{
  "data": {
    "similar": [
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/osmo-cli.json",
        "name": "Osmo CLI",
        "score": 45.2,
        "shared": [
          "image.edit",
          "video.generate",
          "image.generate",
          "speech.tts",
          "design.comments"
        ],
        "slug": "osmo-cli"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/localai.json",
        "name": "LocalAI",
        "score": 68,
        "shared": [
          "speech.tts",
          "image.generate",
          "video.generate"
        ],
        "slug": "localai"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/figma-mcp.json",
        "name": "Figma API + MCP",
        "score": 66,
        "shared": [
          "design.files",
          "design.canvas",
          "design.comments"
        ],
        "slug": "figma-mcp"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/fal-image.json",
        "name": "fal image models",
        "score": 65.2,
        "shared": [
          "image.generate",
          "image.edit",
          "image.upscale"
        ],
        "slug": "fal-image"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/miro.json",
        "name": "Miro API + MCP",
        "score": 65,
        "shared": [
          "design.files",
          "design.canvas",
          "design.comments"
        ],
        "slug": "miro"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/lucid.json",
        "name": "Lucid API + MCP",
        "score": 60.6,
        "shared": [
          "design.files",
          "design.canvas",
          "design.comments"
        ],
        "slug": "lucid"
      }
    ],
    "tool": {
      "slug": "melius",
      "name": "Melius",
      "vendor": "Melius AI, Inc.",
      "vendorUrl": "https://www.melius.com",
      "kind": "http-api",
      "category": "design",
      "summary": "Melius is a hosted node-based canvas for generating images, video, audio and text with many third-party models. Outside agents read and write projects, canvases, nodes, edges, runs and comments through a REST API, an MCP server and the mel CLI.",
      "url": "https://www.anchorterminal.com/tools/melius",
      "markdownUrl": "https://www.anchorterminal.com/tools/melius.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/melius.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/melius.json",
      "license": "Proprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository found",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.melius.com/api/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@melius-ai/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an API key in the Melius app under Team settings, Integrations. The REST API, the CLI and the MCP endpoint at https://api.melius.com/mcp take it as a Bearer token, with an optional `x-team-id` header. The MCP endpoint at https://mcp.melius.com/mcp uses OAuth (authorisation code with S256 PKCE and dynamic client registration), where the user signs in, picks one team and Melius creates a connector key. Keys have no scopes. A key works with its creator's access and that user's role in each team. Access is self-serve, with no app review or sales approval.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with trial credits, amount not published. Creator $20 a month for 20,000 credits, Growth $50 for 50,000, Professional $110 for 110,000, Team $70 a seat for 70,000 pooled credits (2 to 10 seats), Enterprise custom. Annual billing cuts 15 to 20 per cent. API, CLI and MCP calls have no separate charge and generations draw team credits. Per-model credit costs come from an authenticated endpoint, not the pricing page. The page's comparison table shows different figures ($18, $45, $99+, $63). Whether Free teams can create API keys is not stated (https://www.melius.com/pricing, checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API, MCP or CLI docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 75,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 9,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.melius.com",
      "llmsTxt": "https://docs.melius.com/llms.txt",
      "openapi": "https://docs.melius.com/api/openapi.json",
      "capabilities": [
        "design.canvas",
        "design.comments",
        "design.files",
        "image.generate",
        "image.edit",
        "image.upscale",
        "video.generate",
        "speech.tts"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "closed-source",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "cli",
        "async-jobs",
        "status-page",
        "pre-1.0"
      ],
      "lastRelease": "2026-09-10",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.1,
        "grade": "C",
        "agentReady": false,
        "rank": 473,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 66,
          "payments": 20,
          "reliability": 69,
          "schema": 70,
          "security": 43,
          "transparency": 55
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 69,
            "points": 13.8,
            "reason": "Graded on the hosted REST API and MCP server. status.melius.com runs on incident.io with component history for Web app and MCP, though it has no API component (20). Its history lists no incidents from July to October 2026, which is as far back as the page goes (30). No rate-limit numbers are published. The docs say only that no plan has a monthly request quota and that bursts can return 429 (0). 429s carry `Retry-After` and a `retryAfterSeconds` body field, and the docs give a bounded retry policy and tell clients to check canvas or run state after a timeout or 5xx on a write. There are no idempotency keys (12 of 15). No SLA found (0). The API and MCP server carry no beta label, but the CLI is at 0.16.2 and Cast and media-URL inputs are marked beta (7 of 10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "Public OpenAPI 3.0.2 spec with 59 operations (25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). 58 of the 59 operations have a summary and no description. The MCP reference gives each of 75 tools one line, with ordering rules for `get_guide`, `show_presence` and `canvas_plan_layout`, and the tool definitions themselves need a signed-in client, so we didn't read them (8 of 20). Request bodies are typed with 336 enums, ranges, UUID formats and required fields, with 52 open `additionalProperties` objects (13 of 15). 401, 403 and 429 are declared on every operation and 400, 404 and 409 where they apply, but the spec has no examples and most error bodies are a bare `message` (9 of 15). The path is versioned at /api/v1 and the CLI states semantic versioning. No public changelog found (5 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 51,
            "points": 8.29,
            "reason": "The MCP reference lists 75 tools, in the over-30 band, with `get_guide` and `get_docs` loading guidance on demand and 18 Cast tools shown only to teams with access (10 of 25). Four list operations take `limit` and `offset` and three take `search`, canvas content can be narrowed to one node or to media summaries, and the CLI has `--fields` (14 of 20). REST errors carry `statusCode`, `error` and `message`, the CLI adds a `code` and a `suggestion`, and `CANVAS_TOO_LARGE` is documented as not worth retrying. A shortage of credits arrives as a plain 400 (14 of 20). No idempotency keys, and we couldn't read MCP annotations without an account. The docs do give safe-retry guidance (5 of 20). Auto model selection and defaults keep required fields few. There is no SDK library, only the CLI and generated code samples in six languages (8 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 43,
            "points": 7.53,
