{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/basecamp.json",
        "name": "Basecamp",
        "score": 67.9,
        "shared": [
          "work.chat"
        ],
        "slug": "basecamp"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/microsoft-teams.json",
        "name": "Microsoft Teams (Microsoft Graph)",
        "score": 62.2,
        "shared": [
          "work.chat"
        ],
        "slug": "microsoft-teams"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/zulip.json",
        "name": "Zulip",
        "score": 61.5,
        "shared": [
          "work.chat"
        ],
        "slug": "zulip"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/clickup.json",
        "name": "ClickUp",
        "score": 60.9,
        "shared": [
          "work.chat"
        ],
        "slug": "clickup"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/slack-mcp.json",
        "name": "Slack MCP Server (official)",
        "score": 59.7,
        "shared": [
          "work.chat"
        ],
        "slug": "slack-mcp"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/outline.json",
        "name": "Outline",
        "score": 60.3,
        "shared": null,
        "slug": "outline"
      }
    ],
    "tool": {
      "slug": "mattermost",
      "name": "Mattermost",
      "vendor": "Mattermost, Inc.",
      "vendorUrl": "https://mattermost.com",
      "kind": "http-api",
      "category": "productivity",
      "summary": "Mattermost is an open-core team chat server from Mattermost, Inc. that its owner hosts, with channels, threads, calls and playbooks. Agents reach it through the REST API v4, bot accounts, personal access tokens, webhooks and an MCP server.",
      "url": "https://www.anchorterminal.com/tools/mattermost",
      "markdownUrl": "https://www.anchorterminal.com/tools/mattermost.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mattermost.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mattermost.json",
      "repo": "https://github.com/mattermost/mattermost",
      "license": "Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@mattermost/client"
        },
        {
          "registry": "go",
          "name": "github.com/mattermost/mattermost/server/public"
        }
      ],
      "auth": "mixed",
      "authNotes": "Granted by the server's own admin, with no vendor approval. The API takes a Bearer token in the `Authorization` header, either a session token from `POST /api/v4/users/login` or a personal access token. Personal access tokens are off until an admin enables them and lets the account create them, have a description, no scopes and no expiry, and can be revoked or disabled. Bot accounts hold such tokens, cannot be logged into and are created by a System Admin or a plugin once bot creation is enabled. OAuth 2.0 applications are also off by default, support PKCE and optional dynamic client registration, and have no scopes. The MCP server takes OAuth or a personal access token.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Team Edition and the Entry edition are free with no card or vendor account. Entry shows 10,000 messages of history and has community support only. Professional, Enterprise and Enterprise Advanced are annual per-seat subscriptions with no public price, and Mattermost Cloud is single-tenant and sold through sales (https://mattermost.com/pricing/). API calls are not charged, and bot accounts do not count as licensed users. An agent's owner can start on a free edition without a contract. The site's trial environment lasts one hour.",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API introduction, the OpenAPI source or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 39301,
        "npmWeekly": 7727,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.mattermost.com/api",
      "openapi": "https://github.com/mattermost/mattermost/tree/master/api/v4/source",
      "capabilities": [
        "work.chat"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "freemium",
        "sales-led",
        "pat",
        "oauth",
        "openapi",
        "mcp",
        "typescript",
        "go",
        "webhooks",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.8,
        "grade": "B",
        "agentReady": false,
        "rank": 310,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 89,
          "payments": 50,
          "reliability": 83,
          "schema": 76,
          "security": 63,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 83,
            "points": 16.6,
            "reason": "Read with the local-software lines, since the graded surface is the server its owner hosts. Mattermost Cloud is sold through sales only. Official tarballs, Docker images and a Kubernetes operator, with Ubuntu LTS 22.04 or later and PostgreSQL 14 or later stated (20). Public workflows run server, web app, end-to-end and mmctl tests on every push to master, with CodeQL and Scorecards. We did not read the result of the latest run (20 of 25). 612 issues were open on 9 October 2026. The 25 newest were opened between 5 September and 8 October, one of them a server crash when disabling a bot that owns itself, and reply counts were not read (16 of 25). Feature releases come monthly and each changelog entry has a Breaking Changes block and an API Changes list, but removals land in minor versions, such as `POST /api/v4/posts/ids/reactions` in 11.11 (12 of 15). Version 11.11, with API v4 described as stable (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 76,
            "points": 12.35,
            "reason": "The OpenAPI 3.0 source is public in the repository, 57 YAML path files with 604 operations on 485 paths on the master branch. The reference site counts 549 endpoints for the released version (25). No llms.txt on mattermost.com, docs.mattermost.com or developers.mattermost.com. The docs are MDX files in the public repository and are served as HTML (2 of 10). Every operation has a description, median 192 characters. 548 state the permission needed and 304 the minimum server version, and few say when not to use an endpoint (15 of 20). Bodies are JSON with 848 required lists, but only 31 enums and 29 length or range limits across the source (9 of 15). The reference says each endpoint page carries samples in curl, PowerShell, Python, Node and Go, and a quick-start page has six curl recipes. Most operations list 400, 401 and 403 with one shared error shape, and error ids are not catalogued (10 of 15). The API is at v4, and the server changelog is dated with an API Changes list per release (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 63,
            "points": 10.24,
            "reason": "List endpoints take `per_page` up to 200 with a default of 60, and channel posts take `since`, `before` and `after`. No field selection, and posts come back whole with metadata (14 of 25). 103 `page` or `per_page` parameters across the source, plus search endpoints for posts, users, channels and files (17 of 20). Errors are JSON with `id`, `message`, `request_id` and `status_code`. The ids are stable strings with no published list, and the 429 body is plain text (14 of 20). No idempotency key was found. The post schema has an undescribed `pending_post_id`, and nothing documents safe retries for writes (4 of 20). A post needs only `channel_id` and `message`, `me` stands in for the caller's user id, and the official drivers are TypeScript (`@mattermost/client`) and Go (14 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 63,
            "points": 11.03,
            "reason": "Personal access tokens are named, several per account, and can be revoked or disabled by the user or an admin. They carry no scopes and never expire, and a token for a System Admin account has full admin rights. OAuth 2.0 with PKCE and optional dynamic client registration has no scopes either. Tokens travel in the `Authorization` header or a cookie, with no query-string option in the docs (20 of 30). Bot accounts are separate accounts with a role, creating them and creating tokens are both off by default, and roles and permission schemes bound what an account can do. No read-only token and no confirmation step for deletes on the REST API (13 of 20). Messages are other people's text and no prompt-injection guidance was found in the API or Agents plugin docs (2 of 15). Audit logging records REST API and mmctl activity to a JSON schema. The docs label it Beta and it is not written to a file by default (10 of 15). A disclosure policy, a public Bugcrowd bounty, annual penetration tests, and a SOC 2 Type II report (2025) and ISO 27001:2022 certificate listed on the trust centre. No security.txt (18 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 50,
