# Mattermost > Mattermost is an open-core team chat server from Mattermost, Inc. that its owner hosts, with channels, threads, calls and playbooks. Agents reach it through the REST API v4, bot accounts, personal access tokens, webhooks and an MCP server. - Canonical: https://www.anchorterminal.com/tools/mattermost - Markdown: https://www.anchorterminal.com/tools/mattermost.md (~8,850 tokens) - Slim: https://www.anchorterminal.com/tools/mattermost.min.md (~2,030 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/mattermost.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 65.8/100 · rank #310 of 950 · #1 in Work & productivity · not agent-ready · confidence medium** ## Assessment The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical. ## Facts | Field | Value | | --- | --- | | Vendor | Mattermost, Inc. (https://mattermost.com) | | Kind | HTTP API | | Category | Work & productivity (https://www.anchorterminal.com/categories/productivity) | | Transport | HTTP | | Auth | OAuth or key · Granted by the server's own admin, with no vendor approval. The API takes a Bearer token in the `Authorization` header, either a session token from `POST /api/v4/users/login` or a personal access token. Personal access tokens are off until an admin enables them and lets the account create them, have a description, no scopes and no expiry, and can be revoked or disabled. Bot accounts hold such tokens, cannot be logged into and are created by a System Admin or a plugin once bot creation is enabled. OAuth 2.0 applications are also off by default, support PKCE and optional dynamic client registration, and have no scopes. The MCP server takes OAuth or a personal access token. | | Pricing | Freemium (Freemium) · Self-hosted Team Edition and the Entry edition are free with no card or vendor account. Entry shows 10,000 messages of history and has community support only. Professional, Enterprise and Enterprise Advanced are annual per-seat subscriptions with no public price, and Mattermost Cloud is single-tenant and sold through sales (https://mattermost.com/pricing/). API calls are not charged, and bot accounts do not count as licensed users. An agent's owner can start on a free edition without a contract. The site's trial environment lasts one hour. | | x402 | No · No x402, MPP or L402 in the API introduction, the OpenAPI source or the pricing page (checked 2026-10-09). | | Licence | Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0 | | Packages | npm: `@mattermost/client`; go: `github.com/mattermost/mattermost/server/public` | | Source | https://github.com/mattermost/mattermost | | Docs | https://docs.mattermost.com/api | | llms.txt | not found | | Last release | 2026-10-08 | | GitHub stars | 39,301 (as of 2026-10-09) | | npm downloads / week | 7,727 | | Surface graded | The REST API v4 of a self-hosted Mattermost server at https:///api/v4. Mattermost Cloud runs the same software and is sold through sales only | | API | OpenAPI 3.0 source in 57 YAML files, 604 operations on 485 paths on master on 9 October 2026. Users (79 operations), channels (62), system (51), teams (38), posts (28), groups (26). JSON request and response bodies. Events arrive over a WebSocket at `/api/v4/websocket` | | Credentials | Session tokens from `POST /api/v4/users/login`, personal access tokens with no scopes or expiry, bot accounts, and OAuth 2.0 with PKCE and optional dynamic client registration. All sent as a Bearer token | | Rate limits | Off by default on a self-hosted server. When enabled, 10 requests a second with a burst of 100, varied by IP address by default, with `X-Ratelimit-Limit`, `X-Ratelimit-Remaining` and `X-Ratelimit-Reset` headers. A 429 body is the text `limit exceeded` | | Errors | JSON with `id`, `message`, `request_id`, `status_code` and `is_oauth`. 204 operations list 501 for functions the server's edition or configuration does not include | | Pagination | `page` and `per_page`, default 60, maximum 200, larger values cut without an error. Channel posts also take `since`, `before` and `after` | | MCP server | Inside the Agents plugin at https:///plugins/mattermost-ai/mcp-server/mcp over streamable HTTP, off until an admin enables it. 16 built-in tools such as `read_channel`, `search_posts` and `create_post`, more loaded through `search_tools` and `load_tool`. Built-in tools are read-only without an Enterprise licence, which Entry counts as | | Drivers | Official TypeScript `@mattermost/client` 11.9.0 on npm and the Go `Client4` in `github.com/mattermost/mattermost/server/public`, tagged v0.4.4. Community drivers are listed in the marketplace | | Editions | Team Edition (MIT binary, free, no single sign-on), Entry (free mode of Enterprise Edition, 10,000 messages of history, no compliance tools or high availability), Professional, Enterprise and Enterprise Advanced by subscription | | Releases | A feature release on the 16th of each month, supported for three months, and an extended support release every nine months, supported for twelve. 