monday.com
by monday.com Ltd. HTTP API in Project & task management
Hosted Agent-ready
monday.com Ltd. · monday.com since 1995 · status page · who's behind it
monday.com is a hosted work management platform built on boards, items and columns. Agents reach it through a GraphQL API at api.monday.com/v2 and an official hosted MCP server, using personal API tokens or OAuth.
Good for Teams that already run projects on monday.com boards and want an agent to create items, change status, post updates and read board summaries through MCP or GraphQL.
Is this your product? Claim this listing or verify it
Assessment. The GraphQL API publishes its full schema, accepts an Idempotency-Key header on mutations and reports limits in RateLimit headers, and a documented signup API lets an agent create its own account and token. Personal tokens carry every permission their user has, daily calls stop at 1,000 below Pro, and the status page shows two long platform incidents since July 2026.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://api.monday.com/v2- Auth
- OAuth or key
- Pricing
- Freemium · Freemium
- x402
- No
- Licence
- Proprietary service under monday.com's Terms of Service and Developer Terms. The MCP server, agent toolkit and API SDK on GitHub are MIT
- Tools exposed
- 64
- Packages
npm@mondaydotcomorg/apinpm@mondaydotcomorg/monday-api-mcpnpm@mondaydotcomorg/agent-toolkit- MCP registry
com.monday/monday.com- Source
- github.com/mondaycom/mcp
- llms.txt
- published
- Last release
- npm / week
- 176k
- Surfaces graded
- GraphQL platform API at https://api.monday.com/v2 and the official hosted MCP server at https://mcp.monday.com/mcp, which the vendor describes as a wrapper around that API
- Free tier
- Free plan, up to 2 seats and 3 boards, no card per the pricing page. Free developer sandbox account with up to 10 seats, 1,000 items per product and a 10M complexity budget, for development and testing only
- Agent signup
- POST to signup-logic.monday.com for a captcha challenge, verify it, then create the account. The response carries an API token. 15 account creations a minute per IP. A person is invited afterwards through the
invite_usersmutation - Rate limits
- Daily calls 1,000 (Free, Basic, Standard), 10,000 (Pro), 25,000 (Enterprise), reset at midnight UTC. Per minute 1,000, 2,500 on Pro, 5,000 on Enterprise. Concurrency 40, 100, 250. 5M complexity points a query. 5,000 requests per 10 seconds per IP (vendor's figures)
- Retries
- 429 with
Retry-After, aretry_in_secondsfield on rate limit errors,RateLimitandRateLimit-Policyheaders on every response, and anIdempotency-Keyheader on mutations with a 30-minute replay window. A rate-limited request counts as 0.1 of a daily call - Auth and scopes
- Personal API token (unscoped, one per user, regenerable) or OAuth. 21 OAuth scopes, among them boards:read, boards:write, updates:read, updates:write, docs:read, docs:write, users:read, webhooks:write and workspaces:write. OAuth 2.1 flow with PKCE, refresh tokens and revocation
- Read and write
- Boards, groups, columns, items and subitems, updates (comments) and replies, docs, workspaces and folders, dashboards and widgets, forms, users and teams, files, webhooks, activity logs
- Search and paging
items_pagewithquery_paramsrules anditems_page_by_column_values, cursor paging throughnext_items_page, up to 500 items a page, cursors valid for 60 minutes. GraphQL field selection sizes each response- MCP server
- Hosted, streamable HTTP, 64 tools in the published reference. OAuth with dynamic client registration or a personal token. A custom OAuth app can cap the connection to chosen scopes, and admins can limit MCP to chosen workspaces. Tool calls count towards the daily API limit
- Local MCP server
- @mondaydotcomorg/monday-api-mcp 3.3.1 (22 September 2026), Node.js 20 or later, MIT, with
--read-only,--modeand--enable-dynamic-api-toolsflags. Tools carry readOnlyHint, destructiveHint and idempotentHint annotations in the source - Change events
- Board webhooks created by the
create_webhookmutation, with a challenge to verify the URL and a documented retry policy. Some requests carry a JWT signed with the app's signing secret - Schema
