# Nutshell (slim) > Nutshell is a sales CRM for small teams, with email marketing and quoting built in. Agents reach it through a REST API at app.nutshell.com/rest, a legacy JSON-RPC API, webhooks and a hosted read-only MCP server. - Full: https://www.anchorterminal.com/tools/nutshell.md (~7,450 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/nutshell.json · canonical https://www.anchorterminal.com/tools/nutshell - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 49.6/100 · rank #607 of 722 · #12 in CRM & customer platforms · not agent-ready · confidence medium** Assessment: The REST reference is served as Markdown with an OpenAPI fragment per operation, and the hosted MCP server uses OAuth with PKCE and can only read. No rate limit numbers, error format or API changelog were found in the reviewed documentation, and API keys carry no scopes. ## Facts - Kind: HTTP API · vendor: Nutshell, Inc. · category: CRM & customer platforms · legal entity: Nutshell, Inc. · provenance 86/100 - Endpoint: `https://app.nutshell.com/rest` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Nutshell's Terms of Service - Probe metrics: not measured yet (probes haven't run) - APIs: REST at `https://app.nutshell.com/rest` (114 documented operations, spec version 2.0.0), legacy JSON-RPC at `https://app.nutshell.com/api/v1/json`, webhooks, and read-only SQL access on Enterprise - MCP server: Hosted at `https://app.nutshell.com/mcp`, OAuth, read-only. Search and list tools for leads, companies, people, users, pipelines, stages, outcomes, activity types, sources, industries, markets, territories, tags, products, competitors, lead reports, timelines and saved lists - API plan: Every plan and the 14-day trial - Read and write: REST reads and writes accounts, contacts, leads, activities, notes, tasks, products, tags and sources. 69 GET, 28 POST, 10 DELETE, 6 PATCH and 1 PUT operations. Pipelines and stages are read-only - Credentials: API keys as an HTTP Basic password with a user's email, with an optional impersonation permission and no scopes. OAuth with PKCE and `read` and `write` scopes for the MCP server - Rate limits: No numbers published. The JSON-RPC docs say some large find and get requests are limited and that the degree varies - Pagination and filters: `page[limit]` and `page[page]` (0-based), `sort`, `q` for search and `filter[...]` keys listed by `/accounts/list/fields` and its lead and contact equivalents - Webhooks: Created in the web UI. Every webhook receives all events for contacts, companies, leads, activities, scheduler bookings and form submissions - Deletes: Deleted accounts, contacts, leads, notes, sources and tags can be restored within 30 days through an undelete endpoint - Audit: Account audit log on Business and Enterprise, covering logins with IP address, bulk edits and list exports. It cannot be exported - Certifications: SOC 2 Type 1 (December 2025) and a CASA assessment. No bug bounty. Reports go to security@nutshell.com - Status: status.nutshell.com on Statuspage with 12 components. One major incident in the last 90 days, on 28 September 2026 - Data handling: Hosted on AWS. Customer data can be exported for 30 days after termination, then is deleted from production, and backup copies may persist indefinitely. Not used to train generalised AI models - Prices: Foundation (API and MCP included, 100 open leads) $13 per seat per month; Growth $25 per seat per month; Pro $42 per seat per month; Business (first plan with the audit log) $59 per seat per month; Enterprise (SSO and SQL access) $79 per seat per month - Scores: Reliability 42, Performance pending, Schema & documentation 57, Agent ergonomics 44, Security & auth 58, Payments & pricing 35, Task success pending, Maintenance & community 46, Transparency & trust 71 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines. · Schema & documentation, Each of the 114 REST reference pages carries the OpenAPI 3.0 definition of its operation, but whole-spec download is disabled (18 of 25). · Agent ergonomics, The MCP server is read-only with about 17 groups of search and list tools per the help centre. · Security & auth, The MCP server uses OAuth authorisation code with PKCE, dynamic client registration, a revocation endpoint and `read` and `write` scopes. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest REST reference page was updated on 21 August 2026, 48 days before the check (20 of 30). · Transparency & trust, Closed service with clear terms naming Nutshell, Inc. - Sources: 21, open questions: 7, both in the full twin - Capabilities: crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks - JSON: https://www.anchorterminal.com/api/v1/tools/nutshell.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/nutshell.svg` or a link to https://www.anchorterminal.com/tools/nutshell from a page on nutshell.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Authenticate REST calls with HTTP Basic, a Nutshell user's email as username and the API key as password, against `https://app.nutshell.com/rest` 2. Use IDs in the `-` form, such as `3-accounts`, and send updates as JSON Patch with `content-type: application/json-patch+json` 3. Page lists with `page[limit]` and `page[page]`, which is 0-based, and call `/accounts/list/fields` or the lead and contact equivalents for valid filter keys 4. Use the REST API for writes. The MCP server only reads, and OAuth tokens need the `read` scope 5. Filter webhook events yourself, because every webhook receives all events and subscriptions are created in Setup, not through the API ## Connect ```bash curl -u "$NUTSHELL_USER_EMAIL:$NUTSHELL_API_KEY" \ --url https://app.nutshell.com/rest/accounts \ --header 'accept: */*' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/nutshell ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | HubSpot API + MCP | BB | 71.5 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/hubspot-mcp.min.md | | Zoho CRM | BB | 70.8 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/zoho-crm.min.md | | Microsoft Dynamics 365 Sales | B | 69.7 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/dynamics-365-sales.min.md | | Close API + MCP | B | 66.7 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/close.min.md | | Twenty API + MCP | B | 65.9 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/twenty.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)