{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/hubspot-mcp.json",
        "name": "HubSpot API + MCP",
        "score": 71.5,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "hubspot-mcp"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/zoho-crm.json",
        "name": "Zoho CRM",
        "score": 70.8,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "zoho-crm"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/dynamics-365-sales.json",
        "name": "Microsoft Dynamics 365 Sales",
        "score": 69.7,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "dynamics-365-sales"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/close.json",
        "name": "Close API + MCP",
        "score": 66.7,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "close"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/twenty.json",
        "name": "Twenty API + MCP",
        "score": 65.9,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "twenty"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/affinity.json",
        "name": "Affinity",
        "score": 63.4,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "affinity"
      }
    ],
    "tool": {
      "slug": "nutshell",
      "name": "Nutshell",
      "vendor": "Nutshell, Inc.",
      "vendorUrl": "https://www.nutshell.com",
      "kind": "http-api",
      "category": "crm",
      "summary": "Nutshell is a sales CRM for small teams, with email marketing and quoting built in. Agents reach it through a REST API at `app.nutshell.com/rest`, a legacy JSON-RPC API, webhooks and a hosted read-only MCP server.",
      "url": "https://www.anchorterminal.com/tools/nutshell",
      "markdownUrl": "https://www.anchorterminal.com/tools/nutshell.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nutshell.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nutshell.json",
      "license": "Proprietary service under Nutshell's Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://app.nutshell.com/rest",
      "packages": [],
      "auth": "mixed",
      "authNotes": "REST and JSON-RPC use HTTP Basic over HTTPS, with a Nutshell user's email as the username and an API key as the password. An admin creates keys under Setup, API keys, and chooses a permission type, one of which allows impersonating any user. Keys have no scopes. The MCP server at `https://app.nutshell.com/mcp` uses OAuth authorisation code with PKCE (S256), dynamic client registration at `/oauth/register`, a revocation endpoint and two scopes, `read` and `write`. Access is self-serve on every plan and the trial.",
      "pricing": "paid",
      "pricingNotes": "No free plan. A 14-day trial needs no card, and the API and MCP server are included on every plan. Five plans a seat a month billed yearly, Foundation $13, Growth $25, Pro $42, Business $59 and Enterprise $79, or $19, $32, $49, $67 and $89 billed monthly. API calls are not billed separately. The docs publish sandbox credentials for a demo account (https://www.nutshell.com/pricing, checked 2026-10-08).",
      "priceSummary": "$13 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OAuth metadata or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.nutshell.com/",
      "llmsTxt": "https://developers.nutshell.com/llms.txt",
      "capabilities": [
        "crm.records",
        "crm.pipeline",
        "crm.activities",
        "crm.search",
        "crm.webhooks"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "llms-txt",
        "webhooks",
        "no-card",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-08-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 49.6,
        "grade": "D",
        "agentReady": false,
        "rank": 607,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 44,
          "maintenance": 46,
          "payments": 35,
          "reliability": 42,
          "schema": 57,
          "security": 58,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 42,
            "points": 8.4,
            "reason": "Read with the hosted lines. Status page at status.nutshell.com with 12 components and incident history back to 2017 (20). One incident in the last 90 days, a database cluster fault on 28 September 2026 that left the application unavailable for some customers, marked major, mitigated after 43 minutes and closed after about seven hours. Scored between the minor and one-major bands because the outage was partial and under an hour to mitigation (12 of 30). No rate limit numbers for REST, and the JSON-RPC docs say only that limits vary (0). No 429, Retry-After, backoff or idempotency guidance found (0). No SLA found, and the terms supply the service as is (0). The REST API is GA and the MCP server carries no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 57,
            "points": 9.26,
            "reason": "Each of the 114 REST reference pages carries the OpenAPI 3.0 definition of its operation, but whole-spec download is disabled (18 of 25). `llms.txt` and Markdown for every docs page (10). 78 of 114 operations have a description, and the newer ones state scope and visibility rules (11 of 20). Enums on sort fields and patterns on IDs, but filters and custom fields are open objects and `page[limit]` is typed as a string on some operations (9 of 15). Schema examples are present, and error responses appear on 9 operations with no error body schema (5 of 15). The spec is version 2.0.0 and pages carry update stamps, with no dated API changelog (4 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 44,
            "points": 7.15,
            "reason": "The MCP server is read-only with about 17 groups of search and list tools per the help centre. The tool definitions sit behind OAuth and were not read. REST lists take `page[limit]` with no field selection (13 of 25). `page[page]`, `sort`, `q` and `filter[...]` keys, with field lists from `/accounts/list/fields`, and no stated maximum page size (16 of 20). Errors are barely documented and an unauthenticated REST call returned an HTML page (4 of 20). No idempotency keys. Deletes can be undone within 30 days and the MCP server cannot write (6 of 20). Few required fields, and no official REST SDK. The only client is a PHP JSON-RPC sample last pushed in 2023 (5 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 58,
            "points": 10.15,
            "reason": "The MCP server uses OAuth authorisation code with PKCE, dynamic client registration, a revocation endpoint and `read` and `write` scopes. REST uses unscoped API keys sent as an HTTP Basic password with a user's email, and a key can be allowed to impersonate any user (24 of 30). The MCP server is read-only and OAuth has a `read` scope, but no read-only API key type was found (12 of 20). Records hold emails, notes and form submissions, with no injection guidance found (3 of 15). An audit log on Business and Enterprise covers logins, bulk edits and exports, and API changes are logged under the key name or the impersonated user (8 of 15). SOC 2 Type 1 from December 2025, a CASA assessment, a disclosure address, no bounty and no security.txt (11 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 35,
            "points": 4.38,
            "reason": "No x402, MPP or L402 (0). Plan prices are public, $13 to $79 a seat a month billed yearly, with nothing per call (10). 14-day trial with no card, and the API is included (20). A person signs up in a browser and an admin creates the key. The docs publish sandbox credentials for a shared demo account, which lets an agent test calls with no signup but not reach its own data (5 of 20)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 46,
            "points": 4.03,
            "reason": "The newest REST reference page was updated on 21 August 2026, 48 days before the check (20 of 30). Five reference pages changed between 5 and 21 August 2026, for quote and invoice status, to-dos and dashboard fields. These are page stamps, not changelog entries (20). No API changelog, and the product updates page is undated. Live support on every plan per the pricing page, untested (6 of 25). No current official SDK, and the MCP registry was not checked (0). No packages to judge (0)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 71,
            "points": 6.21,
            "note": "editorial 56, provenance 86",