            "reason": "API keys are revocable at once, can expire and are shown once, but have no scopes. A key works with its creator's access in every team that user belongs to, capped at the user's role. The MCP OAuth flow uses S256 PKCE and dynamic client registration, lists no scopes, and ties the connector key to one team (22 of 30). A key made by a viewer can only read, `bulk_delete_node` asks the user to confirm and a run can return a pending approval, but there is no read-only key and the setup guide tells users to select Always Allow for every tool (9 of 20). Canvas text, comments from collaborators and files fetched by `url_to_canvas` reach the model, and no prompt-injection guidance was found (2 of 15). Keys list a `lastUsedAt` time, connector keys are named after the client, and generation history is kept per member. No audit log is documented (7 of 15). No security.txt, disclosure policy or bug bounty found. A Vanta trust centre exists at trust.melius.com but needs JavaScript, so certifications are unchecked (3 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No machine payment protocol (0). Plan prices and monthly credits are public, but per-model credit costs sit behind an authenticated endpoint and the top-up price is not published (10 of 20). A Free plan at $0 gives trial credits. The amount is not published and we couldn't confirm that sign-up needs no card (10 of 20). A person signs up in a browser and creates the first key in Team settings. POST /api-keys needs an existing key (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 66,
            "points": 5.78,
            "reason": "The newest dated release is the CLI, 0.16.2 on 10 September 2026, 28 days before the check (30). npm lists 19 CLI versions since 10 July 2026 (20). Closed service with no public changelog or issue tracker. Support is by email at support@melius.com and a Discord server linked from the site (5 of 15). The server is not in the official MCP registry and there is no SDK library, though the CLI is current on npm and Homebrew (5 of 15). The CLI has three dependencies, needs Node.js 20 and is published from GitHub Actions through npm trusted publishing. Its source is not public (6 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 55,
            "points": 4.81,
            "note": "editorial 38, provenance 72",
            "reason": "Closed service under published terms effective 28 August 2026. The CLI package is MIT with no public repository (15 of 30). The terms, the privacy policy and the pricing FAQ agree that user input and outputs are not used to train models, and say third-party model providers process content under their own terms without a guarantee from Melius. Retention is described as a reasonable period with no numbers, and no DPA was found (14 of 30). Deprecated models keep working for an unstated grace period with an in-app warning. No API deprecation policy found (5 of 20). No sub-processor list or hosting location found beyond a statement that data is processed in the United States (4 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP reference lists 75 tools, in the over-30 band, with `get_guide` and `get_docs` loading guidance on demand and 18 Cast tools shown only to teams with access (10 of 25). Four list operations take `limit` and `offset` and three take `search`, canvas content can be narrowed to one node or to media summaries, and the CLI has `--fields` (14 of 20). REST errors carry `statusCode`, `error` and `message`, the CLI adds a `code` and a `suggestion`, and `CANVAS_TOO_LARGE` is documented as not worth retrying. A shortage of credits arrives as a plain 400 (14 of 20). No idempotency keys, and we couldn't read MCP annotations without an account. The docs do give safe-retry guidance (5 of 20). Auto model selection and defaults keep required fields few. There is no SDK library, only the CLI and generated code samples in six languages (8 of 15).",
            "maintenance": "The newest dated release is the CLI, 0.16.2 on 10 September 2026, 28 days before the check (30). npm lists 19 CLI versions since 10 July 2026 (20). Closed service with no public changelog or issue tracker. Support is by email at support@melius.com and a Discord server linked from the site (5 of 15). The server is not in the official MCP registry and there is no SDK library, though the CLI is current on npm and Homebrew (5 of 15). The CLI has three dependencies, needs Node.js 20 and is published from GitHub Actions through npm trusted publishing. Its source is not public (6 of 10).",
            "payments": "No machine payment protocol (0). Plan prices and monthly credits are public, but per-model credit costs sit behind an authenticated endpoint and the top-up price is not published (10 of 20). A Free plan at $0 gives trial credits. The amount is not published and we couldn't confirm that sign-up needs no card (10 of 20). A person signs up in a browser and creates the first key in Team settings. POST /api-keys needs an existing key (0).",
            "reliability": "Graded on the hosted REST API and MCP server. status.melius.com runs on incident.io with component history for Web app and MCP, though it has no API component (20). Its history lists no incidents from July to October 2026, which is as far back as the page goes (30). No rate-limit numbers are published. The docs say only that no plan has a monthly request quota and that bursts can return 429 (0). 429s carry `Retry-After` and a `retryAfterSeconds` body field, and the docs give a bounded retry policy and tell clients to check canvas or run state after a timeout or 5xx on a write. There are no idempotency keys (12 of 15). No SLA found (0). The API and MCP server carry no beta label, but the CLI is at 0.16.2 and Cast and media-URL inputs are marked beta (7 of 10).",
            "schema": "Public OpenAPI 3.0.2 spec with 59 operations (25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). 58 of the 59 operations have a summary and no description. The MCP reference gives each of 75 tools one line, with ordering rules for `get_guide`, `show_presence` and `canvas_plan_layout`, and the tool definitions themselves need a signed-in client, so we didn't read them (8 of 20). Request bodies are typed with 336 enums, ranges, UUID formats and required fields, with 52 open `additionalProperties` objects (13 of 15). 401, 403 and 429 are declared on every operation and 400, 404 and 409 where they apply, but the spec has no examples and most error bodies are a bare `message` (9 of 15). The path is versioned at /api/v1 and the CLI states semantic versioning. No public changelog found (5 of 15).",
            "security": "API keys are revocable at once, can expire and are shown once, but have no scopes. A key works with its creator's access in every team that user belongs to, capped at the user's role. The MCP OAuth flow uses S256 PKCE and dynamic client registration, lists no scopes, and ties the connector key to one team (22 of 30). A key made by a viewer can only read, `bulk_delete_node` asks the user to confirm and a run can return a pending approval, but there is no read-only key and the setup guide tells users to select Always Allow for every tool (9 of 20). Canvas text, comments from collaborators and files fetched by `url_to_canvas` reach the model, and no prompt-injection guidance was found (2 of 15). Keys list a `lastUsedAt` time, connector keys are named after the client, and generation history is kept per member. No audit log is documented (7 of 15). No security.txt, disclosure policy or bug bounty found. A Vanta trust centre exists at trust.melius.com but needs JavaScript, so certifications are unchecked (3 of 20).",
            "transparency": "Closed service under published terms effective 28 August 2026. The CLI package is MIT with no public repository (15 of 30). The terms, the privacy policy and the pricing FAQ agree that user input and outputs are not used to train models, and say third-party model providers process content under their own terms without a guarantee from Melius. Retention is described as a reasonable period with no numbers, and no DPA was found (14 of 30). Deprecated models keep working for an unstated grace period with an in-app warning. No API deprecation policy found (5 of 20). No sub-processor list or hosting location found beyond a statement that data is processed in the United States (4 of 20)."