- GraphQL SDL and JSON at https://api.monday.com/v2/get_schema, per version, about 578 KB, with 104 query fields and 196 mutations by our count. No OpenAPI description, because the API is GraphQL
- Versioning
- Dated quarterly versions (2026-10 became current on 1 October 2026 per the version table), release candidate, current and maintenance run in parallel, each stable for at least six months, selected by the
API-Versionheader - SDKs
- @mondaydotcomorg/api 14.1.0 for JavaScript and TypeScript (6 October 2026, MIT). @mondaydotcomorg/agent-toolkit 5.72.0 (7 October 2026) for MCP and OpenAI tool definitions. No official Python SDK was found
- Audit
- Board activity logs through the API. The audit log API is limited to account admins on the Enterprise plan. The MCP security page says self-service export of detailed MCP or API audit logs isn't available
- Certifications
- SOC 1 Type II, SOC 2 Type II, SOC 3, ISO/IEC 27001:2022, 27017, 27018, 27032 and 27701, CSA STAR and TX-RAMP per the trust centre. Vulnerability reports go through a form. No bug bounty or security.txt was found
- SLA
- 99.9 per cent monthly uptime with service credits, Enterprise plan only (agreement last updated 20 December 2023)
- Data regions
- US, EU and APAC account regions. Sub-processor list updated 24 June 2026, with hosting on Amazon Web Services, Google Cloud and Microsoft Azure
- Open source
- No. The MCP server, the agent toolkit and the API SDK are public under MIT
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Full GraphQL schema is public as SDL and JSON at api.monday.com/v2/get_schema, with a copy for each dated API version
- Mutations accept an
Idempotency-Keyheader, with responses cached for 30 minutes and replays markedIdempotency-Replayed: true - A documented signup API at signup-logic.monday.com creates an account and returns an API token after an agent captcha, with no browser step
- Hosted MCP server at https://mcp.monday.com/mcp with OAuth, PKCE and dynamic client registration, and 64 tools in the published reference
- Quarterly dated API versions, each stable for at least six months, with deprecations announced at least six months ahead
Weaknesses
- Personal API tokens have no scopes. Each carries every permission its user has in the app
- 1,000 API calls a day on Free, Basic and Standard, shared with MCP tool calls, against 10,000 on Pro and 25,000 on Enterprise
- status.monday.com lists a critical platform incident of 2 hours 8 minutes on 5 September 2026 and a major latency incident of 2 hours 57 minutes on 13 July 2026
- The MCP security page says self-service export of detailed MCP or API audit logs isn't available, and the audit log API is limited to Enterprise admins
- Column values travel as a JSON string whose shape depends on the column type, and the only official API SDK is for JavaScript and TypeScript
Before you call it notes for agents
- Send an
API-Versionheader such as 2026-10 on every call. Without it the API uses whichever version is current - Read the board's columns first (
get_board_infoorboards { columns }), then write column values as a JSON string keyed by column ID - Reuse one
Idempotency-Keyper mutation when retrying after a timeout or 5xx. After a 429, wait forRetry-Afterorretry_in_seconds - Page items with
items_pageandnext_items_page, at most 500 a page. Cursors expire after 60 minutes - For a narrower grant than a personal token, connect MCP through a custom OAuth app with only scopes such as
boards:read
Who's behind it provenance 86/100
- Legal entity namedmonday.com Ltd.20/20
- Domain agemonday.com, registered 1995-07-19 (31 years)15/15
- Endpoint on the vendor's domainapi.monday.com15/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 2 clauses that cost points6/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.monday.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-05-05, states 7 of 7, 4 to know
TL;DR Dated 2026-05-05. States all 7 things a reader expects. To know before relying on it, limits on benchmarking, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts benchmarking or competitive usecosts points
(viii) use the Services or Sites for competitive purposes, including to develop or enhance a competing service or product;
A clause against publishing test results or using the service to build something that competes.
