCP server | `packages/mcp` in the repository, Apache-2.0, version 1.0.0, 12 tools and two carrier resources, stdio or Streamable HTTP on port 3100. Not on npm on 8 October 2026 and not in the official MCP registry | | Packages | PyPI `karrio` 2026.1.32 (Python 3.11 or later), `karrio-server` 2026.1.32 and `karrio-cli`, all uploaded 23 June 2026. Docker Hub `karrio/server`, about 27,000 pulls. The npm client `karrio` is at 2023.1.0 | | Licence | LGPL-3.0 for the server, SDK and modules. `ee/` (multi-tenancy, workflows, audit logging, SSO) under the Karrio Enterprise licence, which needs a subscription for production use. MCP package Apache-2.0 | | Support | GitHub Discussions and Discord for the open-source edition. The platform page lists email and Slack support for Scale customers and an SLA for enterprise and commercial licence customers | | Capabilities | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | | Tags | open-source, self-hosted, api-key, openapi, graphql, webhooks, sandbox, docker, python, mcp | | JSON | https://www.anchorterminal.com/api/v1/tools/karrio.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 76 | 15.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 68 | 11.1 | | Agent ergonomics | 13% | 16.2 | 57 | 9.3 | | Security & auth | 14% | 17.5 | 44 | 7.7 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 29 | 2.5 | | Transparency & trust (editorial 59, provenance 53) | 7% | 8.8 | 56 | 4.9 | | Negative events | up to −15 | up to −15 | 12 March to 23 June 2026. Versions 2026.1.22 to 2026.1.31 applied an MD5 `PASSWORD_HASHERS` override outside the test runner, so production instances stored MD5 password hashes. Fixed in 2026.1.32 and described in the changelog, with no published advisory, so 4 of a possible 15 (https://github.com/karrioapi/karrio/blob/main/CHANGELOG.md). 8 October 2026. The README and the MCP guide tell users to run `npx karrio-mcp` and `npx -y @karrio/mcp`, and the npm registry answers 404 for both. The examples' API host `api.karrio.io` didn't resolve the same day. 3 for a claim the listing can't meet (https://registry.npmjs.org/@karrio%2fmcp, https://www.karrio.io/docs/developing/mcp-server). | -7 | | **Total** | | | | **48.7 → D** | ### Why each score - Reliability 76: Read with the local-software lines, since the graded surface is the open-source server its owner hosts. The managed platform has no status page we could find, and its hosts didn't answer on 8 October 2026. Docker images on Docker Hub and PyPI packages at 2026.1.32, with Python 3.11 or later stated for `karrio`, though `karrio-server` still declares 3.7 or later (18 of 20). A public tests workflow runs SDK type checks, SDK tests and server tests on PostgreSQL, and the last five runs on main, all on 23 June 2026, passed (25). GitHub Issues is switched off, so bug reports go to Discussions. Reports from July and August 2026 on FedEx dimensions and a GraphQL crash had no reply, and a June report that migration 0093 deleted tracker history was fixed in 2026.1.32 (10 of 25). Versions are calendar-based, not semver, and the breaking rename of the `purchased` status shipped in 2026.1.20 with a banner in the changelog (8 of 15). Releases are past 1.0 and numbered for production use (15). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 68: `schemas/openapi.yml` is OpenAPI 3.0.3 at version 2026.1.32, with 65 paths, and the docs site renders a reference from it. GraphQL schemas sit beside it (25). No llms.txt on www.karrio.io or docs.karrio.io, both 404 (0). The spec carries about 1,200 description lines and the guides cover authentication, pagination, shipments, trackers and webhooks, with little on when not to use a call, such as the stored `/v1/shipments` against the pass-through `/v1/proxy/shipping` (12 of 20). Units, statuses and label types are enums and required fields are marked, but carrier `options` and connection `credentials` are open objects whose keys differ by carrier (10 of 15). The guides have cURL and JavaScript examples and the spec has an `ErrorResponse` schema, while the error guide is a table of HTTP statuses only (9 of 15). Versions are dated and `CHANGELOG.md` is current, but the changelog page on the website stops at 2024.12.6 (12 of 15). - Agent ergonomics 57: List calls take `limit` from 1 to 100 with `offset`. No field selection was found, and a shipment response nests addresses, parcels, rates and documents. The MCP server in source has 12 compact tools but isn't published (13 of 25). Offset pagination with `count`, `next` and `previous`, and filters on carrier, status, dates, keyword and metadata (17 of 20). Errors come back as an `errors` array with a code, message and details, and carrier messages pass through. The published guide lists HTTP statuses, not codes (12 of 20). No idempotency keys were found in the server or the spec. A cancel on an already cancelled shipment returns 202, and the MCP tools in source carry `readOnlyHint` and `destructiveHint` (8 of 20). A shipment created with a `service` buys the label in one call and addresses can be nested. The Python SDK is current, while the npm client `karrio` is at 2023.1.0 (7 of 15). - Security & auth 44: Private API keys with a label, bound to test or live