            "reason": "Closed service with clear terms naming Nutshell, Inc. (15). The terms, privacy policy and DPA, all dated 2 June 2026, agree on a 30-day export window after termination, deletion from production afterwards, backup copies that may persist indefinitely and no training of generalised AI models on customer data (24 of 30). The JSON-RPC API is marked legacy with a promise of indefinite support, but there is no deprecation policy and the terms allow functions to be removed without prior notice (5 of 20). The subprocessor list at trust.nutshell.com could not be read. The policy names AWS and regions, and the DPA promises 10 days' notice of a new subprocessor (12 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP server is read-only with about 17 groups of search and list tools per the help centre. The tool definitions sit behind OAuth and were not read. REST lists take `page[limit]` with no field selection (13 of 25). `page[page]`, `sort`, `q` and `filter[...]` keys, with field lists from `/accounts/list/fields`, and no stated maximum page size (16 of 20). Errors are barely documented and an unauthenticated REST call returned an HTML page (4 of 20). No idempotency keys. Deletes can be undone within 30 days and the MCP server cannot write (6 of 20). Few required fields, and no official REST SDK. The only client is a PHP JSON-RPC sample last pushed in 2023 (5 of 15).",
            "maintenance": "The newest REST reference page was updated on 21 August 2026, 48 days before the check (20 of 30). Five reference pages changed between 5 and 21 August 2026, for quote and invoice status, to-dos and dashboard fields. These are page stamps, not changelog entries (20). No API changelog, and the product updates page is undated. Live support on every plan per the pricing page, untested (6 of 25). No current official SDK, and the MCP registry was not checked (0). No packages to judge (0).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public, $13 to $79 a seat a month billed yearly, with nothing per call (10). 14-day trial with no card, and the API is included (20). A person signs up in a browser and an admin creates the key. The docs publish sandbox credentials for a shared demo account, which lets an agent test calls with no signup but not reach its own data (5 of 20).",
            "reliability": "Read with the hosted lines. Status page at status.nutshell.com with 12 components and incident history back to 2017 (20). One incident in the last 90 days, a database cluster fault on 28 September 2026 that left the application unavailable for some customers, marked major, mitigated after 43 minutes and closed after about seven hours. Scored between the minor and one-major bands because the outage was partial and under an hour to mitigation (12 of 30). No rate limit numbers for REST, and the JSON-RPC docs say only that limits vary (0). No 429, Retry-After, backoff or idempotency guidance found (0). No SLA found, and the terms supply the service as is (0). The REST API is GA and the MCP server carries no beta label (10).",
            "schema": "Each of the 114 REST reference pages carries the OpenAPI 3.0 definition of its operation, but whole-spec download is disabled (18 of 25). `llms.txt` and Markdown for every docs page (10). 78 of 114 operations have a description, and the newer ones state scope and visibility rules (11 of 20). Enums on sort fields and patterns on IDs, but filters and custom fields are open objects and `page[limit]` is typed as a string on some operations (9 of 15). Schema examples are present, and error responses appear on 9 operations with no error body schema (5 of 15). The spec is version 2.0.0 and pages carry update stamps, with no dated API changelog (4 of 15).",
            "security": "The MCP server uses OAuth authorisation code with PKCE, dynamic client registration, a revocation endpoint and `read` and `write` scopes. REST uses unscoped API keys sent as an HTTP Basic password with a user's email, and a key can be allowed to impersonate any user (24 of 30). The MCP server is read-only and OAuth has a `read` scope, but no read-only API key type was found (12 of 20). Records hold emails, notes and form submissions, with no injection guidance found (3 of 15). An audit log on Business and Enterprise covers logins, bulk edits and exports, and API changes are logged under the key name or the impersonated user (8 of 15). SOC 2 Type 1 from December 2025, a CASA assessment, a disclosure address, no bounty and no security.txt (11 of 20).",
            "transparency": "Closed service with clear terms naming Nutshell, Inc. (15). The terms, privacy policy and DPA, all dated 2 June 2026, agree on a 30-day export window after termination, deletion from production afterwards, backup copies that may persist indefinitely and no training of generalised AI models on customer data (24 of 30). The JSON-RPC API is marked legacy with a promise of indefinite support, but there is no deprecation policy and the terms allow functions to be removed without prior notice (5 of 20). The subprocessor list at trust.nutshell.com could not be read. The policy names AWS and regions, and the DPA promises 10 days' notice of a new subprocessor (12 of 20)."
          },
          "sources": [
            {
              "what": "developer hub home",
              "url": "https://developers.nutshell.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents, with 114 reference pages read as Markdown",
              "url": "https://developers.nutshell.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "API authentication and sandbox credentials",
              "url": "https://developers.nutshell.com/docs/api-authentication.md",
              "seen": "2026-10-08"
            },
            {
              "what": "filters guide",
              "url": "https://developers.nutshell.com/docs/filters.md",
              "seen": "2026-10-08"
            },
            {
              "what": "webhooks guide",
              "url": "https://developers.nutshell.com/docs/working-with-webhooks.md",
              "seen": "2026-10-08"
            },
            {
              "what": "JSON-RPC docs, permissions and rate limits",
              "url": "https://developers-rpc.nutshell.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server help article",
              "url": "https://support.nutshell.com/en/articles/12631143-mcp-server",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth authorisation server metadata",
              "url": "https://app.nutshell.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP protected resource metadata",
              "url": "https://app.nutshell.com/.well-known/oauth-protected-resource/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "API keys help article",
              "url": "https://support.nutshell.com/en/articles/8429060-api-keys-create-api-keys-for-3rd-party-apps",
              "seen": "2026-10-08"
            },
            {
              "what": "audit log help article",
              "url": "https://support.nutshell.com/en/articles/8428844-nutshell-audit-log-tracking-team-activities",
              "seen": "2026-10-08"
            },
            {
              "what": "SOC 2 help article",
              "url": "https://support.nutshell.com/en/articles/13274534-nutshell-security-soc-2-compliance",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.nutshell.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents feed",
              "url": "https://status.nutshell.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.nutshell.com/security",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.nutshell.com/legal/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.nutshell.com/legal/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "data processing addendum",
              "url": "https://www.nutshell.com/legal/dpa",
              "seen": "2026-10-08"
            },
            {
              "what": "product updates",
              "url": "https://www.nutshell.com/product-updates",
              "seen": "2026-10-08"
            },
            {
              "what": "vendor repositories",
              "url": "https://api.github.com/orgs/nutshellcrm/repos",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.verisign.com/com/v1/domain/nutshell.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the subprocessor list and SOC 2 detail at trust.nutshell.com, a page drawn by script",
            "unchecked: the MCP server's tool definitions, count and annotations, which need an OAuth login",