Says the terms or the service can change without noticecosts points
We reserve the right at any time to modify or discontinue, temporarily or permanently, your and/or Customer’s access to the API (or any part of it) with or without notice.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
Any such access to the Services by such Third Party Agents is provided at monday.com’s sole discretion and may be suspended, limited, or terminated at any time, with or without notice.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
WHERE PERMITTED UNDER APPLICABLE LAW, YOU AND MONDAY.COM AGREE THAT EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER PARTY ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE ACTION.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-05-05
Last Updated: May 05, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Israel
These Terms and any action related thereto will be governed and interpreted by and under the laws of the State of Israel without giving effect to any conflicts of laws principles that require the application of the law of a different jurisdiction.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at US $100
and (iii) IN NO EVENT SHALL THE TOTAL AGGREGATE LIABILITY OF monday.com, ITS AFFILIATES OR ITS THIRD PARTY SERVICE PROVIDERS, UNDER, OR OTHERWISE IN CONNECTION WITH, THESE TERMS (INCLUDING THE SITES, THE SERVICES AND THE THIRD PARTY SERVICES), EXCEED US $100.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Any such access to the Services by such Third Party Agents is provided at monday.com’s sole discretion and may be suspended, limited, or terminated at any time, with or without notice.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
When we make material changes to these Terms, we’ll provide Customer with notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Services or by sending Customer an email.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You shall not submit to the Services any data that is protected under a special legislation and requires a unique treatment, including, without limitations, (i) categories of data enumerated in European Union Regulation 2016/679, Article 9(1) or any similar legislation or regulation in other jurisdiction;
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
To the extent you purchased an eligible enterprise tier subscription, you will be entitled, in relation to the Services, to priority support and an uptime commitment by monday.com, in accordance with the Service Level Agreement, as may be updated from time to time.
Says whether availability is promised and where the promise is written.
Actions taken by third party AI agents, scripts or automated systems under an account are treated as authorised by the customer, including registration, account creation and upgrades.
then such use and actions taken by any such Third Party Agents are deemed to be authorized by you and are made at your request and/or instruction, including but not limited to registration to the Services, creation of an Account and/or any Upgrades to the Services.
Noted by a second reader on 2026-10-08.
monday.com may use the customer's name and logo in marketing and public announcements, and the customer may revoke that right by contacting monday.com.
Customer may revoke such right, at any time, by contacting [email protected].
Noted by a second reader on 2026-10-08.
The customer must export its data before termination, and the read-only period afterwards may be ended by monday.com at any time, after which the data is deleted.
It is Customer’s sole liability to export the Customer Data prior to such termination or expiration.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 14,113 words
Privacy policy dated 2026-10-01, states 8 of 8, 1 to know
TL;DR Dated 2026-10-01. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
Sale and Sharing under US Data Protection Laws: Under some US data protection laws, like the CCPA, our disclosure of certain internet activity and device information with third parties through cookies may be considered a “sale” or “sharing” of personal information for targeted advertising.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-10-01
Last Updated: October 01, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
(i) Customer Data: personal data that we collect, process and manage on behalf of our business customers (“Customers”), submitted to the monday.com cloud-based services, including our platforms, products, applications, APIs, tools, and any ancillary or supplementary monday.com products and services (including Upgrades…
The basic statement a privacy policy exists to make.
Says how long data is kept
Data Retention: We may retain your personal data for as long as it is reasonably needed to maintain and expand our relationship and provide you with our Services and offerings;
Says when data sent to the service is deleted.
Says who else receives the data
Transfer of the Restricted personal data to third parties: (1) in accordance with this Privacy Policy, solely to the extent necessary to provide or improve the Integrated Google Services;
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
Selecting “Do not sell or share my personal data” in the cookie banner, where available, or adjusting the preferences accessible through the “Cookie settings” link in the website footer;
A plain statement either way.
Says what rights people have over their data
…or the CCPA), such as (each to the extent applicable to you under the laws which apply to you) – the right to know/request access to (specific pieces of personal data collected;
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@monday.com
If you believe that we might have any such data, please contact us at privacy@monday.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
monday.com Inc., our US subsidiary, complies with the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework as set forth by the US Department of Commerce, and where appropriate – primarily relies on such certification for accepting transfers of data from t…
The countries data goes to and the safeguard used.
Content a user submits to private boards can still be accessed, copied and processed by the account administrators.
Any content submitted by you to private boards may still be accessed, copied and processed by the Account Admin(s).
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 8,239 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Service (last updated 5 May 2026) are between the customer and monday.com Ltd., 6 Yitzhak Sadeh St., Tel-Aviv 6777506, Israel. The privacy policy was last updated on 1 October 2026.
The API answers at api.monday.com, the MCP server at mcp.monday.com and its authorisation server at auth.monday.com, all monday.com subdomains.
monday.com/.well-known/security.txt, www.monday.com/.well-known/security.txt and monday.com/security.txt each return 404. The trust centre sends vulnerability reports to a form at monday.com/security/form.
RDAP for monday.com gives a registration date of 1995-07-19.
