OpenProject
by OpenProject GmbH HTTP API in Project & task management
OpenProject GmbH · openproject.org since 2003 · status page · who's behind it
OpenProject is open-source project management software for work packages, Gantt plans, boards and time tracking, sold as a cloud service and for self-hosting. Agents reach it through the APIv3 REST API, and paid plans add an MCP server.
Good for Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.
Is this your product? Claim this listing or verify it
Assessment. OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.
Facts
- Transport
- HTTP
- Auth
- OAuth or key
- Pricing
- Freemium · $7.25 / seat-mo
- x402
- No
- Licence
- GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service
- llms.txt
- not found
- Last release
- GitHub stars
- 16k
- Surface graded
- APIv3 of OpenProject Enterprise cloud at
https://<name>.openproject.com/api/v3(or an openproject.eu host on the EU shard). The same API ships in the free Community edition for self-hosting - API
- OpenAPI 3.1, 234 paths and 320 operations (178 GET, 80 POST, 32 PATCH, 30 DELETE). HAL+JSON responses. Covers work packages, projects, portfolios, time entries, memberships, queries, versions, wiki pages, notifications and more
- Authentication
- Personal API token as Bearer or as Basic auth with user name
apikey. OAuth 2.0 authorisation code, PKCE and client credentials with scopesapi_v3,mcp,scim_v2andbcf_v2_1. JWTs from a configured OIDC provider - MCP server
- Enterprise add-on for Professional, Premium and Corporate, at
/mcpon the instance. 23 tools per the docs, among themsearch_work_packages,create_work_package,update_work_package,create_work_package_commentand four time entry tools, plus ten resources. Tools can be switched off one by one - Rate limits
- None published for the cloud API. Self-hosted installs can turn on a rule of six requests per three seconds on API form endpoints
- Pagination and sizing
pageSizeandoffseton collections, with a maximum page size set by the administrator.selecton eight collection endpoints.filterswith operators andsortBy- Errors
errorIdentifierURNs such asurn:openproject-org:api:v3:errors:MissingPermission, withMultipleErrorsgrouping per-property validation failures. 409UpdateConflicton a stalelockVersion- Webhooks
- Set by an administrator, with a signature secret, per-project selection and events for projects, work packages, comments, time entries and attachments
- SLA
- 99.9 per cent availability a calendar year excluding scheduled maintenance, with a credit of 5 per cent of the monthly fee per hour beyond it, claimed within 30 days
- Security programme
- Signed security.txt, disclosure policy, GitHub advisories with CVEs, a YesWeHack bounty sponsored by the European Commission, signed container images with SBOM and VEX documents
- Status
- status.openproject.com on UptimeRobot. Figures load by script from a path robots.txt disallows
- Sub-processors
- openproject.com shard, AWS, MessageBird, Postmark and mailbox.org. openproject.eu shard, Scaleway, rapidmail and mailbox.org. List updated 18 May 2026
- Releases
- 17.9.1 on 1 October 2026, 17.9.0 and 17.8.1 on 30 September, 17.8.0 on 2 September, 17.7.x in August
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- OpenAPI 3.1 document with 234 paths and 320 operations, public on the docs site and served by every instance at
/api/v3/spec.json - Errors carry a stable
errorIdentifierURN, and validation failures list one entry per property - The Community edition is GPL-3.0 and free to self-host with the REST API included, and the cloud trial needs no credit card
- Seven releases between 5 August and 1 October 2026, with security fixes published as GitHub advisories and CVEs
- The service description commits to 99.9 per cent yearly availability with service credits, and an EU shard keeps all sub-processors in the EU
Weaknesses
- 83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection
- No request limit, 429 behaviour or Retry-After guidance is published for the cloud API
- Personal API tokens act with their user's full permissions, and OAuth has one scope per API with no read-only form
- No official SDK. The client libraries the docs list are community projects the vendor says it does not vet
- The MCP server is an Enterprise add-on for the Professional plan and above, which starts at 25 users
Before you call it notes for agents
- Send the API token as
Authorization: Bearer <token>, or as the Basic auth password with the user nameapikey - Read the resource first and send its current
lockVersionwith every PATCH. A stale value returns 409UpdateConflict - POST to the
/formendpoint of a work package to learn writable fields and allowed values before creating or updating - URL-encode
filtersas a JSON array, and addpageSize,offsetandselectto keep work package lists small - Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input
Who's behind it provenance 95/100
- Legal entity namedOpenProject GmbH20/20
- Domain ageopenproject.org, registered 2003-10-24 (22 years)15/15
- Endpoint on the vendor's domainopenproject.org15/15
- Terms of serviceread, states 3 of the 7 things a reader expects6.6/10
- Privacy policyread, states 6 of the 8 things a reader expects8.5/10
- Status pagestatus.openproject.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2026-08-06, states 3 of 7
TL;DR Dated 2026-08-06. States 3 of the 7 things a reader expects, and we didn't find the governing law, a liability limit, how changes are announced or what users may not do. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-08-06
Last updated: 2026-08-06
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
Not found in the text.
