Lokalise

by Lokalise, Inc. HTTP API in Translation

Hosted Agent-ready

Lokalise, Inc. · lokalise.com since 2016 · status page · who's behind it

Lokalise is a hosted translation management system for software strings, documents and marketing content. Agents reach it through a REST API, the lokalise2 CLI, SDKs in four languages and a hosted MCP server in beta.

Good for Agents that manage localisation work, such as adding keys, uploading and exporting string files, keeping a glossary and starting AI or machine translation tasks for a team that already uses Lokalise.

Is this your product? Claim this listing or verify it

Assessment. The REST API has public OpenAPI files, Markdown docs, published rate limits, read-only tokens, scoped OAuth and an audit log endpoint. Access needs a paid plan after a 14-day trial, a person signs up in a browser, and the Master Service Agreement forbids benchmarking. No idempotency keys or deprecation policy were found in the reviewed documentation.

Facts

Transport
HTTP, Streamable HTTP
Endpoint
https://api.lokalise.com/api2
Auth
OAuth or key
Pricing
Paid · $149 / mo
x402
No
Licence
Proprietary service under the Lokalise Master Service Agreement. The CLI and the Node SDK on GitHub are BSD 3-Clause
Packages
npm @lokalise/node-api
pypi python-lokalise-api
go github.com/lokalise/lokalise-cli-2-go
llms.txt
published
Last release
GitHub stars
124
npm / week
338k
PyPI / week
39k
API
REST at https://api.lokalise.com/api2, OpenAPI 3.0.3. Default projects (63 paths, 109 operations), projects with branches, and OTA. GET /v1/audit-logs sits outside /api2
MCP server
Hosted, in beta. https://mcp.lokalise.com/mcp/project-management (22 documented actions) and https://mcp.lokalise.com/mcp/software-development (16). OAuth 2 with PKCE and dynamic client registration, or an API token in the apikey header
Credentials
Personal API tokens, read-only or read/write, no expiry, revocable in the profile. OAuth 2 authorisation code grant for the API, with apps registered through Lokalise support and access tokens lasting about 60 minutes
Rate limits
6 requests a second per token and per IP, 10 concurrent requests per project. Responses carry X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset (observed on 8 October 2026)
Pagination
limit (default 100, maximum 5,000, 500 on keys) and page, with X-Pagination-* headers. Cursor paging on keys, translations, projects and glossary terms
Errors
JSON error object with code and message. Bulk calls return an errors array per failed item. 429 on rate limits
Files
/files/upload queues an import and returns a process to poll. /files/download covers up to 10,000 key-language pairs, /files/async-download the rest
Translation engines
automatic_translation tasks with translation_engine of ai (default), deepl or google. Human translation through /teams/{team_id}/orders
SDKs and CLI
@lokalise/node-api 16.6.0 (21 September 2026), python-lokalise-api 4.3.0 (5 October 2026), Ruby and PHP clients per the docs, and the lokalise2 CLI v3.1.7 (14 July 2026), BSD 3-Clause
Plans
Explorer $149, Growth $379 and Advanced $1,049 a month billed yearly, Enterprise by quote. 14-day trial at Enterprise level with no card
SLA
99.5 per cent a calendar month in the Master Service Agreement, with service credits in Annex B. Trial access has no service levels
Certifications
SOC 2 Type II, ISO 27001 and ISO 27017 per lokalise.com/product/security. Private bug bounty on YesWeHack and a disclosure policy at vdp.lokalise.com
Data location
Customer data on AWS in EU regions per the security page. Sub-processor list updated 1 August 2026, with locations
Status
status.lokalise.com on Statuspage, five components (Lokalise.com, API, App, OTA, Messages)

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Three public OpenAPI 3.0.3 files, llms.txt and a Markdown twin of every reference page
  • Rate limits published as 6 requests a second per token and per IP, with 10 concurrent requests per project
  • API tokens are read-only or read/write, and OAuth 2 carries read and write scopes per resource
  • The MCP server signs in with OAuth, PKCE and dynamic client registration, and lists 22 scopes
  • GET /v1/audit-logs returns team audit events in OCSF 1.3.0 format since 16 July 2026