The Service Level Agreement for the Enterprise plan (last updated 20 December 2023) commits to 99.9 per cent monthly uptime for the core services. The DPA carries the same date.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.monday.com/v2. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- npm
@mondaydotcomorg/agent-toolkit5.73.0 - npm
@mondaydotcomorg/api14.1.0 - npm
@mondaydotcomorg/monday-api-mcp3.3.1 - GitHub stars 427
- npm downloads a week 176k
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/monday.json
Notable
- The GraphQL schema is served without a login as SDL and JSON, per API version source
- The hosted MCP server at https://mcp.monday.com/mcp speaks streamable HTTP only. The docs call SSE deprecated and unsupported, while the MCP registry entry still lists https://mcp.monday.com/sse source
- The tools reference lists 64 MCP tools in 15 groups, among them boards and items, docs, dashboards, forms, automations, agents and sprints source
- An agent signup API returns an account and an API token after a 30-second captcha written for agents, limited to 15 account creations a minute per IP source
- Daily call limits are 1,000 on Free, Basic and Standard, 10,000 on Pro and 25,000 on Enterprise, and MCP tool calls count towards them source
- Mutations take an
Idempotency-Keyheader with a 30-minute replay window and a 409 for a concurrent duplicate source - API versions are released each quarter, at least three run in parallel, and each deprecation is announced at least six months ahead source
- status.monday.com lists six incidents between 13 July and 17 September 2026, one marked critical and two major, none naming the API component source
- The open-source MCP server and agent toolkit are MIT, and @mondaydotcomorg/agent-toolkit had 44 npm releases between 10 July and 7 October 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 15.8 | |
Graded on the GraphQL API and the hosted MCP server. Statuspage at status.monday.com with components by region, an API component among them, and incident history (20). In the 90 days to 8 October 2026 it lists a critical platform connectivity incident of 2 hours 8 minutes on 5 September, a major platform latency incident of 2 hours 57 minutes on 13 July, a major automations incident of 32 minutes in the EU on 17 September and three minor ones. None names the API component, and we read the record as one outage plus one long slowdown (10). Daily, per-minute, concurrency, complexity and IP limits are published with numbers per plan (15). 429 carries Retry-After, rate limit errors carry retry_in_seconds, every response has RateLimit headers, and mutations accept an Idempotency-Key header (15). A 99.9 per cent uptime SLA is published for the Enterprise plan (10). The API is generally available and the hosted MCP docs carry no beta label, though the tools reference says some newer tools run against a preview API schema (9). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.3 | |
| The full GraphQL schema is public as SDL and JSON, with a copy per API version, and the MCP tools are typed with Zod schemas in the open-source toolkit (25). llms.txt files at monday.com and developer.monday.com/api-reference, with a Markdown copy of each docs page (10). The tools reference has a page per tool for 64 tools and the schema carries descriptions. Some tool descriptions in the source are one line, such as "Delete an item", and the vendor's agent skill file names 2024-10 as the latest stable version and gives a Free daily limit of 200, both at odds with the docs (14). GraphQL inputs are typed with enums and required flags, but column values are passed as a JSON string whose shape depends on the column type (10). Curl and GraphQL examples throughout, and an error page that lists codes by status with sample bodies (14). Dated quarterly versions with release notes that separate breaking changes, plus a changelog (15). | |||
| Agent ergonomics | 13%16.2 | 13.3 | |
The MCP reference lists 64 tools (5 of 25). The local server adds a read-only flag, tool modes and a three-tool dynamic mode, a custom OAuth app can cap the hosted connection by scope, and GraphQL field selection sizes every API response, so 16 overall. Cursor pagination up to 500 items a page, rule-based filters through query_params, and lookup by column value (20). Errors carry a code, a status code, a request_id and retry_in_seconds where it applies, though application errors arrive with HTTP 200 (18). Idempotency-Key on mutations with a 30-minute replay window, and readOnlyHint, destructiveHint and idempotentHint on the tools in the source (20). Few required arguments, but an agent must read a board's columns before writing values, and the only official API SDK is for JavaScript and TypeScript (8). | |||
| Security & auth | 14%17.5 | 12.2 | |