          },
          "sources": [
            {
              "what": "API overview, rate limits and retry guidance",
              "url": "https://docs.melius.com/api/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "API authentication and key scoping",
              "url": "https://docs.melius.com/api/authentication",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI spec",
              "url": "https://docs.melius.com/api/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server overview",
              "url": "https://docs.melius.com/mcp/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP tool reference",
              "url": "https://docs.melius.com/mcp/tools",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP OAuth metadata",
              "url": "https://mcp.melius.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI installation, commands and agent guide",
              "url": "https://docs.melius.com/cli/commands",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://docs.melius.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.melius.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "plans and billing",
              "url": "https://docs.melius.com/billing/plans",
              "seen": "2026-10-08"
            },
            {
              "what": "status history",
              "url": "https://status.melius.com/history",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.melius.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.melius.com/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "npm registry entry for the CLI",
              "url": "https://registry.npmjs.org/@melius-ai/cli",
              "seen": "2026-10-08"
            },
            {
              "what": "Homebrew tap",
              "url": "https://github.com/melius-ai/homebrew-tap",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search, no result",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=melius",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for melius.com",
              "url": "https://rdap.verisign.com/com/v1/domain/melius.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: trust.melius.com is a Vanta trust centre that needs JavaScript, so certifications, sub-processors and security policies listed there were not read.",
            "unchecked: MCP tool definitions and annotations (readOnlyHint, destructiveHint), which need a signed-in client.",
            "unchecked: whether the Free plan needs a card, how many trial credits it gives, and whether Free teams can create API keys. The sign-up flow is at app.melius.com behind a login.",
            "The docs say the `mel-mcp` stdio binary ships with the CLI, but @melius-ai/cli 0.16.2 declares only `mel` and its bundle has no MCP command. We found no other package that carries it.",
            "The pricing page shows two sets of figures. Plan cards give $20, $50, $110 and $70 monthly ($17, $43, $93, $56 on annual billing), and the comparison table gives $18, $45, $99+ and $63.",
            "No rate-limit numbers, MCP usage limits, SLA, changelog or API deprecation policy were found. The docs mention a team MCP usage record without describing a cap.",
            "Category kept as design with `design.canvas` first, because every generation is a canvas node and the API has no separate generate endpoint. Image generation is the alternative."
          ]
        },
        "negative": 0,
        "verdict": "One backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.",
        "bestFor": "An agent producing batches of ad creative, product images or short videos on a shared canvas that people then review, with many models behind one key.",
        "strengths": [
          "Public OpenAPI 3.0.2 spec with 59 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
          "Hosted MCP server with OAuth sign-in (PKCE, dynamic client registration) or a bearer API key, tied to one team chosen at authorisation",
          "429 responses carry `Retry-After` and `retryAfterSeconds`, and the docs give a bounded retry policy",
          "The mel CLI prints JSON only, uses six fixed exit codes and returns errors with a `code` and a `suggestion`",
          "status.melius.com lists no incidents for Web app or MCP from July to October 2026"
        ],
        "weaknesses": [
          "API keys have no scopes. A key works with its creator's role in every team the creator belongs to",
          "No rate-limit numbers, SLA, public changelog or API deprecation policy found in the reviewed documentation",
          "The MCP reference lists 75 tools, and the setup guide tells users to select Always Allow for all of them",
          "Per-model credit costs are returned by an authenticated endpoint and shown in the app, not on the pricing page",
          "No security.txt or disclosure policy found, and the Vanta trust centre at trust.melius.com needs JavaScript we couldn't run"
        ],
        "agentNotes": [
          "Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until `status` is finished or failed",
          "Over MCP, call `get_guide` first, `show_presence` before node changes and `canvas_plan_layout` before `bulk_create_nodes`",
          "On 429 wait `Retry-After` seconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys",
          "Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits",
          "Downloads arrive as a ZIP from a signed URL. Fetch that URL without the `Authorization` header"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.1
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 66,
          "payments": 20,
          "reliability": 69,
          "schema": 70,
          "security": 43,
          "transparency": 38
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "npm install -g @melius-ai/cli",
        "http": "curl -s -H \"Authorization: Bearer $MEL_API_KEY\" https://api.melius.com/api/v1/teams",
        "claudeCode": "claude mcp add melius --transport http https://mcp.melius.com/mcp --scope user",
        "config": {
          "mcpServers": {
            "melius": {
              "url": "https://mcp.melius.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.canvas",
        "tool": "https://letme.dev/melius"
      },
      "notable": [
        "The REST API, the CLI and the MCP server run on one backend, and a generation is always a canvas node with a run, with no separate generate endpoint (https://docs.melius.com/api/overview)",
        "MCP connects three ways. OAuth at https://mcp.melius.com/mcp, a bearer API key at https://api.melius.com/mcp, or a local stdio binary `mel-mcp --hosted` (https://docs.melius.com/mcp/overview)",
        "The docs say `mel-mcp` ships with the CLI, but @melius-ai/cli 0.16.2 on npm declares one binary, `mel`, and its bundle has no MCP command (https://registry.npmjs.org/@melius-ai/cli)",
        "An API key works with its creator's access across all that user's teams, capped at the user's role in each, and can be given an expiry (https://docs.melius.com/api/authentication)",
        "OAuth metadata lists the authorisation code grant with S256 PKCE, a registration endpoint and an empty `scopes_supported` (https://mcp.melius.com/.well-known/oauth-authorization-server)",
        "Starting a run can answer 202 with an `approvalId` in place of a run id, and GET /agent/approvals/{approvalId} reports pending, approved or denied (https://docs.melius.com/api/openapi.json)",
        "The CLI was first published on 30 June 2026 and reached 0.16.2 on 10 September 2026, 28 versions in ten weeks (https://registry.npmjs.org/@melius-ai/cli)",
        "The terms say Melius does not train models on user input or outputs, and that third-party model providers process content under their own terms (https://www.melius.com/terms)"
      ],
      "area": "design-diagrams",
      "details": [
        {
          "label": "REST API",