Weaknesses

  • The Master Service Agreement forbids using the service for benchmarking or competitive analysis
  • No free plan. Explorer is $149 a month billed yearly after a 14-day trial without a card
  • No idempotency keys in the OpenAPI files, though the errors page mentions an idempotent key under 409
  • API tokens never expire and carry every permission of the user who made them
  • The Developer Program Agreement lets Lokalise change or end API access with or without notice
  • The MCP server is labelled beta in the help centre article

Before you call it notes for agents

  1. Send the token in the X-Api-Token header to https://api.lokalise.com/api2. OAuth access tokens go in Authorization: Bearer and expire after about 60 minutes.
  2. Stay under 6 requests a second per token and 10 concurrent requests per project. On 429, back off exponentially and read X-RateLimit-Reset.
  3. Use a read-only token for reads. A read/write token can call PUT /projects/{project_id}/empty, which deletes every key and translation.
  4. Use pagination=cursor on /keys and /translations, with limit at most 500 on keys, and follow X-Pagination-Next-Cursor.
  5. Projects above 10,000 key-language pairs need /files/async-download. Poll /processes/{process_id} for the bundle URL, and do the same after /files/upload.

Who's behind it provenance 98/100

  • Legal entity namedLokalise, Inc.20/20
  • Domain agelokalise.com, registered 2016-09-26 (10 years)15/15
  • Endpoint on the vendor's domainapi.lokalise.com15/15
  • Terms of serviceread, states 7 of the 7 things a reader expects, and has 1 clause that costs points8/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagestatus.lokalise.com10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service dated 2025-11-01, states 7 of 7, 2 to know

TL;DR Dated 2025-11-01. States all 7 things a reader expects. To know before relying on it, limits on benchmarking and cut-off without notice or for any reason.

Restricts benchmarking or competitive usecosts points
(c) use or access the Platform or Services for the purpose of developing, offering, or operating any website, platform, large-scale language model, product, or service that is competitive with Lokalise, or for benchmarking or competitive analysis;

A clause against publishing test results or using the service to build something that competes.

Says access can be ended without notice or for any reason
Lokalise may, without prior notice and at its sole discretion, suspend the Services or block access to the Platform, without prejudice to any other remedies available under applicable law.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Gives the date it was last updated Last updated 2025-11-01
Last Updated: November 2025

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of Delaware
…performance, or breach (a “Dispute”), shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of laws principles.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at the fees paid in the 12 months before the claim
Each party’s total aggregate liability for all claims arising out of or relating to this Agreement, whether in contract, tort, or otherwise, shall not exceed the total Fees paid by the Customer to Lokalise during the twelve (12) months immediately preceding the date of the event giving rise to the claim.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
…Users have engaged in any Prohibited Activities or otherwise violated this Section 5, Lokalise may, without prior notice and at its sole discretion, suspend the Services or block access to the Platform, without prejudice to any other remedies available under applicable law.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives thirty days of notice before a change
Unless the Customer objects in writing within thirty (30) days of such notice, the amended terms shall be deemed accepted and effective as of the date specified in the notice.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
The Customer shall not be entitled to refunds or credits for any reduction or non-use of the Platform’s functionality or service capacity during the Subscription Term.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
The Agreement includes and incorporates by reference the following additional annexes: Annex B – Service Level Agreement (SLA) and Annex C – AI Addendum.

Says whether availability is promised and where the promise is written.

Annual and multi-year plans renew automatically unless either party gives notice of non-renewal at least 90 days before the renewal date.
Annual and multi-year Plans along with Add-ons and Bundles shall automatically renew on the following day of the last day of the Term (“Renewal Date”), unless either Party provides written or in Platform notice of non-renewal at least ninety (90) days prior to the Renewal Date.

Noted by a second reader on 2026-10-08.

Lokalise may use the customer's name and logo for marketing unless the customer opts out in writing.
The Customer agrees that Lokalise may use the Customer’s name and logo for marketing purposes and free trial references unless the Customer opts out by providing written notice.

Noted by a second reader on 2026-10-08.

Lokalise may permanently delete the data of an inactive or suspended account after 30 days of inactivity.
Lokalise reserves the right to permanently delete inactive or suspended account data after thirty (30) days of inactivity, subject to applicable laws and retention obligations.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 10,126 words

Privacy policy dated 2026-03-01, states 8 of 8, 1 to know

TL;DR Dated 2026-03-01. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.