11.11.1 on 24 September 2026 and 11.7.12 (extended support) on 8 October 2026. Requires PostgreSQL 14 or later | | Audit | Audit logging records REST API and mmctl activity to a JSON schema, to file, syslog or TCP targets. The docs label it Beta and it is not written to a file by default | | Certifications | The trust centre lists a SOC 2 Type II report (2025), a SOC 3 badge and an ISO 27001:2022 certificate, with annual third-party penetration tests. Public bug bounty on Bugcrowd | | Sub-processors | Thirteen named with role and country, all in the United States, among them Amazon Web Services, Microsoft, Cloudflare, Anthropic and OpenAI, last updated 23 December 2024. They apply to the vendor's services, not to a self-hosted server | | Capabilities | work.chat | | Tags | self-hosted, open-source, freemium, sales-led, pat, oauth, openapi, mcp, typescript, go, webhooks, bug-bounty, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/mattermost.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 83 | 16.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 76 | 12.3 | | Agent ergonomics | 13% | 16.2 | 63 | 10.2 | | Security & auth | 14% | 17.5 | 63 | 11.0 | | Payments & pricing | 10% | 12.5 | 50 | 6.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 89 | 7.8 | | Transparency & trust (editorial 80, provenance 69) | 7% | 8.8 | 75 | 6.6 | | Negative events | up to −15 | up to −15 | 2025-10-28 to 2026-10-08. The v11 changelog marks 52 dot releases in twelve months as carrying security fixes. Three are rated critical, 11.0.4 on 28 October 2025 in the server and 11.0.6 and 11.1.1 on 21 November 2025 in the bundled Jira plugin, and 21 more include high-severity fixes. All were fixed in a release and announced, with details published 30 days later, so 5 points. The advisory table itself is drawn by script and was not read (https://docs.mattermost.com/product-overview/mattermost-v11-changelog). | -5 | | **Total** | | | | **65.8 → B** | ### Why each score - Reliability 83: Read with the local-software lines, since the graded surface is the server its owner hosts. Mattermost Cloud is sold through sales only. Official tarballs, Docker images and a Kubernetes operator, with Ubuntu LTS 22.04 or later and PostgreSQL 14 or later stated (20). Public workflows run server, web app, end-to-end and mmctl tests on every push to master, with CodeQL and Scorecards. We did not read the result of the latest run (20 of 25). 612 issues were open on 9 October 2026. The 25 newest were opened between 5 September and 8 October, one of them a server crash when disabling a bot that owns itself, and reply counts were not read (16 of 25). Feature releases come monthly and each changelog entry has a Breaking Changes block and an API Changes list, but removals land in minor versions, such as `POST /api/v4/posts/ids/reactions` in 11.11 (12 of 15). Version 11.11, with API v4 described as stable (15). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 76: The OpenAPI 3.0 source is public in the repository, 57 YAML path files with 604 operations on 485 paths on the master branch. The reference site counts 549 endpoints for the released version (25). No llms.txt on mattermost.com, docs.mattermost.com or developers.mattermost.com. The docs are MDX files in the public repository and are served as HTML (2 of 10). Every operation has a description, median 192 characters. 548 state the permission needed and 304 the minimum server version, and few say when not to use an endpoint (15 of 20). Bodies are JSON with 848 required lists, but only 31 enums and 29 length or range limits across the source (9 of 15). The reference says each endpoint page carries samples in curl, PowerShell, Python, Node and Go, and a quick-start page has six curl recipes. Most operations list 400, 401 and 403 with one shared error shape, and error ids are not catalogued (10 of 15). The API is at v4, and the server changelog is dated with an API Changes list per release (15). - Agent ergonomics 63: List endpoints take `per_page` up to 200 with a default of 60, and channel posts take `since`, `before` and `after`. No field selection, and posts come back whole with metadata (14 of 25). 