            "unchecked: the API key permission types, which the help article shows only in an image",
            "unchecked: whether the MCP server is in the official MCP registry",
            "unchecked: REST behaviour on 429 and the JSON error body, since no authenticated call was made",
            "No REST rate limit numbers, SLA, API changelog or deprecation policy were found in the reviewed documentation",
            "The lead was right about API access on every plan. It did not mention the hosted MCP server, the legacy JSON-RPC API or that the vendor entity is Nutshell, Inc. in Harrisburg, with WebFX named in the site footer"
          ]
        },
        "negative": 0,
        "verdict": "The REST reference is served as Markdown with an OpenAPI fragment per operation, and the hosted MCP server uses OAuth with PKCE and can only read. No rate limit numbers, error format or API changelog were found in the reviewed documentation, and API keys carry no scopes.",
        "bestFor": "Small sales teams already on Nutshell who want an agent to read pipeline data over MCP or write records over REST at a low seat price.",
        "strengths": [
          "API access and the MCP server are included on every plan, from Foundation at $13 a seat a month billed yearly",
          "`developers.nutshell.com/llms.txt` indexes 114 REST operations, each served as Markdown with its OpenAPI 3.0 definition",
          "Hosted MCP server at `https://app.nutshell.com/mcp` with OAuth, PKCE, dynamic client registration, a revocation endpoint and read-only tools",
          "Terms and privacy policy of 2 June 2026 both state that customer data is not used to train generalised AI models",
          "14-day trial with no card, and the docs publish sandbox credentials for a demo account"
        ],
        "weaknesses": [
          "No rate limit numbers, 429 handling or Retry-After found for the REST API",
          "Error responses are documented on 9 of 114 operations, with no error body schema, and an unauthenticated REST call returns an HTML page",
          "API keys have no scopes or read-only type, and the key travels as an HTTP Basic password with a user's email",
          "No dated API changelog, no official SDK for REST and whole-spec OpenAPI download is disabled",
          "A database fault on 28 September 2026 left the application unavailable for some customers, marked major on the status page"
        ],
        "agentNotes": [
          "Authenticate REST calls with HTTP Basic, a Nutshell user's email as username and the API key as password, against `https://app.nutshell.com/rest`",
          "Use IDs in the `\u003cnumber\u003e-\u003ctype\u003e` form, such as `3-accounts`, and send updates as JSON Patch with `content-type: application/json-patch+json`",
          "Page lists with `page[limit]` and `page[page]`, which is 0-based, and call `/accounts/list/fields` or the lead and contact equivalents for valid filter keys",
          "Use the REST API for writes. The MCP server only reads, and OAuth tokens need the `read` scope",
          "Filter webhook events yourself, because every webhook receives all events and subscriptions are created in Setup, not through the API"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 49.6
          }
        ],
        "editorialScores": {
          "ergonomics": 44,
          "maintenance": 46,
          "payments": 35,
          "reliability": 42,
          "schema": 57,
          "security": 58,
          "transparency": 56
        },
        "provenanceScore": 86
      },
      "connect": {
        "http": "curl -u \"$NUTSHELL_USER_EMAIL:$NUTSHELL_API_KEY\" \\\n  --url https://app.nutshell.com/rest/accounts \\\n  --header 'accept: */*'"
      },
      "letme": {
        "capability": "https://letme.dev/crm.records",
        "tool": "https://letme.dev/nutshell"
      },
      "notable": [
        "The developer hub says API access is available to all customers regardless of plan, and that the JSON-RPC API will be maintained indefinitely while new endpoints go to REST only (https://developers.nutshell.com/)",
        "Each of the 114 REST reference pages is served as Markdown with the OpenAPI 3.0 definition of its operation when `.md` is appended. Whole-spec download is disabled in the docs settings (https://developers.nutshell.com/llms.txt)",
        "The MCP server reads leads, companies, people, users, pipelines, stages, products, lead reports, timelines and saved lists, and the help centre says it cannot change anything in the account (https://support.nutshell.com/en/articles/12631143-mcp-server)",
        "OAuth metadata lists `read` and `write` scopes, PKCE with S256, dynamic client registration and a revocation endpoint (https://app.nutshell.com/.well-known/oauth-authorization-server)",
        "Webhooks are created in Setup, API keys, and every webhook receives all events with no per-event selection (https://developers.nutshell.com/docs/working-with-webhooks)",
        "The terms of 2 June 2026 forbid using the service to benchmark it for competitive purposes and allow functions to be changed or removed without prior notice (https://www.nutshell.com/legal/terms)",
        "SOC 2 Type 1 audit completed in December 2025 per the help centre, and a CASA assessment per the security page (https://support.nutshell.com/en/articles/13274534-nutshell-security-soc-2-compliance)"
      ],
      "area": "business",
      "details": [
        {
          "label": "APIs",
          "value": "REST at `https://app.nutshell.com/rest` (114 documented operations, spec version 2.0.0), legacy JSON-RPC at `https://app.nutshell.com/api/v1/json`, webhooks, and read-only SQL access on Enterprise"
        },
        {
          "label": "MCP server",
          "value": "Hosted at `https://app.nutshell.com/mcp`, OAuth, read-only. Search and list tools for leads, companies, people, users, pipelines, stages, outcomes, activity types, sources, industries, markets, territories, tags, products, competitors, lead reports, timelines and saved lists"
        },
        {
          "label": "API plan",
          "value": "Every plan and the 14-day trial"
        },
        {
          "label": "Read and write",
          "value": "REST reads and writes accounts, contacts, leads, activities, notes, tasks, products, tags and sources. 69 GET, 28 POST, 10 DELETE, 6 PATCH and 1 PUT operations. Pipelines and stages are read-only"
        },
        {
          "label": "Credentials",
          "value": "API keys as an HTTP Basic password with a user's email, with an optional impersonation permission and no scopes. OAuth with PKCE and `read` and `write` scopes for the MCP server"
        },
        {
          "label": "Rate limits",
          "value": "No numbers published. The JSON-RPC docs say some large find and get requests are limited and that the degree varies"
        },
        {
          "label": "Pagination and filters",
          "value": "`page[limit]` and `page[page]` (0-based), `sort`, `q` for search and `filter[...]` keys listed by `/accounts/list/fields` and its lead and contact equivalents"
        },
        {
          "label": "Webhooks",
          "value": "Created in the web UI. Every webhook receives all events for contacts, companies, leads, activities, scheduler bookings and form submissions"
        },
        {
          "label": "Deletes",
          "value": "Deleted accounts, contacts, leads, notes, sources and tags can be restored within 30 days through an undelete endpoint"
        },
        {
          "label": "Audit",
          "value": "Account audit log on Business and Enterprise, covering logins with IP address, bulk edits and list exports. It cannot be exported"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 1 (December 2025) and a CASA assessment. No bug bounty. Reports go to security@nutshell.com"
        },
        {
          "label": "Status",
          "value": "status.nutshell.com on Statuspage with 12 components. One major incident in the last 90 days, on 28 September 2026"
        },
        {
          "label": "Data handling",
          "value": "Hosted on AWS. Customer data can be exported for 30 days after termination, then is deleted from production, and backup copies may persist indefinitely. Not used to train generalised AI models"
        }
      ],
      "unitPrices": [
        {
          "item": "Foundation (API and MCP included, 100 open leads)",
          "unit": "seat-month",
          "usd": 13,