            "points": 6.25,
            "reason": "Read with the self-hosted rule. No x402, MPP or L402 (0). Team Edition and the Entry edition are free and their limits are published. Professional, Enterprise and Enterprise Advanced show Contact Sales, Get Pricing and Request Quote, with no price, so half marks (10). Free to run with no card and no vendor account (20). An owner can start the Docker image, and the docs say `POST /api/v4/users` needs no permission on an open server and that the first account becomes System Admin, so no browser signup with the vendor is needed (20)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 89,
            "points": 7.79,
            "reason": "Server 11.7.12 was released on 8 October 2026, one day before the check, and 11.11.1 on 24 September (30). Sixteen releases since 11 July 2026 by the dated changelog (20). 612 open issues on a repository with 39,301 stars. Several of the newest 25 were updated after they were opened, and a forum and a community server are linked. We did not read reply counts (17 of 25). Official TypeScript and Go drivers. `@mattermost/client` on npm is at 11.9.0 while the server is at 11.11, and the Go module is tagged `server/public/v0.4.4` (12 of 15). CI, CodeQL and Scorecards workflows with actions pinned by commit, and an SBOM published for each release (10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "note": "editorial 80, provenance 69",
            "reason": "Team Edition is MIT as a compiled binary, the source is AGPL v3 or a commercial licence with parts under Apache 2.0, and the Enterprise Edition binary that Entry runs is under a commercial licence. Open core, with the split stated in `LICENSE.txt` (26 of 30). On a self-hosted server the data stays with the owner. The privacy policy of 30 December 2024 is general and gives no retention period in numbers, the Software and Services Licence Agreement of 12 January 2023 covers cloud and on-premise use, and the DPA is a linked document we did not read (19 of 30). A Removed and Deprecated Features page lists upcoming removals by version and month, and each release has a published support end date, with extended support releases kept for 12 months (18 of 20). The telemetry page lists what a server sends, says it is on by default and gives the System Console switches to turn it off on a self-hosted server. Cloud admins cannot turn it off (17 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List endpoints take `per_page` up to 200 with a default of 60, and channel posts take `since`, `before` and `after`. No field selection, and posts come back whole with metadata (14 of 25). 103 `page` or `per_page` parameters across the source, plus search endpoints for posts, users, channels and files (17 of 20). Errors are JSON with `id`, `message`, `request_id` and `status_code`. The ids are stable strings with no published list, and the 429 body is plain text (14 of 20). No idempotency key was found. The post schema has an undescribed `pending_post_id`, and nothing documents safe retries for writes (4 of 20). A post needs only `channel_id` and `message`, `me` stands in for the caller's user id, and the official drivers are TypeScript (`@mattermost/client`) and Go (14 of 15).",
            "maintenance": "Server 11.7.12 was released on 8 October 2026, one day before the check, and 11.11.1 on 24 September (30). Sixteen releases since 11 July 2026 by the dated changelog (20). 612 open issues on a repository with 39,301 stars. Several of the newest 25 were updated after they were opened, and a forum and a community server are linked. We did not read reply counts (17 of 25). Official TypeScript and Go drivers. `@mattermost/client` on npm is at 11.9.0 while the server is at 11.11, and the Go module is tagged `server/public/v0.4.4` (12 of 15). CI, CodeQL and Scorecards workflows with actions pinned by commit, and an SBOM published for each release (10).",
            "payments": "Read with the self-hosted rule. No x402, MPP or L402 (0). Team Edition and the Entry edition are free and their limits are published. Professional, Enterprise and Enterprise Advanced show Contact Sales, Get Pricing and Request Quote, with no price, so half marks (10). Free to run with no card and no vendor account (20). An owner can start the Docker image, and the docs say `POST /api/v4/users` needs no permission on an open server and that the first account becomes System Admin, so no browser signup with the vendor is needed (20).",
            "reliability": "Read with the local-software lines, since the graded surface is the server its owner hosts. Mattermost Cloud is sold through sales only. Official tarballs, Docker images and a Kubernetes operator, with Ubuntu LTS 22.04 or later and PostgreSQL 14 or later stated (20). Public workflows run server, web app, end-to-end and mmctl tests on every push to master, with CodeQL and Scorecards. We did not read the result of the latest run (20 of 25). 612 issues were open on 9 October 2026. The 25 newest were opened between 5 September and 8 October, one of them a server crash when disabling a bot that owns itself, and reply counts were not read (16 of 25). Feature releases come monthly and each changelog entry has a Breaking Changes block and an API Changes list, but removals land in minor versions, such as `POST /api/v4/posts/ids/reactions` in 11.11 (12 of 15). Version 11.11, with API v4 described as stable (15).",
            "schema": "The OpenAPI 3.0 source is public in the repository, 57 YAML path files with 604 operations on 485 paths on the master branch. The reference site counts 549 endpoints for the released version (25). No llms.txt on mattermost.com, docs.mattermost.com or developers.mattermost.com. The docs are MDX files in the public repository and are served as HTML (2 of 10). Every operation has a description, median 192 characters. 548 state the permission needed and 304 the minimum server version, and few say when not to use an endpoint (15 of 20). Bodies are JSON with 848 required lists, but only 31 enums and 29 length or range limits across the source (9 of 15). The reference says each endpoint page carries samples in curl, PowerShell, Python, Node and Go, and a quick-start page has six curl recipes. Most operations list 400, 401 and 403 with one shared error shape, and error ids are not catalogued (10 of 15). The API is at v4, and the server changelog is dated with an API Changes list per release (15).",
            "security": "Personal access tokens are named, several per account, and can be revoked or disabled by the user or an admin. They carry no scopes and never expire, and a token for a System Admin account has full admin rights. OAuth 2.0 with PKCE and optional dynamic client registration has no scopes either. Tokens travel in the `Authorization` header or a cookie, with no query-string option in the docs (20 of 30). Bot accounts are separate accounts with a role, creating them and creating tokens are both off by default, and roles and permission schemes bound what an account can do. No read-only token and no confirmation step for deletes on the REST API (13 of 20). Messages are other people's text and no prompt-injection guidance was found in the API or Agents plugin docs (2 of 15). Audit logging records REST API and mmctl activity to a JSON schema. The docs label it Beta and it is not written to a file by default (10 of 15). A disclosure policy, a public Bugcrowd bounty, annual penetration tests, and a SOC 2 Type II report (2025) and ISO 27001:2022 certificate listed on the trust centre. No security.txt (18 of 20).",
            "transparency": "Team Edition is MIT as a compiled binary, the source is AGPL v3 or a commercial licence with parts under Apache 2.0, and the Enterprise Edition binary that Entry runs is under a commercial licence. Open core, with the split stated in `LICENSE.txt` (26 of 30). On a self-hosted server the data stays with the owner. The privacy policy of 30 December 2024 is general and gives no retention period in numbers, the Software and Services Licence Agreement of 12 January 2023 covers cloud and on-premise use, and the DPA is a linked document we did not read (19 of 30). A Removed and Deprecated Features page lists upcoming removals by version and month, and each release has a published support end date, with extended support releases kept for 12 months (18 of 20). The telemetry page lists what a server sends, says it is on by default and gives the System Console switches to turn it off on a self-hosted server. Cloud admins cannot turn it off (17 of 20)."
