{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/basecamp.json",
        "name": "Basecamp",
        "score": 67.9,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting",
          "events.webhooks-send"
        ],
        "slug": "basecamp"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/plane.json",
        "name": "Plane",
        "score": 67.6,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting",
          "events.webhooks-send"
        ],
        "slug": "plane"
      },
      {
        "grade": "F",
        "json": "https://www.anchorterminal.com/tools/taiga.json",
        "name": "Taiga",
        "score": 31.7,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting",
          "events.webhooks-send"
        ],
        "slug": "taiga"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/monday.json",
        "name": "monday.com",
        "score": 76.4,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting"
        ],
        "slug": "monday"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/asana.json",
        "name": "Asana",
        "score": 70.1,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting"
        ],
        "slug": "asana"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/todoist.json",
        "name": "Todoist",
        "score": 66.9,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting"
        ],
        "slug": "todoist"
      }
    ],
    "tool": {
      "slug": "openproject",
      "name": "OpenProject",
      "vendor": "OpenProject GmbH",
      "vendorUrl": "https://www.openproject.org",
      "kind": "http-api",
      "category": "project-management",
      "summary": "OpenProject is open-source project management software for work packages, Gantt plans, boards and time tracking, sold as a cloud service and for self-hosting. Agents reach it through the APIv3 REST API, and paid plans add an MCP server.",
      "url": "https://www.anchorterminal.com/tools/openproject",
      "markdownUrl": "https://www.anchorterminal.com/tools/openproject.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openproject.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openproject.json",
      "repo": "https://github.com/opf/openproject",
      "license": "GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve. A user creates a named personal API token in account settings and sends it as `Authorization: Bearer`, or as the Basic auth password with the user name `apikey`. The token carries that user's permissions, and no per-token scope or expiry was found. An administrator can register OAuth 2.0 applications for the authorisation code grant, PKCE or client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`). JWTs from a configured OIDC provider are also accepted. No app review or partner approval is described.",
      "pricing": "freemium",
      "pricingNotes": "The Community edition is free to self-host with the REST API included, and the cloud has a 14-day trial with no credit card, so an agent can start without a contract. Cloud plans are per user per month on a yearly term, Basic $7.25 (from 5 users, $8.50 on a monthly term), Professional $13.50 (from 25 users) and Premium $19.50 (from 100 users), with Corporate on request. Euro prices are 5.95, 10.95 and 15.95. API calls are not priced. The MCP server needs Professional or above. Community is not sold as a cloud plan (https://www.openproject.org/pricing/, checked 2026-10-08).",
      "priceSummary": "$7.25 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16352,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.openproject.org/docs/api/",
      "openapi": "https://www.openproject.org/docs/api/v3/spec.yml",
      "capabilities": [
        "tasks.create",
        "tasks.update",
        "projects.manage",
        "tasks.comments",
        "projects.reporting",
        "events.webhooks-send"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "rest",
        "openapi",
        "oauth",
        "mcp",
        "freemium",
        "free-trial",
        "webhooks",
        "status-page",
        "sla",
        "eu-hosting",
        "project-management"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.4,
        "grade": "C",
        "agentReady": false,
        "rank": 550,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 75,
          "payments": 30,
          "reliability": 52,
          "schema": 76,
          "security": 59,
          "transparency": 87
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 52,
            "points": 10.4,
            "reason": "Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. The same API ships in the free Community edition. Status page at status.openproject.com, run on UptimeRobot, with a 90-day uptime view and an update history (20). The page draws its figures by script from a path its robots.txt disallows, so we could not read the incident record. No readable history (5). No request limit for the API is published for the cloud. The only documented rule is an optional one for self-hosted installs, six requests per three seconds on form endpoints, off by default (3 of 15). No 429 or Retry-After guidance and no idempotency keys were found. Updates must send `lockVersion`, and a stale value is refused with 409 `UpdateConflict` (4 of 15). The service description commits to 99.9 per cent availability a year, with a credit of 5 per cent of the monthly fee for each hour beyond it (10). APIv3 is described as the stable API (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 76,
            "points": 12.35,
            "reason": "A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at `/api/v3/spec.json` and `/api/v3/spec.yml` (25). No llms.txt (the path returns 404). The docs are Markdown files in the public repository, not served to agents from the docs site (2 of 10). The reference explains HAL links, collections, filters, forms and each resource's permissions at length, with little on when not to use an endpoint (14 of 20). 204 component schemas and 95 enumerations, but write bodies are HAL objects with `_links`, filters travel as a JSON string in the query, and custom fields appear as `customFieldN`. Form endpoints return the allowed values for a given resource (10 of 15). The spec carries about 1,200 examples and lists 400, 403, 404, 406, 415 and 422 responses per operation, with stable error identifiers (14 of 15). The version sits in the path and release notes are dated and list API changes. No changelog for the API alone was found (11 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "Graded on the REST API. Collections take `pageSize` and `offset`, and eight collection endpoints, work packages among them, take `select` to trim fields. HAL responses embed related resources in full by default (14 of 25). Filters with operators, `sortBy`, grouping and saved queries (20). Errors carry an `errorIdentifier` URN and a message, and validation failures arrive as `MultipleErrors` with one entry per property (18 of 20). No idempotency keys. `lockVersion` stops lost updates, form endpoints validate a change without saving it, and each tool of the paid MCP server sets read-only, destructive and idempotent hints (12 of 20). No official SDK was found. The docs list community clients for JavaScript and Go that the vendor says it does not vet. Creating a work package needs a subject and links to a project and type (6 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 59,