103 `page` or `per_page` parameters across the source, plus search endpoints for posts, users, channels and files (17 of 20). Errors are JSON with `id`, `message`, `request_id` and `status_code`. The ids are stable strings with no published list, and the 429 body is plain text (14 of 20). No idempotency key was found. The post schema has an undescribed `pending_post_id`, and nothing documents safe retries for writes (4 of 20). A post needs only `channel_id` and `message`, `me` stands in for the caller's user id, and the official drivers are TypeScript (`@mattermost/client`) and Go (14 of 15). - Security & auth 63: Personal access tokens are named, several per account, and can be revoked or disabled by the user or an admin. They carry no scopes and never expire, and a token for a System Admin account has full admin rights. OAuth 2.0 with PKCE and optional dynamic client registration has no scopes either. Tokens travel in the `Authorization` header or a cookie, with no query-string option in the docs (20 of 30). Bot accounts are separate accounts with a role, creating them and creating tokens are both off by default, and roles and permission schemes bound what an account can do. No read-only token and no confirmation step for deletes on the REST API (13 of 20). Messages are other people's text and no prompt-injection guidance was found in the API or Agents plugin docs (2 of 15). Audit logging records REST API and mmctl activity to a JSON schema. The docs label it Beta and it is not written to a file by default (10 of 15). A disclosure policy, a public Bugcrowd bounty, annual penetration tests, and a SOC 2 Type II report (2025) and ISO 27001:2022 certificate listed on the trust centre. No security.txt (18 of 20). - Payments & pricing 50: Read with the self-hosted rule. No x402, MPP or L402 (0). Team Edition and the Entry edition are free and their limits are published. Professional, Enterprise and Enterprise Advanced show Contact Sales, Get Pricing and Request Quote, with no price, so half marks (10). Free to run with no card and no vendor account (20). An owner can start the Docker image, and the docs say `POST /api/v4/users` needs no permission on an open server and that the first account becomes System Admin, so no browser signup with the vendor is needed (20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 89: Server 11.7.12 was released on 8 October 2026, one day before the check, and 11.11.1 on 24 September (30). Sixteen releases since 11 July 2026 by the dated changelog (20). 612 open issues on a repository with 39,301 stars. Several of the newest 25 were updated after they were opened, and a forum and a community server are linked. We did not read reply counts (17 of 25). Official TypeScript and Go drivers. `@mattermost/client` on npm is at 11.9.0 while the server is at 11.11, and the Go module is tagged `server/public/v0.4.4` (12 of 15). CI, CodeQL and Scorecards workflows with actions pinned by commit, and an SBOM published for each release (10). - Transparency & trust 75: Team Edition is MIT as a compiled binary, the source is AGPL v3 or a commercial licence with parts under Apache 2.0, and the Enterprise Edition binary that Entry runs is under a commercial licence. Open core, with the split stated in `LICENSE.txt` (26 of 30). On a self-hosted server the data stays with the owner. The privacy policy of 30 December 2024 is general and gives no retention period in numbers, the Software and Services Licence Agreement of 12 January 2023 covers cloud and on-premise use, and the DPA is a linked document we did not read (19 of 30). A Removed and Deprecated Features page lists upcoming removals by version and month, and each release has a published support end date, with extended support releases kept for 12 months (18 of 20). The telemetry page lists what a server sends, says it is on by default and gives the System Console switches to turn it off on a self-hosted server. Cloud admins cannot turn it off (17 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (24 items): https://www.anchorterminal.com/fixes/mattermost.md (JSON https://www.anchorterminal.com/fixes/mattermost.json) ### What we couldn't check - unchecked: the rows of the security updates table (issue ids, CVE numbers and severities per advisory). The page draws them by script from a feed we did not fetch, so the count comes from the changelog's per-release notes - unchecked: whether the latest CI