# MagicBell > MagicBell is a hosted notification service that sends one broadcast to users across an in-app inbox, mobile and web push, email, SMS, Slack and Teams. Agents reach it through a REST API, a CLI and typed clients. - Canonical: https://www.anchorterminal.com/tools/magicbell - Markdown: https://www.anchorterminal.com/tools/magicbell.md (~6,550 tokens) - Slim: https://www.anchorterminal.com/tools/magicbell.min.md (~1,580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/magicbell.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 58.8/100 · rank #515 of 842 · #9 in Notifications · not agent-ready · confidence medium** ## Assessment A public OpenAPI 3.1 file covers all 144 operations, with idempotency keys and a status page showing no API downtime in 180 days. No batching or digest step, llms.txt, error code list, SLA or sub-processor list was found, and project tokens carry no scopes. ## Facts | Field | Value | | --- | --- | | Vendor | MagicBell, Inc. (https://www.magicbell.com) | | Kind | HTTP API | | Category | Notifications (https://www.anchorterminal.com/categories/notifications) | | Transport | HTTP | | Endpoint | `https://api.magicbell.com/v2` | | Auth | API key · Self-serve. Every call takes a JWT as a Bearer token. A Project JWT is created in the dashboard under Project Auth with a name and an expiry, is shown once and can be discarded. It covers the whole project (broadcasts, users, integrations, workflows, events). A User JWT is signed by the customer's backend with HS256 from the project's API key and secret key, and covers one user's inbox, channel tokens and preferences. No scopes on either. | | Pricing | Freemium ($249 / mo) · Builder is $0 a month with 1,000 deliveries and one project, so an agent's owner can start without a contract. Startup is $249 a month with 50,000 deliveries and five projects, then $0.0025 a delivery and $99 a month per extra project. Enterprise is custom. A delivery is one notification on one channel for one user. Whether sign-up asks for a card was not checked (https://www.magicbell.com/pricing, checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-09). | | Licence | Proprietary service under MagicBell's terms. The Go client and the CLI are MIT. The JavaScript client carries MagicBell's own Licence Agreement | | Packages | npm: `magicbell-js`; npm: `magicbell-cli`; go: `github.com/magicbell/magicbell-go` | | Source | https://github.com/magicbell/magicbell-js | | Docs | https://www.magicbell.com/docs | | llms.txt | not found | | Last release | 2026-07-29 | | GitHub stars | 31 (as of 2026-10-09) | | npm downloads / week | 48,674 | | API | REST, version v2 at https://api.magicbell.com/v2. OpenAPI 3.1 with 144 operations. v1 is deprecated | | Channels | In-app inbox, mobile push (APNs, FCM, Expo), web push, email (Mailgun, SendGrid, Amazon SES, SMTP, Ping Email), SMS (Twilio), Slack and Teams | | Credentials | Project JWT from the dashboard, with a name and expiry, discardable. User JWT signed with HS256 by the customer's backend. No scopes | | Rate limits | 500 requests a minute per IP address. A 429 blocks the address for 60 seconds | | Idempotency | `Idempotency-Key` header on some endpoints, first response cached for 24 hours | | Pagination | Cursor based, `limit` (default 50), `starting_after` and `ending_before` | | Preferences | Per-user channel preferences by category at `/v2/channels/user_preferences`, and a delivery plan of ordered channel steps with delays and conditions | | Workflows | Commands broadcast, wait, pause and abort, with conditions and template variables. No batching or digest command found | | Clients | magicbell-js 1.8.0 (29 July 2026), magicbell-go v0.5.0 (24 March 2026), Swift and Java user clients, magicbell-cli 1.4.0 (8 January 2026), and React, Preact, Svelte and web components | | Free tier | Builder, $0, 1,000 deliveries a month, one project | | Billing unit | One delivery is one notification on one channel for one user | | Status | status.magicbell.com on Better Stack. Components are API, Dashboard, In-App Delivery (through Ably) and Email Delivery | | Capabilities | notify.push, notify.in-app, notify.multichannel, notify.preferences | | Tags | hosted, freemium, openapi, typescript, go, swift, java, cli, webhooks, status-page | | JSON | https://www.anchorterminal.com/api/v1/tools/magicbell.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 75 | 15.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 68 | 11.1 | | Agent ergonomics | 13% | 16.2 | 63 | 10.2 | | Security & auth | 14% | 17.5 | 50 | 8.8 | | Payments & pricing | 10% | 12.5 | 35 | 4.4 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 49 | 4.3 | | Transparency & trust (editorial 30, provenance 86) | 7% | 8.8 | 58 | 5.1 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **58.8 → C** | ### Why each score - Reliability 75: Graded as a hosted API. Status page on Better Stack at status.magicbell.com with four components and daily history (20). In the 90 days to 9 October 2026 the API and dashboard show no downtime. In-app delivery shows about 10 minutes on 13 July, 11 minutes on 31 July and 39 minutes on 26 August, and email delivery 39 minutes on 26 August, with no incident