            "points": 10.33,
            "reason": "OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`) and none finer. Personal API tokens are named, can be several and can be deleted, and carry their user's full permissions. No expiry or per-token scope was found. Tokens travel in the Authorization header only (22 of 30). Reach is limited by project roles and permissions, so a dedicated user with a read-only role is the least-privilege route, and administrators can switch off single MCP tools. No confirmation step for deletes (12 of 20). Work package text and comments are untrusted content, and no prompt-injection guidance was found in the API or MCP docs (2 of 15). Every change to a work package is journalled with its author, and application logs record sign-ins and credential changes. No per-token API log for a cloud customer was found (8 of 15). A signed security.txt valid to 31 December 2026, a disclosure policy with a 21-day target for critical fixes, advisories and CVEs published on GitHub, signed container images with SBOMs, and a YesWeHack bounty paid for by the European Commission. No SOC 2 or ISO 27001 certificate for the vendor was found (15 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 (0). Plan prices are public per user per month, Basic at $7.25, Professional at $13.50 and Premium at $19.50 on a yearly term, Corporate on request. API calls are not priced (10). The cloud trial runs 14 days and the signup page says no credit card is needed. The Community edition is free to self-host, API included (20). A person fills in a web form with a domain and an email address to get an instance, and creates the token in account settings (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "reason": "Version 17.9.1 was released on 1 October 2026 (30). Seven releases in the last 90 days, 17.7.0 on 5 August through 17.9.1 (20). OpenProject tracks bugs on community.openproject.org, which we did not sample, so responsiveness is scored on the release record and the advisory handling alone, with fixes published alongside each advisory (15 of 25). No official SDK and no MCP registry entry were found (0 of 15). The repository runs test, CodeQL, Brakeman, dependency review and npm audit workflows, and its default branch had commits on 8 October 2026 (10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 87,
            "points": 7.61,
            "note": "editorial 79, provenance 95",
            "reason": "The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. The cloud runs under the Terms of Service of 6 August 2026 (28 of 30). The privacy policy of 30 July 2026 covers the cloud and names OpenProject GmbH as processor. An instance is deleted six months after the contract ends, web logs within 90 days, and the terms give 21 days' notice to export data. The data processing agreement follows the EU standard clauses and was last updated on 28 March 2024 (25 of 30). No deprecation policy with dates was found. The docs say the vendor strives to keep APIv3 backward compatible in stable releases, and 14 operations are marked deprecated with no removal date (7 of 20). The sub-processor list of 18 May 2026 names four companies for the openproject.com shard (AWS among them) and three for the EU shard (Scaleway among them), with addresses and transfer safeguards (19 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. Collections take `pageSize` and `offset`, and eight collection endpoints, work packages among them, take `select` to trim fields. HAL responses embed related resources in full by default (14 of 25). Filters with operators, `sortBy`, grouping and saved queries (20). Errors carry an `errorIdentifier` URN and a message, and validation failures arrive as `MultipleErrors` with one entry per property (18 of 20). No idempotency keys. `lockVersion` stops lost updates, form endpoints validate a change without saving it, and each tool of the paid MCP server sets read-only, destructive and idempotent hints (12 of 20). No official SDK was found. The docs list community clients for JavaScript and Go that the vendor says it does not vet. Creating a work package needs a subject and links to a project and type (6 of 15).",
            "maintenance": "Version 17.9.1 was released on 1 October 2026 (30). Seven releases in the last 90 days, 17.7.0 on 5 August through 17.9.1 (20). OpenProject tracks bugs on community.openproject.org, which we did not sample, so responsiveness is scored on the release record and the advisory handling alone, with fixes published alongside each advisory (15 of 25). No official SDK and no MCP registry entry were found (0 of 15). The repository runs test, CodeQL, Brakeman, dependency review and npm audit workflows, and its default branch had commits on 8 October 2026 (10).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public per user per month, Basic at $7.25, Professional at $13.50 and Premium at $19.50 on a yearly term, Corporate on request. API calls are not priced (10). The cloud trial runs 14 days and the signup page says no credit card is needed. The Community edition is free to self-host, API included (20). A person fills in a web form with a domain and an email address to get an instance, and creates the token in account settings (0).",
            "reliability": "Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. The same API ships in the free Community edition. Status page at status.openproject.com, run on UptimeRobot, with a 90-day uptime view and an update history (20). The page draws its figures by script from a path its robots.txt disallows, so we could not read the incident record. No readable history (5). No request limit for the API is published for the cloud. The only documented rule is an optional one for self-hosted installs, six requests per three seconds on form endpoints, off by default (3 of 15). No 429 or Retry-After guidance and no idempotency keys were found. Updates must send `lockVersion`, and a stale value is refused with 409 `UpdateConflict` (4 of 15). The service description commits to 99.9 per cent availability a year, with a credit of 5 per cent of the monthly fee for each hour beyond it (10). APIv3 is described as the stable API (10).",
            "schema": "A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at `/api/v3/spec.json` and `/api/v3/spec.yml` (25). No llms.txt (the path returns 404). The docs are Markdown files in the public repository, not served to agents from the docs site (2 of 10). The reference explains HAL links, collections, filters, forms and each resource's permissions at length, with little on when not to use an endpoint (14 of 20). 204 component schemas and 95 enumerations, but write bodies are HAL objects with `_links`, filters travel as a JSON string in the query, and custom fields appear as `customFieldN`. Form endpoints return the allowed values for a given resource (10 of 15). The spec carries about 1,200 examples and lists 400, 403, 404, 406, 415 and 422 responses per operation, with stable error identifiers (14 of 15). The version sits in the path and release notes are dated and list API changes. No changelog for the API alone was found (11 of 15).",