OAuth 2.1 with PKCE, expiring access tokens, refresh tokens and revocation, 21 scopes, and dynamic client registration on the MCP server. Personal tokens are unscoped and carry every permission their user has, and legacy OAuth tokens don't expire (26). A custom OAuth app can limit the MCP connection to scopes such as boards:read, admins can limit MCP to chosen workspaces, and the local server has --read-only. No server-side confirmation for deletes was found (14). The MCP security page places prompt-injection defence on the client, and the vendor's agent skill file tells agents to treat board content as data (8). Board activity logs are available through the API. The audit log API is limited to Enterprise admins, and the MCP security page says self-service export of detailed MCP or API audit logs isn't available (7). SOC 2 Type II and ISO 27001:2022 among ten listed attestations, and a vulnerability report form. No security.txt or bug bounty was found (15). | |||
| Payments & pricing | 10%12.5 | 6.2 | |
| No x402, MPP or L402 found (0). Plan prices are public per seat, with daily API call allowances per plan and no per-call price. Extra calls can be bought, with no price shown (10). A Free plan and a free developer sandbox account, with no card needed per the pricing page (20). A documented signup API at signup-logic.monday.com returns an account and an API token after a captcha written for agents, with no browser step. We requested a challenge and it answered, and we didn't create an account (20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.4 | |
| @mondaydotcomorg/agent-toolkit 5.72.0 was published on 7 October 2026, @mondaydotcomorg/api 14.1.0 on 6 October, and API version 2026-10 became current on 1 October per the version table (30). 44 toolkit releases on npm between 10 July and 7 October 2026 (20). A public changelog, release notes and a developer community forum. We couldn't read the GitHub issue tracker or reply times, so this line is scored conservatively (12). Listed in the official MCP registry as com.monday/monday.com, though the entry is version 0.0.1 from 23 October 2025 and still lists the SSE remote, and the API SDK is current (15). The MCP repository runs lint, build and tests on pull requests and has 78 test files. Git tags stop at v0.0.163 on 14 April 2026 while npm releases continue (8). | |||
| Transparency & trusteditorial 73, provenance 86 | 7%8.8 | 7.0 | |
| Closed service with published Terms of Service (5 May 2026) and Developer Terms. The MCP server, toolkit and API SDK are MIT (15). Privacy policy updated 1 October 2026, a DPA dated 20 December 2023 with deletion or return of data after termination, and an AI trust centre that rules out model training on customer input and output. Retention is stated as for as long as reasonably needed, with no period given (20). API versions are deprecated with at least six months' notice and listed with dates. SSE on the hosted MCP server is called deprecated and unsupported with no date given (18). Sub-processor list updated 24 June 2026 with hosting regions, and US, EU and APAC account regions (20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 76.4 · BB | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on monday.com, or have the agent fetch /fixes/monday.md. A fix counts at the next check, once it's public.
Show it
# Fix list: monday.com
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/monday, the October 2026 research run, assessed 8 October 2026. Grade BB, 76.4 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on monday.com: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Payments & pricing, 50 out of 100, up to 6.3 more on the total
Why it scored 50: No x402, MPP or L402 found (0). Plan prices are public per seat, with daily API call allowances per plan and no per-call price. Extra calls can be bought, with no price shown (10). A Free plan and a free developer sandbox account, with no card needed per the pricing page (20). A documented signup API at signup-logic.monday.com returns an account and an API token after a captcha written for agents, with no browser step. We requested a challenge and it answered, and we didn't create an account (20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 2. Security & auth, 70 out of 100, up to 5.3 more on the total
Why it scored 70: OAuth 2.1 with PKCE, expiring access tokens, refresh tokens and revocation, 21 scopes, and dynamic client registration on the MCP server. Personal tokens are unscoped and carry every permission their user has, and legacy OAuth tokens don't expire (26). A custom OAuth app can limit the MCP connection to scopes such as `boards:read`, admins can limit MCP to chosen workspaces, and the local server has `--read-only`. No server-side confirmation for deletes was found (14). The MCP security page places prompt-injection defence on the client, and the vendor's agent skill file tells agents to treat board content as data (8). Board activity logs are available through the API. The audit log API is limited to Enterprise admins, and the MCP security page says self-service export of detailed MCP or API audit logs isn't available (7). SOC 2 Type II and ISO 27001:2022 among ten listed attestations, and a vulnerability report form. No security.txt or bug bounty was found (15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 3. Reliability, 79 out of 100, up to 4.2 more on the total