write-up in the feed (20). The limit is published as 500 requests a minute per IP address (15). A 429 is documented with a 60-second block, and an `Idempotency-Key` header caches the first response for 24 hours on some endpoints, but no Retry-After header or backoff guidance was found (10). No SLA found on the pricing page or in the terms (0). API v2 is the current version (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 68: OpenAPI 3.1 file at /docs/api/openapi.json with 84 paths and 144 operations (25). /llms.txt returns 404 and no Markdown docs were found (0). Every operation has a description that states its purpose, many of them templated across the 16 integration types, and none says when not to use it (10). Required fields, patterns, length limits and ten enums are present and unknown query parameters are refused, but `custom_attributes` and workflow `input` are free-form objects and the file declares no security schemes (11). 88 schema examples, but only 200, 201 and 204 responses are described, and the docs show one error example with no list of codes (7). The path carries the version, v1 is marked deprecated and the changelog is public on GitHub Discussions (15). - Agent ergonomics 63: List endpoints take `limit` (default 50) and there is no field selection (12). Cursor pagination with `starting_after` and `ending_before` on 21 endpoints, and notifications filter by status, category and topic (14). Errors return an array of `code` and `message` pairs, with no published list of codes (8). `Idempotency-Key` holds for 24 hours on some endpoints, which the docs don't name, and saves are PUT upserts (14). A broadcast needs only `title` and `recipients`, and official clients exist for JavaScript, Go, Swift and Java, with a CLI (15). - Security & auth 50: Two credentials. A Project JWT is created in the dashboard with a name and an expiry, is shown once and can be discarded. A User JWT is signed by the customer's backend with HS256 and limits calls to one user. Project tokens carry no scopes (22). The User JWT confines a client to one user's inbox, but no read-only project token or confirmation for deletes was found, and `DELETE /users/{user_id}` removes a user and all associated data (6). Responses carry the project's own notifications plus event payloads from connected sources such as Stripe and GitHub, with no guidance on untrusted content (8). An events feed in the API and dashboard records deliveries with the HTTP request and response. No audit log of token or admin actions was found (8). The Trust Centre states GDPR compliance, AES-256 encryption and penetration testing. No SOC 2 or ISO 27001 statement, bug bounty or security.txt was found, and vulnerability reports go through a contact form (6). - Payments & pricing 35: No x402, MPP or L402 (0). Plans and a unit price are public. Builder is $0 for 1,000 deliveries a month, Startup $249 for 50,000 and $0.0025 for each further delivery (20). The $0 plan needs only a sign-up, but the pricing page doesn't say whether a card is asked for and we did not create an account (15). A person signs up in a browser and creates the token in the dashboard, and the terms forbid accounts registered by automated methods (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 49: The last release is magicbell-js 1.8.0 on 29 July 2026, with a changelog entry the same day, 72 days before this check (20). One release or dated changelog entry since 11 July 2026 (0). A public changelog, GitHub Discussions and a Slack community exist. We did not test how fast questions are answered (8). Official clients are published for JavaScript (1.8.0, July 2026), Go (v0.5.0, March 2026), Swift and Java, and the CLI's last npm release is 1.4.0 of 8 January 2026 (13). The JavaScript repository runs test, lint and release workflows and took automated dependency updates up to 3 August 2026 (8). - Transparency & trust 58: Closed service under published terms. The Go client and the CLI are MIT, and the JavaScript client carries MagicBell's own Licence Agreement, which bars benchmarking the software (15). The privacy policy of 2 July 2024 covers visitors and account holders, gives no retention period beyond the time necessary, and does not address notification content or recipients. The Trust Centre says data is never sold or shared with third parties, while the policy marks account data as sold or shared with Google, X, Segment and Mixpanel. The Trust Centre mentions data processing agreements and none is published (6). API v1 and the old `@magicbell/cli` package are marked deprecated, with no policy or dates (5). The status page names Ably for in-app delivery and the policy names four analytics services with their countries. No sub-processor list or hosting region for the service was found (4). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/magicbell.md (JSON https://www.anchorterminal.com/fixes/magicbell.json) ### What we couldn't check - unchecked: live error bodies and response headers, because api.magicbell.com/robots.txt disallows every path and no request was sent to the API - unchecked: whether sign-up for the Builder plan asks for a card, since we did not create an account - Which endpoints honour `Idempotency-Key`. The docs say some and name only notification creation as an example - Whether a 429 carries a Retry-After header. The docs state only a 60-second block - Whether a data processing agreement or sub-processor list exists. The Trust Centre mentions agreements and links none - unchecked: the body of the 29 July 2026 changelog entry, which the page did not show our reader, and whether community questions get answers - The status history is in two-day buckets, so the downtime dates are the start of each bucket ### Sources - pricing: (seen 2026-10-09) - REST API overview, rate limit, errors and idempotency: (seen 2026-10-09) - OpenAPI 3.1 description: (seen 2026-10-09) - API authentication: (seen 2026-10-09) - Project JWT: (seen 2026-10-09) - User JWT: (seen 2026-10-09) - CLI docs: (seen 2026-10-09) - workflows page: (seen 2026-10-09) - events: (seen 2026-10-09) - terms and conditions: (seen 2026-10-09) - privacy policy: (seen 2026-10-09) - Trust Centre: (seen 2026-10-09) - status page and its JSON feed: (seen 2026-10-09) - changelog on GitHub Discussions: (seen 2026-10-09) - JavaScript client repository, tags, changelog and licence: (seen 2026-10-09) - Go client repository and changelog: (seen 2026-10-09) - npm registry, magicbell-js: (seen 2026-10-09) - npm registry, magicbell-cli: (seen 2026-10-09) - domain registration (RDAP): (seen 2026-10-09) ## Who's behind it (provenance 86/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | MagicBell, Inc. | 20/20 | | Domain age | magicbell.com, registered 2004-04-17 (22 years) | 15/15 | | Endpoint on the vendor's domain | api.magicbell.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | status.magicbell.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The terms and the privacy policy name MagicBell, Inc., 2261 Market Street #4311, San Francisco, California 94114. Both are dated 2 July 2024. The terms cover the website, the service and the API in one document, with a short section of API usage terms. They are governed by the law of the place where the owner is based. www.magicbell.com/.well-known/security.txt returns 404. The footer's vulnerability disclosure link is a contact form. RDAP for magicbell.com gives a registration date of 2004-04-17. The changelog is a category of GitHub Discussions, reached from magicbell.to/changelog. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.magicbell.com/terms-and-conditions), read 2026-10-08, gives no date, states 6 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Accounts registered by bots or any other automated methods are not permitted." - To know. Says access can be ended without notice or for any reason. "The Owner reserves the right, at its sole discretion, to suspend or delete at any time and without notice, User accounts that it deems inappropriate, offensive or in violation of these Terms." - Not found in the text. Gives the date it was last updated. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Says how changes to the terms are announced. Says it gives notice of a change. - Also in the text (2026-10-08). MagicBell accepts no liability for damages or losses from use of the API or of third-party products that access data through the API. "the User expressly understands and agrees that the Owner bears no responsibility and shall not be held liable for any damages or losses resulting from the User’s use of the API or their use of any third-party products/services that access data through the API." - Also in the text (2026-10-08). Subscriptions renew automatically through the payment method chosen at purchase. "Subscriptions are automatically renewed through the payment method that the User chose during purchase." - Also in the text (2026-10-08). A user cannot terminate an account until the paid subscription period has expired. "However, termination of the account will not be possible until the subscription period paid for by the User has expired." **Privacy policy** (https://www.magicbell.com/privacy-policy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "Google may use the Data collected to contextualize and personalize the ads of its own advertising network." - Not found in the text. Gives the date it was last updated. - Says how long data is kept. For as long as needed, with no period named. ## Live (updated 2026-10-09 10:14 UTC) - Right now: up, HTTP 405, 61 ms, checked 2026-10-09 10:14 UTC (get on `https://api.magicbell.com/v2`) - Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 72 ms · p95 108 ms - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/magicbell.