# monday.com (slim) > monday.com is a hosted work management platform built on boards, items and columns. Agents reach it through a GraphQL API at api.monday.com/v2 and an official hosted MCP server, using personal API tokens or OAuth. - Full: https://www.anchorterminal.com/tools/monday.md (~9,150 tokens) · this version ~2,330 tokens · JSON https://www.anchorterminal.com/tools/monday.json · canonical https://www.anchorterminal.com/tools/monday - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 76.4/100 · rank #32 of 629 · #1 in Project & task management · agent-ready · confidence medium** Assessment: The GraphQL API publishes its full schema, accepts an `Idempotency-Key` header on mutations and reports limits in `RateLimit` headers, and a documented signup API lets an agent create its own account and token. Personal tokens carry every permission their user has, daily calls stop at 1,000 below Pro, and the status page shows two long platform incidents since July 2026. ## Facts - Kind: HTTP API · vendor: monday.com Ltd. · category: Project & task management · legal entity: monday.com Ltd. · provenance 86/100 - Endpoint: `https://api.monday.com/v2` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under monday.com's Terms of Service and Developer Terms. The MCP server, agent toolkit and API SDK on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - Surfaces graded: GraphQL platform API at https://api.monday.com/v2 and the official hosted MCP server at https://mcp.monday.com/mcp, which the vendor describes as a wrapper around that API - Free tier: Free plan, up to 2 seats and 3 boards, no card per the pricing page. Free developer sandbox account with up to 10 seats, 1,000 items per product and a 10M complexity budget, for development and testing only - Agent signup: POST to signup-logic.monday.com for a captcha challenge, verify it, then create the account. The response carries an API token. 15 account creations a minute per IP. A person is invited afterwards through the `invite_users` mutation - Rate limits: Daily calls 1,000 (Free, Basic, Standard), 10,000 (Pro), 25,000 (Enterprise), reset at midnight UTC. Per minute 1,000, 2,500 on Pro, 5,000 on Enterprise. Concurrency 40, 100, 250. 5M complexity points a query. 5,000 requests per 10 seconds per IP (vendor's figures) - Retries: 429 with `Retry-After`, a `retry_in_seconds` field on rate limit errors, `RateLimit` and `RateLimit-Policy` headers on every response, and an `Idempotency-Key` header on mutations with a 30-minute replay window. A rate-limited request counts as 0.1 of a daily call - Auth and scopes: Personal API token (unscoped, one per user, regenerable) or OAuth. 21 OAuth scopes, among them boards:read, boards:write, updates:read, updates:write, docs:read, docs:write, users:read, webhooks:write and workspaces:write. OAuth 2.1 flow with PKCE, refresh tokens and revocation - Read and write: Boards, groups, columns, items and subitems, updates (comments) and replies, docs, workspaces and folders, dashboards and widgets, forms, users and teams, files, webhooks, activity logs - Search and paging: `items_page` with `query_params` rules and `items_page_by_column_values`, cursor paging through `next_items_page`, up to 500 items a page, cursors valid for 60 minutes. GraphQL field selection sizes each response - MCP server: Hosted, streamable HTTP, 64 tools in the published reference. OAuth with dynamic client registration or a personal token. A custom OAuth app can cap the connection to chosen scopes, and admins can limit MCP to chosen workspaces. Tool calls count towards the daily API limit - Local MCP server: @mondaydotcomorg/monday-api-mcp 3.3.1 (22 September 2026), Node.js 20 or later, MIT, with `--read-only`, `--mode` and `--enable-dynamic-api-tools` flags. Tools carry readOnlyHint, destructiveHint and idempotentHint annotations in the source - Change events: Board webhooks created by the `create_webhook` mutation, with a challenge to verify the URL and a documented retry policy. Some requests carry a JWT signed with the app's signing secret - Schema: GraphQL SDL and JSON at https://api.monday.com/v2/get_schema, per version, about 578 KB, with 104 query fields and 196 mutations by our count. No OpenAPI description, because the API is GraphQL - Versioning: Dated quarterly