          "note": "billed yearly; $19 billed monthly"
        },
        {
          "item": "Growth",
          "unit": "seat-month",
          "usd": 25,
          "note": "billed yearly; $32 billed monthly"
        },
        {
          "item": "Pro",
          "unit": "seat-month",
          "usd": 42,
          "note": "billed yearly; $49 billed monthly"
        },
        {
          "item": "Business (first plan with the audit log)",
          "unit": "seat-month",
          "usd": 59,
          "note": "billed yearly; $67 billed monthly"
        },
        {
          "item": "Enterprise (SSO and SQL access)",
          "unit": "seat-month",
          "usd": 79,
          "note": "billed yearly; $89 billed monthly"
        }
      ],
      "provenance": {
        "legalEntity": "Nutshell, Inc.",
        "domain": "nutshell.com",
        "domainRegistered": "1995-05-02",
        "endpointOnVendorDomain": true,
        "terms": "https://www.nutshell.com/legal/terms",
        "privacy": "https://www.nutshell.com/legal/privacy",
        "statusPage": "https://status.nutshell.com",
        "changelog": "https://www.nutshell.com/product-updates",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 2 June 2026) name Nutshell, Inc., 1705 North Front Street, Harrisburg, PA 17102, cover the applications and APIs, and are governed by Pennsylvania law. The site footer says Nutshell is brought to you by WebFX.",
          "The REST API, the JSON-RPC API and the MCP server all answer at app.nutshell.com.",
          "www.nutshell.com/.well-known/security.txt returns 404. The security page asks for reports at security@nutshell.com and says there is no bug bounty.",
          "The product updates page lists launches without dates and is not an API changelog. No dated API changelog was found.",
          "The subprocessor list is at trust.nutshell.com/subprocessors, a page drawn by script that we could not read.",
          "RDAP for nutshell.com gives a registration date of 1995-05-02."
        ],
        "score": 86,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Nutshell, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "nutshell.com, registered 1995-05-02 (31 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "app.nutshell.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 6,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.nutshell.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.nutshell.com/legal/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-06-02",
            "words": 6642,
            "points": 6,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: June 2, 2026",
                "says": "Last updated 2026-06-02"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These Terms are governed by the laws of the Commonwealth of Pennsylvania, without regard to its conflict-of-laws principles.",
                "says": "The law of the Commonwealth of Pennsylvania"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATING TO THESE TERMS, WHETHER IN CONTRACT, TORT, OR OTHERWISE, WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO NUTSHELL UNDER THESE TERMS DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE LIABILITY.",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Nutshell is not obligated to mediate or adjudicate such disputes and may, in its sole discretion, suspend account access pending resolution."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Material changes will be communicated by posting the updated Terms at nutshell.com/legal/terms (or a successor URL) and updating the “Last updated” date;",
                "says": "Changes are posted, with no other notice named"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you do not have such authority, or if you do not agree to these Terms, you must not accept them and may not use the Service."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Beta Features are provided AS IS, without warranty, may be modified or discontinued at any time, may not be supported, and are not subject to any service-level commitments."
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(h) use the Service to build a competing product or service or to benchmark the Service for competitive purposes;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "Nutshell may at any time, in its sole discretion and without prior notice, add, modify, remove, or discontinue features, functionality, integrations, or other aspects of the Service.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Nutshell may terminate these Terms for any reason or no reason on thirty (30) days’ written notice, in which case Nutshell will refund any prepaid fees for the unused portion of the Subscription Term."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "THE PARTIES AGREE THAT ANY DISPUTE WILL BE BROUGHT IN AN INDIVIDUAL CAPACITY ONLY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "After the account ends, customer data can be exported for 30 days on written request, and copies may stay in encrypted backups with no set purge date.",
                "quote": "Residual copies of Customer Data may persist in encrypted backup systems indefinitely following deletion from production."
              },
              {
                "date": "2026-10-08",
                "text": "Subscriptions renew automatically for a period equal to the prior term, at the rates then current.",
                "quote": "Customer’s subscription automatically renews for successive periods equal to the prior Subscription Term, at Nutshell’s then-current rates"
              },
              {
                "date": "2026-10-08",
                "text": "Nutshell may show the customer's name and logo on its website and in general marketing materials, and the customer can opt out by email.",
                "quote": "Customer may opt out of Nutshell’s marketing use of Customer’s name and logo at any time by emailing [email protected]."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.nutshell.com/legal/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-06-02",
            "words": 4594,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: June 2, 2026",
                "says": "Last updated 2026-06-02"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy explains what personal data we collect about visitors to our websites, prospects, customers, customers’ authorized users, and other individuals whose data we process;"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain personal data only for as long as necessary to fulfill the purposes for which we collected it, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "…otherwise submit to the Service (“Customer Data“), Nutshell acts as a “processor” or “service provider” under applicable data protection laws (including the EU and UK GDPR, the Swiss FADP, the California Consumer Privacy Act (“CCPA”), the Canadian PIPEDA, and the Brazilian LGPD), and the Nutshell customer is the “cont…"
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Submit requests at [email protected] or via the “Do Not Sell or Share My Personal Information” link on our website.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You have the right to know, delete, correct, opt out of “sale” and “sharing,” limit use of sensitive personal information, and to non-discrimination."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you receive a request that appears to ask for a credential outside this scope, do not provide it and report it to [email protected].",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "For transfers of personal data from the EEA, UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss-equivalent mechanisms set forth in the DPA.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We engage in certain advertising activities (see Section 5) that may be classified as “sharing” or as “sale” of personal information under some U.S. state privacy laws even though no money changes hands; you may opt out of these activities as described in Section 9."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Conversations with Nutshell's chatbots and AI functions may be recorded, logged and used to operate, secure and improve the service.",
                "quote": "Recordings: Conversations with Nutshell-provided chatbots and AI features may be recorded, logged, and used to operate, secure, and improve the Service, subject to Section 2.6 and Section 3.2."