mode, sent as the Basic username or in the `Authorization` header. The docs say a private key can perform any request without restriction. Short-lived resource tokens for document links can travel in a `?token=` query string, which we didn't count against the score because they expire in five minutes by default and open one resource (20 of 30). Test-mode keys keep building away from live carriers. Team permissions are in the paid `ee/` code, and the MCP guide asks the agent to confirm with the user before `create_shipment` (7 of 20). Responses carry carrier tracking text and addresses, and no injection guidance was found (3 of 15). API logs, tracing records and events are stored and readable in the open-source edition, and audit logging is listed as an enterprise feature (10 of 15). `SECURITY.md` gives an email address only. No security.txt, bug bounty or certification was found, and GitHub lists no published advisories although 2026.1.32 fixed MD5 password storage (4 of 20). - Payments & pricing 40: Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). Self-hosting is free, and the platform page gives starting prices only, $499 a month for the managed Scale platform with pay-as-you-go usage and $50,000 a year for a commercial licence, with no unit price (10 of 20). The open-source edition needs no card or account (20). Install is scriptable with Docker Compose and `POST /api/token` issues a JWT for an email and password, but carrier accounts and the API key are set up by a person, so half (10 of 20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 29: The newest release, 2026.1.32, is dated 23 June 2026, 107 days before the check, and nothing has landed on main since (10 of 30). No release between 10 July and 8 October 2026 (0 of 20). Of the 15 newest Discussions threads, 10 showed no maintainer reply, and fix pull requests opened between 23 September and 2 October 2026 each had one or two comments and were unmerged, among 83 open pull requests (8 of 25). No entry in the official MCP registry and no MCP package on npm. The PyPI packages match the last release and the npm client is at 2023.1.0 (5 of 15). CI passed on the last commit and the changelog records pinning axios away from compromised versions, while dependency pull requests from April and June 2026 remain open (6 of 10). - Transparency & trust 56: The server, SDK and modules are LGPL-3.0, an OSI licence. `ee/` is under a proprietary licence in the same repository, and the PyPI metadata for `karrio` leaves the licence field empty (26 of 30). On a self-hosted instance the data stays with the owner. The privacy policy (8 April 2025) covers the website and associated services, excludes customer data, gives no retention periods and names 12 service providers. No data processing addendum was found (14 of 30). Breaking changes are flagged in the changelog and the spec says a new dated version marks an incompatible change. No deprecation policy with notice periods was found (7 of 20). Sentry and PostHog reporting are documented and stay off unless the operator sets their keys. The Compose files pull images through a Scarf gateway and the README carries a Scarf pixel, neither described in the docs we read (12 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/karrio.md (JSON https://www.anchorterminal.com/fixes/karrio.json) ### What we couldn't check - unchecked: whether the managed platform is still operating. `api.karrio.io` didn't resolve and `app.karrio.io` and `platform.karrio.io` returned Vercel's paused-deployment error on 8 October 2026, which may be temporary - unchecked: the community carrier submodule, which we didn't fetch, so the connector count of 30 covers `modules/connectors` only - unchecked: reply times in Discord, and the sponsorship prices for Insiders, since polar.sh/karrioapi returned 404 - Whether releases have moved to a private or Insiders repository since June 2026 wasn't established - No address validation endpoint was found in the OpenAPI file, so `shipping.address-validation` is left out. Returns rest on the `is_return` and `return_shipment` fields in the spec, which we didn't exercise - The lead said REST API and SDKs with a cloud option. The cloud option couldn't be reached, and the listing grades the self-hosted server ### Sources - repository at tag v2026.1.32 (README, licences, changelog, OpenAPI file, settings, MCP package, CI workflows): (seen 2026-10-08) - changelog: (seen 2026-10-08) - OpenAPI 3.0.3 file: (seen 2026-10-08) - MCP package source: (seen 2026-10-08) - MCP guide: (seen 2026-10-08) - npm registry lookup for the MCP package, 404: (seen 2026-10-08) - platform page with prices: (seen 2026-10-08) - home page: (seen 2026-10-08) - Customer Terms and Conditions: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - older terms referenced by the enterprise licence: (seen 2026-10-08) - dashboard host, 503 with a paused deployment: (seen 2026-10-08) - Discussions: (seen 2026-10-08) - GitHub API for stars, open pull requests and test runs: (seen 2026-10-08) - PyPI package: (seen 2026-10-08) - Docker Hub image: (seen 2026-10-08) - official MCP registry search, no result: (seen 2026-10-08) - RDAP record for karrio.io: (seen 2026-10-08) ## Who's behind it (provenance 