            "security": "OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`) and none finer. Personal API tokens are named, can be several and can be deleted, and carry their user's full permissions. No expiry or per-token scope was found. Tokens travel in the Authorization header only (22 of 30). Reach is limited by project roles and permissions, so a dedicated user with a read-only role is the least-privilege route, and administrators can switch off single MCP tools. No confirmation step for deletes (12 of 20). Work package text and comments are untrusted content, and no prompt-injection guidance was found in the API or MCP docs (2 of 15). Every change to a work package is journalled with its author, and application logs record sign-ins and credential changes. No per-token API log for a cloud customer was found (8 of 15). A signed security.txt valid to 31 December 2026, a disclosure policy with a 21-day target for critical fixes, advisories and CVEs published on GitHub, signed container images with SBOMs, and a YesWeHack bounty paid for by the European Commission. No SOC 2 or ISO 27001 certificate for the vendor was found (15 of 20).",
            "transparency": "The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. The cloud runs under the Terms of Service of 6 August 2026 (28 of 30). The privacy policy of 30 July 2026 covers the cloud and names OpenProject GmbH as processor. An instance is deleted six months after the contract ends, web logs within 90 days, and the terms give 21 days' notice to export data. The data processing agreement follows the EU standard clauses and was last updated on 28 March 2024 (25 of 30). No deprecation policy with dates was found. The docs say the vendor strives to keep APIv3 backward compatible in stable releases, and 14 operations are marked deprecated with no removal date (7 of 20). The sub-processor list of 18 May 2026 names four companies for the openproject.com shard (AWS among them) and three for the EU shard (Scaleway among them), with addresses and transfer safeguards (19 of 20)."
          },
          "sources": [
            {
              "what": "API introduction (authentication, HAL, methods)",
              "url": "https://www.openproject.org/docs/api/introduction/",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI 3.1 document, as served by the community instance",
              "url": "https://community.openproject.org/api/v3/spec.yml",
              "seen": "2026-10-08"
            },
            {
              "what": "repository, cloned (API docs, release notes, MCP tool code, configuration docs, workflows)",
              "url": "https://github.com/opf/openproject",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server docs",
              "url": "https://www.openproject.org/docs/system-admin-guide/integrations/mcp-server/",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing page and its price table script",
              "url": "https://www.openproject.org/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "cloud trial signup page",
              "url": "https://start.openproject.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "status page",
              "url": "https://status.openproject.com",
              "seen": "2026-10-08"
            },
            {
              "what": "Terms of Service",
              "url": "https://www.openproject.org/legal/terms-of-service/",
              "seen": "2026-10-08"
            },
            {
              "what": "service description (availability, credits, support levels)",
              "url": "https://www.openproject.org/legal/description-of-services/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.openproject.org/legal/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "data processing agreement",
              "url": "https://www.openproject.org/legal/data-processing-agreement/",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://www.openproject.org/legal/data-processing-agreement/sub-processors/",
              "seen": "2026-10-08"
            },
            {
              "what": "statement on security",
              "url": "https://www.openproject.org/docs/security-and-privacy/statement-on-security/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.openproject.org/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisories, nine pages read",
              "url": "https://github.com/opf/openproject/security/advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "release notes",
              "url": "https://www.openproject.org/docs/release-notes/",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP record for openproject.org",
              "url": "https://rdap.org/domain/openproject.org",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the incident record. status.openproject.com draws its uptime figures and update history by script from `/api/`, which its robots.txt disallows, so Reliability is scored without a readable history",
            "unchecked: issue responsiveness. Bugs are tracked on community.openproject.org, which we did not sample",
            "unchecked: the official MCP registry and the live tool list of the MCP server. The tool list was read from the docs and the repository",
            "Whether OpenProject Enterprise cloud applies any request limit to APIv3, and what it returns when one is hit",
            "When the cloud received the fixes in the advisories published in 2026. The advisories give self-hosted version numbers only",
            "Whether API tokens can expire. No expiry setting was found in the access token docs",
            "Which certifications OpenProject GmbH holds. The security page mentions regular external audits without naming a standard",
            "The lead described the product correctly. It did not mention the MCP server, which is an Enterprise add-on, or that the Community edition is not sold as a cloud plan"
          ]
        },
        "negative": -5,
        "negativeNotes": [
          "2026-06-08. 13 advisories rated critical were published against opf/openproject between January and June 2026, among them cache store poisoning leading to remote code execution (GHSA-qj96-f42f-6336, fixed in 17.3.3 and 17.4.1), SQL injection in the timestamps function (GHSA-98vw-2r87-fx2r) and a pre-authentication remote code execution in the Docker image through a default secret key (GHSA-r85r-gjq2-f83r, 13 May 2026). OpenProject published them itself, and its policy is to publish each advisory with the fixing release, so the deduction is reduced, -3 (https://github.com/opf/openproject/security/advisories).",
          "2026-09-30. 83 advisories in all were published in the twelve months to 8 October 2026, several of them missing permission checks in APIv3 that exposed private work package data across projects. Several credit the YesWeHack bounty sponsored by the European Commission. The advisories give self-hosted version numbers and do not say when the cloud was patched. Fixed and published, -2 (https://github.com/opf/openproject/security/advisories)."