              },
              {
                "date": "2026-10-08",
                "text": "AI assistants reach Nutshell data through MCP connectors using OAuth 2.0, limited to the scopes the user grants, and that access can be revoked at any time.",
                "quote": "Authentication: Access to authenticated Nutshell data through MCP connectors uses OAuth 2.0 and is limited to the scopes the user grants."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/nutshell.json",
      "live": {
        "slug": "nutshell",
        "probe": {
          "target": "https://app.nutshell.com/rest",
          "method": "get",
          "lastAt": "2026-10-08T21:41:44.542705588Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 333,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 269,
          "p95ms24h": 314,
          "samples24h": 26,
          "samples30d": 26,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 26,
              "ok": 26
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.nutshell.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:36:36.770165801Z"
        },
        "updatedAt": "2026-10-08T21:41:44.542705588Z"
      }
    },
    "verify": {
      "accepts": "a page on nutshell.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/nutshell.svg",
      "body": {
        "slug": "nutshell",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/nutshell",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/nutshell\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/nutshell.svg\" alt=\"Nutshell on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Nutshell on Anchor Terminal](https://www.anchorterminal.com/badges/nutshell.svg)](https://www.anchorterminal.com/tools/nutshell)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/nutshell\"\u003eNutshell on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/nutshell",
    "json": "https://www.anchorterminal.com/tools/nutshell.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/nutshell.md",
    "slim": "https://www.anchorterminal.com/tools/nutshell.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 49.6/100 · rank #607 of 722 · #12 in CRM \u0026 customer platforms · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe REST reference is served as Markdown with an OpenAPI fragment per operation, and the hosted MCP server uses OAuth with PKCE and can only read. No rate limit numbers, error format or API changelog were found in the reviewed documentation, and API keys carry no scopes.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Nutshell, Inc. (https://www.nutshell.com) |\n| Kind | HTTP API |\n| Category | CRM \u0026 customer platforms (https://www.anchorterminal.com/categories/crm) |\n| Transport | HTTP |\n| Endpoint | `https://app.nutshell.com/rest` |\n| Auth | OAuth or key · REST and JSON-RPC use HTTP Basic over HTTPS, with a Nutshell user's email as the username and an API key as the password. An admin creates keys under Setup, API keys, and chooses a permission type, one of which allows impersonating any user. Keys have no scopes. The MCP server at `https://app.nutshell.com/mcp` uses OAuth authorisation code with PKCE (S256), dynamic client registration at `/oauth/register`, a revocation endpoint and two scopes, `read` and `write`. Access is self-serve on every plan and the trial. |\n| Pricing | Paid ($13 / seat-mo) · No free plan. A 14-day trial needs no card, and the API and MCP server are included on every plan. Five plans a seat a month billed yearly, Foundation $13, Growth $25, Pro $42, Business $59 and Enterprise $79, or $19, $32, $49, $67 and $89 billed monthly. API calls are not billed separately. The docs publish sandbox credentials for a demo account (https://www.nutshell.com/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the developer docs, the OAuth metadata or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Nutshell's Terms of Service |\n| Docs | https://developers.nutshell.com/ |\n| llms.txt | https://developers.nutshell.com/llms.txt |\n| Last release | 2026-08-21 |\n| APIs | REST at `https://app.nutshell.com/rest` (114 documented operations, spec version 2.0.0), legacy JSON-RPC at `https://app.nutshell.com/api/v1/json`, webhooks, and read-only SQL access on Enterprise |\n| MCP server | Hosted at `https://app.nutshell.com/mcp`, OAuth, read-only. Search and list tools for leads, companies, people, users, pipelines, stages, outcomes, activity types, sources, industries, markets, territories, tags, products, competitors, lead reports, timelines and saved lists |\n| API plan | Every plan and the 14-day trial |\n| Read and write | REST reads and writes accounts, contacts, leads, activities, notes, tasks, products, tags and sources. 69 GET, 28 POST, 10 DELETE, 6 PATCH and 1 PUT operations. Pipelines and stages are read-only |\n| Credentials | API keys as an HTTP Basic password with a user's email, with an optional impersonation permission and no scopes. OAuth with PKCE and `read` and `write` scopes for the MCP server |\n| Rate limits | No numbers published. The JSON-RPC docs say some large find and get requests are limited and that the degree varies |\n| Pagination and filters | `page[limit]` and `page[page]` (0-based), `sort`, `q` for search and `filter[...]` keys listed by `/accounts/list/fields` and its lead and contact equivalents |\n| Webhooks | Created in the web UI. Every webhook receives all events for contacts, companies, leads, activities, scheduler bookings and form submissions |\n| Deletes | Deleted accounts, contacts, leads, notes, sources and tags can be restored within 30 days through an undelete endpoint |\n| Audit | Account audit log on Business and Enterprise, covering logins with IP address, bulk edits and list exports. It cannot be exported |\n| Certifications | SOC 2 Type 1 (December 2025) and a CASA assessment. No bug bounty. Reports go to security@nutshell.com |\n| Status | status.nutshell.com on Statuspage with 12 components. One major incident in the last 90 days, on 28 September 2026 |\n| Data handling | Hosted on AWS. Customer data can be exported for 30 days after termination, then is deleted from production, and backup copies may persist indefinitely. Not used to train generalised AI models |\n| Capabilities | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks |\n| Tags | hosted, closed-source, mcp, oauth, llms-txt, webhooks, no-card, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/nutshell.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 42 | 8.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 57 | 9.3 |\n| Agent ergonomics | 13% | 16.2 | 44 | 7.2 |\n| Security \u0026 auth | 14% | 17.5 | 58 | 10.