run on the master branch passed. The workflows were read, the run results were not - unchecked: reply counts and response times on GitHub issues - unchecked: the Data Processing Addendum, the SOC 2 report and the other trust centre documents, which sit behind an access request or a link we did not follow - unchecked: the publish date of `@mattermost/client` 11.9.0 on npm, and whether the MCP server has an entry in the official MCP registry - unchecked: the terms the API introduction links at about.mattermost.com/default-terms, which were not requested - The lead named a self-hosted option beside a hosted one. On 9 October 2026 the pricing page shows no price for any paid edition and its FAQ says Mattermost Cloud Enterprise is single-tenant and sold through sales, so the grade is on the self-hosted server - The lead's docs link, docs.mattermost.com/api, is right. api.mattermost.com redirects to it - The 99.9 per cent uptime SLA in the docs is for the Cloud dedicated add-on only, and status.mattermost.com covers the vendor's cloud and sites, not a server its owner runs - The MCP server ships inside the Agents plugin. Its tool definitions were read in the plugin's docs and readme only, and the plugin was not installed or run. Write tools need an Enterprise licence, which Entry counts as - Whether the free Entry edition's limits marked as coming in a future release (board cards, playbook runs, agent queries, call length, push notifications) are enforced yet was not established - No prompt-injection guidance, llms.txt or security.txt was found on the pages and files read ### Sources - website terms of use and acceptable use policy: (seen 2026-10-09) - Software and Services Licence Agreement: (seen 2026-10-09) - privacy policy: (seen 2026-10-09) - pricing page and FAQ: (seen 2026-10-09) - sub-processor list: (seen 2026-10-09) - Data Processing Addendum landing page: (seen 2026-10-09) - security page: (seen 2026-10-09) - responsible disclosure policy and bug bounty: (seen 2026-10-09) - trust centre: (seen 2026-10-09) - security.txt, 404: (seen 2026-10-09) - llms.txt, 404: (seen 2026-10-09) - API reference landing page: (seen 2026-10-09) - OpenAPI source, read as files in the repository and not as rendered pages: (seen 2026-10-09) - API introduction (authentication, rate limiting, errors, drivers): (seen 2026-10-09) - curl quick-start, read from the docs source: (seen 2026-10-09) - editions page: (seen 2026-10-09) - v11 changelog, read from the docs source: (seen 2026-10-09) - server releases and support end dates, read from the docs source: (seen 2026-10-09) - release policy, read from the docs source: (seen 2026-10-09) - removed and deprecated list, read from the docs source: (seen 2026-10-09) - telemetry, read from the docs source: (seen 2026-10-09) - rate limiting settings, read from the docs source: (seen 2026-10-09) - logging and audit logging, read from the docs source: (seen 2026-10-09) - personal access tokens, read from the docs source: (seen 2026-10-09) - bot accounts, read from the docs source: (seen 2026-10-09) - OAuth 2.0, read from the docs source: (seen 2026-10-09) - software and hardware requirements, read from the docs source: (seen 2026-10-09) - certifications and compliance, read from the docs source: (seen 2026-10-09) - security updates page, a script-drawn table whose rows were not read: (seen 2026-10-09) - rate limit response headers in the server source: (seen 2026-10-09) - licence file: (seen 2026-10-09) - security policy: (seen 2026-10-09) - CI workflows: (seen 2026-10-09) - repository page, stars: (seen 2026-10-09) - open issues: (seen 2026-10-09) - Agents plugin admin guide, Mattermost MCP server: (seen 2026-10-09) - MCP server readme in the Agents plugin repository: (seen 2026-10-09) - status page: (seen 2026-10-09) - status history: (seen 2026-10-09) - npm registry, @mattermost/client: (seen 2026-10-09) - npm downloads: (seen 2026-10-09) - RDAP for mattermost.com: (seen 2026-10-09) ## Who's behind it (provenance 69/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Mattermost, Inc. | 20/20 | | Domain age | mattermost.com, registered 2012-12-22 (13 years) | 15/15 | | Endpoint on the vendor's domain | is not on mattermost.com | 0/15 | | Terms of service | read, states 4 of the 7 things a reader expects, and has 1 clause that costs points | 5.4/10 | | Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 | | Status page | status.mattermost.