Melius
by Melius AI, Inc. HTTP API in Design workspaces & canvases
Hosted
Melius AI, Inc. · melius.com since 1998 · status page · who's behind it
Melius is a hosted node-based canvas for generating images, video, audio and text with many third-party models. Outside agents read and write projects, canvases, nodes, edges, runs and comments through a REST API, an MCP server and the mel CLI.
Good for An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.
Is this your product? Claim this listing or verify it
Assessment. One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://api.melius.com/api/v1- Auth
- OAuth or key
- Pricing
- Freemium · $20 / mo
- x402
- No
- Licence
- Proprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository found
- Tools exposed
- 75
- Packages
npm@melius-ai/cli- Docs
- docs.melius.com
- llms.txt
- published
- Last release
- npm / week
- 9
- REST API
- https://api.melius.com/api/v1, OpenAPI 3.0.2, 59 operations on 51 paths. Projects, canvases, nodes, edges, runs, bulk runs, downloads, comments, presence, uploads, assets, models, voices, fonts, presets, templates, teams and API keys
- MCP server
- Hosted, Streamable HTTP. https://mcp.melius.com/mcp with OAuth sign-in, or https://api.melius.com/mcp with a bearer API key. 75 tools in the reference, 18 of them for Cast, which is in beta
- CLI
- @melius-ai/cli 0.16.2 (10 September 2026), MIT, Node.js 20 or later, also on Homebrew as melius-ai/tap/mel. JSON on stdout, exit codes 0 to 5
- Read vs write
- Reads projects, canvases, nodes, edges, runs, comments, presets, teams and models. Creates and updates the same, starts generations, uploads files, and deletes projects, canvases, nodes and edges
- Generation model
- Asynchronous. Create a node, start a run, poll the run, then request a download URL. Bulk runs take several nodes.
seedfrom 0 to 2147483647 where the model supports it - Credentials
- Bearer API keys (
mel_...) made in Team settings, shown once, optional expiry, revocable at once, no scopes. OAuth for MCP creates a connector key named after the client and tied to one team - Rate limits
- No numbers published. The docs say no plan has a monthly request quota and that bursts can return 429 with
Retry-After. A canvas whose saved state passes 48 MiB returns 400CANVAS_TOO_LARGE - Errors
- 401, 403 and 429 on every operation with
statusCode,errorandmessage. 400, 404 and 409 carrymessage. 400 also covers too few credits - Models
- Third-party image, video, audio and text models. The home page counts 117. GET /generation/models lists them with variants, settings and credit costs
- Free tier
- Free plan at $0 with trial credits, amount not published. Whether sign-up needs a card, and whether Free teams can create API keys, is not stated
- Status
- status.melius.com on incident.io with two components, Web app and MCP. No incidents listed from July to October 2026. No API component
- Data handling
- Terms effective 28 August 2026 say no training on user input or outputs. Privacy policy effective 12 August 2025 gives no retention periods and no named sub-processors
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.0.2 spec with 59 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page
- Hosted MCP server with OAuth sign-in (PKCE, dynamic client registration) or a bearer API key, tied to one team chosen at authorisation
- 429 responses carry
Retry-AfterandretryAfterSeconds, and the docs give a bounded retry policy - The mel CLI prints JSON only, uses six fixed exit codes and returns errors with a
codeand asuggestion - status.melius.com lists no incidents for Web app or MCP from July to October 2026
Weaknesses
- API keys have no scopes. A key works with its creator's role in every team the creator belongs to
- No rate-limit numbers, SLA, public changelog or API deprecation policy found in the reviewed documentation
- The MCP reference lists 75 tools, and the setup guide tells users to select Always Allow for all of them
- Per-model credit costs are returned by an authenticated endpoint and shown in the app, not on the pricing page
- No security.txt or disclosure policy found, and the Vanta trust centre at trust.melius.com needs JavaScript we couldn't run
Before you call it notes for agents
- Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until
statusis finished or failed - Over MCP, call
get_guidefirst,show_presencebefore node changes andcanvas_plan_layoutbeforebulk_create_nodes - On 429 wait
Retry-Afterseconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys - Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits
- Downloads arrive as a ZIP from a signed URL. Fetch that URL without the
Authorizationheader
Who's behind it provenance 72/100
- Legal entity namedMelius AI, Inc.20/20
- Domain agemelius.com, registered 1998-11-24 (27 years)15/15
- Endpoint on the vendor's domainapi.melius.com15/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 3 clauses that cost points2.3/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagestatus.melius.com10/10
- Changelognot found0/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 5 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts automated accesscosts points
(d) Use automated means (including bots, scrapers, or crawlers) to access the Service, except as expressly permitted by Melius;
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
(h) Create an Account or access the Service for the purpose of benchmarking, competitive analysis, or monitoring the availability, performance, or functionality of the Service, or for any other purpose that is competitive with Melius;
A clause against publishing test results or using the service to build something that competes.