          "value": "https://api.melius.com/api/v1, OpenAPI 3.0.2, 59 operations on 51 paths. Projects, canvases, nodes, edges, runs, bulk runs, downloads, comments, presence, uploads, assets, models, voices, fonts, presets, templates, teams and API keys"
        },
        {
          "label": "MCP server",
          "value": "Hosted, Streamable HTTP. https://mcp.melius.com/mcp with OAuth sign-in, or https://api.melius.com/mcp with a bearer API key. 75 tools in the reference, 18 of them for Cast, which is in beta"
        },
        {
          "label": "CLI",
          "value": "@melius-ai/cli 0.16.2 (10 September 2026), MIT, Node.js 20 or later, also on Homebrew as melius-ai/tap/mel. JSON on stdout, exit codes 0 to 5"
        },
        {
          "label": "Read vs write",
          "value": "Reads projects, canvases, nodes, edges, runs, comments, presets, teams and models. Creates and updates the same, starts generations, uploads files, and deletes projects, canvases, nodes and edges"
        },
        {
          "label": "Generation model",
          "value": "Asynchronous. Create a node, start a run, poll the run, then request a download URL. Bulk runs take several nodes. `seed` from 0 to 2147483647 where the model supports it"
        },
        {
          "label": "Credentials",
          "value": "Bearer API keys (`mel_...`) made in Team settings, shown once, optional expiry, revocable at once, no scopes. OAuth for MCP creates a connector key named after the client and tied to one team"
        },
        {
          "label": "Rate limits",
          "value": "No numbers published. The docs say no plan has a monthly request quota and that bursts can return 429 with `Retry-After`. A canvas whose saved state passes 48 MiB returns 400 `CANVAS_TOO_LARGE`"
        },
        {
          "label": "Errors",
          "value": "401, 403 and 429 on every operation with `statusCode`, `error` and `message`. 400, 404 and 409 carry `message`. 400 also covers too few credits"
        },
        {
          "label": "Models",
          "value": "Third-party image, video, audio and text models. The home page counts 117. GET /generation/models lists them with variants, settings and credit costs"
        },
        {
          "label": "Free tier",
          "value": "Free plan at $0 with trial credits, amount not published. Whether sign-up needs a card, and whether Free teams can create API keys, is not stated"
        },
        {
          "label": "Status",
          "value": "status.melius.com on incident.io with two components, Web app and MCP. No incidents listed from July to October 2026. No API component"
        },
        {
          "label": "Data handling",
          "value": "Terms effective 28 August 2026 say no training on user input or outputs. Privacy policy effective 12 August 2025 gives no retention periods and no named sub-processors"
        }
      ],
      "unitPrices": [
        {
          "item": "Creator plan",
          "unit": "month",
          "usd": 20,
          "note": "20,000 credits a month, $17 a month on annual billing"
        },
        {
          "item": "Growth plan",
          "unit": "month",
          "usd": 50,
          "note": "50,000 credits a month, $43 on annual billing"
        },
        {
          "item": "Professional plan",
          "unit": "month",
          "usd": 110,
          "note": "110,000 credits a month, $93 on annual billing. A 300,000-credit option is also listed"
        },
        {
          "item": "Team plan",
          "unit": "seat-month",
          "usd": 70,
          "note": "70,000 pooled credits a seat, 2 to 10 seats, $56 on annual billing"
        }
      ],
      "provenance": {
        "legalEntity": "Melius AI, Inc.",
        "domain": "melius.com",
        "domainRegistered": "1998-11-24",
        "endpointOnVendorDomain": true,
        "terms": "https://www.melius.com/terms",
        "privacy": "https://www.melius.com/privacy",
        "statusPage": "https://status.melius.com",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (effective 28 August 2026) name Melius AI, Inc., 420 Lexington Avenue, New York, as the contracting party and are governed by Delaware law.",
          "The API answers at api.melius.com, the OAuth MCP endpoint at mcp.melius.com and the docs at docs.melius.com, all melius.com subdomains.",
          "/.well-known/security.txt returns 404 on www.melius.com, docs.melius.com and api.melius.com.",
          "RDAP for melius.com gives a registration date of 1998-11-24, which predates the company. The site says it is not affiliated with other organisations that share the Melius name.",
          "No public changelog was found. docs.melius.com/changelog and www.melius.com/changelog return 404, and release dates come from the npm registry.",
          "trust.melius.com is a Vanta trust centre that renders only with JavaScript, so its contents were not read."
        ],
        "score": 72,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Melius AI, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "melius.com, registered 1998-11-24 (27 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.melius.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 2.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.melius.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.melius.com/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 8300,
            "points": 2.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These Terms and any Disputes will be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-laws principles.",
                "says": "The law of the State of Delaware"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…OF THE MELIUS PARTIES FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF: (A) THE AMOUNTS YOU HAVE PAID TO MELIUS IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM;",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If Melius becomes aware that a user under thirteen (13) years of age has created an Account, Melius will terminate that Account."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If Melius makes material changes to these Terms, Melius will provide notice by posting the updated Terms on the Service at www.melius.com/terms, sending you an email notification, or through other reasonable means.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT ACCESS OR USE THE SERVICE."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "(d) Use automated means (including bots, scrapers, or crawlers) to access the Service, except as expressly permitted by Melius;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(h) Create an Account or access the Service for the purpose of benchmarking, competitive analysis, or monitoring the availability, performance, or functionality of the Service, or for any other purpose that is competitive with Melius;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "ARBITRATION NOTICE: SECTION 16 CONTAINS A BINDING ARBITRATION CLAUSE AND A CLASS ACTION WAIVER."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Melius does not warrant that third-party AI model providers will refrain from using inputs or outputs for model training or improvement.",
                "quote": "(c) Melius does not warrant that Third-Party AI Model providers will not use your User Input or Outputs in ways beyond Melius's control, including for model training or improvement."
              },
              {
                "date": "2026-10-08",
                "text": "Paid subscriptions renew automatically each billing period at the then-current price unless cancelled before the period ends.",
                "quote": "Your Subscription will automatically renew at the end of each billing period at Melius's then-current pricing unless you cancel your Subscription before the end of the current billing period."