        ],
        "verdict": "OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.",
        "bestFor": "Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.",
        "strengths": [
          "OpenAPI 3.1 document with 234 paths and 320 operations, public on the docs site and served by every instance at `/api/v3/spec.json`",
          "Errors carry a stable `errorIdentifier` URN, and validation failures list one entry per property",
          "The Community edition is GPL-3.0 and free to self-host with the REST API included, and the cloud trial needs no credit card",
          "Seven releases between 5 August and 1 October 2026, with security fixes published as GitHub advisories and CVEs",
          "The service description commits to 99.9 per cent yearly availability with service credits, and an EU shard keeps all sub-processors in the EU"
        ],
        "weaknesses": [
          "83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection",
          "No request limit, 429 behaviour or Retry-After guidance is published for the cloud API",
          "Personal API tokens act with their user's full permissions, and OAuth has one scope per API with no read-only form",
          "No official SDK. The client libraries the docs list are community projects the vendor says it does not vet",
          "The MCP server is an Enterprise add-on for the Professional plan and above, which starts at 25 users"
        ],
        "agentNotes": [
          "Send the API token as `Authorization: Bearer \u003ctoken\u003e`, or as the Basic auth password with the user name `apikey`",
          "Read the resource first and send its current `lockVersion` with every PATCH. A stale value returns 409 `UpdateConflict`",
          "POST to the `/form` endpoint of a work package to learn writable fields and allowed values before creating or updating",
          "URL-encode `filters` as a JSON array, and add `pageSize`, `offset` and `select` to keep work package lists small",
          "Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.4
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 75,
          "payments": 30,
          "reliability": 52,
          "schema": 76,
          "security": 59,
          "transparency": 79
        },
        "provenanceScore": 95
      },
      "connect": {
        "http": "curl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42"
      },
      "letme": {
        "capability": "https://letme.dev/tasks.create",
        "tool": "https://letme.dev/openproject"
      },
      "notable": [
        "APIv3 is a hypermedia REST API in HAL+JSON, documented in one OpenAPI 3.1 file with 234 paths and 320 operations, which each instance also serves at `/api/v3/spec.json` (https://www.openproject.org/docs/api/introduction/)",
        "The MCP server at `/mcp` is an Enterprise add-on for the Professional, Premium and Corporate plans. The docs list 23 tools and ten resources, and version 17.9 added time entry tools (https://www.openproject.org/docs/system-admin-guide/integrations/mcp-server/)",
        "83 security advisories were published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical. Several credit a YesWeHack bounty sponsored by the European Commission (https://github.com/opf/openproject/security/advisories)",
        "The service description commits to 99.9 per cent availability a year for the cloud, with a 5 per cent credit per hour beyond it (https://www.openproject.org/legal/description-of-services/)",
        "The cloud runs as two shards, openproject.com on AWS and openproject.eu on Scaleway, with every EU-shard sub-processor based in the EU (https://www.openproject.org/legal/data-processing-agreement/sub-processors/)",
        "No request limit for the API is published. The configuration docs describe one optional rule for self-hosted installs, six requests per three seconds on form endpoints (https://github.com/opf/openproject/blob/dev/docs/installation-and-operations/configuration/README.md)",
        "The security statement says OpenProject has no bug bounty programme of its own and targets a fix for critical and high findings within 21 days of confirmation (https://www.openproject.org/docs/security-and-privacy/statement-on-security/)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "APIv3 of OpenProject Enterprise cloud at `https://\u003cname\u003e.openproject.com/api/v3` (or an openproject.eu host on the EU shard). The same API ships in the free Community edition for self-hosting"
        },
        {
          "label": "API",
          "value": "OpenAPI 3.1, 234 paths and 320 operations (178 GET, 80 POST, 32 PATCH, 30 DELETE). HAL+JSON responses. Covers work packages, projects, portfolios, time entries, memberships, queries, versions, wiki pages, notifications and more"
        },
        {
          "label": "Authentication",
          "value": "Personal API token as Bearer or as Basic auth with user name `apikey`. OAuth 2.0 authorisation code, PKCE and client credentials with scopes `api_v3`, `mcp`, `scim_v2` and `bcf_v2_1`. JWTs from a configured OIDC provider"
        },
        {
          "label": "MCP server",
          "value": "Enterprise add-on for Professional, Premium and Corporate, at `/mcp` on the instance. 23 tools per the docs, among them `search_work_packages`, `create_work_package`, `update_work_package`, `create_work_package_comment` and four time entry tools, plus ten resources. Tools can be switched off one by one"
        },
        {
          "label": "Rate limits",
          "value": "None published for the cloud API. Self-hosted installs can turn on a rule of six requests per three seconds on API form endpoints"
        },
        {
          "label": "Pagination and sizing",
          "value": "`pageSize` and `offset` on collections, with a maximum page size set by the administrator. `select` on eight collection endpoints. `filters` with operators and `sortBy`"
        },
        {
          "label": "Errors",
          "value": "`errorIdentifier` URNs such as `urn:openproject-org:api:v3:errors:MissingPermission`, with `MultipleErrors` grouping per-property validation failures. 409 `UpdateConflict` on a stale `lockVersion`"
        },
        {
          "label": "Webhooks",
          "value": "Set by an administrator, with a signature secret, per-project selection and events for projects, work packages, comments, time entries and attachments"
        },
        {
          "label": "SLA",
          "value": "99.9 per cent availability a calendar year excluding scheduled maintenance, with a credit of 5 per cent of the monthly fee per hour beyond it, claimed within 30 days"
        },
        {
          "label": "Security programme",
          "value": "Signed security.txt, disclosure policy, GitHub advisories with CVEs, a YesWeHack bounty sponsored by the European Commission, signed container images with SBOM and VEX documents"