Says the terms or the service can change without noticecosts points
We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
ARBITRATION NOTICE: SECTION 16 CONTAINS A BINDING ARBITRATION CLAUSE AND A CLASS ACTION WAIVER.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Delaware
These Terms and any Disputes will be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-laws principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
…OF THE MELIUS PARTIES FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF: (A) THE AMOUNTS YOU HAVE PAID TO MELIUS IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM;
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
If Melius becomes aware that a user under thirteen (13) years of age has created an Account, Melius will terminate that Account.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
If Melius makes material changes to these Terms, Melius will provide notice by posting the updated Terms on the Service at www.melius.com/terms, sending you an email notification, or through other reasonable means.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT ACCESS OR USE THE SERVICE.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Melius does not warrant that third-party AI model providers will refrain from using inputs or outputs for model training or improvement.
(c) Melius does not warrant that Third-Party AI Model providers will not use your User Input or Outputs in ways beyond Melius's control, including for model training or improvement.
Noted by a second reader on 2026-10-08.
Paid subscriptions renew automatically each billing period at the then-current price unless cancelled before the period ends.
Your Subscription will automatically renew at the end of each billing period at Melius's then-current pricing unless you cancel your Subscription before the end of the current billing period.
Noted by a second reader on 2026-10-08.
After termination Melius may delete the account and all associated content, including inputs and outputs, within a reasonable period.
(c) Melius may delete your Account and all associated Content, including User Input, Outputs, and Account data, within a reasonable period following termination.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 8,300 words
Privacy policy gives no date, states 7 of 8, 1 to know
TL;DR Gives no date. States 7 of the 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
We may "share" personal information (as defined under the CCPA) with analytics and advertising partners for purposes of cross-context behavioral advertising.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We may provide additional or supplemental privacy notices for specific products, features, or services at the time we collect information from you.
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We retain your personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law.
Says when data sent to the service is deleted.
Says who else receives the data
The Service integrates third-party artificial intelligence and machine learning models, services, and APIs provided by third-party vendors ("Third-Party AI Models") to process user inputs and produce outputs.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell personal information for monetary consideration.
A plain statement either way.
Says what rights people have over their data
You have the right to object to processing of your personal data based on our legitimate interests.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@melius.com
You may opt out of receiving marketing communications from us by following the unsubscribe instructions in any marketing email we send you, or by contacting us at privacy@melius.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
Standard Contractual Clauses approved by the European Commission (for transfers from the EEA);
The countries data goes to and the safeguard used.
Melius states that it does not control and cannot guarantee how third-party AI model providers handle data.
However, Melius does not control and cannot guarantee the data handling practices of third-party providers.
Noted by a second reader on 2026-10-08.
Users are told not to include sensitive personal information or confidential information in inputs.
Do not include sensitive personal information, confidential information, or information you are not authorized to share in your User Input.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,221 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (effective 28 August 2026) name Melius AI, Inc., 420 Lexington Avenue, New York, as the contracting party and are governed by Delaware law.
The API answers at api.melius.com, the OAuth MCP endpoint at mcp.melius.com and the docs at docs.melius.com, all melius.com subdomains.
/.well-known/security.txt returns 404 on www.melius.com, docs.melius.com and api.melius.com.
RDAP for melius.com gives a registration date of 1998-11-24, which predates the company. The site says it is not affiliated with other organisations that share the Melius name.