53/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Karrio, Inc. | 20/20 | | Domain age | karrio.io, registered 2022-01-20 (4 years) | 7/15 | | Endpoint on the vendor's domain | is not on karrio.io | 0/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 1 clause that costs points | 6.3/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Customer Terms and Conditions (last modified 8 April 2025) name Karrio, Inc., a Delaware corporation at 760 Chemin Marie-Le Ber, Verdun, Quebec, Canada, and govern the hosted platform. The self-hosted open-source edition is governed by LGPL-3.0, and `LICENSE_EE` points `ee/` users to the subscription terms at docs.karrio.io/product/resources/terms, an older copy dated 19 April 2022. The privacy policy (last modified 8 April 2025) covers karrio.io and associated services and excludes customer data processed on a customer's behalf. No data processing addendum was found. The graded surface is an instance on the owner's own host, so the endpoint isn't on the vendor's domain. `api.karrio.io` didn't resolve and `app.karrio.io` returned 503 on 8 October 2026. No status page was found. `status.karrio.io` didn't resolve and the site links none. www.karrio.io/.well-known/security.txt returns 404. `SECURITY.md` in the repository sends reports to hello@karrio.io. The changelog page on www.karrio.io stops at 2024.12.6. `CHANGELOG.md` in the repository is current to 2026.1.32. RDAP for karrio.io gives a registration date of 2022-01-20. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.karrio.io/terms-of-service), read 2026-10-08, dated 2025-04-08, states 5 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "(vi) access or use any Karrio IP for purposes of competitive analysis of Karrio or the Services, the development, provision, or use of a competing software service or product, or any other purpose that is to Karrio’s detriment or commercial disadvantage" - Gives the date it was last updated. Last updated 2025-04-08. - Names the governing law or courts. The law of the State of California. - Not found in the text. Says how changes to the terms are announced. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Karrio may name the customer and use its name, logo and trademarks in its customer list, press releases, blog posts, advertisements and website. "Karrio may identify Customer as a user of the Services and may use Customer’s name, logo, and other trademarks in Karrio’s customer list, press releases, blog posts, advertisements, and website" - Also in the text (2026-10-08). Karrio may make aggregated data compiled from customer data available to third parties, including its other customers. "Customer agrees that Karrio may (i) make Aggregated Data available to third parties including its other customers in compliance with applicable law, and (ii) use Aggregated Data to the extent and in the manner permitted under applicable law." - Also in the text (2026-10-08). Storing payment cardholder information through the service needs Karrio's prior written approval. "Customer may not store any payment cardholder information using the Services without Karrio’s prior written approval." **Privacy policy** (https://www.karrio.io/privacy-policy), read 2026-10-08, dated 2025-04-08, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2025-04-08. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@karrio.io. - Also in the text (2026-10-08). The notice does not cover customer data that Karrio processes on a customer's behalf, and it refers readers to that customer's own privacy notice. "This Privacy Notice does not apply to such processing and we recommend you read the Privacy Notice of the respective customer, if their processing concerns your personal information." ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Open-source edition, self-hosted | free | per month (plan) | LGPL-3.0, you pay for your own hosting and carrier postage | | Scale managed platform, starting price | $499 | per month (plan) | plus pay-as-you-go usage with no published unit price, by demo booking | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - OpenAPI 3.0.3 contract in the repository at version 2026.1.32, with 65 paths covering rates, shipments, trackers, pickups, manifests, orders, documents and webhooks - The core server and SDK are LGPL-3.0 and run on the owner's infrastructure with Docker Compose, with no fee to Karrio - 30 carrier connectors in `modules/connectors`, among them UPS, FedEx, USPS, DHL Express, Canada Post, DPD and Australia Post, used with the owner's own carrier accounts - API keys are bound to test or live mode, and test mode runs rates, labels, trackers and pickups against carrier sandboxes - Default throttles are in the settings file with numbers (600 requests a minute per user, 300 for carrier calls) and can be changed by environment variable ## Weaknesses - No release since 2026.1.32 on 23 June 2026, 107 days before this check, and fix pull requests opened in September 2026 were still open - Neither `@karrio/mcp` nor `karrio-mcp` exists on npm, though the README and the MCP guide give `npx` commands for them - `api.karrio.io` didn't resolve and `app.karrio.io` answered 503 with a paused deployment on 8 October 2026, and