Says it sells personal data or shares it for advertising
These services may involve sharing limited identifiers (such as hashed email addresses or similar identifiers) with advertising partners in order to measure campaign performance and deliver targeted advertising to business audiences.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2026-03-01
Last Updated: March 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
We may collect information from visitors to and/or users of our Platform (collectively, “Users” or “you”).

The basic statement a privacy policy exists to make.

Says how long data is kept
We will process and store the User Data no longer than necessary.

Says when data sent to the service is deleted.

Says who else receives the data
We may transfer your Personal Data without de-identification or anonymization to our partners and service providers if it’s needed to improve our Services and Platform in case you have consented to this.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
In connection with any personal information we may sell or disclose to a third party for a business purpose, you have the right to know (i) the categories of personal information about you that we sold and the categories of third parties to whom the personal information was sold;

A plain statement either way.

Says what rights people have over their data
This policy describes how we use Personal Data (as defined below) when you browse our Website, visit or use our Platform (including our Website and Services), with whom we share it, your rights and choices, and how you can contact us about our privacy practices.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@lokalise.com
If you have any questions about the lawful basis upon which we collect and use your personal data, please feel free to contact our Data Protection Officer at: privacy@lokalise.com.

An address or officer to send a request to.

Says where data is transferred or stored Relies on the Data Privacy Framework
To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

The countries data goes to and the safeguard used.

Personal or confidential information typed into a free-text AI chat message or prompt may be sent to the LLM provider.
However, if a user voluntarily includes personal data, sensitive information, or other confidential information in a free-text chat message or prompt, that content may be transmitted to the relevant LLM provider as part of the request in order to provide the AI feature.

Noted by a second reader on 2026-10-08.

Lokalise says it does not train general-purpose AI models on data submitted through its AI tools unless this is disclosed and authorised by the customer or user.
We do not use Customer Data or Personal Data submitted through these features to train general-purpose AI models, except as expressly disclosed otherwise and authorised by the Customer or user.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 9,079 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Master Service Agreement (last updated November 2025) names Lokalise, Inc., a Delaware company at 3500 South DuPont Highway, Suite BZ-101, Dover, DE 19901. It governs paid subscriptions.

Trial and individual users fall under the User and Trial Access Terms of Service at https://lokalise.com/terms-of-service/ (November 2025). API integrations published in the app library fall under the Developer Program Agreement at https://lokalise.com/dev-hub-terms/, which shows no date.

The privacy policy (last updated March 2026) covers the website, platform and services, and says Lokalise is the processor for customer data.

The API answers at api.lokalise.com and the MCP server at mcp.lokalise.com.

https://lokalise.com/.well-known/security.txt gives vdp.lokalise.com and security@lokalise.com as contacts and expires on 20 August 2027.

RDAP for lokalise.com gives a registration date of 2016-09-26.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 21:12 UTC

Right nowUpHTTP 404 · 88 ms · under a minute ago
Uptime 24h100.0%21 probes
Uptime 30 days100.0%21 probes
p50 24h91 msget
p95 24h137 msopen endpoint

Probed every five minutes at https://api.lokalise.com/api2. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 6 minutes ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/lokalise.json