        },
        {
          "label": "Status",
          "value": "status.openproject.com on UptimeRobot. Figures load by script from a path robots.txt disallows"
        },
        {
          "label": "Sub-processors",
          "value": "openproject.com shard, AWS, MessageBird, Postmark and mailbox.org. openproject.eu shard, Scaleway, rapidmail and mailbox.org. List updated 18 May 2026"
        },
        {
          "label": "Releases",
          "value": "17.9.1 on 1 October 2026, 17.9.0 and 17.8.1 on 30 September, 17.8.0 on 2 September, 17.7.x in August"
        }
      ],
      "unitPrices": [
        {
          "item": "Community (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, REST API included; not sold as a cloud plan"
        },
        {
          "item": "Basic (cloud)",
          "unit": "seat-month",
          "usd": 7.25,
          "note": "yearly term, from 5 users; $8.50 on a monthly term"
        },
        {
          "item": "Professional (cloud)",
          "unit": "seat-month",
          "usd": 13.5,
          "note": "yearly term, from 25 users; includes the MCP server"
        },
        {
          "item": "Premium (cloud)",
          "unit": "seat-month",
          "usd": 19.5,
          "note": "yearly term, from 100 users"
        }
      ],
      "provenance": {
        "legalEntity": "OpenProject GmbH",
        "domain": "openproject.org",
        "domainRegistered": "2003-10-24",
        "endpointOnVendorDomain": true,
        "terms": "https://www.openproject.org/legal/terms-of-service/",
        "privacy": "https://www.openproject.org/legal/privacy/",
        "statusPage": "https://status.openproject.com",
        "changelog": "https://www.openproject.org/docs/release-notes/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 6 August 2026) name OpenProject GmbH, Krausenstrasse 9, 10117 Berlin, Germany, and cover both the cloud and the on-premises Enterprise edition. The German version takes precedence.",
          "The privacy policy (version 30 July 2026) has a section on OpenProject Enterprise Cloud, where OpenProject GmbH is processor and the customer controller. The data processing agreement at https://www.openproject.org/legal/data-processing-agreement/ is part of the terms.",
          "Cloud instances answer at \u003cname\u003e.openproject.com or, on the EU shard, an openproject.eu host. Both are the vendor's domains, apart from the openproject.org site that carries the docs and legal pages. Self-hosted instances answer on the owner's domain.",
          "www.openproject.org/.well-known/security.txt is PGP-signed, names security@openproject.com and expires on 31 December 2026.",
          "RDAP for openproject.org gives a registration date of 2003-10-24 and InterNetX GmbH as registrar."
        ],
        "score": 95,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "OpenProject GmbH",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "openproject.org, registered 2003-10-24 (22 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "openproject.org",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 3 of the 7 things a reader expects",
            "points": 6.6,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 6 of the 8 things a reader expects",
            "points": 8.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.openproject.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.openproject.org/legal/terms-of-service/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-08-06",
            "words": 7259,
            "points": 6.6,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: 2026-08-06",
                "says": "Last updated 2026-08-06"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": false
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "§ 5 Contractual Term and Termination of the Agreement"
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": false
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Further details regarding the services that OpenProject will provide, in particular as regards the functional scope of the software or its technical and hours of availability, data portability, or applicable service levels, can be found in the service or selected rate plan description."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The contract term renews automatically for the originally selected period unless the customer terminates it.",
                "quote": "The contractual term shall be automatically extended by the originally selected period, unless the contract is terminated as follows:"
              },
              {
                "date": "2026-10-08",
                "text": "OpenProject may name the customer as a user of its products in reference lists and external communications, to an appropriate and customary extent.",
                "quote": "OpenProject may refer to the Customer’s use of OpenProject products pursuant to a contractual relationship with OpenProject and to an appropriate and customary extent in reference lists and in its external communications."
              },
              {
                "date": "2026-10-08",
                "text": "If the customer gives no deletion instructions by the end of the term, OpenProject asks it to back up its data on its own systems within 21 days.",
                "quote": "If the Customer fails to specify any corresponding provisions by the end of the contractual term, OpenProject will request the Customer to back up their data on their own systems within 21 days."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.openproject.org/legal/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 7432,
            "points": 8.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "In this process, we collect and process the following personal data:"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Your data will be deleted no later than 90 days.",
                "says": "Names a period of 90 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Our service provider is based in the European Economic Area, does not use the texts translated for us for further training of its AI, does not store the texts beyond the translation process, and is bound to us by a data processing agreement regarding data protection and professional confidentiality."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "In some cases, your consent is the legal basis, pursuant to Article 6 (1) (a) and Article 7 GDPR, which you may revoke at any time with with effect for the future by sending an email to privacy@openproject.com."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "In some cases, your consent is the legal basis, pursuant to Article 6 (1) (a) and Article 7 GDPR, which you may revoke at any time with with effect for the future by sending an email to privacy@openproject.com.",