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 35 | 4.4 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 46 | 4.0 |\n| Transparency \u0026 trust (editorial 56, provenance 86) | 7% | 8.8 | 71 | 6.2 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **49.6 → D** |\n\n### Why each score\n\n- Reliability 42: Read with the hosted lines. Status page at status.nutshell.com with 12 components and incident history back to 2017 (20). One incident in the last 90 days, a database cluster fault on 28 September 2026 that left the application unavailable for some customers, marked major, mitigated after 43 minutes and closed after about seven hours. Scored between the minor and one-major bands because the outage was partial and under an hour to mitigation (12 of 30). No rate limit numbers for REST, and the JSON-RPC docs say only that limits vary (0). No 429, Retry-After, backoff or idempotency guidance found (0). No SLA found, and the terms supply the service as is (0). The REST API is GA and the MCP server carries no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 57: Each of the 114 REST reference pages carries the OpenAPI 3.0 definition of its operation, but whole-spec download is disabled (18 of 25). `llms.txt` and Markdown for every docs page (10). 78 of 114 operations have a description, and the newer ones state scope and visibility rules (11 of 20). Enums on sort fields and patterns on IDs, but filters and custom fields are open objects and `page[limit]` is typed as a string on some operations (9 of 15). Schema examples are present, and error responses appear on 9 operations with no error body schema (5 of 15). The spec is version 2.0.0 and pages carry update stamps, with no dated API changelog (4 of 15).\n- Agent ergonomics 44: The MCP server is read-only with about 17 groups of search and list tools per the help centre. The tool definitions sit behind OAuth and were not read. REST lists take `page[limit]` with no field selection (13 of 25). `page[page]`, `sort`, `q` and `filter[...]` keys, with field lists from `/accounts/list/fields`, and no stated maximum page size (16 of 20). Errors are barely documented and an unauthenticated REST call returned an HTML page (4 of 20). No idempotency keys. Deletes can be undone within 30 days and the MCP server cannot write (6 of 20). Few required fields, and no official REST SDK. The only client is a PHP JSON-RPC sample last pushed in 2023 (5 of 15).\n- Security \u0026 auth 58: The MCP server uses OAuth authorisation code with PKCE, dynamic client registration, a revocation endpoint and `read` and `write` scopes. REST uses unscoped API keys sent as an HTTP Basic password with a user's email, and a key can be allowed to impersonate any user (24 of 30). The MCP server is read-only and OAuth has a `read` scope, but no read-only API key type was found (12 of 20). Records hold emails, notes and form submissions, with no injection guidance found (3 of 15). An audit log on Business and Enterprise covers logins, bulk edits and exports, and API changes are logged under the key name or the impersonated user (8 of 15). SOC 2 Type 1 from December 2025, a CASA assessment, a disclosure address, no bounty and no security.txt (11 of 20).\n- Payments \u0026 pricing 35: No x402, MPP or L402 (0). Plan prices are public, $13 to $79 a seat a month billed yearly, with nothing per call (10). 14-day trial with no card, and the API is included (20). A person signs up in a browser and an admin creates the key. The docs publish sandbox credentials for a shared demo account, which lets an agent test calls with no signup but not reach its own data (5 of 20).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 46: The newest REST reference page was updated on 21 August 2026, 48 days before the check (20 of 30). Five reference pages changed between 5 and 21 August 2026, for quote and invoice status, to-dos and dashboard fields. These are page stamps, not changelog entries (20). No API changelog, and the product updates page is undated. Live support on every plan per the pricing page, untested (6 of 25). No current official SDK, and the MCP registry was not checked (0). No packages to judge (0).\n- Transparency \u0026 trust 71: Closed service with clear terms naming Nutshell, Inc. (15). The terms, privacy policy and DPA, all dated 2 June 2026, agree on a 30-day export window after termination, deletion from production afterwards, backup copies that may persist indefinitely and no training of generalised AI models on customer data (24 of 30). The JSON-RPC API is marked legacy with a promise of indefinite support, but there is no deprecation policy and the terms allow functions to be removed without prior notice (5 of 20). The subprocessor list at trust.nutshell.com could not be read. The policy names AWS and regions, and the DPA promises 10 days' notice of a new subprocessor (12 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/nutshell.md (JSON https://www.anchorterminal.com/fixes/nutshell.json)\n\n### What we couldn't check\n\n- unchecked: the subprocessor list and SOC 2 detail at trust.nutshell.com, a page drawn by script\n- unchecked: the MCP server's tool definitions, count and annotations, which need an OAuth login\n- unchecked: the API key permission types, which the help article shows only in an image\n- unchecked: whether the MCP server is in the official MCP registry\n- unchecked: REST behaviour on 429 and the JSON error body, since no authenticated call was made\n- No REST rate limit numbers, SLA, API changelog or deprecation policy were found in the reviewed documentation\n- The lead was right about API access on every plan. It did not mention the hosted MCP server, the legacy JSON-RPC API or that the vendor entity is Nutshell, Inc. in Harrisburg, with WebFX named in the site footer\n\n### Sources\n\n- developer hub home: \u003chttps://developers.nutshell.com/\u003e (seen 2026-10-08)\n- docs index for agents, with 114 reference pages read as Markdown: \u003chttps://developers.nutshell.com/llms.txt\u003e (seen 2026-10-08)\n- API authentication and sandbox credentials: \u003chttps://developers.nutshell.com/docs/api-authentication.md\u003e (seen 2026-10-08)\n- filters guide: \u003chttps://developers.nutshell.com/docs/filters.md\u003e (seen 2026-10-08)\n- webhooks guide: \u003chttps://developers.nutshell.com/docs/working-with-webhooks.md\u003e (seen 2026-10-08)\n- JSON-RPC docs, permissions and rate limits: \u003chttps://developers-rpc.nutshell.com/\u003e (seen 2026-10-08)\n- MCP server help article: \u003chttps://support.nutshell.com/en/articles/12631143-mcp-server\u003e (seen 2026-10-08)\n- OAuth authorisation server metadata: \u003chttps://app.nutshell.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- MCP protected resource metadata: \u003chttps://app.nutshell.com/.well-known/oauth-protected-resource/mcp\u003e (seen 2026-10-08)\n- API keys help article: \u003chttps://support.nutshell.com/en/articles/8429060-api-keys-create-api-keys-for-3rd-party-apps\u003e (seen 2026-10-08)\n- audit log help article: \u003chttps://support.nutshell.com/en/articles/8428844-nutshell-audit-log-tracking-team-activities\u003e (seen 2026-10-08)\n- SOC 2 help article: \u003chttps://support.nutshell.com/en/articles/13274534-nutshell-security-soc-2-compliance\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.nutshell.com/pricing\u003e (seen 2026-10-08)\n- status incidents feed: \u003chttps://status.nutshell.