Notable

  • The REST API's three OpenAPI 3.0.3 files are linked from the reference introduction, and the default-projects file has 63 paths and 109 operations source
  • Rate limits are 6 requests a second per token and per IP and 10 concurrent requests per project, answered with 429 source
  • The hosted MCP server has two endpoints, https://mcp.lokalise.com/mcp/project-management and https://mcp.lokalise.com/mcp/software-development, and the help centre article labels it beta source
  • The changelog entry of 23 September 2026 says the MCP server is available on all plans source
  • Automatic translation tasks run on Lokalise AI, DeepL or Google through task_type: automatic_translation and translation_engine source
  • The Master Service Agreement, last updated November 2025, commits to 99.5 per cent monthly uptime and forbids use for benchmarking or competitive analysis source
  • status.lokalise.com lists two incidents in the 90 days to 8 October 2026, a 42-minute search outage on 17 August and three hours of partial email delivery failures on 14 September source
  • The AI statement, updated September 2026, says customer content can train Lokalise's own models such as AI Scoring where the customer consents through the AI Addendum, and is not shared with LLM providers for their training source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.8
Graded on the REST API with the hosted lines. Statuspage site at status.lokalise.com with five components and history back to 2022 (20). Two incidents in the 90 days to 8 October 2026, a 42-minute search outage on 17 August marked critical and three hours of partial email delivery failures on 14 September marked major, neither an hour of the core API down (20 of 30). Limits published as 6 requests a second per token and per IP and 10 concurrent requests per project (15). 429 is documented with advice to back off exponentially, and responses carry X-RateLimit-* headers, but no Retry-After is documented and writes take no idempotency key (9 of 15). The Master Service Agreement commits to 99.5 per cent a month with service credits (10). The REST API is generally available, while the MCP server is in beta (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 12.3
Three public OpenAPI 3.0.3 files, the default-projects one with 63 paths and 109 operations (25). llms.txt with about 160 reference links and a Markdown twin of each page (10). Every operation has a description that names the admin right and OAuth scope it needs and which project types it works on, with little on when not to call it (14 of 20). 65 enums and required fields marked, but boolean flags are numbers 0 and 1 and many filters are comma-separated strings (9 of 15). 213 examples, but 108 of 109 operations document only the 200 response and the error list is one general page (8 of 15). The path is versioned at /api2 and there is a dated API changelog, whose newest entry is 29 May 2025 while later API changes appear only in the product changelog (10 of 15).
Agent ergonomics 13%16.2 11.2
API reading of the checklist. include_translations, include_comments and similar flags and a limit size the responses, and the MCP server splits its tools into two toolkits of 22 and 16 documented actions (18 of 25). Page and cursor paging with X-Pagination-* headers and filters by tag, file name, platform and untranslated state (20). Errors carry a code and a message, and bulk calls return an error per failed item, but messages are short and codes are HTTP statuses only (13 of 20). No idempotency key was found in the OpenAPI files, and we could not read the MCP tool annotations without an account. File imports return a process to poll (4 of 20). Few required fields (one on a task, three on an upload) and official clients for Node, Python, Ruby and PHP plus a CLI written in Go (14 of 15).
Security & auth 14%17.5 12.8
OAuth 2 with read and write scopes per resource, and personal API tokens that are read-only or read/write and revocable. Tokens never expire and carry all of the creating user's access, and the MCP server adds PKCE and dynamic client registration (26 of 30). Read-only tokens, scopes and role-based project permissions limit access, but no confirmation step was found for calls such as emptying a project (13 of 20). The API returns strings written by translators and contributors, and no guidance on untrusted content was found in the reviewed documentation (3 of 15). GET /v1/audit-logs returns team audit events in OCSF 1.3.0, and the security page says logs are kept 12 months (13 of 15). security.txt valid to 20 August 2027, a disclosure policy at vdp.lokalise.com, a private bug bounty on YesWeHack, SOC 2 Type II, ISO 27001 and ISO 27017 per the security page (18 of 20).
Payments & pricing 10%12.5 3.8
No x402, MPP or L402 (0). Plan prices are public at $149, $379 and $1,049 a month billed yearly, with no per-unit price for processed words on the page we read, so plan-only credit (10). A 14-day trial with no card (20). A person signs up in a browser, and the MCP server's dynamic client registration still ends in a Lokalise account login (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.3
python-lokalise-api 4.3.0 on 5 October 2026, @lokalise/node-api 16.6.0 on 21 September and a product changelog entry on 1 October (30). Seven Node SDK releases and twelve changelog entries since 6 July (20). Public changelog and 24/7 support listed on the pricing page. The Node SDK has 1 open issue, while the CLI has 62 open issues and pull requests and went from May 2025 to July 2026 without a release (11 of 15). Official SDKs are current (15). The Node SDK runs CI on GitHub Actions and needs Node 22.19 or later, and the CLI builds with GoReleaser (8 of 10).
Transparency & trusteditorial 63, provenance 98 7%8.8 7.1
Closed service with a published Master Service Agreement, and the CLI and SDKs under BSD 3-Clause (15). Privacy policy of March 2026, a DPA dated 21 March 2023, an AI statement and a sub-processor list. The agreement deletes inactive account data after 30 days. The privacy policy says customer data doesn't train general-purpose models, and the AI statement says it can train Lokalise's own models with consent. We did not read the DPA PDF (22 of 30). No deprecation policy found. The API changelog carries dated notices from 2021 and 2022, and the Developer Program Agreement allows changes to API access with or without notice (6 of 20). Sub-processors listed with purpose and location, updated 1 August 2026, and customer data hosted on AWS in EU regions (20).
Negative events≤15None recorded0
Total71.3 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 16 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Lokalise, or have the agent fetch /fixes/lokalise.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Lokalise