Says where a dispute would be heard and under whose law.
States a limit on its liability
Not found in the text.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
§ 5 Contractual Term and Termination of the Agreement
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced
Not found in the text.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Not found in the text.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Further details regarding the services that OpenProject will provide, in particular as regards the functional scope of the software or its technical and hours of availability, data portability, or applicable service levels, can be found in the service or selected rate plan description.
Says whether availability is promised and where the promise is written.
The contract term renews automatically for the originally selected period unless the customer terminates it.
The contractual term shall be automatically extended by the originally selected period, unless the contract is terminated as follows:
Noted by a second reader on 2026-10-08.
OpenProject may name the customer as a user of its products in reference lists and external communications, to an appropriate and customary extent.
OpenProject may refer to the Customer’s use of OpenProject products pursuant to a contractual relationship with OpenProject and to an appropriate and customary extent in reference lists and in its external communications.
Noted by a second reader on 2026-10-08.
If the customer gives no deletion instructions by the end of the term, OpenProject asks it to back up its data on its own systems within 21 days.
If the Customer fails to specify any corresponding provisions by the end of the contractual term, OpenProject will request the Customer to back up their data on their own systems within 21 days.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 7,259 words
Privacy policy gives no date, states 6 of 8
TL;DR Gives no date. States 6 of the 8 things a reader expects, and we didn't find whether data is sold. The rules found no clause to flag.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
In this process, we collect and process the following personal data:
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 90 days
Your data will be deleted no later than 90 days.
Says when data sent to the service is deleted.
Says who else receives the data
Our service provider is based in the European Economic Area, does not use the texts translated for us for further training of its AI, does not store the texts beyond the translation process, and is bound to us by a data processing agreement regarding data protection and professional confidentiality.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
In some cases, your consent is the legal basis, pursuant to Article 6 (1) (a) and Article 7 GDPR, which you may revoke at any time with with effect for the future by sending an email to privacy@openproject.com.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@openproject.com
In some cases, your consent is the legal basis, pursuant to Article 6 (1) (a) and Article 7 GDPR, which you may revoke at any time with with effect for the future by sending an email to privacy@openproject.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards, including the European Commission’s Standard Contractual Clauses where applicable, are in place.
The countries data goes to and the safeguard used.
An Enterprise Cloud instance is deleted automatically six months after the contract expires.
Your instance of the OpenProject Enterprise Cloud will be automatically deleted six months after the expiry of your contract.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 7,432 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Service (last updated 6 August 2026) name OpenProject GmbH, Krausenstrasse 9, 10117 Berlin, Germany, and cover both the cloud and the on-premises Enterprise edition. The German version takes precedence.
The privacy policy (version 30 July 2026) has a section on OpenProject Enterprise Cloud, where OpenProject GmbH is processor and the customer controller. The data processing agreement at https://www.openproject.org/legal/data-processing-agreement/ is part of the terms.