                "says": "privacy@openproject.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards, including the European Commission’s Standard Contractual Clauses where applicable, are in place.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "An Enterprise Cloud instance is deleted automatically six months after the contract expires.",
                "quote": "Your instance of the OpenProject Enterprise Cloud will be automatically deleted six months after the expiry of your contract."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openproject.json",
      "live": {
        "slug": "openproject",
        "vendorStatus": {
          "page": "https://status.openproject.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:22.822468534Z"
        },
        "updatedAt": "2026-10-09T07:58:22.822468534Z"
      }
    },
    "verify": {
      "accepts": "a page on openproject.org or one of its subdomains, or the README of github.com/opf/openproject",
      "badgeUrl": "https://www.anchorterminal.com/badges/openproject.svg",
      "body": {
        "slug": "openproject",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/openproject",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/openproject\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/openproject.svg\" alt=\"OpenProject on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![OpenProject on Anchor Terminal](https://www.anchorterminal.com/badges/openproject.svg)](https://www.anchorterminal.com/tools/openproject)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/openproject\"\u003eOpenProject on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/openproject",
    "json": "https://www.anchorterminal.com/tools/openproject.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/openproject.md",
    "slim": "https://www.anchorterminal.com/tools/openproject.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 57.4/100 · rank #550 of 842 · #11 in Project \u0026 task management · not agent-ready · confidence medium**\n\n\n## Assessment\n\nOpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | OpenProject GmbH (https://www.openproject.org) |\n| Kind | HTTP API |\n| Category | Project \u0026 task management (https://www.anchorterminal.com/categories/project-management) |\n| Transport | HTTP |\n| Auth | OAuth or key · Access is self-serve. A user creates a named personal API token in account settings and sends it as `Authorization: Bearer`, or as the Basic auth password with the user name `apikey`. The token carries that user's permissions, and no per-token scope or expiry was found. An administrator can register OAuth 2.0 applications for the authorisation code grant, PKCE or client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`). JWTs from a configured OIDC provider are also accepted. No app review or partner approval is described. |\n| Pricing | Freemium ($7.25 / seat-mo) · The Community edition is free to self-host with the REST API included, and the cloud has a 14-day trial with no credit card, so an agent can start without a contract. Cloud plans are per user per month on a yearly term, Basic $7.25 (from 5 users, $8.50 on a monthly term), Professional $13.50 (from 25 users) and Premium $19.50 (from 100 users), with Corporate on request. Euro prices are 5.95, 10.95 and 15.95. API calls are not priced. The MCP server needs Professional or above. Community is not sold as a cloud plan (https://www.openproject.org/pricing/, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI document or the pricing page (checked 2026-10-08). |\n| Licence | GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service |\n| Source | https://github.com/opf/openproject |\n| Docs | https://www.openproject.org/docs/api/ |\n| llms.txt | not found |\n| Last release | 2026-10-01 |\n| GitHub stars | 16,352 (as of 2026-10-08) |\n| Surface graded | APIv3 of OpenProject Enterprise cloud at `https://\u003cname\u003e.openproject.com/api/v3` (or an openproject.eu host on the EU shard). The same API ships in the free Community edition for self-hosting |\n| API | OpenAPI 3.1, 234 paths and 320 operations (178 GET, 80 POST, 32 PATCH, 30 DELETE). HAL+JSON responses. Covers work packages, projects, portfolios, time entries, memberships, queries, versions, wiki pages, notifications and more |\n| Authentication | Personal API token as Bearer or as Basic auth with user name `apikey`. OAuth 2.0 authorisation code, PKCE and client credentials with scopes `api_v3`, `mcp`, `scim_v2` and `bcf_v2_1`. JWTs from a configured OIDC provider |\n| MCP server | Enterprise add-on for Professional, Premium and Corporate, at `/mcp` on the instance. 23 tools per the docs, among them `search_work_packages`, `create_work_package`, `update_work_package`, `create_work_package_comment` and four time entry tools, plus ten resources. Tools can be switched off one by one |\n| Rate limits | None published for the cloud API. Self-hosted installs can turn on a rule of six requests per three seconds on API form endpoints |\n| Pagination and sizing | `pageSize` and `offset` on collections, with a maximum page size set by the administrator. `select` on eight collection endpoints. `filters` with operators and `sortBy` |\n| Errors | `errorIdentifier` URNs such as `urn:openproject-org:api:v3:errors:MissingPermission`, with `MultipleErrors` grouping per-property validation failures. 409 `UpdateConflict` on a stale `lockVersion` |\n| Webhooks | Set by an administrator, with a signature secret, per-project selection and events for projects, work packages, comments, time entries and attachments |\n| SLA | 99.9 per cent availability a calendar year excluding scheduled maintenance, with a credit of 5 per cent of the monthly fee per hour beyond it, claimed within 30 days |\n| Security programme | Signed security.txt, disclosure policy, GitHub advisories with CVEs, a YesWeHack bounty sponsored by the European Commission, signed container images with SBOM and VEX documents |\n| Status | status.openproject.com on UptimeRobot. Figures load by script from a path robots.txt disallows |\n| Sub-processors | openproject.com shard, AWS, MessageBird, Postmark and mailbox.org. openproject.eu shard, Scaleway, rapidmail and mailbox.org. List updated 18 May 2026 |\n| Releases | 17.9.1 on 1 October 2026, 17.9.0 and 17.8.1 on 30 September, 17.8.0 on 2 September, 17.7.x in August |\n| Capabilities | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send |\n| Tags | official, hosted, self-hosted, open-source, rest, openapi, oauth, mcp, freemium, free-trial, webhooks, status-page, sla, eu-hosting, project-management |\n| JSON | https://www.anchorterminal.com/api/v1/tools/openproject.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 52 | 10.