# Mattermost (slim) > Mattermost is an open-core team chat server from Mattermost, Inc. that its owner hosts, with channels, threads, calls and playbooks. Agents reach it through the REST API v4, bot accounts, personal access tokens, webhooks and an MCP server. - Full: https://www.anchorterminal.com/tools/mattermost.md (~8,850 tokens) · this version ~2,030 tokens · JSON https://www.anchorterminal.com/tools/mattermost.json · canonical https://www.anchorterminal.com/tools/mattermost - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 65.8/100 · rank #310 of 950 · #1 in Work & productivity · not agent-ready · confidence medium** Assessment: The REST API v4 has a public OpenAPI source of about 600 operations, a dated changelog with API changes per release, and 16 server releases in 90 days. Personal access tokens have no scopes or expiry, paid editions have no public price, and 52 dot releases in twelve months carried security fixes, three of them rated critical. ## Facts - Kind: HTTP API · vendor: Mattermost, Inc. · category: Work & productivity · legal entity: Mattermost, Inc. · provenance 69/100 - Local only (HTTP): npm `@mattermost/client`, go `github.com/mattermost/mattermost/server/public` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Open core. Team Edition is MIT as a compiled binary. The source is AGPL v3 or a commercial licence, with admin tools and configuration files under Apache 2.0. Enterprise Edition, which the free Entry edition runs, is under a commercial licence. The Agents plugin is Apache 2.0 - Probe metrics: not measured yet (probes haven't run) - Surface graded: The REST API v4 of a self-hosted Mattermost server at https:///api/v4. Mattermost Cloud runs the same software and is sold through sales only - API: OpenAPI 3.0 source in 57 YAML files, 604 operations on 485 paths on master on 9 October 2026. Users (79 operations), channels (62), system (51), teams (38), posts (28), groups (26). JSON request and response bodies. Events arrive over a WebSocket at `/api/v4/websocket` - Credentials: Session tokens from `POST /api/v4/users/login`, personal access tokens with no scopes or expiry, bot accounts, and OAuth 2.0 with PKCE and optional dynamic client registration. All sent as a Bearer token - Rate limits: Off by default on a self-hosted server. When enabled, 10 requests a second with a burst of 100, varied by IP address by default, with `X-Ratelimit-Limit`, `X-Ratelimit-Remaining` and `X-Ratelimit-Reset` headers. A 429 body is the text `limit exceeded` - Errors: JSON with `id`, `message`, `request_id`, `status_code` and `is_oauth`. 204 operations list 501 for functions the server's edition or configuration does not include - Pagination: `page` and `per_page`, default 60, maximum 200, larger values cut without an error. Channel posts also take `since`, `before` and `after` - MCP server: Inside the Agents plugin at https:///plugins/mattermost-ai/mcp-server/mcp over streamable HTTP, off until an admin enables it. 16 built-in tools such as `read_channel`, `search_posts` and `create_post`, more loaded through `search_tools` and `load_tool`. Built-in tools are read-only without an Enterprise licence, which Entry counts as - Drivers: Official TypeScript `@mattermost/client` 11.9.0 on npm and the Go `Client4` in `github.com/mattermost/mattermost/server/public`, tagged v0.4.4. Community drivers are listed in the marketplace - Editions: Team Edition (MIT binary, free, no single sign-on), Entry (free mode of Enterprise Edition, 10,000 messages of history, no compliance tools or high availability), Professional, Enterprise and Enterprise Advanced by subscription - Releases: A feature release on the 16th of each month, supported for three months, and an extended support release every nine months, supported for twelve. 11.11.1 on 24 September 2026 and 11.7.12 (extended support) on 8 October 2026. Requires PostgreSQL 14 or later - Audit: Audit logging records REST API and mmctl activity to a JSON schema, to file, syslog or TCP targets. The docs label it Beta and it is not written to a file by default - Certifications: The trust centre lists a SOC 2 Type II report (2025), a SOC 3 badge and an ISO 27001:2022 certificate, with annual third-party penetration tests. Public bug bounty on Bugcrowd - Sub-processors: Thirteen named with role and country, all in the United States, among them Amazon Web Services, Microsoft, Cloudflare, Anthropic and OpenAI, last updated 23 December 2024. They apply to the vendor's services, not to a self-hosted server - Prices: Team Edition (self-hosted) free per seat per month; Entry (self-hosted) free per seat per month - Scores: Reliability 83, Performance pending, Schema & documentation 76, Agent ergonomics 63, Security & auth 63, Payments & pricing 50, Task success pending, Maintenance & community 89, Transparency & trust 75 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, since the graded surface is the server its owner hosts. · Schema & documentation, The OpenAPI 3.0 source is public in the repository, 57 YAML path files with 604 operations on 485 paths on the master branch. · Agent ergonomics, List endpoints take `per_page` up to 200 with a default of 60, and channel posts take `since`, `before` and `after`. · Security & auth, Personal access tokens are named, several per account, and can be revoked or disabled by the user or an admin. · Payments & pricing, Read with the self-hosted rule. · Maintenance & community, Server 11.7.12 was released on 8 October 2026, one day before the check, and 11.11.1 on 24 September (30). · Transparency & trust, Team Edition is MIT as a compiled binary, the source is AGPL v3 or a commercial licence with parts under Apache 2.0, and the Enterprise Edit… - Sources: 42, open questions: 12, both in the full twin - Capabilities: work.chat - JSON: https://www.anchorterminal.com/api/v1/tools/mattermost.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/mattermost.svg` or a link to https://www.anchorterminal.com/tools/mattermost from a page on mattermost.com or one of its subdomains, or the README of github.com/mattermost/mattermost, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask the system admin for a bot account and its token. Bot creation and personal access tokens are both off until enabled in the System Console 2. Send `Authorization: Bearer ` to `https:///api/v4`. Use `me` in place of a user id for the token's own account 3. Page with `page` and `per_page`. The maximum is 200, the default 60, and larger values are cut without an error 4. Read the error `id` and `status_code`. A 501 means the server's edition or licence does not include that endpoint 5. If the server has rate limiting on, read `X-Ratelimit-Remaining` and `X-Ratelimit-Reset`. The 429 body is the plain text `limit exceeded` ## Connect ```bash docker run --name mattermost-preview -d --publish 8065:8065 mattermost/mattermost-preview ``` ```bash curl -X POST https://your-mattermost-server.com/api/v4/posts -H 'Authorization: Bearer ' -H 'Content-Type: application/json' -d '{"channel_id": "", "message": "Status update from API"}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/mattermost ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Basecamp | B | 67.9 | work.chat | https://www.anchorterminal.com/tools/basecamp.min.md | | Microsoft Teams (Microsoft Graph) | B | 62.2 | work.chat | https://www.anchorterminal.com/tools/microsoft-teams.min.md | | Zulip | C | 61.5 | work.chat | https://www.anchorterminal.com/tools/zulip.min.md | | ClickUp | C | 60.9 | work.chat | https://www.anchorterminal.com/tools/clickup.min.md | | Slack MCP Server (official) | C | 59.7 | work.chat | https://www.anchorterminal.com/tools/slack-mcp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)