              },
              {
                "date": "2026-10-08",
                "text": "After termination Melius may delete the account and all associated content, including inputs and outputs, within a reasonable period.",
                "quote": "(c) Melius may delete your Account and all associated Content, including User Input, Outputs, and Account data, within a reasonable period following termination."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.melius.com/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 5221,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We may provide additional or supplemental privacy notices for specific products, features, or services at the time we collect information from you."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain your personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "The Service integrates third-party artificial intelligence and machine learning models, services, and APIs provided by third-party vendors (\"Third-Party AI Models\") to process user inputs and produce outputs."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not sell personal information for monetary consideration.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You have the right to object to processing of your personal data based on our legitimate interests."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "You may opt out of receiving marketing communications from us by following the unsubscribe instructions in any marketing email we send you, or by contacting us at privacy@melius.com.",
                "says": "privacy@melius.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Standard Contractual Clauses approved by the European Commission (for transfers from the EEA);",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We may \"share\" personal information (as defined under the CCPA) with analytics and advertising partners for purposes of cross-context behavioral advertising."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Melius states that it does not control and cannot guarantee how third-party AI model providers handle data.",
                "quote": "However, Melius does not control and cannot guarantee the data handling practices of third-party providers."
              },
              {
                "date": "2026-10-08",
                "text": "Users are told not to include sensitive personal information or confidential information in inputs.",
                "quote": "Do not include sensitive personal information, confidential information, or information you are not authorized to share in your User Input."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/melius.json",
      "live": {
        "slug": "melius",
        "probe": {
          "target": "https://api.melius.com/api/v1",
          "method": "get",
          "lastAt": "2026-10-08T17:36:39.838644152Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 332,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 340,
          "p95ms24h": 382,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.melius.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T17:25:10.682429849Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@melius-ai/cli",
            "version": "0.16.2",
            "seenAt": "2026-10-08T16:20:12.72497812Z"
          }
        ],
        "npmWeekly": 9,
        "securityTxt": {
          "url": "https://melius.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:50.537934736Z"
        },
        "updatedAt": "2026-10-08T17:36:39.838644152Z"
      }
    },
    "verify": {
      "accepts": "a page on melius.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/melius.svg",
      "body": {
        "slug": "melius",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/melius",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/melius\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/melius.svg\" alt=\"Melius on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Melius on Anchor Terminal](https://www.anchorterminal.com/badges/melius.svg)](https://www.anchorterminal.com/tools/melius)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/melius\"\u003eMelius on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/melius",
    "json": "https://www.anchorterminal.com/tools/melius.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/melius.md",
    "slim": "https://www.anchorterminal.com/tools/melius.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 54.1/100 · rank #473 of 629 · #3 in Design workspaces \u0026 canvases · not agent-ready · confidence medium**\n\n\n## Assessment\n\nOne backend serves a 59-operation REST API with a public OpenAPI spec, a hosted MCP server with OAuth sign-in and a JSON-only CLI, and the status page shows no incidents since July 2026. API keys carry no scopes and work with their creator's role, and no rate-limit numbers, changelog or per-model credit prices are published.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Melius AI, Inc. (https://www.melius.com) |\n| Kind | HTTP API |\n| Category | Design workspaces \u0026 canvases (https://www.anchorterminal.com/categories/design) |\n| Transport | HTTP, Streamable HTTP |\n| Endpoint | `https://api.melius.com/api/v1` |\n| Auth | OAuth or key · A person creates an API key in the Melius app under Team settings, Integrations. The REST API, the CLI and the MCP endpoint at https://api.melius.com/mcp take it as a Bearer token, with an optional `x-team-id` header. The MCP endpoint at https://mcp.melius.com/mcp uses OAuth (authorisation code with S256 PKCE and dynamic client registration), where the user signs in, picks one team and Melius creates a connector key. Keys have no scopes. A key works with its creator's access and that user's role in each team. Access is self-serve, with no app review or sales approval. |\n| Pricing | Freemium ($20 / mo) · Free plan at $0 with trial credits, amount not published. Creator $20 a month for 20,000 credits, Growth $50 for 50,000, Professional $110 for 110,000, Team $70 a seat for 70,000 pooled credits (2 to 10 seats), Enterprise custom. Annual billing cuts 15 to 20 per cent. API, CLI and MCP calls have no separate charge and generations draw team credits. Per-model credit costs come from an authenticated endpoint, not the pricing page. The page's comparison table shows different figures ($18, $45, $99+, $63). Whether Free teams can create API keys is not stated (https://www.melius.com/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the API, MCP or CLI docs, the OpenAPI spec or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Melius's terms of service. The mel CLI on npm is MIT, with no public source repository found |\n| Tools exposed | 75 |\n| Packages | npm: `@melius-ai/cli` |\n| Docs | https://docs.melius.com |\n| llms.txt | https://docs.melius.com/llms.txt |\n| Last release | 2026-09-10 |\n| npm downloads / week | 9 |\n| REST API | https://api.melius.com/api/v1, OpenAPI 3.0.2, 59 operations on 51 paths. Projects, canvases, nodes, edges, runs, bulk runs, downloads, comments, presence, uploads, assets, models, voices, fonts, presets, templates, teams and API keys |\n| MCP server | Hosted, Streamable HTTP. https://mcp.melius.com/mcp with OAuth sign-in, or https://api.melius.com/mcp with a bearer API key. 75 tools in the reference, 18 of them for Cast, which is in beta |\n| CLI | @melius-ai/cli 0.16.2 (10 September 2026), MIT, Node.js 20 or later, also on Homebrew as melius-ai/tap/mel. JSON on stdout, exit codes 0 to 5 |\n| Read vs write | Reads projects, canvases, nodes, edges, runs, comments, presets, teams and models. Creates and updates the same, starts generations, uploads files, and deletes projects, canvases, nodes and edges |\n| Generation model | Asynchronous. Create a node, start a run, poll the run, then request a download URL. Bulk runs take several nodes. `seed` from 0 to 2147483647 where the model supports it |\n| Credentials | Bearer API keys (`mel_...