No public changelog was found. docs.melius.com/changelog and www.melius.com/changelog return 404, and release dates come from the npm registry.
trust.melius.com is a Vanta trust centre that renders only with JavaScript, so its contents were not read.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.melius.com/api/v1. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- npm
@melius-ai/cli0.16.2 - npm downloads a week 9
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/melius.json
Notable
- The REST API, the CLI and the MCP server run on one backend, and a generation is always a canvas node with a run, with no separate generate endpoint source
- MCP connects three ways. OAuth at https://mcp.melius.com/mcp, a bearer API key at https://api.melius.com/mcp, or a local stdio binary
mel-mcp --hostedsource - The docs say
mel-mcpships with the CLI, but @melius-ai/cli 0.16.2 on npm declares one binary,mel, and its bundle has no MCP command source - An API key works with its creator's access across all that user's teams, capped at the user's role in each, and can be given an expiry source
- OAuth metadata lists the authorisation code grant with S256 PKCE, a registration endpoint and an empty
scopes_supportedsource - Starting a run can answer 202 with an
approvalIdin place of a run id, and GET /agent/approvals/{approvalId} reports pending, approved or denied source - The CLI was first published on 30 June 2026 and reached 0.16.2 on 10 September 2026, 28 versions in ten weeks source
- The terms say Melius does not train models on user input or outputs, and that third-party model providers process content under their own terms source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.8 | |
Graded on the hosted REST API and MCP server. status.melius.com runs on incident.io with component history for Web app and MCP, though it has no API component (20). Its history lists no incidents from July to October 2026, which is as far back as the page goes (30). No rate-limit numbers are published. The docs say only that no plan has a monthly request quota and that bursts can return 429 (0). 429s carry Retry-After and a retryAfterSeconds body field, and the docs give a bounded retry policy and tell clients to check canvas or run state after a timeout or 5xx on a write. There are no idempotency keys (12 of 15). No SLA found (0). The API and MCP server carry no beta label, but the CLI is at 0.16.2 and Cast and media-URL inputs are marked beta (7 of 10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 11.4 | |
Public OpenAPI 3.0.2 spec with 59 operations (25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). 58 of the 59 operations have a summary and no description. The MCP reference gives each of 75 tools one line, with ordering rules for get_guide, show_presence and canvas_plan_layout, and the tool definitions themselves need a signed-in client, so we didn't read them (8 of 20). Request bodies are typed with 336 enums, ranges, UUID formats and required fields, with 52 open additionalProperties objects (13 of 15). 401, 403 and 429 are declared on every operation and 400, 404 and 409 where they apply, but the spec has no examples and most error bodies are a bare message (9 of 15). The path is versioned at /api/v1 and the CLI states semantic versioning. No public changelog found (5 of 15). | |||
| Agent ergonomics | 13%16.2 | 8.3 | |
The MCP reference lists 75 tools, in the over-30 band, with get_guide and get_docs loading guidance on demand and 18 Cast tools shown only to teams with access (10 of 25). Four list operations take limit and offset and three take search, canvas content can be narrowed to one node or to media summaries, and the CLI has --fields (14 of 20). REST errors carry statusCode, error and message, the CLI adds a code and a suggestion, and CANVAS_TOO_LARGE is documented as not worth retrying. A shortage of credits arrives as a plain 400 (14 of 20). No idempotency keys, and we couldn't read MCP annotations without an account. The docs do give safe-retry guidance (5 of 20). Auto model selection and defaults keep required fields few. There is no SDK library, only the CLI and generated code samples in six languages (8 of 15). | |||
| Security & auth | 14%17.5 | 7.5 | |
API keys are revocable at once, can expire and are shown once, but have no scopes. A key works with its creator's access in every team that user belongs to, capped at the user's role. The MCP OAuth flow uses S256 PKCE and dynamic client registration, lists no scopes, and ties the connector key to one team (22 of 30). A key made by a viewer can only read, bulk_delete_node asks the user to confirm and a run can return a pending approval, but there is no read-only key and the setup guide tells users to select Always Allow for every tool (9 of 20). Canvas text, comments from collaborators and files fetched by url_to_canvas reach the model, and no prompt-injection guidance was found (2 of 15). Keys list a lastUsedAt time, connector keys are named after the client, and generation history is kept per member. No audit log is documented (7 of 15). No security.txt, disclosure policy or bug bounty found. A Vanta trust centre exists at trust.melius.com but needs JavaScript, so certifications are unchecked (3 of 20). | |||
| Payments & pricing | 10%12.5 | 2.5 | |
| No machine payment protocol (0). Plan prices and monthly credits are public, but per-model credit costs sit behind an authenticated endpoint and the top-up price is not published (10 of 20). A Free plan at $0 gives trial credits. The amount is not published and we couldn't confirm that sign-up needs no card (10 of 20). A person signs up in a browser and creates the first key in Team settings. POST /api-keys needs an existing key (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.8 | |
| The newest dated release is the CLI, 0.16.2 on 10 September 2026, 28 days before the check (30). npm lists 19 CLI versions since 10 July 2026 (20). Closed service with no public changelog or issue tracker. Support is by email at support@melius.com and a Discord server linked from the site (5 of 15). The server is not in the official MCP registry and there is no SDK library, though the CLI is current on npm and Homebrew (5 of 15). The CLI has three dependencies, needs Node.js 20 and is published from GitHub Actions through npm trusted publishing. Its source is not public (6 of 10). | |||