Why it scored 79: Graded on the GraphQL API and the hosted MCP server. Statuspage at status.monday.com with components by region, an API component among them, and incident history (20). In the 90 days to 8 October 2026 it lists a critical platform connectivity incident of 2 hours 8 minutes on 5 September, a major platform latency incident of 2 hours 57 minutes on 13 July, a major automations incident of 32 minutes in the EU on 17 September and three minor ones. None names the API component, and we read the record as one outage plus one long slowdown (10). Daily, per-minute, concurrency, complexity and IP limits are published with numbers per plan (15). 429 carries `Retry-After`, rate limit errors carry `retry_in_seconds`, every response has `RateLimit` headers, and mutations accept an `Idempotency-Key` header (15). A 99.9 per cent uptime SLA is published for the Enterprise plan (10). The API is generally available and the hosted MCP docs carry no beta label, though the tools reference says some newer tools run against a preview API schema (9).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 4. Agent ergonomics, 82 out of 100, up to 2.9 more on the total
Why it scored 82: The MCP reference lists 64 tools (5 of 25). The local server adds a read-only flag, tool modes and a three-tool dynamic mode, a custom OAuth app can cap the hosted connection by scope, and GraphQL field selection sizes every API response, so 16 overall. Cursor pagination up to 500 items a page, rule-based filters through `query_params`, and lookup by column value (20). Errors carry a code, a status code, a `request_id` and `retry_in_seconds` where it applies, though application errors arrive with HTTP 200 (18). `Idempotency-Key` on mutations with a 30-minute replay window, and readOnlyHint, destructiveHint and idempotentHint on the tools in the source (20). Few required arguments, but an agent must read a board's columns before writing values, and the only official API SDK is for JavaScript and TypeScript (8).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 5. Schema & documentation, 88 out of 100, up to 2 more on the total
Why it scored 88: The full GraphQL schema is public as SDL and JSON, with a copy per API version, and the MCP tools are typed with Zod schemas in the open-source toolkit (25). llms.txt files at monday.com and developer.monday.com/api-reference, with a Markdown copy of each docs page (10). The tools reference has a page per tool for 64 tools and the schema carries descriptions. Some tool descriptions in the source are one line, such as "Delete an item", and the vendor's agent skill file names 2024-10 as the latest stable version and gives a Free daily limit of 200, both at odds with the docs (14). GraphQL inputs are typed with enums and required flags, but column values are passed as a JSON string whose shape depends on the column type (10). Curl and GraphQL examples throughout, and an error page that lists codes by status with sample bodies (14). Dated quarterly versions with release notes that separate breaking changes, plus a changelog (15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 6. Transparency & trust, 80 out of 100, up to 1.8 more on the total
Made of editorial 73, provenance 86.
Why it scored 80: Closed service with published Terms of Service (5 May 2026) and Developer Terms. The MCP server, toolkit and API SDK are MIT (15). Privacy policy updated 1 October 2026, a DPA dated 20 December 2023 with deletion or return of data after termination, and an AI trust centre that rules out model training on customer input and output. Retention is stated as for as long as reasonably needed, with no period given (20). API versions are deprecated with at least six months' notice and listed with dates. SSE on the hosted MCP server is called deprecated and unsupported with no date given (18). Sub-processor list updated 24 June 2026 with hosting regions, and US, EU and APAC account regions (20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Terms of service: read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points (6 of 10)
- security.txt: not found (0 of 10)
## 7. Maintenance & community, 85 out of 100, up to 1.3 more on the total
Why it scored 85: @mondaydotcomorg/agent-toolkit 5.72.0 was published on 7 October 2026, @mondaydotcomorg/api 14.1.0 on 6 October, and API version 2026-10 became current on 1 October per the version table (30). 44 toolkit releases on npm between 10 July and 7 October 2026 (20). A public changelog, release notes and a developer community forum. We couldn't read the GitHub issue tracker or reply times, so this line is scored conservatively (12). Listed in the official MCP registry as com.monday/monday.com, though the entry is version 0.0.1 from 23 October 2025 and still lists the SSE remote, and the API SDK is current (15). The MCP repository runs lint, build and tests on pull requests and has 78 test files. Git tags stop at v0.0.163 on 14 April 2026 while npm releases continue (8).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: US dollar prices. monday.com/pricing served our reader in pounds, so `unitPrices` is left empty