`) made in Team settings, shown once, optional expiry, revocable at once, no scopes. OAuth for MCP creates a connector key named after the client and tied to one team |\n| Rate limits | No numbers published. The docs say no plan has a monthly request quota and that bursts can return 429 with `Retry-After`. A canvas whose saved state passes 48 MiB returns 400 `CANVAS_TOO_LARGE` |\n| Errors | 401, 403 and 429 on every operation with `statusCode`, `error` and `message`. 400, 404 and 409 carry `message`. 400 also covers too few credits |\n| Models | Third-party image, video, audio and text models. The home page counts 117. GET /generation/models lists them with variants, settings and credit costs |\n| Free tier | Free plan at $0 with trial credits, amount not published. Whether sign-up needs a card, and whether Free teams can create API keys, is not stated |\n| Status | status.melius.com on incident.io with two components, Web app and MCP. No incidents listed from July to October 2026. No API component |\n| Data handling | Terms effective 28 August 2026 say no training on user input or outputs. Privacy policy effective 12 August 2025 gives no retention periods and no named sub-processors |\n| Capabilities | design.canvas, design.comments, design.files, image.generate, image.edit, image.upscale, video.generate, speech.tts |\n| Tags | hosted, freemium, free-tier, closed-source, mcp, oauth, api-key, openapi, llms-txt, cli, async-jobs, status-page, pre-1.0 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/melius.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 69 | 13.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 70 | 11.4 |\n| Agent ergonomics | 13% | 16.2 | 51 | 8.3 |\n| Security \u0026 auth | 14% | 17.5 | 43 | 7.5 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 66 | 5.8 |\n| Transparency \u0026 trust (editorial 38, provenance 72) | 7% | 8.8 | 55 | 4.8 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **54.1 → C** |\n\n### Why each score\n\n- Reliability 69: Graded on the hosted REST API and MCP server. status.melius.com runs on incident.io with component history for Web app and MCP, though it has no API component (20). Its history lists no incidents from July to October 2026, which is as far back as the page goes (30). No rate-limit numbers are published. The docs say only that no plan has a monthly request quota and that bursts can return 429 (0). 429s carry `Retry-After` and a `retryAfterSeconds` body field, and the docs give a bounded retry policy and tell clients to check canvas or run state after a timeout or 5xx on a write. There are no idempotency keys (12 of 15). No SLA found (0). The API and MCP server carry no beta label, but the CLI is at 0.16.2 and Cast and media-URL inputs are marked beta (7 of 10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 70: Public OpenAPI 3.0.2 spec with 59 operations (25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). 58 of the 59 operations have a summary and no description. The MCP reference gives each of 75 tools one line, with ordering rules for `get_guide`, `show_presence` and `canvas_plan_layout`, and the tool definitions themselves need a signed-in client, so we didn't read them (8 of 20). Request bodies are typed with 336 enums, ranges, UUID formats and required fields, with 52 open `additionalProperties` objects (13 of 15). 401, 403 and 429 are declared on every operation and 400, 404 and 409 where they apply, but the spec has no examples and most error bodies are a bare `message` (9 of 15). The path is versioned at /api/v1 and the CLI states semantic versioning. No public changelog found (5 of 15).\n- Agent ergonomics 51: The MCP reference lists 75 tools, in the over-30 band, with `get_guide` and `get_docs` loading guidance on demand and 18 Cast tools shown only to teams with access (10 of 25). Four list operations take `limit` and `offset` and three take `search`, canvas content can be narrowed to one node or to media summaries, and the CLI has `--fields` (14 of 20). REST errors carry `statusCode`, `error` and `message`, the CLI adds a `code` and a `suggestion`, and `CANVAS_TOO_LARGE` is documented as not worth retrying. A shortage of credits arrives as a plain 400 (14 of 20). No idempotency keys, and we couldn't read MCP annotations without an account. The docs do give safe-retry guidance (5 of 20). Auto model selection and defaults keep required fields few. There is no SDK library, only the CLI and generated code samples in six languages (8 of 15).\n- Security \u0026 auth 43: API keys are revocable at once, can expire and are shown once, but have no scopes. A key works with its creator's access in every team that user belongs to, capped at the user's role. The MCP OAuth flow uses S256 PKCE and dynamic client registration, lists no scopes, and ties the connector key to one team (22 of 30). A key made by a viewer can only read, `bulk_delete_node` asks the user to confirm and a run can return a pending approval, but there is no read-only key and the setup guide tells users to select Always Allow for every tool (9 of 20). Canvas text, comments from collaborators and files fetched by `url_to_canvas` reach the model, and no prompt-injection guidance was found (2 of 15). Keys list a `lastUsedAt` time, connector keys are named after the client, and generation history is kept per member. No audit log is documented (7 of 15). No security.txt, disclosure policy or bug bounty found. A Vanta trust centre exists at trust.melius.com but needs JavaScript, so certifications are unchecked (3 of 20).\n- Payments \u0026 pricing 20: No machine payment protocol (0). Plan prices and monthly credits are public, but per-model credit costs sit behind an authenticated endpoint and the top-up price is not published (10 of 20). A Free plan at $0 gives trial credits. The amount is not published and we couldn't confirm that sign-up needs no card (10 of 20). A person signs up in a browser and creates the first key in Team settings. POST /api-keys needs an existing key (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 66: The newest dated release is the CLI, 0.16.2 on 10 September 2026, 28 days before the check (30). npm lists 19 CLI versions since 10 July 2026 (20). Closed service with no public changelog or issue tracker. Support is by email at support@melius.com and a Discord server linked from the site (5 of 15). The server is not in the official MCP registry and there is no SDK library, though the CLI is current on npm and Homebrew (5 of 15). The CLI has three dependencies, needs Node.js 20 and is published from GitHub Actions through npm trusted publishing. Its source is not public (6 of 10).\n- Transparency \u0026 trust 55: Closed service under published terms effective 28 August 2026. The CLI package is MIT with no public repository (15 of 30). The terms, the privacy policy and the pricing FAQ agree that user input and outputs are not used to train models, and say third-party model providers process content under their own terms without a guarantee from Melius. Retention is described as a reasonable period with no numbers, and no DPA was found (14 of 30). Deprecated models keep working for an unstated grace period with an in-app warning. No API deprecation policy found (5 of 20). No sub-processor list or hosting location found beyond a statement that data is processed in the United States (4 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/melius.md (JSON https://www.anchorterminal.com/fixes/melius.json)\n\n### What we couldn't check\n\n- unchecked: trust.melius.com is a Vanta trust centre that needs JavaScript, so certifications, sub-processors and security policies listed there were not read.