          },
          "sources": [
            {
              "what": "website terms of use and acceptable use policy",
              "url": "https://mattermost.com/terms-of-use/",
              "seen": "2026-10-09"
            },
            {
              "what": "Software and Services Licence Agreement",
              "url": "https://mattermost.com/software-services-license-agreement/",
              "seen": "2026-10-09"
            },
            {
              "what": "privacy policy",
              "url": "https://mattermost.com/privacy-policy/",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing page and FAQ",
              "url": "https://mattermost.com/pricing/",
              "seen": "2026-10-09"
            },
            {
              "what": "sub-processor list",
              "url": "https://mattermost.com/subprocessors/",
              "seen": "2026-10-09"
            },
            {
              "what": "Data Processing Addendum landing page",
              "url": "https://mattermost.com/data-processing-addendum/",
              "seen": "2026-10-09"
            },
            {
              "what": "security page",
              "url": "https://mattermost.com/platform/security/",
              "seen": "2026-10-09"
            },
            {
              "what": "responsible disclosure policy and bug bounty",
              "url": "https://mattermost.com/company/responsible-disclosure/",
              "seen": "2026-10-09"
            },
            {
              "what": "trust centre",
              "url": "https://trust.mattermost.com/",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt, 404",
              "url": "https://mattermost.com/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "llms.txt, 404",
              "url": "https://mattermost.com/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "API reference landing page",
              "url": "https://docs.mattermost.com/api",
              "seen": "2026-10-09"
            },
            {
              "what": "OpenAPI source, read as files in the repository and not as rendered pages",
              "url": "https://github.com/mattermost/mattermost/tree/master/api/v4/source",
              "seen": "2026-10-09"
            },
            {
              "what": "API introduction (authentication, rate limiting, errors, drivers)",
              "url": "https://github.com/mattermost/mattermost/blob/master/api/v4/source/introduction.yaml",
              "seen": "2026-10-09"
            },
            {
              "what": "curl quick-start, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/api/examples.mdx",
              "seen": "2026-10-09"
            },
            {
              "what": "editions page",
              "url": "https://docs.mattermost.com/product-overview/editions-and-offerings",
              "seen": "2026-10-09"
            },
            {
              "what": "v11 changelog, read from the docs source",
              "url": "https://docs.mattermost.com/product-overview/mattermost-v11-changelog",
              "seen": "2026-10-09"
            },
            {
              "what": "server releases and support end dates, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/main/product-overview/mattermost-server-releases.mdx",
              "seen": "2026-10-09"
            },
            {
              "what": "release policy, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/main/product-overview/release-policy.mdx",
              "seen": "2026-10-09"
            },
            {
              "what": "removed and deprecated list, read from the docs source",
              "url": "https://docs.mattermost.com/product-overview/deprecated-features",
              "seen": "2026-10-09"
            },
            {
              "what": "telemetry, read from the docs source",
              "url": "https://docs.mattermost.com/administration-guide/manage/telemetry",
              "seen": "2026-10-09"
            },
            {
              "what": "rate limiting settings, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/main/administration-guide/configure/rate-limiting-configuration-settings.mdx",
              "seen": "2026-10-09"
            },
            {
              "what": "logging and audit logging, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/main/administration-guide/manage/logging.mdx",
              "seen": "2026-10-09"
            },
            {
              "what": "personal access tokens, read from the docs source",
              "url": "https://docs.mattermost.com/developers/integrate/reference/personal-access-token",
              "seen": "2026-10-09"
            },
            {
              "what": "bot accounts, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/develop/integrate/reference/bot-accounts/index.md",
              "seen": "2026-10-09"
            },
            {
              "what": "OAuth 2.0, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/develop/integrate/apps/authentication/oauth2/index.md",
              "seen": "2026-10-09"
            },
            {
              "what": "software and hardware requirements, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/main/deployment-guide/software-hardware-requirements.mdx",
              "seen": "2026-10-09"
            },
            {
              "what": "certifications and compliance, read from the docs source",
              "url": "https://github.com/mattermost/mattermost/blob/master/docs/main/product-overview/certifications-and-compliance.mdx",
              "seen": "2026-10-09"
            },
            {
              "what": "security updates page, a script-drawn table whose rows were not read",
              "url": "https://docs.mattermost.com/security-guide/security-updates",
              "seen": "2026-10-09"
            },
            {
              "what": "rate limit response headers in the server source",
              "url": "https://github.com/mattermost/mattermost/blob/master/server/channels/app/ratelimit.go",
              "seen": "2026-10-09"
            },
            {
              "what": "licence file",
              "url": "https://github.com/mattermost/mattermost/blob/master/LICENSE.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "security policy",
              "url": "https://github.com/mattermost/mattermost/blob/master/SECURITY.md",
              "seen": "2026-10-09"
            },
            {
              "what": "CI workflows",
              "url": "https://github.com/mattermost/mattermost/tree/master/.github/workflows",
              "seen": "2026-10-09"
            },
            {
              "what": "repository page, stars",
              "url": "https://github.com/mattermost/mattermost",
              "seen": "2026-10-09"
            },
            {
              "what": "open issues",
              "url": "https://github.com/mattermost/mattermost/issues",
              "seen": "2026-10-09"
            },
            {
              "what": "Agents plugin admin guide, Mattermost MCP server",
              "url": "https://docs.mattermost.com/agents/docs/admin_guide",
              "seen": "2026-10-09"
            },
            {
              "what": "MCP server readme in the Agents plugin repository",
              "url": "https://github.com/mattermost/mattermost-plugin-agents/blob/master/mcpserver/README.md",
              "seen": "2026-10-09"
            },
            {
              "what": "status page",
              "url": "https://status.mattermost.com/",
              "seen": "2026-10-09"
            },
            {
              "what": "status history",
              "url": "https://status.mattermost.com/history",
              "seen": "2026-10-09"
            },
            {
              "what": "npm registry, @mattermost/client",
              "url": "https://registry.npmjs.org/@mattermost%2Fclient/latest",
              "seen": "2026-10-09"
            },
            {
              "what": "npm downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/@mattermost%2Fclient",
              "seen": "2026-10-09"
            },
            {
              "what": "RDAP for mattermost.com",
              "url": "https://rdap.verisign.com/com/v1/domain/mattermost.com",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: the rows of the security updates table (issue ids, CVE numbers and severities per advisory). The page draws them by script from a feed we did not fetch, so the count comes from the changelog's per-release notes",
            "unchecked: whether the latest CI run on the master branch passed. The workflows were read, the run results were not",
            "unchecked: reply counts and response times on GitHub issues",
            "unchecked: the Data Processing Addendum, the SOC 2 report and the other trust centre documents, which sit behind an access request or a link we did not follow",
            "unchecked: the publish date of `@mattermost/client` 11.9.0 on npm, and whether the MCP server has an entry in the official MCP registry",
            "unchecked: the terms the API introduction links at about.mattermost.com/default-terms, which were not requested",
            "The lead named a self-hosted option beside a hosted one. On 9 October 2026 the pricing page shows no price for any paid edition and its FAQ says Mattermost Cloud Enterprise is single-tenant and sold through sales, so the grade is on the self-hosted server",
            "The lead's docs link, docs.mattermost.com/api, is right. api.mattermost.com redirects to it",
            "The 99.9 per cent uptime SLA in the docs is for the Cloud dedicated add-on only, and status.mattermost.com covers the vendor's cloud and sites, not a server its owner runs",
            "The MCP server ships inside the Agents plugin. Its tool definitions were read in the plugin's docs and readme only, and the plugin was not installed or run. Write tools need an Enterprise licence, which Entry counts as",
            "Whether the free Entry edition's limits marked as coming in a future release (board cards, playbook runs, agent queries, call length, push notifications) are enforced yet was not established",
            "No prompt-injection guidance, llms.txt or security.txt was found on the pages and files read"
          ]
        },
        "negative": -5,
        "negativeNotes": [
          "2025-10-28 to 2026-10-08. The v11 changelog marks 52 dot releases in twelve months as carrying security fixes. Three are rated critical, 11.0.4 on 28 October 2025 in the server and 11.0.6 and 11.1.1 on 21 November 2025 in the bundled Jira plugin, and 21 more include high-severity fixes. All were fixed in a release and announced, with details published 30 days later, so 5 points. The advisory table itself is drawn by script and was not read (https://docs.mattermost.com/product-overview/mattermost-v11-changelog)."