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Software and Services Licence Agreement (effective 12 January 2023) is a contract with Mattermost, Inc. and covers both Cloud Edition and On-Premise subscriptions. The privacy policy (effective 30 December 2024) gives the address 530 Lytton Avenue, Suite 201, Palo Alto, CA 94301. The graded API answers on the owner's own server at https:///api/v4, so the endpoint is not on the vendor's domain. The compiled Team Edition is under MIT and needs no agreement with the vendor. The agreement linked here governs the Enterprise Edition binary, subscriptions and the cloud. status.mattermost.com is a Statuspage site with five components (Sign-Up, Customer Portal, Cloud Workspaces, Calls, Community) and lists no incidents from August to 9 October 2026. It covers the vendor's services, not a self-hosted server. https://mattermost.com/.well-known/security.txt returns 404. SECURITY.md gives responsibledisclosure@mattermost.com, and the disclosure page links a public Bugcrowd programme. The website Terms of Use (effective 8 October 2021) and its Acceptable Use Policy were read first and do not forbid automated access. robots.txt on mattermost.com and docs.mattermost.com allows every path. The Data Processing Addendum page links a document dated 23 December 2022, which was not read. RDAP for mattermost.com gives a registration date of 2012-12-22. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://mattermost.com/software-services-license-agreement/), read 2026-10-09, gives no date, states 4 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "(g) access or use any Product Materials or Services in order to build a competitive product or service." - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Says how changes to the terms are announced. Changes are posted, with no other notice named. - Not found in the text. Lists what users may not do. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Paid subscriptions renew automatically at the fees then current unless the licensee gives written notice at least thirty days before the term ends. "Paid Subscriptions will automatically renew for successive terms (the same length as the Subscription Term) at Mattermost’s then-current fees unless Licensee provides written notice of non-renewal to Mattermost at least thirty days prior to the end of the then-current term" - Also in the text (2026-10-08). The licensee grants Mattermost the right to use its company name and logo as a marketing reference, subject to the licensee’s trademark guidelines. "Licensee grants to Mattermost the right to use Licensee’s company name and logo as a reference for marketing or promotional purposes on Mattermost’s website and in other public or private communications with Mattermost’s existing or potential customers" - Also in the text (2026-10-08). For the Cloud Edition, Mattermost says it backs up the database and has no obligation to do so. "Mattermost regularly backs up the database used in conjunction with the Services, but is under no obligation to do so." **Privacy policy** (https://mattermost.com/privacy-policy/), read 2026-10-09, gives no date, states 6 of the 8 things a reader expects. - Not found in the text. Gives the date it was last updated. - Says how long data is kept. For as long as needed, with no period named. - Not found in the text. Says whether personal data is sold or shared for advertising. - Gives a privacy contact. privacy@mattermost.com. ## Live (updated 2026-10-10 02:50 UTC) - Vendor status page: none, All Systems Operational - github `mattermost/mattermost` v11.11.1, released 2026-09-24 - npm `@mattermost/client` 11.9.0 - Watching changelog - Watching pricing - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/mattermost.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Team Edition (self-hosted) | free | per seat per month | free, MIT binary, REST API included | | Entry (self-hosted) | free | per seat per month | free, 10,000 messages of viewable history, community support only; paid editions have no public price | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Public OpenAPI 3.0 source for API v4, every operation described, 548 of 604 stating the permission needed - Sixteen server releases between 11 July and 8 October 2026, each with a dated changelog entry and an API changes list - Team Edition is free under MIT as a compiled binary, and the free Entry edition needs no card or vendor account - Bot accounts are separate from people, do not count as licensed users, and their tokens can be revoked or disabled - Public Bugcrowd bounty, and a SOC 2 Type II report and ISO 27001:2022 certificate listed on the trust centre ## Weaknesses - Personal access tokens have no scopes and no expiry. A token does whatever its account can do - 52 dot releases from 28 October 2025 to 8 October 2026 carried security fixes, three rated critical and 21 including high-severity fixes - No public price for Professional, Enterprise or Enterprise Advanced, and Mattermost Cloud is sold through sales only - No idempotency key on `POST /api/v4/posts`, so a retried send can post twice - Rate limiting is off by default on a self-hosted server, and no llms.txt or security.txt was found ## Before you call it (notes for agents) 1. Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console 2. Send `Authorization: Bearer ` to `https:///api/v4`. Use `me` in place of a user id for the token's own account 3. Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error 4. Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint 5. If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded` ## Connect Install: ```bash docker run --name mattermost-preview -d --publish 8065:8065 mattermost/mattermost-preview ``` First request: ```bash curl -X POST https://your-mattermost-server.com/api/v4/posts -H 'Authorization: Bearer ' -H 'Content-Type: application/json' -d '{"channel_id": "", "message": "Status update from API"}' ``` Through letme (picks today, calling later): https://letme.dev/mattermost. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Basecamp | B | 67.9 | 237 | work.chat | no | https://www.anchorterminal.com/tools/basecamp.md | | Microsoft Teams (Microsoft Graph) | B | 62.2 | 441 | work.chat | no | https://www.anchorterminal.com/tools/microsoft-teams.md | | Zulip | C | 61.5 | 466 | work.chat | no | https://www.anchorterminal.com/tools/zulip.md | | ClickUp | C | 60.9 | 489 | work.chat | no | https://www.anchorterminal.com/tools/clickup.md | | Slack MCP Server (official) | C | 59.7 | 539 | work.chat | no | https://www.anchorterminal.com/tools/slack-mcp.md | | Outline | C | 60.3 | 523 | same category (Work & productivity) | no | https://www.anchorterminal.com/tools/outline.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The API reference is generated from the OpenAPI source in the server repository and counts 549 endpoints in 38 groups, with samples in curl, PowerShell, Python, Node and Go (source: ) - Bot accounts cannot be logged into, do not count towards the licensed user total, and keep working when the person who created them leaves (source: ) - The Agents plugin has a Mattermost MCP server with 16 built-in tools and a larger catalogue loaded on demand through `search_tools` and `load_tool`. External clients reach it over streamable HTTP with OAuth or a personal access token, from server v11.2 (source: ) - From server v12.0, due in October 2026, sessions and personal access tokens can no longer set post identity override props such as `override_username` (source: ) - Telemetry is on by default. The docs list what is sent and say a self-hosted admin can turn it off in the System Console, while cloud admins cannot (source: ) - The v11 changelog marks 52 dot releases between 28 October 2025 and 8 October 2026 as carrying security fixes, with details published 30 days after each fix (source: ) - #1 of 8 in Best issue tracking, docs and chat tools for AI agents: https://www.anchorterminal.com/best/productivity/index.md - All 40 work comparisons: https://www.anchorterminal.com/compare/productivity/index.md ## Compare - [Mattermost vs Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/compare/mattermost-vs-microsoft-teams.md): B 65.8 vs B 62.2 - [Mattermost vs Slack MCP Server (official)](https://www.anchorterminal.com/compare/mattermost-vs-slack-mcp.md): B 65.8 vs C 59.7 - [Mattermost vs Zulip](https://www.anchorterminal.com/compare/mattermost-vs-zulip.md): B 65.8 vs C 61.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on mattermost.com or one of its subdomains, or the README of github.com/mattermost/mattermost. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "mattermost", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Mattermost on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Mattermost on Anchor Terminal](https://www.anchorterminal.com/badges/mattermost.svg)](https://www.anchorterminal.com/tools/mattermost) ``` Plain link: ```html Mattermost on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Mattermost is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/mattermost-dark.png - Light: https://www.anchorterminal.com/assets/share/mattermost-light.png