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 76 | 12.3 |\n| Agent ergonomics | 13% | 16.2 | 70 | 11.4 |\n| Security \u0026 auth | 14% | 17.5 | 59 | 10.3 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 75 | 6.6 |\n| Transparency \u0026 trust (editorial 79, provenance 95) | 7% | 8.8 | 87 | 7.6 |\n| Negative events | up to −15 | up to −15 | 2026-06-08. 13 advisories rated critical were published against opf/openproject between January and June 2026, among them cache store poisoning leading to remote code execution (GHSA-qj96-f42f-6336, fixed in 17.3.3 and 17.4.1), SQL injection in the timestamps function (GHSA-98vw-2r87-fx2r) and a pre-authentication remote code execution in the Docker image through a default secret key (GHSA-r85r-gjq2-f83r, 13 May 2026). OpenProject published them itself, and its policy is to publish each advisory with the fixing release, so the deduction is reduced, -3 (https://github.com/opf/openproject/security/advisories). 2026-09-30. 83 advisories in all were published in the twelve months to 8 October 2026, several of them missing permission checks in APIv3 that exposed private work package data across projects. Several credit the YesWeHack bounty sponsored by the European Commission. The advisories give self-hosted version numbers and do not say when the cloud was patched. Fixed and published, -2 (https://github.com/opf/openproject/security/advisories).  | -5 |\n| **Total** | | | | **57.4 → C** |\n\n### Why each score\n\n- Reliability 52: Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. The same API ships in the free Community edition. Status page at status.openproject.com, run on UptimeRobot, with a 90-day uptime view and an update history (20). The page draws its figures by script from a path its robots.txt disallows, so we could not read the incident record. No readable history (5). No request limit for the API is published for the cloud. The only documented rule is an optional one for self-hosted installs, six requests per three seconds on form endpoints, off by default (3 of 15). No 429 or Retry-After guidance and no idempotency keys were found. Updates must send `lockVersion`, and a stale value is refused with 409 `UpdateConflict` (4 of 15). The service description commits to 99.9 per cent availability a year, with a credit of 5 per cent of the monthly fee for each hour beyond it (10). APIv3 is described as the stable API (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 76: A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at `/api/v3/spec.json` and `/api/v3/spec.yml` (25). No llms.txt (the path returns 404). The docs are Markdown files in the public repository, not served to agents from the docs site (2 of 10). The reference explains HAL links, collections, filters, forms and each resource's permissions at length, with little on when not to use an endpoint (14 of 20). 204 component schemas and 95 enumerations, but write bodies are HAL objects with `_links`, filters travel as a JSON string in the query, and custom fields appear as `customFieldN`. Form endpoints return the allowed values for a given resource (10 of 15). The spec carries about 1,200 examples and lists 400, 403, 404, 406, 415 and 422 responses per operation, with stable error identifiers (14 of 15). The version sits in the path and release notes are dated and list API changes. No changelog for the API alone was found (11 of 15).\n- Agent ergonomics 70: Graded on the REST API. Collections take `pageSize` and `offset`, and eight collection endpoints, work packages among them, take `select` to trim fields. HAL responses embed related resources in full by default (14 of 25). Filters with operators, `sortBy`, grouping and saved queries (20). Errors carry an `errorIdentifier` URN and a message, and validation failures arrive as `MultipleErrors` with one entry per property (18 of 20). No idempotency keys. `lockVersion` stops lost updates, form endpoints validate a change without saving it, and each tool of the paid MCP server sets read-only, destructive and idempotent hints (12 of 20). No official SDK was found. The docs list community clients for JavaScript and Go that the vendor says it does not vet. Creating a work package needs a subject and links to a project and type (6 of 15).\n- Security \u0026 auth 59: OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`) and none finer. Personal API tokens are named, can be several and can be deleted, and carry their user's full permissions. No expiry or per-token scope was found. Tokens travel in the Authorization header only (22 of 30). Reach is limited by project roles and permissions, so a dedicated user with a read-only role is the least-privilege route, and administrators can switch off single MCP tools. No confirmation step for deletes (12 of 20). Work package text and comments are untrusted content, and no prompt-injection guidance was found in the API or MCP docs (2 of 15). Every change to a work package is journalled with its author, and application logs record sign-ins and credential changes. No per-token API log for a cloud customer was found (8 of 15). A signed security.txt valid to 31 December 2026, a disclosure policy with a 21-day target for critical fixes, advisories and CVEs published on GitHub, signed container images with SBOMs, and a YesWeHack bounty paid for by the European Commission. No SOC 2 or ISO 27001 certificate for the vendor was found (15 of 20).\n- Payments \u0026 pricing 30: No x402, MPP or L402 (0). Plan prices are public per user per month, Basic at $7.25, Professional at $13.50 and Premium at $19.50 on a yearly term, Corporate on request. API calls are not priced (10). The cloud trial runs 14 days and the signup page says no credit card is needed. The Community edition is free to self-host, API included (20). A person fills in a web form with a domain and an email address to get an instance, and creates the token in account settings (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 75: Version 17.9.1 was released on 1 October 2026 (30). Seven releases in the last 90 days, 17.7.0 on 5 August through 17.9.1 (20). OpenProject tracks bugs on community.openproject.org, which we did not sample, so responsiveness is scored on the release record and the advisory handling alone, with fixes published alongside each advisory (15 of 25). No official SDK and no MCP registry entry were found (0 of 15). The repository runs test, CodeQL, Brakeman, dependency review and npm audit workflows, and its default branch had commits on 8 October 2026 (10).