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.nutshell.com/security\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.nutshell.com/legal/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.nutshell.com/legal/privacy\u003e (seen 2026-10-08)\n- data processing addendum: \u003chttps://www.nutshell.com/legal/dpa\u003e (seen 2026-10-08)\n- product updates: \u003chttps://www.nutshell.com/product-updates\u003e (seen 2026-10-08)\n- vendor repositories: \u003chttps://api.github.com/orgs/nutshellcrm/repos\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.verisign.com/com/v1/domain/nutshell.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 86/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Nutshell, Inc. | 20/20 |\n| Domain age | nutshell.com, registered 1995-05-02 (31 years) | 15/15 |\n| Endpoint on the vendor's domain | app.nutshell.com | 15/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points | 6/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.nutshell.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Terms of Service (last updated 2 June 2026) name Nutshell, Inc., 1705 North Front Street, Harrisburg, PA 17102, cover the applications and APIs, and are governed by Pennsylvania law. The site footer says Nutshell is brought to you by WebFX.\n\nThe REST API, the JSON-RPC API and the MCP server all answer at app.nutshell.com.\n\nwww.nutshell.com/.well-known/security.txt returns 404. The security page asks for reports at security@nutshell.com and says there is no bug bounty.\n\nThe product updates page lists launches without dates and is not an API changelog. No dated API changelog was found.\n\nThe subprocessor list is at trust.nutshell.com/subprocessors, a page drawn by script that we could not read.\n\nRDAP for nutshell.com gives a registration date of 1995-05-02.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.nutshell.com/legal/terms), read 2026-10-08, dated 2026-06-02, states 7 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"(h) use the Service to build a competing product or service or to benchmark the Service for competitive purposes;\"\n- To know. Says the terms or the service can change without notice (costs points). \"Nutshell may at any time, in its sole discretion and without prior notice, add, modify, remove, or discontinue features, functionality, integrations, or other aspects of the Service.\"\n- To know. Says access can be ended without notice or for any reason. \"Nutshell may terminate these Terms for any reason or no reason on thirty (30) days’ written notice, in which case Nutshell will refund any prepaid fees for the unused portion of the Subscription Term.\"\n- To know. Requires arbitration or waives class actions. \"THE PARTIES AGREE THAT ANY DISPUTE WILL BE BROUGHT IN AN INDIVIDUAL CAPACITY ONLY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING.\"\n- Gives the date it was last updated. Last updated 2026-06-02.\n- Names the governing law or courts. The law of the Commonwealth of Pennsylvania.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Says how changes to the terms are announced. Changes are posted, with no other notice named.\n- Also in the text (2026-10-08). After the account ends, customer data can be exported for 30 days on written request, and copies may stay in encrypted backups with no set purge date. \"Residual copies of Customer Data may persist in encrypted backup systems indefinitely following deletion from production.\"\n- Also in the text (2026-10-08). Subscriptions renew automatically for a period equal to the prior term, at the rates then current. \"Customer’s subscription automatically renews for successive periods equal to the prior Subscription Term, at Nutshell’s then-current rates\"\n- Also in the text (2026-10-08). Nutshell may show the customer's name and logo on its website and in general marketing materials, and the customer can opt out by email. \"Customer may opt out of Nutshell’s marketing use of Customer’s name and logo at any time by emailing [email protected].\"\n\n**Privacy policy** (https://www.nutshell.com/legal/privacy), read 2026-10-08, dated 2026-06-02, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"We engage in certain advertising activities (see Section 5) that may be classified as “sharing” or as “sale” of personal information under some U.S. state privacy laws even though no money changes hands; you may opt out of these activities as described in Section 9.\"\n- Gives the date it was last updated. Last updated 2026-06-02.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Conversations with Nutshell's chatbots and AI functions may be recorded, logged and used to operate, secure and improve the service. \"Recordings: Conversations with Nutshell-provided chatbots and AI features may be recorded, logged, and used to operate, secure, and improve the Service, subject to Section 2.6 and Section 3.2.\"\n- Also in the text (2026-10-08). AI assistants reach Nutshell data through MCP connectors using OAuth 2.0, limited to the scopes the user grants, and that access can be revoked at any time. \"Authentication: Access to authenticated Nutshell data through MCP connectors uses OAuth 2.0 and is limited to the scopes the user grants.\"\n\n## Live (updated 2026-10-08 21:41 UTC)\n\n- Right now: up, HTTP 404, 333 ms, checked 2026-10-08 21:41 UTC (get on `https://app.nutshell.com/rest`)\n- Uptime 24h 100.0% (26 probes) · 30 days 100.0% (26 probes) · p50 269 ms · p95 314 ms\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/nutshell.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Foundation (API and MCP included, 100 open leads) | $13 | per seat per month | billed yearly; $19 billed monthly |\n| Growth | $25 | per seat per month | billed yearly; $32 billed monthly |\n| Pro | $42 | per seat per month | billed yearly; $49 billed monthly |\n| Business (first plan with the audit log) | $59 | per seat per month | billed yearly; $67 billed monthly |\n| Enterprise (SSO and SQL access) | $79 | per seat per month | billed yearly; $89 billed monthly |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- API access and the MCP server are included on every plan, from Foundation at $13 a seat a month billed yearly\n- `developers.nutshell.com/llms.txt` indexes 114 REST operations, each served as Markdown with its OpenAPI 3.0 definition\n- Hosted MCP server at `https://app.nutshell.com/mcp` with OAuth, PKCE, dynamic client registration, a revocation endpoint and read-only tools\n- Terms and privacy policy of 2 June 2026 both state that customer data is not used to train generalised AI models\n- 14-day trial with no card, and the docs publish sandbox credentials for a demo account\n\n## Weaknesses\n\n- No rate limit numbers, 429 handling or Retry-After found for the REST API\n- Error responses are documented on 9 of 114 operations, with no error