        ],
        "verdict": "The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.",
        "bestFor": "A team that runs its own chat server and wants an agent to read channels, post, search and manage members through a bot account, including in air-gapped networks.",
        "strengths": [
          "Public OpenAPI 3.0 source for API v4, every operation described, 548 of 604 stating the permission needed",
          "Sixteen server releases between 11 July and 8 October 2026, each with a dated changelog entry and an API changes list",
          "Team Edition is free under MIT as a compiled binary, and the free Entry edition needs no card or vendor account",
          "Bot accounts are separate from people, do not count as licensed users, and their tokens can be revoked or disabled",
          "Public Bugcrowd bounty, and a SOC 2 Type II report and ISO 27001:2022 certificate listed on the trust centre"
        ],
        "weaknesses": [
          "Personal access tokens have no scopes and no expiry. A token does whatever its account can do",
          "52 dot releases from 28 October 2025 to 8 October 2026 carried security fixes, three rated critical and 21 including high-severity fixes",
          "No public price for Professional, Enterprise or Enterprise Advanced, and Mattermost Cloud is sold through sales only",
          "No idempotency key on `POST /api/v4/posts`, so a retried send can post twice",
          "Rate limiting is off by default on a self-hosted server, and no llms.txt or security.txt was found"
        ],
        "agentNotes": [
          "Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console",
          "Send `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cserver\u003e/api/v4`. Use `me` in place of a user id for the token's own account",
          "Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error",
          "Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint",
          "If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded`"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.8
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 89,
          "payments": 50,
          "reliability": 83,
          "schema": 76,
          "security": 63,
          "transparency": 80
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "docker run --name mattermost-preview -d --publish 8065:8065 mattermost/mattermost-preview",
        "http": "curl -X POST https://your-mattermost-server.com/api/v4/posts -H 'Authorization: Bearer \u003cTOKEN\u003e' -H 'Content-Type: application/json' -d '{\"channel_id\": \"\u003cCHANNEL_ID\u003e\", \"message\": \"Status update from API\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/work.chat",
        "tool": "https://letme.dev/mattermost"
      },
      "notable": [
        "The API reference is generated from the OpenAPI source in the server repository and counts 549 endpoints in 38 groups, with samples in curl, PowerShell, Python, Node and Go (https://docs.mattermost.com/api)",
        "Bot accounts cannot be logged into, do not count towards the licensed user total, and keep working when the person who created them leaves (https://docs.mattermost.com/developers/integrate/reference/bot-accounts)",
        "The Agents plugin has a Mattermost MCP server with 16 built-in tools and a larger catalogue loaded on demand through `search_tools` and `load_tool`. External clients reach it over streamable HTTP with OAuth or a personal access token, from server v11.2 (https://docs.mattermost.com/agents/docs/admin_guide)",
        "From server v12.0, due in October 2026, sessions and personal access tokens can no longer set post identity override props such as `override_username` (https://docs.mattermost.com/product-overview/deprecated-features)",
        "Telemetry is on by default. The docs list what is sent and say a self-hosted admin can turn it off in the System Console, while cloud admins cannot (https://docs.mattermost.com/administration-guide/manage/telemetry)",
        "The v11 changelog marks 52 dot releases between 28 October 2025 and 8 October 2026 as carrying security fixes, with details published 30 days after each fix (https://docs.mattermost.com/product-overview/mattermost-v11-changelog)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "The REST API v4 of a self-hosted Mattermost server at https://\u003cserver\u003e/api/v4. Mattermost Cloud runs the same software and is sold through sales only"
        },
        {
          "label": "API",
          "value": "OpenAPI 3.0 source in 57 YAML files, 604 operations on 485 paths on master on 9 October 2026. Users (79 operations), channels (62), system (51), teams (38), posts (28), groups (26). JSON request and response bodies. Events arrive over a WebSocket at `/api/v4/websocket`"
        },
        {
          "label": "Credentials",
          "value": "Session tokens from `POST /api/v4/users/login`, personal access tokens with no scopes or expiry, bot accounts, and OAuth 2.0 with PKCE and optional dynamic client registration. All sent as a Bearer token"
        },
        {
          "label": "Rate limits",
          "value": "Off by default on a self-hosted server. When enabled, 10 requests a second with a burst of 100, varied by IP address by default, with `X-Ratelimit-Limit`, `X-Ratelimit-Remaining` and `X-Ratelimit-Reset` headers. A 429 body is the text `limit exceeded`"
        },
        {
          "label": "Errors",
          "value": "JSON with `id`, `message`, `request_id`, `status_code` and `is_oauth`. 204 operations list 501 for functions the server's edition or configuration does not include"
        },
        {
          "label": "Pagination",
          "value": "`page` and `per_page`, default 60, maximum 200, larger values cut without an error. Channel posts also take `since`, `before` and `after`"
        },
        {
          "label": "MCP server",
          "value": "Inside the Agents plugin at https://\u003cserver\u003e/plugins/mattermost-ai/mcp-server/mcp over streamable HTTP, off until an admin enables it. 16 built-in tools such as `read_channel`, `search_posts` and `create_post`, more loaded through `search_tools` and `load_tool`. Built-in tools are read-only without an Enterprise licence, which Entry counts as"
        },
        {
          "label": "Drivers",
          "value": "Official TypeScript `@mattermost/client` 11.9.0 on npm and the Go `Client4` in `github.com/mattermost/mattermost/server/public`, tagged v0.4.4. Community drivers are listed in the marketplace"
        },
        {
          "label": "Editions",
          "value": "Team Edition (MIT binary, free, no single sign-on), Entry (free mode of Enterprise Edition, 10,000 messages of history, no compliance tools or high availability), Professional, Enterprise and Enterprise Advanced by subscription"
        },
        {
          "label": "Releases",
          "value": "A feature release on the 16th of each month, supported for three months, and an extended support release every nine months, supported for twelve. 11.11.1 on 24 September 2026 and 11.7.12 (extended support) on 8 October 2026. Requires PostgreSQL 14 or later"
        },
        {
          "label": "Audit",
          "value": "Audit logging records REST API and mmctl activity to a JSON schema, to file, syslog or TCP targets. The docs label it Beta and it is not written to a file by default"
        },
        {
          "label": "Certifications",
          "value": "The trust centre lists a SOC 2 Type II report (2025), a SOC 3 badge and an ISO 27001:2022 certificate, with annual third-party penetration tests. Public bug bounty on Bugcrowd"
        },
        {
          "label": "Sub-processors",
          "value": "Thirteen named with role and country, all in the United States, among them Amazon Web Services, Microsoft, Cloudflare, Anthropic and OpenAI, last updated 23 December 2024. They apply to the vendor's services, not to a self-hosted server"
        }
      ],
      "unitPrices": [
        {
          "item": "Team Edition (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, MIT binary, REST API included"
        },
        {
          "item": "Entry (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, 10,000 messages of viewable history, community support only; paid editions have no public price"
        }
      ],
      "provenance": {
        "legalEntity": "Mattermost, Inc.",
        "domain": "mattermost.com",
        "domainRegistered": "2012-12-22",
        "endpointOnVendorDomain": false,
        "terms": "https://mattermost.com/software-services-license-agreement/",
        "privacy": "https://mattermost.com/privacy-policy/",
        "statusPage": "https://status.mattermost.com",
        "changelog": "https://docs.mattermost.com/product-overview/mattermost-v11-changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Software and Services Licence Agreement (effective 12 January 2023) is a contract with Mattermost, Inc. and covers both Cloud Edition and On-Premise subscriptions. The privacy policy (effective 30 December 2024) gives the address 530 Lytton Avenue, Suite 201, Palo Alto, CA 94301.",
          "The graded API answers on the owner's own server at https://\u003cserver\u003e/api/v4, so the endpoint is not on the vendor's domain.",
          "The compiled Team Edition is under MIT and needs no agreement with the vendor. The agreement linked here governs the Enterprise Edition binary, subscriptions and the cloud.",
          "status.mattermost.com is a Statuspage site with five components (Sign-Up, Customer Portal, Cloud Workspaces, Calls, Community) and lists no incidents from August to 9 October 2026. It covers the vendor's services, not a self-hosted server.",
          "https://mattermost.com/.well-known/security.txt returns 404. SECURITY.md gives responsibledisclosure@mattermost.com, and the disclosure page links a public Bugcrowd programme.",
          "The website Terms of Use (effective 8 October 2021) and its Acceptable Use Policy were read first and do not forbid automated access. robots.txt on mattermost.com and docs.mattermost.com allows every path.",
          "The Data Processing Addendum page links a document dated 23 December 2022, which was not read.",
          "RDAP for mattermost.com gives a registration date of 2012-12-22."