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/lokalise, the October 2026 research run, assessed 8 October 2026. Grade BB, 71.3 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Lokalise: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total

Why it scored 30: No x402, MPP or L402 (0). Plan prices are public at $149, $379 and $1,049 a month billed yearly, with no per-unit price for processed words on the page we read, so plan-only credit (10). A 14-day trial with no card (20). A person signs up in a browser, and the MCP server's dynamic client registration still ends in a Lokalise account login (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Agent ergonomics, 69 out of 100, up to 5 more on the total

Why it scored 69: API reading of the checklist. `include_translations`, `include_comments` and similar flags and a `limit` size the responses, and the MCP server splits its tools into two toolkits of 22 and 16 documented actions (18 of 25). Page and cursor paging with `X-Pagination-*` headers and filters by tag, file name, platform and untranslated state (20). Errors carry a code and a message, and bulk calls return an error per failed item, but messages are short and codes are HTTP statuses only (13 of 20). No idempotency key was found in the OpenAPI files, and we could not read the MCP tool annotations without an account. File imports return a process to poll (4 of 20). Few required fields (one on a task, three on an upload) and official clients for Node, Python, Ruby and PHP plus a CLI written in Go (14 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 3. Security & auth, 73 out of 100, up to 4.7 more on the total

Why it scored 73: OAuth 2 with read and write scopes per resource, and personal API tokens that are read-only or read/write and revocable. Tokens never expire and carry all of the creating user's access, and the MCP server adds PKCE and dynamic client registration (26 of 30). Read-only tokens, scopes and role-based project permissions limit access, but no confirmation step was found for calls such as emptying a project (13 of 20). The API returns strings written by translators and contributors, and no guidance on untrusted content was found in the reviewed documentation (3 of 15). `GET /v1/audit-logs` returns team audit events in OCSF 1.3.0, and the security page says logs are kept 12 months (13 of 15). security.txt valid to 20 August 2027, a disclosure policy at vdp.lokalise.com, a private bug bounty on YesWeHack, SOC 2 Type II, ISO 27001 and ISO 27017 per the security page (18 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 4. Schema & documentation, 76 out of 100, up to 3.9 more on the total

Why it scored 76: Three public OpenAPI 3.0.3 files, the default-projects one with 63 paths and 109 operations (25). llms.txt with about 160 reference links and a Markdown twin of each page (10). Every operation has a description that names the admin right and OAuth scope it needs and which project types it works on, with little on when not to call it (14 of 20). 65 enums and required fields marked, but boolean flags are numbers 0 and 1 and many filters are comma-separated strings (9 of 15). 213 examples, but 108 of 109 operations document only the 200 response and the error list is one general page (8 of 15). The path is versioned at `/api2` and there is a dated API changelog, whose newest entry is 29 May 2025 while later API changes appear only in the product changelog (10 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 5. Reliability, 84 out of 100, up to 3.2 more on the total

Why it scored 84: Graded on the REST API with the hosted lines. Statuspage site at status.lokalise.com with five components and history back to 2022 (20). Two incidents in the 90 days to 8 October 2026, a 42-minute search outage on 17 August marked critical and three hours of partial email delivery failures on 14 September marked major, neither an hour of the core API down (20 of 30). Limits published as 6 requests a second per token and per IP and 10 concurrent requests per project (15). 429 is documented with advice to back off exponentially, and responses carry `X-RateLimit-*` headers, but no Retry-After is documented and writes take no idempotency key (9 of 15). The Master Service Agreement commits to 99.5 per cent a month with service credits (10). The REST API is generally available, while the MCP server is in beta (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 6. Transparency & trust, 81 out of 100, up to 1.7 more on the total

Made of editorial 63, provenance 98.