\n- unchecked: MCP tool definitions and annotations (readOnlyHint, destructiveHint), which need a signed-in client.\n- unchecked: whether the Free plan needs a card, how many trial credits it gives, and whether Free teams can create API keys. The sign-up flow is at app.melius.com behind a login.\n- The docs say the `mel-mcp` stdio binary ships with the CLI, but @melius-ai/cli 0.16.2 declares only `mel` and its bundle has no MCP command. We found no other package that carries it.\n- The pricing page shows two sets of figures. Plan cards give $20, $50, $110 and $70 monthly ($17, $43, $93, $56 on annual billing), and the comparison table gives $18, $45, $99+ and $63.\n- No rate-limit numbers, MCP usage limits, SLA, changelog or API deprecation policy were found. The docs mention a team MCP usage record without describing a cap.\n- Category kept as design with `design.canvas` first, because every generation is a canvas node and the API has no separate generate endpoint. Image generation is the alternative.\n\n### Sources\n\n- API overview, rate limits and retry guidance: \u003chttps://docs.melius.com/api/overview\u003e (seen 2026-10-08)\n- API authentication and key scoping: \u003chttps://docs.melius.com/api/authentication\u003e (seen 2026-10-08)\n- OpenAPI spec: \u003chttps://docs.melius.com/api/openapi.json\u003e (seen 2026-10-08)\n- MCP server overview: \u003chttps://docs.melius.com/mcp/overview\u003e (seen 2026-10-08)\n- MCP tool reference: \u003chttps://docs.melius.com/mcp/tools\u003e (seen 2026-10-08)\n- MCP OAuth metadata: \u003chttps://mcp.melius.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- CLI installation, commands and agent guide: \u003chttps://docs.melius.com/cli/commands\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://docs.melius.com/llms.txt\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.melius.com/pricing\u003e (seen 2026-10-08)\n- plans and billing: \u003chttps://docs.melius.com/billing/plans\u003e (seen 2026-10-08)\n- status history: \u003chttps://status.melius.com/history\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.melius.com/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.melius.com/privacy\u003e (seen 2026-10-08)\n- npm registry entry for the CLI: \u003chttps://registry.npmjs.org/@melius-ai/cli\u003e (seen 2026-10-08)\n- Homebrew tap: \u003chttps://github.com/melius-ai/homebrew-tap\u003e (seen 2026-10-08)\n- official MCP registry search, no result: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=melius\u003e (seen 2026-10-08)\n- RDAP for melius.com: \u003chttps://rdap.verisign.com/com/v1/domain/melius.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 72/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Melius AI, Inc. | 20/20 |\n| Domain age | melius.com, registered 1998-11-24 (27 years) | 15/15 |\n| Endpoint on the vendor's domain | api.melius.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | status.melius.com | 10/10 |\n| Changelog | not found | 0/10 |\n| security.txt | not found | 0/10 |\n\nThe terms of service (effective 28 August 2026) name Melius AI, Inc., 420 Lexington Avenue, New York, as the contracting party and are governed by Delaware law.\n\nThe API answers at api.melius.com, the OAuth MCP endpoint at mcp.melius.com and the docs at docs.melius.com, all melius.com subdomains.\n\n/.well-known/security.txt returns 404 on www.melius.com, docs.melius.com and api.melius.com.\n\nRDAP for melius.com gives a registration date of 1998-11-24, which predates the company. The site says it is not affiliated with other organisations that share the Melius name.\n\nNo public changelog was found. docs.melius.com/changelog and www.melius.com/changelog return 404, and release dates come from the npm registry.\n\ntrust.melius.com is a Vanta trust centre that renders only with JavaScript, so its contents were not read.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.melius.com/terms), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"(d) Use automated means (including bots, scrapers, or crawlers) to access the Service, except as expressly permitted by Melius;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"(h) Create an Account or access the Service for the purpose of benchmarking, competitive analysis, or monitoring the availability, performance, or functionality of the Service, or for any other purpose that is competitive with Melius;\"\n- To know. Says the terms or the service can change without notice (costs points). \"We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice.\"\n- To know. Says access can be ended without notice or for any reason. \"We reserve the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice.\"\n- To know. Requires arbitration or waives class actions. \"ARBITRATION NOTICE: SECTION 16 CONTAINS A BINDING ARBITRATION CLAUSE AND A CLASS ACTION WAIVER.\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of Delaware.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Melius does not warrant that third-party AI model providers will refrain from using inputs or outputs for model training or improvement. \"(c) Melius does not warrant that Third-Party AI Model providers will not use your User Input or Outputs in ways beyond Melius's control, including for model training or improvement.\"\n- Also in the text (2026-10-08). Paid subscriptions renew automatically each billing period at the then-current price unless cancelled before the period ends. \"Your Subscription will automatically renew at the end of each billing period at Melius's then-current pricing unless you cancel your Subscription before the end of the current billing period.\"\n- Also in the text (2026-10-08). After termination Melius may delete the account and all associated content, including inputs and outputs, within a reasonable period. \"(c) Melius may delete your Account and all associated Content, including User Input, Outputs, and Account data, within a reasonable period following termination.\"\n\n**Privacy policy** (https://www.melius.com/privacy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"We may \"share\" personal information (as defined under the CCPA) with analytics and advertising partners for purposes of cross-context behavioral advertising.\"\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@melius.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Melius states that it does not control and cannot guarantee how third-party AI model providers handle data. \"However, Melius does not control and cannot guarantee the data handling practices of third-party providers.\"\n- Also in the text (2026-10-08). Users are told not to include sensitive personal information or confidential information in inputs. \"Do not include sensitive personal information, confidential information, or information you are not authorized to share in your User Input.\"\n\n## Live (updated 2026-10-08 17:36 UTC)\n\n- Right now: up, HTTP 404, 332 ms, checked 2026-10-08 17:36 UTC (get on `https://api.melius.com/api/v1`)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 340 ms · p95 382 ms\n- Vendor status page: none, All Systems Operational\n- npm `@melius-ai/cli` 0.16.2\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/melius.