the managed platform starts with a demo booking - Versions 2026.1.22 to 2026.1.31 stored passwords as MD5 hashes in production, fixed in 2026.1.32 with a changelog line and no published advisory - No idempotency keys were found, and a private API key can perform any request. Team permissions and audit logging sit in the paid `ee/` code ## Before you call it (notes for agents) 1. Run your own instance with Docker Compose and call it at `http://localhost:5002`. Don't rely on `api.karrio.io`, which didn't resolve on 8 October 2026 2. Don't run `npx karrio-mcp` or `npx -y @karrio/mcp`. Neither name is published on npm, so build the server from `packages/mcp` in the repository 3. Change the default `admin@example.com` and `demo` login before the instance is reachable, and upgrade to 2026.1.32 or later so passwords aren't stored as MD5 4. Don't blind-retry `POST /v1/shipments` with a `service` set or `POST /v1/shipments/{id}/purchase`. Fetch the shipment and check its status first, since no idempotency key exists 5. Use a test-mode API key while building. Send it as the HTTP Basic username or as `Authorization: Token key_...` ## Connect Install: ```bash git clone --depth 1 https://github.com/karrioapi/karrio cd karrio git submodule update --init community cd docker docker compose up ``` First request: ```bash curl http://localhost:5002/v1/shipments \ -u key_xxxxxx: ``` Through letme (picks today, calling later): https://letme.dev/karrio. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Easyship | B | 68.8 | 173 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | no | https://www.anchorterminal.com/tools/easyship.md | | Sendcloud | B | 62 | 352 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | no | https://www.anchorterminal.com/tools/sendcloud.md | | Shippo | C | 61.9 | 355 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | no | https://www.anchorterminal.com/tools/shippo.md | | ShipBob | C | 60.8 | 387 | shipping.rates, shipping.tracking, shipping.returns, shipping.labels | no | https://www.anchorterminal.com/tools/shipbob.md | | ShipStation API | C | 59.3 | 433 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | no | https://www.anchorterminal.com/tools/shipstation.md | | EasyPost | C | 54.3 | 531 | shipping.rates, shipping.labels, shipping.tracking, shipping.returns | no | https://www.anchorterminal.com/tools/easypost.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The repository's default branch and newest tag are both at 2026.1.32, dated 23 June 2026, with 33 dated 2026 entries in `CHANGELOG.md` before it (source: ) - The README configures the MCP server with `npx karrio-mcp` and the MCP guide with `npx -y @karrio/mcp`. The npm registry answered 404 for both names on 8 October 2026 (source: ) - `packages/mcp` holds 12 tools in source, each with `readOnlyHint` and `destructiveHint` annotations, over stdio or Streamable HTTP (source: ) - `api.karrio.io`, the base URL in the docs' examples, didn't resolve in DNS on 8 October 2026, and `app.karrio.io` returned 503 with Vercel's `DEPLOYMENT_PAUSED` error (source: ) - The platform page says self-hosting is free, the managed Scale platform starts at $499 a month with pay-as-you-go pricing, and a commercial licence for embedding starts at $50,000 a year (source: ) - The 2026.1.32 changelog says the MD5 `PASSWORD_HASHERS` override is now scoped to the test runner so production no longer stores MD5 password hashes. The override arrived in a commit of 12 March 2026 (source: ) - GitHub Issues is switched off and questions go to Discussions, where 10 of the 15 newest threads showed no maintainer reply on 8 October 2026 (source: ) - The Compose files pull images through `karrio.docker.scarf.sh`, a Scarf gateway, and Sentry and PostHog reporting run only when the operator sets `SENTRY_DSN` or `POSTHOG_KEY` (source: ) ## Compare - [EasyPost vs Karrio](https://www.anchorterminal.com/compare/easypost-vs-karrio.md): C 54.3 vs D 48.7 - [Easyship vs Karrio](https://www.anchorterminal.com/compare/easyship-vs-karrio.md): B 68.8 vs D 48.7 - [Karrio vs Sendcloud](https://www.anchorterminal.com/compare/karrio-vs-sendcloud.md): D 48.7 vs B 62 - [Karrio vs ShipBob](https://www.anchorterminal.com/compare/karrio-vs-shipbob.md): D 48.7 vs C 60.8 - [Karrio vs Shippo](https://www.anchorterminal.com/compare/karrio-vs-shippo.md): D 48.7 vs C 61.9 - [Karrio vs ShipStation API](https://www.anchorterminal.com/compare/karrio-vs-shipstation.md): D 48.7 vs C 59.3 - [Karrio vs Ship24](https://www.anchorterminal.com/compare/karrio-vs-ship24.md): D 48.7 vs C 55 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on karrio.io or one of its subdomains, or the README of github.com/karrioapi/karrio. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "karrio", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Karrio on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Karrio on Anchor Terminal](https://www.anchorterminal.com/badges/karrio.svg)](https://www.anchorterminal.com/tools/karrio) ``` Plain link: ```html Karrio on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Karrio is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/karrio-dark.png - Light: https://www.anchorterminal.com/assets/share/karrio-light.png