        ],
        "score": 69,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Mattermost, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "mattermost.com, registered 2012-12-22 (13 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": " is not on mattermost.com",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "read, states 4 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 5.4,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 6 of the 8 things a reader expects",
            "points": 8.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.mattermost.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://mattermost.com/software-services-license-agreement/",
            "state": "read",
            "readAt": "2026-10-09",
            "words": 8207,
            "points": 5.4,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement shall be governed by and construed in accordance with the laws of the State of California without regard to the conflict of law provisions thereof.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "IN NO EVENT WILL EITHER PARTY WILL BE LIABLE FOR ANY PUNITIVE OR SPECIAL DAMAGES, OR FOR ANY USE OR COST OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES INCURRED BY THE OTHER PARTY, WHETHER SUCH DAMAGES ARE CHARACTERIZED AS DIRECT, INDIRECT OR OTHER, AND WHETHER IN AN ACTION IN CONTRACT OR TORT OR BASED ON A WARRANTY,…",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "8.1 This Agreement shall continue until terminated in accordance with the provisions of this Section 8."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Mattermost may change, supplement or update this Agreement by posting any changes to this Agreement on its website.",
                "says": "Changes are posted, with no other notice named"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": false
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(g) access or use any Product Materials or Services in order to build a competitive product or service.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Paid subscriptions renew automatically at the fees then current unless the licensee gives written notice at least thirty days before the term ends.",
                "quote": "Paid Subscriptions will automatically renew for successive terms (the same length as the Subscription Term) at Mattermost’s then-current fees unless Licensee provides written notice of non-renewal to Mattermost at least thirty days prior to the end of the then-current term"
              },
              {
                "date": "2026-10-08",
                "text": "The licensee grants Mattermost the right to use its company name and logo as a marketing reference, subject to the licensee’s trademark guidelines.",
                "quote": "Licensee grants to Mattermost the right to use Licensee’s company name and logo as a reference for marketing or promotional purposes on Mattermost’s website and in other public or private communications with Mattermost’s existing or potential customers"
              },
              {
                "date": "2026-10-08",
                "text": "For the Cloud Edition, Mattermost says it backs up the database and has no obligation to do so.",
                "quote": "Mattermost regularly backs up the database used in conjunction with the Services, but is under no obligation to do so."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://mattermost.com/privacy-policy/",
            "state": "read",
            "readAt": "2026-10-09",
            "words": 1336,
            "points": 8.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy explains what information we collect, how we use it, and the choices available to you when you visit our websites, use our products and services, or otherwise interact with Mattermost."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Information Shared with Third Parties and For What Purposes"
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "states may have additional rights regarding personal information, including the right to know, access, delete, correct, or opt out of certain processing activities, subject to applicable exceptions."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have questions about this Privacy Policy or our privacy practices, contact us at privacy@mattermost.com or Mattermost, Inc., 530 Lytton Avenue, Suite 201, Palo Alto, CA 94301, United States.",
                "says": "privacy@mattermost.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Where applicable, Mattermost complies with recognized data transfer frameworks and maintains appropriate safeguards for cross-border data transfers as described in our published compliance materials."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/mattermost.json",
      "live": {
        "slug": "mattermost",
        "vendorStatus": {
          "page": "https://status.mattermost.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:06:08.099173704Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "mattermost/mattermost",
            "version": "v11.11.1",
            "released": "2026-09-24",
            "seenAt": "2026-10-09T17:04:27.316421252Z"
          },
          {
            "registry": "npm",
            "name": "@mattermost/client",
            "version": "11.9.0",
            "seenAt": "2026-10-09T17:04:26.706218366Z"
          }
        ],
        "githubStars": 39305,
        "npmWeekly": 7727,
        "pages": [
          {
            "url": "https://docs.mattermost.com/product-overview/mattermost-v11-changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:37:42.65234154Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "950ba2c3c535"
          },
          {
            "url": "https://mattermost.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:51.25914555Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e2a34bb97731"
          },
          {
            "url": "https://mattermost.com/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:53.36052989Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a7313cffaf8b"
          },
          {
            "url": "https://mattermost.com/software-services-license-agreement/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:41:55.328783558Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0b65701c3d2f"
          }
        ],
        "updatedAt": "2026-10-10T02:06:08.099173704Z"
      }
    },
    "verify": {
      "accepts": "a page on mattermost.com or one of its subdomains, or the README of github.com/mattermost/mattermost",
      "badgeUrl": "https://www.anchorterminal.com/badges/mattermost.svg",
      "body": {
        "slug": "mattermost",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/mattermost",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/mattermost\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/mattermost.svg\" alt=\"Mattermost on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Mattermost on Anchor Terminal](https://www.anchorterminal.com/badges/mattermost.svg)](https://www.anchorterminal.com/tools/mattermost)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/mattermost\"\u003eMattermost on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/mattermost",
    "json": "https://www.anchorterminal.com/tools/mattermost.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/mattermost.md",
    "slim": "https://www.anchorterminal.com/tools/mattermost.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 65.8/100 · rank #310 of 950 · #1 in Work \u0026 productivity · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Mattermost, Inc. (https://mattermost.com) |\n| Kind | HTTP API |\n| Category | Work \u0026 productivity (https://www.anchorterminal.com/categories/productivity) |\n| Transport | HTTP |\n| Auth | OAuth or key · Granted by the server's own admin, with no vendor approval. The API takes a Bearer token in the `Authorization` header, either a session token from `POST /api/v4/users/login` or a personal access token. Personal access tokens are off until an admin enables them and lets the account create them, have a description, no scopes and no expiry, and can be revoked or disabled. Bot accounts hold such tokens, cannot be logged into and are created by a System Admin or a plugin once bot creation is enabled. OAuth 2.0 applications are also off by default, support PKCE and optional dynamic client registration, and have no scopes. The MCP server takes OAuth or a personal access token. |\n| Pricing | Freemium (Freemium) · Self-hosted Team Edition and the Entry edition are free with no card or vendor account. Entry shows 10,000 messages of history and has community support only. Professional, Enterprise and Enterprise Advanced are annual per-seat subscriptions with no public price, and Mattermost Cloud is single-tenant and sold through sales (https://mattermost.com/pricing/). API calls are not charged, and bot accounts do not count as licensed users. An agent's owner can start on a free edition without a contract. The site's trial environment lasts one hour. |\n| x402 | No · No x402, MPP or L402 in the API introduction, the OpenAPI source or the pricing page (checked 2026-10-09). |\n| Licence | Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0 |\n| Packages | npm: `@mattermost/client`; go: `github.com/mattermost/mattermost/server/public` |\n| Source | https://github.com/mattermost/mattermost |\n| Docs | https://docs.mattermost.com/api |\n| llms.txt | not found |\n| Last release | 2026-10-08 |\n| GitHub stars | 39,301 (as of 2026-10-09) |\n| npm downloads / week | 7,727 |\n| Surface graded | The REST API v4 of a self-hosted Mattermost server at https://\u003cserver\u003e/api/v4. Mattermost Cloud runs the same software and is sold through sales only |\n| API | OpenAPI 3.0 source in 57 YAML files, 604 operations on 485 paths on master on 9 October 2026. Users (79 operations), channels (62), system (51), teams (38), posts (28), groups (26). JSON request and response bodies. Events arrive over a WebSocket at `/api/v4/websocket` |\n| Credentials | Session tokens from `POST /api/v4/users/login`, personal access tokens with no scopes or expiry, bot accounts, and OAuth 2.0 with PKCE and optional dynamic client registration. All sent as a Bearer token |\n| Rate limits | Off by default on a self-hosted server. When enabled, 10 requests a second with a burst of 100, varied by IP address by default, with `X-Ratelimit-Limit`, `X-Ratelimit-Remaining` and `X-Ratelimit-Reset` headers. A 429 body is the text `limit exceeded` |\n| Errors | JSON with `id`, `message`, `request_id`, `status_code` and `is_oauth`. 