| Transparency & trusteditorial 38, provenance 72 | 7%8.8 | 4.8 | |
| Closed service under published terms effective 28 August 2026. The CLI package is MIT with no public repository (15 of 30). The terms, the privacy policy and the pricing FAQ agree that user input and outputs are not used to train models, and say third-party model providers process content under their own terms without a guarantee from Melius. Retention is described as a reasonable period with no numbers, and no DPA was found (14 of 30). Deprecated models keep working for an unstated grace period with an in-app warning. No API deprecation policy found (5 of 20). No sub-processor list or hosting location found beyond a statement that data is processed in the United States (4 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 54.1 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Melius, or have the agent fetch /fixes/melius.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Melius
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/melius, the October 2026 research run, assessed 8 October 2026. Grade C, 54.1 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Melius: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Security & auth, 43 out of 100, up to 10 more on the total
Why it scored 43: API keys are revocable at once, can expire and are shown once, but have no scopes. A key works with its creator's access in every team that user belongs to, capped at the user's role. The MCP OAuth flow uses S256 PKCE and dynamic client registration, lists no scopes, and ties the connector key to one team (22 of 30). A key made by a viewer can only read, `bulk_delete_node` asks the user to confirm and a run can return a pending approval, but there is no read-only key and the setup guide tells users to select Always Allow for every tool (9 of 20). Canvas text, comments from collaborators and files fetched by `url_to_canvas` reach the model, and no prompt-injection guidance was found (2 of 15). Keys list a `lastUsedAt` time, connector keys are named after the client, and generation history is kept per member. No audit log is documented (7 of 15). No security.txt, disclosure policy or bug bounty found. A Vanta trust centre exists at trust.melius.com but needs JavaScript, so certifications are unchecked (3 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 2. Payments & pricing, 20 out of 100, up to 10 more on the total
Why it scored 20: No machine payment protocol (0). Plan prices and monthly credits are public, but per-model credit costs sit behind an authenticated endpoint and the top-up price is not published (10 of 20). A Free plan at $0 gives trial credits. The amount is not published and we couldn't confirm that sign-up needs no card (10 of 20). A person signs up in a browser and creates the first key in Team settings. POST /api-keys needs an existing key (0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 3. Agent ergonomics, 51 out of 100, up to 8 more on the total
Why it scored 51: The MCP reference lists 75 tools, in the over-30 band, with `get_guide` and `get_docs` loading guidance on demand and 18 Cast tools shown only to teams with access (10 of 25). Four list operations take `limit` and `offset` and three take `search`, canvas content can be narrowed to one node or to media summaries, and the CLI has `--fields` (14 of 20). REST errors carry `statusCode`, `error` and `message`, the CLI adds a `code` and a `suggestion`, and `CANVAS_TOO_LARGE` is documented as not worth retrying. A shortage of credits arrives as a plain 400 (14 of 20). No idempotency keys, and we couldn't read MCP annotations without an account. The docs do give safe-retry guidance (5 of 20). Auto model selection and defaults keep required fields few. There is no SDK library, only the CLI and generated code samples in six languages (8 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 4. Reliability, 69 out of 100, up to 6.2 more on the total
Why it scored 69: Graded on the hosted REST API and MCP server. status.melius.com runs on incident.io with component history for Web app and MCP, though it has no API component (20). Its history lists no incidents from July to October 2026, which is as far back as the page goes (30). No rate-limit numbers are published. The docs say only that no plan has a monthly request quota and that bursts can return 429 (0). 429s carry `Retry-After` and a `retryAfterSeconds` body field, and the docs give a bounded retry policy and tell clients to check canvas or run state after a timeout or 5xx on a write. There are no idempotency keys (12 of 15). No SLA found (0). The API and MCP server carry no beta label, but the CLI is at 0.16.2 and Cast and media-URL inputs are marked beta (7 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 5. Schema & documentation, 70 out of 100, up to 4.9 more on the total
Why it scored 70: Public OpenAPI 3.0.2 spec with 59 operations (25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). 58 of the 59 operations have a summary and no description. The MCP reference gives each of 75 tools one line, with ordering rules for `get_guide`, `show_presence` and `canvas_plan_layout`, and the tool definitions themselves need a signed-in client, so we didn't read them (8 of 20). Request bodies are typed with 336 enums, ranges, UUID formats and required fields, with 52 open `additionalProperties` objects (13 of 15). 401, 403 and 429 are declared on every operation and 400, 404 and 409 where they apply, but the spec has no examples and most error bodies are a bare `message` (9 of 15). The path is versioned at /api/v1 and the CLI states semantic versioning. No public changelog found (5 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 6. Transparency & trust, 55 out of 100, up to 3.9 more on the total
Made of editorial 38, provenance 72.