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Startup | $249 | per month (plan) | 50,000 deliveries and five projects included | | Startup overage, per delivery | $0.0025 | per message | | | Additional project | $99 | per month (plan) | | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - OpenAPI 3.1 file with 144 operations, published at `/docs/api/openapi.json` without a login - `Idempotency-Key` header caches the first response for 24 hours on some endpoints - Status page shows 100 per cent for the API and dashboard over 180 days to 7 October 2026 - Project tokens are named, take an expiry and can be discarded in the dashboard - Builder plan at $0 with 1,000 deliveries a month, and overage on Startup at $0.0025 a delivery ## Weaknesses - No batching or digest step found. Workflows have four commands (broadcast, wait, pause, abort) - No llms.txt or Markdown docs, and the OpenAPI file documents no error responses - Project tokens are project-wide with no scopes or read-only mode - No SLA, SOC 2 or ISO 27001 statement, security.txt or sub-processor list found - The Trust Centre says data is never sold or shared, while the privacy policy of 2 July 2024 marks account data as sold or shared ## Before you call it (notes for agents) 1. Ask the owner for a Project JWT from the dashboard's Project Auth page. The terms forbid accounts registered by automated methods 2. Send `Idempotency-Key` with a UUID on `POST /v2/broadcasts`, and reuse it on a retry within 24 hours 3. Stay under 500 requests a minute per IP. A 429 blocks the address for 60 seconds, so put many recipients in one broadcast 4. Use a Project JWT for broadcasts, users, integrations and workflows, and a User JWT for one user's inbox, tokens and preferences 5. Read delivery failures from `GET /v2/events` and the broadcast's `status`, since email, SMS and push go through providers the owner connects ## Connect Install: ```bash npm install magicbell-js ``` First request: ```bash curl --request POST \ --url 'https://api.magicbell.com/v2/broadcasts' \ --header 'content-type: application/json' \ --header "authorization: Bearer $TOKEN" \ --data '{"title":"Build finished","recipients":[{"email":"test@example.com"}]}' ``` Through letme (picks today, calling later): https://letme.dev/magicbell. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | SuprSend | BB | 72.6 | 99 | notify.push, notify.in-app, notify.multichannel, notify.preferences | no | https://www.anchorterminal.com/tools/suprsend.md | | Courier | BB | 70.5 | 146 | notify.push, notify.in-app, notify.multichannel, notify.preferences | no | https://www.anchorterminal.com/tools/courier.md | | Knock | B | 66.5 | 265 | notify.push, notify.in-app, notify.multichannel, notify.preferences | no | https://www.anchorterminal.com/tools/knock.md | | Novu | B | 64.2 | 322 | notify.push, notify.in-app, notify.multichannel, notify.preferences | no | https://www.anchorterminal.com/tools/novu.md | | OneSignal | B | 69.3 | 180 | notify.push, notify.in-app, notify.multichannel | no | https://www.anchorterminal.com/tools/onesignal.md | | Customer.io | BB | 74.5 | 68 | notify.push, notify.in-app | no | https://www.anchorterminal.com/tools/customer-io.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The OpenAPI 3.1 file lists 144 operations on 84 paths, 89 for a Project JWT and 55 for a User JWT, marked by `x-magicbell-auth-jwt-type` (source: ) - The rate limit is 500 requests a minute per IP address, and a 429 blocks the address for 60 seconds (source: ) - An `Idempotency-Key` header caches the first response's status and body for 24 hours on some endpoints (source: ) - api.magicbell.com/robots.txt disallows every path, so we sent the API no request and read its behaviour from the docs only - The terms say accounts registered by bots or other automated methods are not permitted (source: ) - The JavaScript client's Licence Agreement bars using the software for comparisons or benchmarking (source: ) - Workflows run four commands (broadcast, wait, pause, abort) with conditions, and can start from Stripe or GitHub webhooks or `POST /v2/workflows/runs` (source: ) ## Compare - [Amazon SNS vs MagicBell](https://www.anchorterminal.com/compare/amazon-sns-vs-magicbell.md): BB 72.8 vs C 58.8 - [Courier vs MagicBell](https://www.anchorterminal.com/compare/courier-vs-magicbell.md): BB 70.5 vs C 58.8 - [Firebase Cloud Messaging vs MagicBell](https://www.anchorterminal.com/compare/firebase-cloud-messaging-vs-magicbell.md): B 69.8 vs C 58.8 - [Knock vs MagicBell](https://www.anchorterminal.com/compare/knock-vs-magicbell.md): B 66.5 vs C 58.8 - [MagicBell vs Novu](https://www.anchorterminal.com/compare/magicbell-vs-novu.md): C 58.8 vs B 64.2 - [MagicBell vs ntfy](https://www.anchorterminal.com/compare/magicbell-vs-ntfy.md): C 58.8 vs C 61.5 - [MagicBell vs OneSignal](https://www.anchorterminal.com/compare/magicbell-vs-onesignal.md): C 58.8 vs B 69.3 - [MagicBell vs Pushover](https://www.anchorterminal.com/compare/magicbell-vs-pushover.md): C 58.8 vs D 53.1 - [MagicBell vs SuprSend](https://www.anchorterminal.com/compare/magicbell-vs-suprsend.md): C 58.8 vs BB 72.6 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on magicbell.com or one of its subdomains, or the README of github.com/magicbell/magicbell-js. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "magicbell", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html MagicBell on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![MagicBell on Anchor Terminal](https://www.anchorterminal.com/badges/magicbell.svg)](https://www.anchorterminal.com/tools/magicbell) ``` Plain link: ```html MagicBell on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say MagicBell is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/magicbell-dark.png - Light: https://www.anchorterminal.com/assets/share/magicbell-light.png