204 operations list 501 for functions the server's edition or configuration does not include |\n| Pagination | `page` and `per_page`, default 60, maximum 200, larger values cut without an error. Channel posts also take `since`, `before` and `after` |\n| MCP server | Inside the Agents plugin at https://\u003cserver\u003e/plugins/mattermost-ai/mcp-server/mcp over streamable HTTP, off until an admin enables it. 16 built-in tools such as `read_channel`, `search_posts` and `create_post`, more loaded through `search_tools` and `load_tool`. Built-in tools are read-only without an Enterprise licence, which Entry counts as |\n| Drivers | Official TypeScript `@mattermost/client` 11.9.0 on npm and the Go `Client4` in `github.com/mattermost/mattermost/server/public`, tagged v0.4.4. Community drivers are listed in the marketplace |\n| Editions | Team Edition (MIT binary, free, no single sign-on), Entry (free mode of Enterprise Edition, 10,000 messages of history, no compliance tools or high availability), Professional, Enterprise and Enterprise Advanced by subscription |\n| Releases | A feature release on the 16th of each month, supported for three months, and an extended support release every nine months, supported for twelve. 11.11.1 on 24 September 2026 and 11.7.12 (extended support) on 8 October 2026. Requires PostgreSQL 14 or later |\n| Audit | Audit logging records REST API and mmctl activity to a JSON schema, to file, syslog or TCP targets. The docs label it Beta and it is not written to a file by default |\n| Certifications | The trust centre lists a SOC 2 Type II report (2025), a SOC 3 badge and an ISO 27001:2022 certificate, with annual third-party penetration tests. Public bug bounty on Bugcrowd |\n| Sub-processors | Thirteen named with role and country, all in the United States, among them Amazon Web Services, Microsoft, Cloudflare, Anthropic and OpenAI, last updated 23 December 2024. They apply to the vendor's services, not to a self-hosted server |\n| Capabilities | work.chat |\n| Tags | self-hosted, open-source, freemium, sales-led, pat, oauth, openapi, mcp, typescript, go, webhooks, bug-bounty, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/mattermost.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 83 | 16.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 76 | 12.3 |\n| Agent ergonomics | 13% | 16.2 | 63 | 10.2 |\n| Security \u0026 auth | 14% | 17.5 | 63 | 11.0 |\n| Payments \u0026 pricing | 10% | 12.5 | 50 | 6.2 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 89 | 7.8 |\n| Transparency \u0026 trust (editorial 80, provenance 69) | 7% | 8.8 | 75 | 6.6 |\n| Negative events | up to −15 | up to −15 | 2025-10-28 to 2026-10-08. The v11 changelog marks 52 dot releases in twelve months as carrying security fixes. Three are rated critical, 11.0.4 on 28 October 2025 in the server and 11.0.6 and 11.1.1 on 21 November 2025 in the bundled Jira plugin, and 21 more include high-severity fixes. All were fixed in a release and announced, with details published 30 days later, so 5 points. The advisory table itself is drawn by script and was not read (https://docs.mattermost.com/product-overview/mattermost-v11-changelog).  | -5 |\n| **Total** | | | | **65.8 → B** |\n\n### Why each score\n\n- Reliability 83: Read with the local-software lines, since the graded surface is the server its owner hosts. Mattermost Cloud is sold through sales only. Official tarballs, Docker images and a Kubernetes operator, with Ubuntu LTS 22.04 or later and PostgreSQL 14 or later stated (20). Public workflows run server, web app, end-to-end and mmctl tests on every push to master, with CodeQL and Scorecards. We did not read the result of the latest run (20 of 25). 612 issues were open on 9 October 2026. The 25 newest were opened between 5 September and 8 October, one of them a server crash when disabling a bot that owns itself, and reply counts were not read (16 of 25). Feature releases come monthly and each changelog entry has a Breaking Changes block and an API Changes list, but removals land in minor versions, such as `POST /api/v4/posts/ids/reactions` in 11.11 (12 of 15). Version 11.11, with API v4 described as stable (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 76: The OpenAPI 3.0 source is public in the repository, 57 YAML path files with 604 operations on 485 paths on the master branch. The reference site counts 549 endpoints for the released version (25). No llms.txt on mattermost.com, docs.mattermost.com or developers.mattermost.com. The docs are MDX files in the public repository and are served as HTML (2 of 10). Every operation has a description, median 192 characters. 548 state the permission needed and 304 the minimum server version, and few say when not to use an endpoint (15 of 20). Bodies are JSON with 848 required lists, but only 31 enums and 29 length or range limits across the source (9 of 15). The reference says each endpoint page carries samples in curl, PowerShell, Python, Node and Go, and a quick-start page has six curl recipes. Most operations list 400, 401 and 403 with one shared error shape, and error ids are not catalogued (10 of 15). The API is at v4, and the server changelog is dated with an API Changes list per release (15).\n- Agent ergonomics 63: List endpoints take `per_page` up to 200 with a default of 60, and channel posts take `since`, `before` and `after`. No field selection, and posts come back whole with metadata (14 of 25). 103 `page` or `per_page` parameters across the source, plus search endpoints for posts, users, channels and files (17 of 20). Errors are JSON with `id`, `message`, `request_id` and `status_code`. The ids are stable strings with no published list, and the 429 body is plain text (14 of 20). No idempotency key was found. The post schema has an undescribed `pending_post_id`, and nothing documents safe retries for writes (4 of 20). A post needs only `channel_id` and `message`, `me` stands in for the caller's user id, and the official drivers are TypeScript (`@mattermost/client`) and Go (14 of 15).\n- Security \u0026 auth 63: Personal access tokens are named, several per account, and can be revoked or disabled by the user or an admin. They carry no scopes and never expire, and a token for a System Admin account has full admin rights. OAuth 2.0 with PKCE and optional dynamic client registration has no scopes either. Tokens travel in the `Authorization` header or a cookie, with no query-string option in the docs (20 of 30). Bot accounts are separate accounts with a role, creating them and creating tokens are both off by default, and roles and permission schemes bound what an account can do. No read-only token and no confirmation step for deletes on the REST API (13 of 20). Messages are other people's text and no prompt-injection guidance was found in the API or Agents plugin docs (2 of 15). Audit logging records REST API and mmctl activity to a JSON schema. The docs label it Beta and it is not written to a file by default (10 of 15). A disclosure policy, a public Bugcrowd bounty, annual penetration tests, and a SOC 2 Type II report (2025) and ISO 27001:2022 certificate listed on the trust centre. No security.txt (18 of 20).\n- Payments \u0026 pricing 50: Read with the self-hosted rule. No x402, MPP or L402 (0). Team Edition and the Entry edition are free and their limits are published. Professional, Enterprise and Enterprise Advanced show Contact Sales, Get Pricing and Request Quote, with no price, so half marks (10). Free to run with no card and no vendor account (20). An owner can start the Docker image, and the docs say `POST /api/v4/users` needs no permission on an open server and that the first account becomes System Admin, so no browser signup with the vendor is needed (20).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 89: Server 11.7.12 was released on 8 October 2026, one day before the check, and 11.11.1 on 24 September (30). Sixteen releases since 11 July 2026 by the dated changelog (20). 612 open issues on a repository with 39,301 stars. Several of the newest 25 were updated after they were opened, and a forum and a community server are linked. We did not read reply counts (17 of 25). Official TypeScript and Go drivers. `@mattermost/client` on npm is at 11.9.0 while the server is at 11.11, and the Go module is tagged `server/public/v0.4.4` (12 of 15). CI, CodeQL and Scorecards workflows with actions pinned by commit, and an SBOM published for each release (10).