Cloud instances answer at <name>.openproject.com or, on the EU shard, an openproject.eu host. Both are the vendor's domains, apart from the openproject.org site that carries the docs and legal pages. Self-hosted instances answer on the owner's domain.
www.openproject.org/.well-known/security.txt is PGP-signed, names security@openproject.com and expires on 31 December 2026.
RDAP for openproject.org gives a registration date of 2003-10-24 and InterNetX GmbH as registrar.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-09 07:58 UTC
- Vendor status page unknown, no machine-readable status found · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/openproject.json
Notable
- APIv3 is a hypermedia REST API in HAL+JSON, documented in one OpenAPI 3.1 file with 234 paths and 320 operations, which each instance also serves at
/api/v3/spec.jsonsource - The MCP server at
/mcpis an Enterprise add-on for the Professional, Premium and Corporate plans. The docs list 23 tools and ten resources, and version 17.9 added time entry tools source - 83 security advisories were published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical. Several credit a YesWeHack bounty sponsored by the European Commission source
- The service description commits to 99.9 per cent availability a year for the cloud, with a 5 per cent credit per hour beyond it source
- The cloud runs as two shards, openproject.com on AWS and openproject.eu on Scaleway, with every EU-shard sub-processor based in the EU source
- No request limit for the API is published. The configuration docs describe one optional rule for self-hosted installs, six requests per three seconds on form endpoints source
- The security statement says OpenProject has no bug bounty programme of its own and targets a fix for critical and high findings within 21 days of confirmation source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 10.4 | |
Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. The same API ships in the free Community edition. Status page at status.openproject.com, run on UptimeRobot, with a 90-day uptime view and an update history (20). The page draws its figures by script from a path its robots.txt disallows, so we could not read the incident record. No readable history (5). No request limit for the API is published for the cloud. The only documented rule is an optional one for self-hosted installs, six requests per three seconds on form endpoints, off by default (3 of 15). No 429 or Retry-After guidance and no idempotency keys were found. Updates must send lockVersion, and a stale value is refused with 409 UpdateConflict (4 of 15). The service description commits to 99.9 per cent availability a year, with a credit of 5 per cent of the monthly fee for each hour beyond it (10). APIv3 is described as the stable API (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.3 | |
A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at /api/v3/spec.json and /api/v3/spec.yml (25). No llms.txt (the path returns 404). The docs are Markdown files in the public repository, not served to agents from the docs site (2 of 10). The reference explains HAL links, collections, filters, forms and each resource's permissions at length, with little on when not to use an endpoint (14 of 20). 204 component schemas and 95 enumerations, but write bodies are HAL objects with _links, filters travel as a JSON string in the query, and custom fields appear as customFieldN. Form endpoints return the allowed values for a given resource (10 of 15). The spec carries about 1,200 examples and lists 400, 403, 404, 406, 415 and 422 responses per operation, with stable error identifiers (14 of 15). The version sits in the path and release notes are dated and list API changes. No changelog for the API alone was found (11 of 15). | |||
| Agent ergonomics | 13%16.2 | 11.4 | |
Graded on the REST API. Collections take pageSize and offset, and eight collection endpoints, work packages among them, take select to trim fields. HAL responses embed related resources in full by default (14 of 25). Filters with operators, sortBy, grouping and saved queries (20). Errors carry an errorIdentifier URN and a message, and validation failures arrive as MultipleErrors with one entry per property (18 of 20). No idempotency keys. lockVersion stops lost updates, form endpoints validate a change without saving it, and each tool of the paid MCP server sets read-only, destructive and idempotent hints (12 of 20). No official SDK was found. The docs list community clients for JavaScript and Go that the vendor says it does not vet. Creating a work package needs a subject and links to a project and type (6 of 15). | |||
| Security & auth | 14%17.5 | 10.3 | |
OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (api_v3, mcp, scim_v2, bcf_v2_1) and none finer. Personal API tokens are named, can be several and can be deleted, and carry their user's full permissions. No expiry or per-token scope was found. Tokens travel in the Authorization header only (22 of 30). Reach is limited by project roles and permissions, so a dedicated user with a read-only role is the least-privilege route, and administrators can switch off single MCP tools. No confirmation step for deletes (12 of 20). Work package text and comments are untrusted content, and no prompt-injection guidance was found in the API or MCP docs (2 of 15). Every change to a work package is journalled with its author, and application logs record sign-ins and credential changes. No per-token API log for a cloud customer was found (8 of 15). A signed security.txt valid to 31 December 2026, a disclosure policy with a 21-day target for critical fixes, advisories and CVEs published on GitHub, signed container images with SBOMs, and a YesWeHack bounty paid for by the European Commission. No SOC 2 or ISO 27001 certificate for the vendor was found (15 of 20). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| No x402, MPP or L402 (0). Plan prices are public per user per month, Basic at $7.25, Professional at $13.50 and Premium at $19.50 on a yearly term, Corporate on request. API calls are not priced (10). The cloud trial runs 14 days and the signup page says no credit card is needed. The Community edition is free to self-host, API included (20). A person fills in a web form with a domain and an email address to get an instance, and creates the token in account settings (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.6 | |
| Version 17.9.1 was released on 1 October 2026 (30). Seven releases in the last 90 days, 17.7.0 on 5 August through 17.9.1 (20). OpenProject tracks bugs on community.openproject.org, which we did not sample, so responsiveness is scored on the release record and the advisory handling alone, with fixes published alongside each advisory (15 of 25). No official SDK and no MCP registry entry were found (0 of 15). The repository runs test, CodeQL, Brakeman, dependency review and npm audit workflows, and its default branch had commits on 8 October 2026 (10). | |||
| Transparency & trusteditorial 79, provenance 95 | 7%8.8 | 7.6 | |
| The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. The cloud runs under the Terms of Service of 6 August 2026 (28 of 30). The privacy policy of 30 July 2026 covers the cloud and names OpenProject GmbH as processor. An instance is deleted six months after the contract ends, web logs within 90 days, and the terms give 21 days' notice to export data. The data processing agreement follows the EU standard clauses and was last updated on 28 March 2024 (25 of 30). No deprecation policy with dates was found. The docs say the vendor strives to keep APIv3 backward compatible in stable releases, and 14 operations are marked deprecated with no removal date (7 of 20). The sub-processor list of 18 May 2026 names four companies for the openproject.com shard (AWS among them) and three for the EU shard (Scaleway among them), with addresses and transfer safeguards (19 of 20). | |||
| Negative events | ≤15 |
| -5 |
| Total | 57.4 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 19 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on OpenProject, or have the agent fetch /fixes/openproject.md. A fix counts at the next check, once it's public.
Show it
# Fix list: OpenProject From Anchor Terminal's listing at https://www.anchorterminal.com/tools/openproject, the October 2026 research run, assessed 8 October 2026. Grade C, 57.4 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on OpenProject: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 52 out of 100, up to 9.6 more on the total Why it scored 52: Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. The same API ships in the free Community edition. Status page at status.openproject.com, run on UptimeRobot, with a 90-day uptime view and an update history (20). The page draws its figures by script from a path its robots.txt disallows, so we could not read the incident record. No readable history (5). No request limit for the API is published for the cloud. The only documented rule is an optional one for self-hosted installs, six requests per three seconds on form endpoints, off by default (3 of 15). No 429 or Retry-After guidance and no idempotency keys were found. Updates must send `lockVersion`, and a stale value is refused with 409 `UpdateConflict` (4 of 15). The service description commits to 99.9 per cent availability a year, with a credit of 5 per cent of the monthly fee for each hour beyond it (10). APIv3 is described as the stable API (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No x402, MPP or L402 (0). Plan prices are public per user per month, Basic at $7.25, Professional at $13.50 and Premium at $19.50 on a yearly term, Corporate on request. API calls are not priced (10). The cloud trial runs 14 days and the signup page says no credit card is needed. The Community edition is free to self-host, API included (20). A person fills in a web form with a domain and an email address to get an instance, and creates the token in account settings (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 59 out of 100, up to 7.2 more on the total Why it scored 59: OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`) and none finer. Personal API tokens are named, can be several and can be deleted, and carry their user's full permissions. No expiry or per-token scope was found. Tokens travel in the Authorization header only (22 of 30). Reach is limited by project roles and permissions, so a dedicated user with a read-only role is the least-privilege route, and administrators can switch off single MCP tools. No confirmation step for deletes (12 of 20). Work package text and comments are untrusted content, and no prompt-injection guidance was found in the API or MCP docs (2 of 15). Every change to a work package is journalled with its author, and application logs record sign-ins and credential changes. No per-token API log for a cloud customer was found (8 of 15). A signed security.txt valid to 31 December 2026, a disclosure policy with a 21-day target for critical fixes, advisories and CVEs published on GitHub, signed container images with SBOMs, and a YesWeHack bounty paid for by the European Commission. No SOC 2 or ISO 27001 certificate for the vendor was found (15 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Agent ergonomics, 70 out of 100, up to 4.9 more on the total Why it scored 70: Graded on the REST API. Collections take `pageSize` and `offset`, and eight collection endpoints, work packages among them, take `select` to trim fields. HAL responses embed related resources in full by default (14 of 25). Filters with operators, `sortBy`, grouping and saved queries (20). Errors carry an `errorIdentifier` URN and a message, and validation failures arrive as `MultipleErrors` with one entry per property (18 of 20). No idempotency keys. `lockVersion` stops lost updates, form endpoints validate a change without saving it, and each tool of the paid MCP server sets read-only, destructive and idempotent hints (12 of 20). No official SDK was found. The docs list community clients for JavaScript and Go that the vendor says it does not vet. Creating a work package needs a subject and links to a project and type (6 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Schema & documentation, 76 out of 100, up to 3.9 more on the total Why it scored 76: A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at `/api/v3/spec.json` and `/api/v3/spec.yml` (25). No llms.txt (the path returns 404). The docs are Markdown files in the public repository, not served to agents from the docs site (2 of 10). The reference explains HAL links, collections, filters, forms and each resource's permissions at length, with little on when not to use an endpoint (14 of 20). 204 component schemas and 95 enumerations, but write bodies are HAL objects with `_links`, filters travel as a JSON string in the query, and custom fields appear as `customFieldN`. Form endpoints return the allowed values for a given resource (10 of 15). The spec carries about 1,200 examples and lists 400, 403, 404, 406, 415 and 422 responses per operation, with stable error identifiers (14 of 15). The version sits in the path and release notes are dated and list API changes. No changelog for the API alone was found (11 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Maintenance & community, 75 out of 100, up to 2.2 more on the total Why it scored 75: Version 17.9.1 was released on 1 October 2026 (30). Seven releases in the last 90 days, 17.7.0 on 5 August through 17.9.1 (20). OpenProject tracks bugs on community.openproject.org, which we did not sample, so responsiveness is scored on the release record and the advisory handling alone, with fixes published alongside each advisory (15 of 25). No official SDK and no MCP registry entry were found (0 of 15). The repository runs test, CodeQL, Brakeman, dependency review and npm audit workflows, and its default branch had commits on 8 October 2026 (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 87 out of 100, up to 1.1 more on the total Made of editorial 79, provenance 95. Why it scored 87: The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. The cloud runs under the Terms of Service of 6 August 2026 (28 of 30). The privacy policy of 30 July 2026 covers the cloud and names OpenProject GmbH as processor. An instance is deleted six months after the contract ends, web logs within 90 days, and the terms give 21 days' notice to export data. The