Why it scored 81: Closed service with a published Master Service Agreement, and the CLI and SDKs under BSD 3-Clause (15). Privacy policy of March 2026, a DPA dated 21 March 2023, an AI statement and a sub-processor list. The agreement deletes inactive account data after 30 days. The privacy policy says customer data doesn't train general-purpose models, and the AI statement says it can train Lokalise's own models with consent. We did not read the DPA PDF (22 of 30). No deprecation policy found. The API changelog carries dated notices from 2021 and 2022, and the Developer Program Agreement allows changes to API access with or without notice (6 of 20). Sub-processors listed with purpose and location, updated 1 August 2026, and customer data hosted on AWS in EU regions (20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 7 of the 7 things a reader expects, and has 1 clause that costs points (8 of 10)

## 7. Maintenance & community, 84 out of 100, up to 1.4 more on the total

Why it scored 84: `python-lokalise-api` 4.3.0 on 5 October 2026, `@lokalise/node-api` 16.6.0 on 21 September and a product changelog entry on 1 October (30). Seven Node SDK releases and twelve changelog entries since 6 July (20). Public changelog and 24/7 support listed on the pricing page. The Node SDK has 1 open issue, while the CLI has 62 open issues and pull requests and went from May 2025 to July 2026 without a release (11 of 15). Official SDKs are current (15). The Node SDK runs CI on GitHub Actions and needs Node 22.19 or later, and the CLI builds with GoReleaser (8 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the MCP server's tool definitions and annotations, which need a Lokalise account to list. The counts of 22 and 16 come from the help centre table of actions.
- unchecked: plan allowances (processed words, seats, projects) and monthly-billing prices, which the pricing page draws by script.
- unchecked: the DPA PDF and Annex B of the Master Service Agreement (service credits), which we did not read.
- unchecked: the AI sub-processor list at lokalise.com/ai-subprocessor-list and its retention periods.
- Which plans include API access is not stated on the pages we read. The MCP article says teams on a plan with API access, and the changelog of 23 September 2026 says the MCP server is available on all plans.
- The lead's category is machine translation. Lokalise is a translation management system that runs AI and machine translation as tasks, so it sits in this category as the nearest fit, with no synchronous translate call.
- The Master Service Agreement forbids benchmarking or competitive analysis, which matters before our probes run. Recorded as a fact, with no deduction.
- The help centre calls the MCP server beta, while the product page shows no beta label.

## Weaknesses

- The Master Service Agreement forbids using the service for benchmarking or competitive analysis
- No free plan. Explorer is $149 a month billed yearly after a 14-day trial without a card
- No idempotency keys in the OpenAPI files, though the errors page mentions an idempotent key under 409
- API tokens never expire and carry every permission of the user who made them
- The Developer Program Agreement lets Lokalise change or end API access with or without notice
- The MCP server is labelled beta in the help centre article

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send the token in the `X-Api-Token` header to `https://api.lokalise.com/api2`. OAuth access tokens go in `Authorization: Bearer` and expire after about 60 minutes.
- Stay under 6 requests a second per token and 10 concurrent requests per project. On 429, back off exponentially and read `X-RateLimit-Reset`.
- Use a read-only token for reads. A read/write token can call `PUT /projects/{project_id}/empty`, which deletes every key and translation.
- Use `pagination=cursor` on `/keys` and `/translations`, with `limit` at most 500 on keys, and follow `X-Pagination-Next-Cursor`.
- Projects above 10,000 key-language pairs need `/files/async-download`. Poll `/processes/{process_id}` for the bundle URL, and do the same after `/files/upload`.

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the MCP server's tool definitions and annotations, which need a Lokalise account to list. The counts of 22 and 16 come from the help centre table of actions.
  • unchecked: plan allowances (processed words, seats, projects) and monthly-billing prices, which the pricing page draws by script.
  • unchecked: the DPA PDF and Annex B of the Master Service Agreement (service credits), which we did not read.
  • unchecked: the AI sub-processor list at lokalise.com/ai-subprocessor-list and its retention periods.
  • Which plans include API access is not stated on the pages we read. The MCP article says teams on a plan with API access, and the changelog of 23 September 2026 says the MCP server is available on all plans.
  • The lead's category is machine translation. Lokalise is a translation management system that runs AI and machine translation as tasks, so it sits in this category as the nearest fit, with no synchronous translate call.
  • The Master Service Agreement forbids benchmarking or competitive analysis, which matters before our probes run. Recorded as a fact, with no deduction.
  • The help centre calls the MCP server beta, while the product page shows no beta label.