\n- Transparency \u0026 trust 75: Team Edition is MIT as a compiled binary, the source is AGPL v3 or a commercial licence with parts under Apache 2.0, and the Enterprise Edition binary that Entry runs is under a commercial licence. Open core, with the split stated in `LICENSE.txt` (26 of 30). On a self-hosted server the data stays with the owner. The privacy policy of 30 December 2024 is general and gives no retention period in numbers, the Software and Services Licence Agreement of 12 January 2023 covers cloud and on-premise use, and the DPA is a linked document we did not read (19 of 30). A Removed and Deprecated Features page lists upcoming removals by version and month, and each release has a published support end date, with extended support releases kept for 12 months (18 of 20). The telemetry page lists what a server sends, says it is on by default and gives the System Console switches to turn it off on a self-hosted server. Cloud admins cannot turn it off (17 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (24 items): https://www.anchorterminal.com/fixes/mattermost.md (JSON https://www.anchorterminal.com/fixes/mattermost.json)\n\n### What we couldn't check\n\n- unchecked: the rows of the security updates table (issue ids, CVE numbers and severities per advisory). The page draws them by script from a feed we did not fetch, so the count comes from the changelog's per-release notes\n- unchecked: whether the latest CI run on the master branch passed. The workflows were read, the run results were not\n- unchecked: reply counts and response times on GitHub issues\n- unchecked: the Data Processing Addendum, the SOC 2 report and the other trust centre documents, which sit behind an access request or a link we did not follow\n- unchecked: the publish date of `@mattermost/client` 11.9.0 on npm, and whether the MCP server has an entry in the official MCP registry\n- unchecked: the terms the API introduction links at about.mattermost.com/default-terms, which were not requested\n- The lead named a self-hosted option beside a hosted one. On 9 October 2026 the pricing page shows no price for any paid edition and its FAQ says Mattermost Cloud Enterprise is single-tenant and sold through sales, so the grade is on the self-hosted server\n- The lead's docs link, docs.mattermost.com/api, is right. api.mattermost.com redirects to it\n- The 99.9 per cent uptime SLA in the docs is for the Cloud dedicated add-on only, and status.mattermost.com covers the vendor's cloud and sites, not a server its owner runs\n- The MCP server ships inside the Agents plugin. Its tool definitions were read in the plugin's docs and readme only, and the plugin was not installed or run. Write tools need an Enterprise licence, which Entry counts as\n- Whether the free Entry edition's limits marked as coming in a future release (board cards, playbook runs, agent queries, call length, push notifications) are enforced yet was not established\n- No prompt-injection guidance, llms.txt or security.txt was found on the pages and files read\n\n### Sources\n\n- website terms of use and acceptable use policy: \u003chttps://mattermost.com/terms-of-use/\u003e (seen 2026-10-09)\n- Software and Services Licence Agreement: \u003chttps://mattermost.com/software-services-license-agreement/\u003e (seen 2026-10-09)\n- privacy policy: \u003chttps://mattermost.com/privacy-policy/\u003e (seen 2026-10-09)\n- pricing page and FAQ: \u003chttps://mattermost.com/pricing/\u003e (seen 2026-10-09)\n- sub-processor list: \u003chttps://mattermost.com/subprocessors/\u003e (seen 2026-10-09)\n- Data Processing Addendum landing page: \u003chttps://mattermost.com/data-processing-addendum/\u003e (seen 2026-10-09)\n- security page: \u003chttps://mattermost.com/platform/security/\u003e (seen 2026-10-09)\n- responsible disclosure policy and bug bounty: \u003chttps://mattermost.com/company/responsible-disclosure/\u003e (seen 2026-10-09)\n- trust centre: \u003chttps://trust.mattermost.com/\u003e (seen 2026-10-09)\n- security.txt, 404: \u003chttps://mattermost.com/.well-known/security.txt\u003e (seen 2026-10-09)\n- llms.txt, 404: \u003chttps://mattermost.com/llms.txt\u003e (seen 2026-10-09)\n- API reference landing page: \u003chttps://docs.mattermost.com/api\u003e (seen 2026-10-09)\n- OpenAPI source, read as files in the repository and not as rendered pages: \u003chttps://github.com/mattermost/mattermost/tree/master/api/v4/source\u003e (seen 2026-10-09)\n- API introduction (authentication, rate limiting, errors, drivers): \u003chttps://github.com/mattermost/mattermost/blob/master/api/v4/source/introduction.yaml\u003e (seen 2026-10-09)\n- curl quick-start, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/api/examples.mdx\u003e (seen 2026-10-09)\n- editions page: \u003chttps://docs.mattermost.com/product-overview/editions-and-offerings\u003e (seen 2026-10-09)\n- v11 changelog, read from the docs source: \u003chttps://docs.mattermost.com/product-overview/mattermost-v11-changelog\u003e (seen 2026-10-09)\n- server releases and support end dates, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/main/product-overview/mattermost-server-releases.mdx\u003e (seen 2026-10-09)\n- release policy, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/main/product-overview/release-policy.mdx\u003e (seen 2026-10-09)\n- removed and deprecated list, read from the docs source: \u003chttps://docs.mattermost.com/product-overview/deprecated-features\u003e (seen 2026-10-09)\n- telemetry, read from the docs source: \u003chttps://docs.mattermost.com/administration-guide/manage/telemetry\u003e (seen 2026-10-09)\n- rate limiting settings, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/main/administration-guide/configure/rate-limiting-configuration-settings.mdx\u003e (seen 2026-10-09)\n- logging and audit logging, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/main/administration-guide/manage/logging.mdx\u003e (seen 2026-10-09)\n- personal access tokens, read from the docs source: \u003chttps://docs.mattermost.com/developers/integrate/reference/personal-access-token\u003e (seen 2026-10-09)\n- bot accounts, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/develop/integrate/reference/bot-accounts/index.md\u003e (seen 2026-10-09)\n- OAuth 2.0, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/develop/integrate/apps/authentication/oauth2/index.md\u003e (seen 2026-10-09)\n- software and hardware requirements, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/main/deployment-guide/software-hardware-requirements.mdx\u003e (seen 2026-10-09)\n- certifications and compliance, read from the docs source: \u003chttps://github.com/mattermost/mattermost/blob/master/docs/main/product-overview/certifications-and-compliance.mdx\u003e (seen 2026-10-09)\n- security updates page, a script-drawn table whose rows were not read: \u003chttps://docs.mattermost.com/security-guide/security-updates\u003e (seen 2026-10-09)\n- rate limit response headers in the server source: \u003chttps://github.com/mattermost/mattermost/blob/master/server/channels/app/ratelimit.go\u003e (seen 2026-10-09)\n- licence file: \u003chttps://github.com/mattermost/mattermost/blob/master/LICENSE.txt\u003e (seen 2026-10-09)\n- security policy: \u003chttps://github.com/mattermost/mattermost/blob/master/SECURITY.md\u003e (seen 2026-10-09)\n- CI workflows: \u003chttps://github.com/mattermost/mattermost/tree/master/.github/workflows\u003e (seen 2026-10-09)\n- repository page, stars: \u003chttps://github.com/mattermost/mattermost\u003e (seen 2026-10-09)\n- open issues: \u003chttps://github.com/mattermost/mattermost/issues\u003e (seen 2026-10-09)\n- Agents plugin admin guide, Mattermost MCP server: \u003chttps://docs.mattermost.com/agents/docs/admin_guide\u003e (seen 2026-10-09)\n- MCP server readme in the Agents plugin repository: \u003chttps://github.com/mattermost/mattermost-plugin-agents/blob/master/mcpserver/README.md\u003e (seen 2026-10-09)\n- status page: \u003chttps://status.mattermost.com/\u003e (seen 2026-10-09)\n- status history: \u003chttps://status.mattermost.com/history\u003e (seen 2026-10-09)\n- npm registry, @mattermost/client: \u003chttps://registry.npmjs.org/@mattermost%2Fclient/latest\u003e (seen 2026-10-09)\n- npm downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/@mattermost%2Fclient\u003e (seen 2026-10-09)\n- RDAP for mattermost.com: \u003chttps://rdap.verisign.com/com/v1/domain/mattermost.com\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 69/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Mattermost, Inc. | 20/20 |\n| Domain age | mattermost.com, registered 2012-12-22 (13 years) | 15/15 |\n| Endpoint on the vendor's domain |  is not on mattermost.com | 0/15 |\n| Terms of service | read, states 4 of the 7 things a reader expects, and has 1 clause that costs points | 5.4/10 |\n| Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 |\n| Status page | status.mattermost.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Software and Services Licence Agreement (effective 12 January 2023) is a contract with Mattermost, Inc. and covers both Cloud Edition and On-Premise subscriptions. The privacy policy (effective 30 December 2024) gives the address 530 Lytton Avenue, Suite 201, Palo Alto, CA 94301.\n\nThe graded API answers on the owner's own server at https://\u003cserver\u003e/api/v4, so the endpoint is not on the vendor's domain.\n\nThe compiled Team Edition is under MIT and needs no agreement with the vendor. The agreement linked here governs the Enterprise Edition binary, subscriptions and the cloud.\n\nstatus.mattermost.com is a Statuspage site with five components (Sign-Up, Customer Portal, Cloud Workspaces, Calls, Community) and lists no incidents from August to 9 October 2026. It covers the vendor's services, not a self-hosted server.\n\nhttps://mattermost.com/.well-known/security.txt returns 404. SECURITY.md gives responsibledisclosure@mattermost.com, and the disclosure page links a public Bugcrowd programme.\n\nThe website Terms of Use (effective 8 October 2021) and its Acceptable Use Policy were read first and do not forbid automated access. robots.txt on mattermost.com and docs.mattermost.com allows every path.