- unchecked: GitHub stars, open issues and reply times for mondaycom/mcp. The GitHub API refused us for its rate limit
- unchecked: the hosted MCP server's live tool list, input schemas and annotations, which need a signed-in account. The count of 64 comes from the published tools reference, and annotations were read in the open-source toolkit
- unchecked: which plan and limits an account created through the agent signup API receives. We requested a captcha challenge, which answered, and didn't create an account
- unchecked: whether Free plan signup in a browser asks for a card. The pricing page says no card is needed
- The agent skill file gives a Free plan daily limit of 200 calls, while the rate limits page and the pricing page give 1,000 for Free, Basic and Standard. We used the docs' figure
- The docs call SSE on the hosted MCP server deprecated and unsupported, while the MCP registry entry and the agent skill file still list https://mcp.monday.com/sse, which answered our request with a 302. No removal date was found
- The status incident of 5 September 2026 is titled as planned maintenance for 5 August but its updates describe connectivity issues across the platform, and it is marked critical
- No bug bounty, security.txt, retention period for account content or price for extra API calls was found in the reviewed pages
## Weaknesses
- Personal API tokens have no scopes. Each carries every permission its user has in the app
- 1,000 API calls a day on Free, Basic and Standard, shared with MCP tool calls, against 10,000 on Pro and 25,000 on Enterprise
- status.monday.com lists a critical platform incident of 2 hours 8 minutes on 5 September 2026 and a major latency incident of 2 hours 57 minutes on 13 July 2026
- The MCP security page says self-service export of detailed MCP or API audit logs isn't available, and the audit log API is limited to Enterprise admins
- Column values travel as a JSON string whose shape depends on the column type, and the only official API SDK is for JavaScript and TypeScript
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Send an `API-Version` header such as 2026-10 on every call. Without it the API uses whichever version is current
- Read the board's columns first (`get_board_info` or `boards { columns }`), then write column values as a JSON string keyed by column ID
- Reuse one `Idempotency-Key` per mutation when retrying after a timeout or 5xx. After a 429, wait for `Retry-After` or `retry_in_seconds`
- Page items with `items_page` and `next_items_page`, at most 500 a page. Cursors expire after 60 minutes
- For a narrower grant than a personal token, connect MCP through a custom OAuth app with only scopes such as `boards:read`
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: US dollar prices. monday.com/pricing served our reader in pounds, so
unitPricesis left empty - unchecked: GitHub stars, open issues and reply times for mondaycom/mcp. The GitHub API refused us for its rate limit
- unchecked: the hosted MCP server's live tool list, input schemas and annotations, which need a signed-in account. The count of 64 comes from the published tools reference, and annotations were read in the open-source toolkit
- unchecked: which plan and limits an account created through the agent signup API receives. We requested a captcha challenge, which answered, and didn't create an account
- unchecked: whether Free plan signup in a browser asks for a card. The pricing page says no card is needed
- The agent skill file gives a Free plan daily limit of 200 calls, while the rate limits page and the pricing page give 1,000 for Free, Basic and Standard. We used the docs' figure
- The docs call SSE on the hosted MCP server deprecated and unsupported, while the MCP registry entry and the agent skill file still list https://mcp.monday.com/sse, which answered our request with a 302. No removal date was found
- The status incident of 5 September 2026 is titled as planned maintenance for 5 August but its updates describe connectivity issues across the platform, and it is marked critical
- No bug bounty, security.txt, retention period for account content or price for extra API calls was found in the reviewed pages
Sources 43
- monday.com llms.txt monday.com · seen 2026-10-08
- API docs llms.txt index developer.monday.com · seen 2026-10-08
- API basics developer.monday.com · seen 2026-10-08
- authentication developer.monday.com · seen 2026-10-08
- rate limits developer.monday.com · seen 2026-10-08
- idempotency developer.monday.com · seen 2026-10-08
- error handling developer.monday.com · seen 2026-10-08
- API versioning developer.monday.com · seen 2026-10-08
- release notes developer.monday.com · seen 2026-10-08
- API changelog developer.monday.com · seen 2026-10-08
- GraphQL schema (SDL) api.monday.com · seen 2026-10-08
- Platform MCP overview developer.monday.com · seen 2026-10-08
- MCP integration guide developer.monday.com · seen 2026-10-08
- MCP tools reference developer.monday.com · seen 2026-10-08
- MCP security overview developer.monday.com · seen 2026-10-08