versions (2026-10 became current on 1 October 2026 per the version table), release candidate, current and maintenance run in parallel, each stable for at least six months, selected by the `API-Version` header - SDKs: @mondaydotcomorg/api 14.1.0 for JavaScript and TypeScript (6 October 2026, MIT). @mondaydotcomorg/agent-toolkit 5.72.0 (7 October 2026) for MCP and OpenAI tool definitions. No official Python SDK was found - Audit: Board activity logs through the API. The audit log API is limited to account admins on the Enterprise plan. The MCP security page says self-service export of detailed MCP or API audit logs isn't available - Certifications: SOC 1 Type II, SOC 2 Type II, SOC 3, ISO/IEC 27001:2022, 27017, 27018, 27032 and 27701, CSA STAR and TX-RAMP per the trust centre. Vulnerability reports go through a form. No bug bounty or security.txt was found - SLA: 99.9 per cent monthly uptime with service credits, Enterprise plan only (agreement last updated 20 December 2023) - Data regions: US, EU and APAC account regions. Sub-processor list updated 24 June 2026, with hosting on Amazon Web Services, Google Cloud and Microsoft Azure - Open source: No. The MCP server, the agent toolkit and the API SDK are public under MIT - Scores: Reliability 79, Performance pending, Schema & documentation 88, Agent ergonomics 82, Security & auth 70, Payments & pricing 50, Task success pending, Maintenance & community 85, Transparency & trust 80 · total over the 7 assessed categories - Why: Reliability, Graded on the GraphQL API and the hosted MCP server. · Schema & documentation, The full GraphQL schema is public as SDL and JSON, with a copy per API version, and the MCP tools are typed with Zod schemas in the open-sou… · Agent ergonomics, The MCP reference lists 64 tools (5 of 25). · Security & auth, OAuth 2.1 with PKCE, expiring access tokens, refresh tokens and revocation, 21 scopes, and dynamic client registration on the MCP server. · Payments & pricing, No x402, MPP or L402 found (0). · Maintenance & community, @mondaydotcomorg/agent-toolkit 5.72.0 was published on 7 October 2026, @mondaydotcomorg/api 14.1.0 on 6 October, and API version 2026-10 bec… · Transparency & trust, Closed service with published Terms of Service (5 May 2026) and Developer Terms. - Sources: 43, open questions: 9, both in the full twin - Capabilities: tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, work.docs, forms.create - JSON: https://www.anchorterminal.com/api/v1/tools/monday.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/monday.svg` or a link to https://www.anchorterminal.com/tools/monday from a page on monday.com or one of its subdomains, or the README of github.com/mondaycom/mcp, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send an `API-Version` header such as 2026-10 on every call. Without it the API uses whichever version is current 2. Read the board's columns first (`get_board_info` or `boards { columns }`), then write column values as a JSON string keyed by column ID 3. Reuse one `Idempotency-Key` per mutation when retrying after a timeout or 5xx. After a 429, wait for `Retry-After` or `retry_in_seconds` 4. Page items with `items_page` and `next_items_page`, at most 500 a page. Cursors expire after 60 minutes 5. For a narrower grant than a personal token, connect MCP through a custom OAuth app with only scopes such as `boards:read` ## Connect ```bash npx @mondaydotcomorg/monday-api-mcp@latest ``` ```bash curl -X POST https://api.monday.com/v2 \ -H "Authorization: YOUR_API_TOKEN" \ -H "Content-Type: application/json" \ -d '{"query": "query { me { id name } }"}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/monday ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | ClickUp | C | 60.9 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, work.docs | https://www.anchorterminal.com/tools/clickup.min.md | | Asana | BB | 70.1 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/asana.min.md | | Todoist | B | 66.9 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/todoist.min.md | | Wrike | C | 60.1 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/wrike.min.md | | Trello | C | 61.1 | tasks.create, tasks.update, projects.manage, tasks.comments | https://www.anchorterminal.com/tools/trello.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)