Sources 28

  1. docs index for agents developers.lokalise.com · seen 2026-10-08
  2. API introduction and OpenAPI links developers.lokalise.com · seen 2026-10-08
  3. OpenAPI file, default projects developers.lokalise.com · seen 2026-10-08
  4. authentication developers.lokalise.com · seen 2026-10-08
  5. rate limits developers.lokalise.com · seen 2026-10-08
  6. errors developers.lokalise.com · seen 2026-10-08
  7. pagination developers.lokalise.com · seen 2026-10-08
  8. API changelog developers.lokalise.com · seen 2026-10-08
  9. audit logs endpoint developers.lokalise.com · seen 2026-10-08
  10. MCP server setup article docs.lokalise.com · seen 2026-10-08
  11. MCP OAuth metadata mcp.lokalise.com · seen 2026-10-08
  12. API tokens article docs.lokalise.com · seen 2026-10-08
  13. pricing lokalise.com · seen 2026-10-08
  14. product changelog lokalise.com · seen 2026-10-08
  15. status incidents status.lokalise.com · seen 2026-10-08
  16. Master Service Agreement lokalise.com · seen 2026-10-08
  17. User and Trial Access Terms of Service lokalise.com · seen 2026-10-08
  18. Developer Program Agreement lokalise.com · seen 2026-10-08
  19. privacy policy lokalise.com · seen 2026-10-08
  20. DPA page lokalise.com · seen 2026-10-08
  21. AI statement lokalise.com · seen 2026-10-08
  22. sub-processors lokalise.com · seen 2026-10-08
  23. security page lokalise.com · seen 2026-10-08
  24. security.txt lokalise.com · seen 2026-10-08
  25. CLI repository github.com · seen 2026-10-08
  26. Node SDK repository github.com · seen 2026-10-08
  27. npm registry registry.npmjs.org · seen 2026-10-08
  28. PyPI pypi.org · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid $149 / mo Explorer $149, Growth $379 and Advanced $1,049 a month billed yearly, Enterprise by quote. Monthly-billing prices load only in a browser and were not read. Every plan starts with a 14-day trial with no card, so an agent can start without a contract. There is no free plan except for open-source non-profit projects on request. The MCP article says API access depends on the plan, and the page did not show which plans include it (checked 2026-10-08).

Prices

ItemPriceUnitNote
Explorer$149per month (plan)billed yearly
Growth$379per month (plan)billed yearly
Advanced$1049per month (plan)billed yearly

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/lokalise.xml, or this listing's score history at history.json.

Connect

Install

brew tap lokalise/cli-2
brew install lokalise2

First request

curl "https://api.lokalise.com/api2/projects?limit=5" -H "X-Api-Token: $LOKALISE_API_TOKEN"

Claude Code

claude mcp add lokalise_pm --transport http https://mcp.lokalise.com/mcp/project-management

MCP client configuration

{
  "lokalise_pm": {
    "url": "https://mcp.lokalise.com/mcp/project-management"
  },
  "lokalise_sd": {
    "url": "https://mcp.lokalise.com/mcp/software-development"
  }
}

Through letme picks today, calling later

GET https://letme.dev/lokalise

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Azure Translator Microsoft AzureBB72translate.text translate.documents translate.glossaryno
DeepL API DeepLBB72translate.text translate.documents translate.glossaryno
Crowdin Crowdin OÜB69.6translate.text translate.documents translate.glossaryno
Amazon Translate Amazon Web ServicesB69.5translate.text translate.documents translate.glossaryno
Google Cloud Translation Google CloudB68.1translate.text translate.documents translate.glossaryno
Phrase Phrase a.s.B64.2translate.text translate.documents translate.glossaryno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Lokalise on Anchor Terminal, BB, 71.3/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/lokalise"><img src="https://www.anchorterminal.com/badges/lokalise.svg" alt="Lokalise on Anchor Terminal" height="20"></a>
    [![Lokalise on Anchor Terminal](https://www.anchorterminal.com/badges/lokalise.svg)](https://www.anchorterminal.com/tools/lokalise)

    It counts on a page on lokalise.com or one of its subdomains, or the README of github.com/lokalise/lokalise-cli-2-go.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "lokalise", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.