data processing agreement follows the EU standard clauses and was last updated on 28 March 2024 (25 of 30). No deprecation policy with dates was found. The docs say the vendor strives to keep APIv3 backward compatible in stable releases, and 14 operations are marked deprecated with no removal date (7 of 20). The sub-processor list of 18 May 2026 names four companies for the openproject.com shard (AWS among them) and three for the EU shard (Scaleway among them), with addresses and transfer safeguards (19 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 3 of the 7 things a reader expects (6.6 of 10) - Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10) ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 2026-06-08. 13 advisories rated critical were published against opf/openproject between January and June 2026, among them cache store poisoning leading to remote code execution (GHSA-qj96-f42f-6336, fixed in 17.3.3 and 17.4.1), SQL injection in the timestamps function (GHSA-98vw-2r87-fx2r) and a pre-authentication remote code execution in the Docker image through a default secret key (GHSA-r85r-gjq2-f83r, 13 May 2026). OpenProject published them itself, and its policy is to publish each advisory with the fixing release, so the deduction is reduced, -3 (https://github.com/opf/openproject/security/advisories). - 2026-09-30. 83 advisories in all were published in the twelve months to 8 October 2026, several of them missing permission checks in APIv3 that exposed private work package data across projects. Several credit the YesWeHack bounty sponsored by the European Commission. The advisories give self-hosted version numbers and do not say when the cloud was patched. Fixed and published, -2 (https://github.com/opf/openproject/security/advisories). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the incident record. status.openproject.com draws its uptime figures and update history by script from `/api/`, which its robots.txt disallows, so Reliability is scored without a readable history - unchecked: issue responsiveness. Bugs are tracked on community.openproject.org, which we did not sample - unchecked: the official MCP registry and the live tool list of the MCP server. The tool list was read from the docs and the repository - Whether OpenProject Enterprise cloud applies any request limit to APIv3, and what it returns when one is hit - When the cloud received the fixes in the advisories published in 2026. The advisories give self-hosted version numbers only - Whether API tokens can expire. No expiry setting was found in the access token docs - Which certifications OpenProject GmbH holds. The security page mentions regular external audits without naming a standard - The lead described the product correctly. It did not mention the MCP server, which is an Enterprise add-on, or that the Community edition is not sold as a cloud plan ## Weaknesses - 83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection - No request limit, 429 behaviour or Retry-After guidance is published for the cloud API - Personal API tokens act with their user's full permissions, and OAuth has one scope per API with no read-only form - No official SDK. The client libraries the docs list are community projects the vendor says it does not vet - The MCP server is an Enterprise add-on for the Professional plan and above, which starts at 25 users ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send the API token as `Authorization: Bearer <token>`, or as the Basic auth password with the user name `apikey` - Read the resource first and send its current `lockVersion` with every PATCH. A stale value returns 409 `UpdateConflict` - POST to the `/form` endpoint of a work package to learn writable fields and allowed values before creating or updating - URL-encode `filters` as a JSON array, and add `pageSize`, `offset` and `select` to keep work package lists small - Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the incident record. status.openproject.com draws its uptime figures and update history by script from
/api/, which its robots.txt disallows, so Reliability is scored without a readable history - unchecked: issue responsiveness. Bugs are tracked on community.openproject.org, which we did not sample
- unchecked: the official MCP registry and the live tool list of the MCP server. The tool list was read from the docs and the repository
- Whether OpenProject Enterprise cloud applies any request limit to APIv3, and what it returns when one is hit
- When the cloud received the fixes in the advisories published in 2026. The advisories give self-hosted version numbers only
- Whether API tokens can expire. No expiry setting was found in the access token docs
- Which certifications OpenProject GmbH holds. The security page mentions regular external audits without naming a standard