\n\nThe Data Processing Addendum page links a document dated 23 December 2022, which was not read.\n\nRDAP for mattermost.com gives a registration date of 2012-12-22.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://mattermost.com/software-services-license-agreement/), read 2026-10-09, gives no date, states 4 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"(g) access or use any Product Materials or Services in order to build a competitive product or service.\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Changes are posted, with no other notice named.\n- Not found in the text. Lists what users may not do.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Paid subscriptions renew automatically at the fees then current unless the licensee gives written notice at least thirty days before the term ends. \"Paid Subscriptions will automatically renew for successive terms (the same length as the Subscription Term) at Mattermost’s then-current fees unless Licensee provides written notice of non-renewal to Mattermost at least thirty days prior to the end of the then-current term\"\n- Also in the text (2026-10-08). The licensee grants Mattermost the right to use its company name and logo as a marketing reference, subject to the licensee’s trademark guidelines. \"Licensee grants to Mattermost the right to use Licensee’s company name and logo as a reference for marketing or promotional purposes on Mattermost’s website and in other public or private communications with Mattermost’s existing or potential customers\"\n- Also in the text (2026-10-08). For the Cloud Edition, Mattermost says it backs up the database and has no obligation to do so. \"Mattermost regularly backs up the database used in conjunction with the Services, but is under no obligation to do so.\"\n\n**Privacy policy** (https://mattermost.com/privacy-policy/), read 2026-10-09, gives no date, states 6 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. For as long as needed, with no period named.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Gives a privacy contact. privacy@mattermost.com.\n\n## Live (updated 2026-10-10 02:06 UTC)\n\n- Vendor status page: none, All Systems Operational\n- github `mattermost/mattermost` v11.11.1, released 2026-09-24\n- npm `@mattermost/client` 11.9.0\n- Watching changelog \u003chttps://docs.mattermost.com/product-overview/mattermost-v11-changelog\u003e\n- Watching pricing \u003chttps://mattermost.com/pricing/\u003e\n- Watching privacy \u003chttps://mattermost.com/privacy-policy/\u003e\n- Watching terms \u003chttps://mattermost.com/software-services-license-agreement/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/mattermost.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Team Edition (self-hosted) | free | per seat per month | free, MIT binary, REST API included |\n| Entry (self-hosted) | free | per seat per month | free, 10,000 messages of viewable history, community support only; paid editions have no public price |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0 source for API v4, every operation described, 548 of 604 stating the permission needed\n- Sixteen server releases between 11 July and 8 October 2026, each with a dated changelog entry and an API changes list\n- Team Edition is free under MIT as a compiled binary, and the free Entry edition needs no card or vendor account\n- Bot accounts are separate from people, do not count as licensed users, and their tokens can be revoked or disabled\n- Public Bugcrowd bounty, and a SOC 2 Type II report and ISO 27001:2022 certificate listed on the trust centre\n\n## Weaknesses\n\n- Personal access tokens have no scopes and no expiry. A token does whatever its account can do\n- 52 dot releases from 28 October 2025 to 8 October 2026 carried security fixes, three rated critical and 21 including high-severity fixes\n- No public price for Professional, Enterprise or Enterprise Advanced, and Mattermost Cloud is sold through sales only\n- No idempotency key on `POST /api/v4/posts`, so a retried send can post twice\n- Rate limiting is off by default on a self-hosted server, and no llms.txt or security.txt was found\n\n## Before you call it (notes for agents)\n\n1. Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console\n2. Send `Authorization: Bearer \u003ctoken\u003e` to `https://\u003cserver\u003e/api/v4`. Use `me` in place of a user id for the token's own account\n3. Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error\n4. Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint\n5. If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded`\n\n## Connect\n\nInstall:\n\n```bash\ndocker run --name mattermost-preview -d --publish 8065:8065 mattermost/mattermost-preview\n```\n\nFirst request:\n\n```bash\ncurl -X POST https://your-mattermost-server.com/api/v4/posts -H 'Authorization: Bearer \u003cTOKEN\u003e' -H 'Content-Type: application/json' -d '{\"channel_id\": \"\u003cCHANNEL_ID\u003e\", \"message\": \"Status update from API\"}'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/mattermost. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Basecamp | B | 67.9 | 237 | work.chat | no | https://www.anchorterminal.com/tools/basecamp.md |\n| Microsoft Teams (Microsoft Graph) | B | 62.2 | 441 | work.chat | no | https://www.anchorterminal.com/tools/microsoft-teams.md |\n| Zulip | C | 61.5 | 466 | work.chat | no | https://www.anchorterminal.com/tools/zulip.md |\n| ClickUp | C | 60.9 | 489 | work.chat | no | https://www.anchorterminal.com/tools/clickup.md |\n| Slack MCP Server (official) | C | 59.7 | 539 | work.chat | no | https://www.anchorterminal.com/tools/slack-mcp.md |\n| Outline | C | 60.3 | 523 | same category (Work \u0026 productivity) | no | https://www.anchorterminal.com/tools/outline.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The API reference is generated from the OpenAPI source in the server repository and counts 549 endpoints in 38 groups, with samples in curl, PowerShell, Python, Node and Go (source: \u003chttps://docs.mattermost.com/api\u003e)\n- Bot accounts cannot be logged into, do not count towards the licensed user total, and keep working when the person who created them leaves (source: \u003chttps://docs.mattermost.com/developers/integrate/reference/bot-accounts\u003e)\n- The Agents plugin has a Mattermost MCP server with 16 built-in tools and a larger catalogue loaded on demand through `search_tools` and `load_tool`. External clients reach it over streamable HTTP with OAuth or a personal access token, from server v11.2 (source: \u003chttps://docs.mattermost.com/agents/docs/admin_guide\u003e)\n- From server v12.0, due in October 2026, sessions and personal access tokens can no longer set post identity override props such as `override_username` (source: \u003chttps://docs.mattermost.com/product-overview/deprecated-features\u003e)\n- Telemetry is on by default. The docs list what is sent and say a self-hosted admin can turn it off in the System Console, while cloud admins cannot (source: \u003chttps://docs.mattermost.com/administration-guide/manage/telemetry\u003e)\n- The v11 changelog marks 52 dot releases between 28 October 2025 and 8 October 2026 as carrying security fixes, with details published 30 days after each fix (source: \u003chttps://docs.mattermost.com/product-overview/mattermost-v11-changelog\u003e)\n\n- #1 of 8 in Best issue tracking, docs and chat tools for AI agents: https://www.anchorterminal.com/best/productivity/index.md\n- All 40 work comparisons: https://www.anchorterminal.com/compare/productivity/index.md\n\n## Compare\n\n- [Mattermost vs Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.md): B 65.8 vs B 62.2\n- [Mattermost vs Slack MCP Server (official)](https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp.md): B 65.8 vs C 59.7\n- [Mattermost vs Zulip](https://www.anchorterminal.com/compare/mattermost-vs-zulip.md): B 65.8 vs C 61.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on mattermost.com or one of its subdomains, or the README of github.com/mattermost/mattermost. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"mattermost\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/mattermost\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/mattermost.svg\" alt=\"Mattermost on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Mattermost on Anchor Terminal](https://www.anchorterminal.com/badges/mattermost.svg)](https://www.anchorterminal.com/tools/mattermost)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/mattermost\"\u003eMattermost on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Mattermost is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/mattermost-dark.png\n- Light: https://www.anchorterminal.com/assets/share/mattermost-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Work \u0026 productivity",
        "url": "https://www.anchorterminal.com/categories/productivity"
      },
      {
        "name": "Mattermost",
        "url": ""
      }
    ],
    "description": "Mattermost is an open-core team chat server from Mattermost, Inc. that its owner hosts, with channels, threads, calls and playbooks. Agents reach it through the REST API v4, bot accounts, personal access tokens, webhooks and an MCP server.",
    "facts": [
      "rank #310 of 950",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Mattermost",
    "image": "https://www.anchorterminal.com/assets/og/tools-mattermost.png",
    "path": "/tools/mattermost",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Mattermost review (2026): pricing, alternatives and grade B",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/mattermost"
  },
  "tokens": {
    "markdown": 8850,
    "slim": 2030
  },
  "version": 1
}