body schema, and an unauthenticated REST call returns an HTML page\n- API keys have no scopes or read-only type, and the key travels as an HTTP Basic password with a user's email\n- No dated API changelog, no official SDK for REST and whole-spec OpenAPI download is disabled\n- A database fault on 28 September 2026 left the application unavailable for some customers, marked major on the status page\n\n## Before you call it (notes for agents)\n\n1. Authenticate REST calls with HTTP Basic, a Nutshell user's email as username and the API key as password, against `https://app.nutshell.com/rest`\n2. Use IDs in the `\u003cnumber\u003e-\u003ctype\u003e` form, such as `3-accounts`, and send updates as JSON Patch with `content-type: application/json-patch+json`\n3. Page lists with `page[limit]` and `page[page]`, which is 0-based, and call `/accounts/list/fields` or the lead and contact equivalents for valid filter keys\n4. Use the REST API for writes. The MCP server only reads, and OAuth tokens need the `read` scope\n5. Filter webhook events yourself, because every webhook receives all events and subscriptions are created in Setup, not through the API\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -u \"$NUTSHELL_USER_EMAIL:$NUTSHELL_API_KEY\" \\\n  --url https://app.nutshell.com/rest/accounts \\\n  --header 'accept: */*'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/nutshell. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| HubSpot API + MCP | BB | 71.5 | 105 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/hubspot-mcp.md |\n| Zoho CRM | BB | 70.8 | 128 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/zoho-crm.md |\n| Microsoft Dynamics 365 Sales | B | 69.7 | 150 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/dynamics-365-sales.md |\n| Close API + MCP | B | 66.7 | 229 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/close.md |\n| Twenty API + MCP | B | 65.9 | 250 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/twenty.md |\n| Affinity | B | 63.4 | 311 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/affinity.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The developer hub says API access is available to all customers regardless of plan, and that the JSON-RPC API will be maintained indefinitely while new endpoints go to REST only (source: \u003chttps://developers.nutshell.com/\u003e)\n- Each of the 114 REST reference pages is served as Markdown with the OpenAPI 3.0 definition of its operation when `.md` is appended. Whole-spec download is disabled in the docs settings (source: \u003chttps://developers.nutshell.com/llms.txt\u003e)\n- The MCP server reads leads, companies, people, users, pipelines, stages, products, lead reports, timelines and saved lists, and the help centre says it cannot change anything in the account (source: \u003chttps://support.nutshell.com/en/articles/12631143-mcp-server\u003e)\n- OAuth metadata lists `read` and `write` scopes, PKCE with S256, dynamic client registration and a revocation endpoint (source: \u003chttps://app.nutshell.com/.well-known/oauth-authorization-server\u003e)\n- Webhooks are created in Setup, API keys, and every webhook receives all events with no per-event selection (source: \u003chttps://developers.nutshell.com/docs/working-with-webhooks\u003e)\n- The terms of 2 June 2026 forbid using the service to benchmark it for competitive purposes and allow functions to be changed or removed without prior notice (source: \u003chttps://www.nutshell.com/legal/terms\u003e)\n- SOC 2 Type 1 audit completed in December 2025 per the help centre, and a CASA assessment per the security page (source: \u003chttps://support.nutshell.com/en/articles/13274534-nutshell-security-soc-2-compliance\u003e)\n\n## Compare\n\n- [Affinity vs Nutshell](https://www.anchorterminal.com/compare/affinity-vs-nutshell.md): B 63.4 vs D 49.6\n- [Attio API + MCP vs Nutshell](https://www.anchorterminal.com/compare/attio-vs-nutshell.md): B 63.1 vs D 49.6\n- [Capsule CRM vs Nutshell](https://www.anchorterminal.com/compare/capsule-crm-vs-nutshell.md): C 55.7 vs D 49.6\n- [Close API + MCP vs Nutshell](https://www.anchorterminal.com/compare/close-vs-nutshell.md): B 66.7 vs D 49.6\n- [Copper API vs Nutshell](https://www.anchorterminal.com/compare/copper-vs-nutshell.md): D 46.7 vs D 49.6\n- [Microsoft Dynamics 365 Sales vs Nutshell](https://www.anchorterminal.com/compare/dynamics-365-sales-vs-nutshell.md): B 69.7 vs D 49.6\n- [folk API + MCP vs Nutshell](https://www.anchorterminal.com/compare/folk-vs-nutshell.md): C 60.8 vs D 49.6\n- [Freshsales API vs Nutshell](https://www.anchorterminal.com/compare/freshsales-vs-nutshell.md): E 40.6 vs D 49.6\n- [HubSpot API + MCP vs Nutshell](https://www.anchorterminal.com/compare/hubspot-mcp-vs-nutshell.md): BB 71.5 vs D 49.6\n- [Nutshell vs Pipedrive API + MCP](https://www.anchorterminal.com/compare/nutshell-vs-pipedrive.md): D 49.6 vs C 60.5\n- [Nutshell vs Salesforce API + MCP](https://www.anchorterminal.com/compare/nutshell-vs-salesforce.md): D 49.6 vs C 60.5\n- [Nutshell vs Streak API + MCP](https://www.anchorterminal.com/compare/nutshell-vs-streak.md): D 49.6 vs D 46.4\n- [Nutshell vs Twenty API + MCP](https://www.anchorterminal.com/compare/nutshell-vs-twenty.md): D 49.6 vs B 65.9\n- [Nutshell vs Zoho CRM](https://www.anchorterminal.com/compare/nutshell-vs-zoho-crm.md): D 49.6 vs BB 70.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on nutshell.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"nutshell\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/nutshell\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/nutshell.svg\" alt=\"Nutshell on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Nutshell on Anchor Terminal](https://www.anchorterminal.com/badges/nutshell.svg)](https://www.anchorterminal.com/tools/nutshell)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/nutshell\"\u003eNutshell on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Nutshell is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/nutshell-dark.png\n- Light: https://www.anchorterminal.com/assets/share/nutshell-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "CRM \u0026 customer platforms",
        "url": "https://www.anchorterminal.com/categories/crm"
      },
      {
        "name": "Nutshell",
        "url": ""
      }
    ],
    "description": "Nutshell is a sales CRM for small teams, with email marketing and quoting built in. Agents reach it through a REST API at app.nutshell.com/rest, a legacy JSON-RPC API, webhooks and a hosted read-only MCP server.",
    "facts": [
      "rank #607 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Nutshell",
    "image": "https://www.anchorterminal.com/assets/og/tools-nutshell.png",
    "path": "/tools/nutshell",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Nutshell review for AI agents, grade D (49.6/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/nutshell"
  },
  "tokens": {
    "markdown": 7450,
    "slim": 1780
  },
  "version": 1
}