Why it scored 55: Closed service under published terms effective 28 August 2026. The CLI package is MIT with no public repository (15 of 30). The terms, the privacy policy and the pricing FAQ agree that user input and outputs are not used to train models, and say third-party model providers process content under their own terms without a guarantee from Melius. Retention is described as a reasonable period with no numbers, and no DPA was found (14 of 30). Deprecated models keep working for an unstated grace period with an in-app warning. No API deprecation policy found (5 of 20). No sub-processor list or hosting location found beyond a statement that data is processed in the United States (4 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Terms of service: read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points (2.3 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)
- Changelog: not found (0 of 10)
- security.txt: not found (0 of 10)
## 7. Maintenance & community, 66 out of 100, up to 3 more on the total
Why it scored 66: The newest dated release is the CLI, 0.16.2 on 10 September 2026, 28 days before the check (30). npm lists 19 CLI versions since 10 July 2026 (20). Closed service with no public changelog or issue tracker. Support is by email at support@melius.com and a Discord server linked from the site (5 of 15). The server is not in the official MCP registry and there is no SDK library, though the CLI is current on npm and Homebrew (5 of 15). The CLI has three dependencies, needs Node.js 20 and is published from GitHub Actions through npm trusted publishing. Its source is not public (6 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: trust.melius.com is a Vanta trust centre that needs JavaScript, so certifications, sub-processors and security policies listed there were not read.
- unchecked: MCP tool definitions and annotations (readOnlyHint, destructiveHint), which need a signed-in client.
- unchecked: whether the Free plan needs a card, how many trial credits it gives, and whether Free teams can create API keys. The sign-up flow is at app.melius.com behind a login.
- The docs say the `mel-mcp` stdio binary ships with the CLI, but @melius-ai/cli 0.16.2 declares only `mel` and its bundle has no MCP command. We found no other package that carries it.
- The pricing page shows two sets of figures. Plan cards give $20, $50, $110 and $70 monthly ($17, $43, $93, $56 on annual billing), and the comparison table gives $18, $45, $99+ and $63.
- No rate-limit numbers, MCP usage limits, SLA, changelog or API deprecation policy were found. The docs mention a team MCP usage record without describing a cap.
- Category kept as design with `design.canvas` first, because every generation is a canvas node and the API has no separate generate endpoint. Image generation is the alternative.
## Weaknesses
- API keys have no scopes. A key works with its creator's role in every team the creator belongs to
- No rate-limit numbers, SLA, public changelog or API deprecation policy found in the reviewed documentation
- The MCP reference lists 75 tools, and the setup guide tells users to select Always Allow for all of them
- Per-model credit costs are returned by an authenticated endpoint and shown in the app, not on the pricing page
- No security.txt or disclosure policy found, and the Vanta trust centre at trust.melius.com needs JavaScript we couldn't run
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until `status` is finished or failed
- Over MCP, call `get_guide` first, `show_presence` before node changes and `canvas_plan_layout` before `bulk_create_nodes`
- On 429 wait `Retry-After` seconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys
- Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits
- Downloads arrive as a ZIP from a signed URL. Fetch that URL without the `Authorization` header
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: trust.melius.com is a Vanta trust centre that needs JavaScript, so certifications, sub-processors and security policies listed there were not read.
- unchecked: MCP tool definitions and annotations (readOnlyHint, destructiveHint), which need a signed-in client.
- unchecked: whether the Free plan needs a card, how many trial credits it gives, and whether Free teams can create API keys. The sign-up flow is at app.melius.com behind a login.
- The docs say the
mel-mcpstdio binary ships with the CLI, but @melius-ai/cli 0.16.2 declares onlymeland its bundle has no MCP command. We found no other package that carries it. - The pricing page shows two sets of figures. Plan cards give $20, $50, $110 and $70 monthly ($17, $43, $93, $56 on annual billing), and the comparison table gives $18, $45, $99+ and $63.