- The lead described the product correctly. It did not mention the MCP server, which is an Enterprise add-on, or that the Community edition is not sold as a cloud plan
Sources 17
- API introduction (authentication, HAL, methods) openproject.org · seen 2026-10-08
- OpenAPI 3.1 document, as served by the community instance community.openproject.org · seen 2026-10-08
- repository, cloned (API docs, release notes, MCP tool code, configuration docs, workflows) github.com · seen 2026-10-08
- MCP server docs openproject.org · seen 2026-10-08
- pricing page and its price table script openproject.org · seen 2026-10-08
- cloud trial signup page start.openproject.com · seen 2026-10-08
- status page status.openproject.com · seen 2026-10-08
- Terms of Service openproject.org · seen 2026-10-08
- service description (availability, credits, support levels) openproject.org · seen 2026-10-08
- privacy policy openproject.org · seen 2026-10-08
- data processing agreement openproject.org · seen 2026-10-08
- sub-processors openproject.org · seen 2026-10-08
- statement on security openproject.org · seen 2026-10-08
- security.txt openproject.org · seen 2026-10-08
- security advisories, nine pages read github.com · seen 2026-10-08
- release notes openproject.org · seen 2026-10-08
- RDAP record for openproject.org rdap.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $7.25 / seat-mo The Community edition is free to self-host with the REST API included, and the cloud has a 14-day trial with no credit card, so an agent can start without a contract. Cloud plans are per user per month on a yearly term, Basic $7.25 (from 5 users, $8.50 on a monthly term), Professional $13.50 (from 25 users) and Premium $19.50 (from 100 users), with Corporate on request. Euro prices are 5.95, 10.95 and 15.95. API calls are not priced. The MCP server needs Professional or above. Community is not sold as a cloud plan (https://www.openproject.org/pricing/, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Community (self-hosted) | free | per seat per month | free, REST API included; not sold as a cloud plan |
| Basic (cloud) | $7.25 | per seat per month | yearly term, from 5 users; $8.50 on a monthly term |
| Professional (cloud) | $13.50 | per seat per month | yearly term, from 25 users; includes the MCP server |
| Premium (cloud) | $19.50 | per seat per month | yearly term, from 100 users |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/openproject.xml, or this listing's score history at history.json.
Connect
First request
curl -H "Authorization: Bearer $API_KEY" https://community.openproject.org/api/v3/users/42
Through letme picks today, calling later
GET https://letme.dev/openproject
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Basecamp BPlane BTaiga Fmonday.com BBAsana BBTodoist B
Head to head Asana vs OpenProject · Basecamp vs OpenProject · ClickUp vs OpenProject · monday.com vs OpenProject · OpenProject vs Plane · OpenProject vs Roma · OpenProject vs Shortcut · OpenProject vs Taiga · OpenProject vs Teamwork.com · OpenProject vs Todoist · OpenProject vs Trello · OpenProject vs Wrike · OpenProject vs YouTrack
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Basecamp 37signals LLC | B | 67.9 | tasks.create tasks.update projects.manage tasks.comments projects.reporting events.webhooks-send | no |
| Plane Plane Software, Inc. | B | 67.6 | tasks.create tasks.update projects.manage tasks.comments projects.reporting events.webhooks-send | no |
| Taiga Taiga Cloud Services, S.L. | F | 31.7 | tasks.create tasks.update projects.manage tasks.comments projects.reporting events.webhooks-send | no |
| monday.com monday.com Ltd. | BB | 76.4 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Asana Asana, Inc. | BB | 70.1 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
| Todoist Doist | B | 66.9 | tasks.create tasks.update projects.manage tasks.comments projects.reporting | no |
Machine-readable
- JSON
/api/v1/tools/openproject.json· historyhistory.json· badge/badges/openproject.svg· changes feed/feeds/tools/openproject.xml - Markdown
/tools/openproject.md· slim/tools/openproject.min.md(or sendAccept: text/markdown) - Fix list
/fixes/openproject.md·/fixes/openproject.json - From a terminal
anchor tool openproject --md(the CLI) · over MCPget_tool {"slug": "openproject"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/openproject"><img src="https://www.anchorterminal.com/badges/openproject.svg" alt="OpenProject on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/openproject)<a href="https://www.anchorterminal.com/tools/openproject">OpenProject on Anchor Terminal</a>It counts on a page on openproject.org or one of its subdomains, or the README of github.com/opf/openproject.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "openproject", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