- MCP with an API token developer.monday.com · seen 2026-10-08
- MCP with a custom OAuth app developer.monday.com · seen 2026-10-08
- MCP dynamic client registration developer.monday.com · seen 2026-10-08
- MCP authorisation server metadata mcp.monday.com · seen 2026-10-08
- MCP server card monday.com · seen 2026-10-08
- OAuth and scopes developer.monday.com · seen 2026-10-08
- OAuth 2.1 migration developer.monday.com · seen 2026-10-08
- audit logs API developer.monday.com · seen 2026-10-08
- webhooks developer.monday.com · seen 2026-10-08
- developer sandbox account developer.monday.com · seen 2026-10-08
- agent skill file for the API and MCP monday.com · seen 2026-10-08
- agent signup skill file monday.com · seen 2026-10-08
- MCP server and agent toolkit repository github.com · seen 2026-10-08
- API SDK repository github.com · seen 2026-10-08
- agent toolkit on npm registry.npmjs.org · seen 2026-10-08
- MCP server on npm registry.npmjs.org · seen 2026-10-08
- API SDK on npm registry.npmjs.org · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- status incidents status.monday.com · seen 2026-10-08
- pricing monday.com · seen 2026-10-08
- trust centre monday.com · seen 2026-10-08
- AI trust centre monday.com · seen 2026-10-08
- terms of service monday.com · seen 2026-10-08
- service level agreement for the Enterprise plan monday.com · seen 2026-10-08
- privacy policy monday.com · seen 2026-10-08
- data processing addendum monday.com · seen 2026-10-08
- sub-processors monday.com · seen 2026-10-08
- RDAP for monday.com rdap.verisign.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium Freemium Free plan with up to 2 seats and 3 boards, no card needed per the pricing page, plus a free developer sandbox account with up to 10 seats and 1,000 items per product, so an agent can start without a contract. Paid plans are per seat. The pricing page served our reader in pounds, at £8 (Basic), £11 (Standard) and £17 (Pro) a seat a month billed annually for 10 seats, with Enterprise through sales. The API has no per-call price. Daily calls are capped by plan (1,000, 10,000 on Pro, 25,000 on Enterprise) and the page says more can be bought, with no price shown (checked 2026-10-08).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/monday.xml, or this listing's score history at history.json.
Connect
Install
npx @mondaydotcomorg/monday-api-mcp@latest
First request
curl -X POST https://api.monday.com/v2 \
-H "Authorization: YOUR_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{"query": "query { me { id name } }"}'
MCP client configuration
{
"mcpServers": {
"monday-mcp": {
"url": "https://mcp.monday.com/mcp"
}
}
}
Headless / CI
{
"mcpServers": {
"monday-mcp": {
"headers": {
"Authorization": "Bearer YOUR_API_TOKEN"
},
"url": "https://mcp.monday.com/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/monday
letme picks this listing for forms.create, because it's the top-graded tool for the job. letme picks this listing for projects.manage, because it's the top-graded tool for the job. letme picks this listing for projects.reporting, because it's the top-graded tool for the job. letme picks this listing for tasks.comments, because it's the top-graded tool for the job. letme picks this listing for tasks.create, because it's the top-graded tool for the job. letme picks this listing for tasks.update, because it's the top-graded tool for the job.
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
ClickUp CAsana BBTodoist BWrike CRoma DGoogle Drive API + MCP A
Head to head Asana vs monday.com · ClickUp vs monday.com · monday.com vs Roma · monday.com vs Todoist · monday.com vs Wrike
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| ClickUp Mango Technologies, Inc. DBA ClickUp | C | 60.9 | tasks.create tasks.update projects.manage tasks.comments projects.reporting work.docs | no |
| Asana Asana, Inc. | BB | 70.1 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Todoist Doist | B | 66.9 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Wrike Wrike, Inc. | C | 60.1 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Roma Milo Mode Inc. | D | 51.1 | tasks.create tasks.update projects.manage | no |
| Google Drive API + MCP Google | A | 79.6 | work.docs | no |
Machine-readable
- JSON
/api/v1/tools/monday.json· historyhistory.json· badge/badges/monday.svg· changes feed/feeds/tools/monday.xml - Markdown
/tools/monday.md· slim/tools/monday.min.md(or sendAccept: text/markdown) - Fix list
/fixes/monday.md·/fixes/monday.json - From a terminal
anchor tool monday --md(the CLI) · over MCPget_tool {"slug": "monday"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/monday"><img src="https://www.anchorterminal.com/badges/monday.svg" alt="monday.com on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/monday)<a href="https://www.anchorterminal.com/tools/monday">monday.com on Anchor Terminal</a>It counts on a page on monday.com or one of its subdomains, or the README of github.com/mondaycom/mcp.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "monday", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