- No rate-limit numbers, MCP usage limits, SLA, changelog or API deprecation policy were found. The docs mention a team MCP usage record without describing a cap.
- Category kept as design with
design.canvasfirst, because every generation is a canvas node and the API has no separate generate endpoint. Image generation is the alternative.
Sources 17
- API overview, rate limits and retry guidance docs.melius.com · seen 2026-10-08
- API authentication and key scoping docs.melius.com · seen 2026-10-08
- OpenAPI spec docs.melius.com · seen 2026-10-08
- MCP server overview docs.melius.com · seen 2026-10-08
- MCP tool reference docs.melius.com · seen 2026-10-08
- MCP OAuth metadata mcp.melius.com · seen 2026-10-08
- CLI installation, commands and agent guide docs.melius.com · seen 2026-10-08
- docs index for agents docs.melius.com · seen 2026-10-08
- pricing melius.com · seen 2026-10-08
- plans and billing docs.melius.com · seen 2026-10-08
- status history status.melius.com · seen 2026-10-08
- terms of service melius.com · seen 2026-10-08
- privacy policy melius.com · seen 2026-10-08
- npm registry entry for the CLI registry.npmjs.org · seen 2026-10-08
- Homebrew tap github.com · seen 2026-10-08
- official MCP registry search, no result registry.modelcontextprotocol.io · seen 2026-10-08
- RDAP for melius.com rdap.verisign.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $20 / mo Free plan at $0 with trial credits, amount not published. Creator $20 a month for 20,000 credits, Growth $50 for 50,000, Professional $110 for 110,000, Team $70 a seat for 70,000 pooled credits (2 to 10 seats), Enterprise custom. Annual billing cuts 15 to 20 per cent. API, CLI and MCP calls have no separate charge and generations draw team credits. Per-model credit costs come from an authenticated endpoint, not the pricing page. The page's comparison table shows different figures ($18, $45, $99+, $63). Whether Free teams can create API keys is not stated (https://www.melius.com/pricing, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Creator plan | $20 | per month (plan) | 20,000 credits a month, $17 a month on annual billing |
| Growth plan | $50 | per month (plan) | 50,000 credits a month, $43 on annual billing |
| Professional plan | $110 | per month (plan) | 110,000 credits a month, $93 on annual billing. A 300,000-credit option is also listed |
| Team plan | $70 | per seat per month | 70,000 pooled credits a seat, 2 to 10 seats, $56 on annual billing |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/melius.xml, or this listing's score history at history.json.
Connect
Install
npm install -g @melius-ai/cli
First request
curl -s -H "Authorization: Bearer $MEL_API_KEY" https://api.melius.com/api/v1/teams
Claude Code
claude mcp add melius --transport http https://mcp.melius.com/mcp --scope user
MCP client configuration
{
"mcpServers": {
"melius": {
"url": "https://mcp.melius.com/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/melius
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Osmo CLI ELocalAI BFigma API + MCP Bfal image models BMiro API + MCP BLucid API + MCP C
Head to head Figma API + MCP vs Melius · Framer Server API vs Melius · Melius vs Miro API + MCP · Melius vs Penpot API + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Osmo CLI Osmo Technologies Inc. | E | 45.2 | image.edit video.generate image.generate speech.tts design.comments | no |
| LocalAI Ettore Di Giacinto and the LocalAI team | B | 68 | speech.tts image.generate video.generate | no |
| Figma API + MCP Figma | B | 66 | design.files design.canvas design.comments | no |
| fal image models fal (Features & Labels, Inc.) | B | 65.2 | image.generate image.edit image.upscale | no |
| Miro API + MCP Miro | B | 65 | design.files design.canvas design.comments | no |
| Lucid API + MCP Lucid Software | C | 60.6 | design.files design.canvas design.comments | no |
Machine-readable
- JSON
/api/v1/tools/melius.json· historyhistory.json· badge/badges/melius.svg· changes feed/feeds/tools/melius.xml - Markdown
/tools/melius.md· slim/tools/melius.min.md(or sendAccept: text/markdown) - Fix list
/fixes/melius.md·/fixes/melius.json - From a terminal
anchor tool melius --md(the CLI) · over MCPget_tool {"slug": "melius"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/melius"><img src="https://www.anchorterminal.com/badges/melius.svg" alt="Melius on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/melius)<a href="https://www.anchorterminal.com/tools/melius">Melius on Anchor Terminal</a>It counts on a page on melius.com or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "melius", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