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Creator plan | $20 | per month (plan) | 20,000 credits a month, $17 a month on annual billing |\n| Growth plan | $50 | per month (plan) | 50,000 credits a month, $43 on annual billing |\n| Professional plan | $110 | per month (plan) | 110,000 credits a month, $93 on annual billing. A 300,000-credit option is also listed |\n| Team plan | $70 | per seat per month | 70,000 pooled credits a seat, 2 to 10 seats, $56 on annual billing |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0.2 spec with 59 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page\n- Hosted MCP server with OAuth sign-in (PKCE, dynamic client registration) or a bearer API key, tied to one team chosen at authorisation\n- 429 responses carry `Retry-After` and `retryAfterSeconds`, and the docs give a bounded retry policy\n- The mel CLI prints JSON only, uses six fixed exit codes and returns errors with a `code` and a `suggestion`\n- status.melius.com lists no incidents for Web app or MCP from July to October 2026\n\n## Weaknesses\n\n- API keys have no scopes. A key works with its creator's role in every team the creator belongs to\n- No rate-limit numbers, SLA, public changelog or API deprecation policy found in the reviewed documentation\n- The MCP reference lists 75 tools, and the setup guide tells users to select Always Allow for all of them\n- Per-model credit costs are returned by an authenticated endpoint and shown in the app, not on the pricing page\n- No security.txt or disclosure policy found, and the Vanta trust centre at trust.melius.com needs JavaScript we couldn't run\n\n## Before you call it (notes for agents)\n\n1. Generate by creating a node on a canvas, starting a run with POST /nodes/{nodeId}/runs, then polling GET /node-runs/{nodeRunId} until `status` is finished or failed\n2. Over MCP, call `get_guide` first, `show_presence` before node changes and `canvas_plan_layout` before `bulk_create_nodes`\n3. On 429 wait `Retry-After` seconds. After a timeout or 5xx on a write, read the canvas or run state before resubmitting, because there are no idempotency keys\n4. Read credit costs from GET /generation/models?category=image before a bulk run. A 400 can mean the team is out of credits\n5. Downloads arrive as a ZIP from a signed URL. Fetch that URL without the `Authorization` header\n\n## Connect\n\nInstall:\n\n```bash\nnpm install -g @melius-ai/cli\n```\n\nFirst request:\n\n```bash\ncurl -s -H \"Authorization: Bearer $MEL_API_KEY\" https://api.melius.com/api/v1/teams\n```\n\nClaude Code:\n\n```bash\nclaude mcp add melius --transport http https://mcp.melius.com/mcp --scope user\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"melius\": {\n      \"url\": \"https://mcp.melius.com/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/melius. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Osmo CLI | E | 45.2 | 573 | image.edit, video.generate, image.generate, speech.tts, design.comments | no | https://www.anchorterminal.com/tools/osmo-cli.md |\n| LocalAI | B | 68 | 182 | speech.tts, image.generate, video.generate | no | https://www.anchorterminal.com/tools/localai.md |\n| Figma API + MCP | B | 66 | 226 | design.files, design.canvas, design.comments | no | https://www.anchorterminal.com/tools/figma-mcp.md |\n| fal image models | B | 65.2 | 239 | image.generate, image.edit, image.upscale | no | https://www.anchorterminal.com/tools/fal-image.md |\n| Miro API + MCP | B | 65 | 242 | design.files, design.canvas, design.comments | no | https://www.anchorterminal.com/tools/miro.md |\n| Lucid API + MCP | C | 60.6 | 346 | design.files, design.canvas, design.comments | no | https://www.anchorterminal.com/tools/lucid.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The REST API, the CLI and the MCP server run on one backend, and a generation is always a canvas node with a run, with no separate generate endpoint (source: \u003chttps://docs.melius.com/api/overview\u003e)\n- MCP connects three ways. OAuth at https://mcp.melius.com/mcp, a bearer API key at https://api.melius.com/mcp, or a local stdio binary `mel-mcp --hosted` (source: \u003chttps://docs.melius.com/mcp/overview\u003e)\n- The docs say `mel-mcp` ships with the CLI, but @melius-ai/cli 0.16.2 on npm declares one binary, `mel`, and its bundle has no MCP command (source: \u003chttps://registry.npmjs.org/@melius-ai/cli\u003e)\n- An API key works with its creator's access across all that user's teams, capped at the user's role in each, and can be given an expiry (source: \u003chttps://docs.melius.com/api/authentication\u003e)\n- OAuth metadata lists the authorisation code grant with S256 PKCE, a registration endpoint and an empty `scopes_supported` (source: \u003chttps://mcp.melius.com/.well-known/oauth-authorization-server\u003e)\n- Starting a run can answer 202 with an `approvalId` in place of a run id, and GET /agent/approvals/{approvalId} reports pending, approved or denied (source: \u003chttps://docs.melius.com/api/openapi.json\u003e)\n- The CLI was first published on 30 June 2026 and reached 0.16.2 on 10 September 2026, 28 versions in ten weeks (source: \u003chttps://registry.npmjs.org/@melius-ai/cli\u003e)\n- The terms say Melius does not train models on user input or outputs, and that third-party model providers process content under their own terms (source: \u003chttps://www.melius.com/terms\u003e)\n\n## Compare\n\n- [Figma API + MCP vs Melius](https://www.anchorterminal.com/compare/figma-mcp-vs-melius.md): B 66 vs C 54.1\n- [Framer Server API vs Melius](https://www.anchorterminal.com/compare/framer-vs-melius.md): D 52.6 vs C 54.1\n- [Melius vs Miro API + MCP](https://www.anchorterminal.com/compare/melius-vs-miro.md): C 54.1 vs B 65\n- [Melius vs Penpot API + MCP](https://www.anchorterminal.com/compare/melius-vs-penpot.md): C 54.1 vs E 43.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on melius.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"melius\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/melius\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/melius.svg\" alt=\"Melius on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Melius on Anchor Terminal](https://www.anchorterminal.com/badges/melius.svg)](https://www.anchorterminal.com/tools/melius)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/melius\"\u003eMelius on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Melius is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/melius-dark.png\n- Light: https://www.anchorterminal.com/assets/share/melius-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Design workspaces \u0026 canvases",
        "url": "https://www.anchorterminal.com/categories/design"
      },
      {
        "name": "Melius",
        "url": ""
      }
    ],
    "description": "Melius is a hosted node-based canvas for generating images, video, audio and text with many third-party models. Outside agents read and write projects, canvases, nodes, edges, runs and comments through a REST API, an MCP server and the mel CLI.",
    "facts": [
      "rank #473 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Melius",
    "image": "https://www.anchorterminal.com/assets/og/tools-melius.png",
    "path": "/tools/melius",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Melius review for AI agents, grade C (54.1/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/melius"
  },
  "tokens": {
    "markdown": 7450,
    "slim": 1830
  },
  "version": 1
}