\n- Transparency \u0026 trust 87: The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. The cloud runs under the Terms of Service of 6 August 2026 (28 of 30). The privacy policy of 30 July 2026 covers the cloud and names OpenProject GmbH as processor. An instance is deleted six months after the contract ends, web logs within 90 days, and the terms give 21 days' notice to export data. The data processing agreement follows the EU standard clauses and was last updated on 28 March 2024 (25 of 30). No deprecation policy with dates was found. The docs say the vendor strives to keep APIv3 backward compatible in stable releases, and 14 operations are marked deprecated with no removal date (7 of 20). The sub-processor list of 18 May 2026 names four companies for the openproject.com shard (AWS among them) and three for the EU shard (Scaleway among them), with addresses and transfer safeguards (19 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/openproject.md (JSON https://www.anchorterminal.com/fixes/openproject.json)\n\n### What we couldn't check\n\n- unchecked: the incident record. status.openproject.com draws its uptime figures and update history by script from `/api/`, which its robots.txt disallows, so Reliability is scored without a readable history\n- unchecked: issue responsiveness. Bugs are tracked on community.openproject.org, which we did not sample\n- unchecked: the official MCP registry and the live tool list of the MCP server. The tool list was read from the docs and the repository\n- Whether OpenProject Enterprise cloud applies any request limit to APIv3, and what it returns when one is hit\n- When the cloud received the fixes in the advisories published in 2026. The advisories give self-hosted version numbers only\n- Whether API tokens can expire. No expiry setting was found in the access token docs\n- Which certifications OpenProject GmbH holds. The security page mentions regular external audits without naming a standard\n- The lead described the product correctly. It did not mention the MCP server, which is an Enterprise add-on, or that the Community edition is not sold as a cloud plan\n\n### Sources\n\n- API introduction (authentication, HAL, methods): \u003chttps://www.openproject.org/docs/api/introduction/\u003e (seen 2026-10-08)\n- OpenAPI 3.1 document, as served by the community instance: \u003chttps://community.openproject.org/api/v3/spec.yml\u003e (seen 2026-10-08)\n- repository, cloned (API docs, release notes, MCP tool code, configuration docs, workflows): \u003chttps://github.com/opf/openproject\u003e (seen 2026-10-08)\n- MCP server docs: \u003chttps://www.openproject.org/docs/system-admin-guide/integrations/mcp-server/\u003e (seen 2026-10-08)\n- pricing page and its price table script: \u003chttps://www.openproject.org/pricing/\u003e (seen 2026-10-08)\n- cloud trial signup page: \u003chttps://start.openproject.com/\u003e (seen 2026-10-08)\n- status page: \u003chttps://status.openproject.com\u003e (seen 2026-10-08)\n- Terms of Service: \u003chttps://www.openproject.org/legal/terms-of-service/\u003e (seen 2026-10-08)\n- service description (availability, credits, support levels): \u003chttps://www.openproject.org/legal/description-of-services/\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.openproject.org/legal/privacy/\u003e (seen 2026-10-08)\n- data processing agreement: \u003chttps://www.openproject.org/legal/data-processing-agreement/\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://www.openproject.org/legal/data-processing-agreement/sub-processors/\u003e (seen 2026-10-08)\n- statement on security: \u003chttps://www.openproject.org/docs/security-and-privacy/statement-on-security/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.openproject.org/.well-known/security.txt\u003e (seen 2026-10-08)\n- security advisories, nine pages read: \u003chttps://github.com/opf/openproject/security/advisories\u003e (seen 2026-10-08)\n- release notes: \u003chttps://www.openproject.org/docs/release-notes/\u003e (seen 2026-10-08)\n- RDAP record for openproject.org: \u003chttps://rdap.org/domain/openproject.org\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 95/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | OpenProject GmbH | 20/20 |\n| Domain age | openproject.org, registered 2003-10-24 (22 years) | 15/15 |\n| Endpoint on the vendor's domain | openproject.org | 15/15 |\n| Terms of service | read, states 3 of the 7 things a reader expects | 6.6/10 |\n| Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 |\n| Status page | status.openproject.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe Terms of Service (last updated 6 August 2026) name OpenProject GmbH, Krausenstrasse 9, 10117 Berlin, Germany, and cover both the cloud and the on-premises Enterprise edition. The German version takes precedence.\n\nThe privacy policy (version 30 July 2026) has a section on OpenProject Enterprise Cloud, where OpenProject GmbH is processor and the customer controller. The data processing agreement at https://www.openproject.org/legal/data-processing-agreement/ is part of the terms.\n\nCloud instances answer at \u003cname\u003e.openproject.com or, on the EU shard, an openproject.eu host. Both are the vendor's domains, apart from the openproject.org site that carries the docs and legal pages. Self-hosted instances answer on the owner's domain.\n\nwww.openproject.org/.well-known/security.txt is PGP-signed, names security@openproject.com and expires on 31 December 2026.\n\nRDAP for openproject.org gives a registration date of 2003-10-24 and InterNetX GmbH as registrar.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.openproject.org/legal/terms-of-service/), read 2026-10-08, dated 2026-08-06, states 3 of the 7 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-08-06.\n- Not found in the text. Names the governing law or courts.\n- Not found in the text. States a limit on its liability.\n- Not found in the text. Says how changes to the terms are announced.\n- Not found in the text. Lists what users may not do.\n- Also in the text (2026-10-08). The contract term renews automatically for the originally selected period unless the customer terminates it. \"The contractual term shall be automatically extended by the originally selected period, unless the contract is terminated as follows:\"\n- Also in the text (2026-10-08). OpenProject may name the customer as a user of its products in reference lists and external communications, to an appropriate and customary extent. \"OpenProject may refer to the Customer’s use of OpenProject products pursuant to a contractual relationship with OpenProject and to an appropriate and customary extent in reference lists and in its external communications.\"\n- Also in the text (2026-10-08). If the customer gives no deletion instructions by the end of the term, OpenProject asks it to back up its data on its own systems within 21 days. \"If the Customer fails to specify any corresponding provisions by the end of the contractual term, OpenProject will request the Customer to back up their data on their own systems within 21 days.\"\n\n**Privacy policy** (https://www.openproject.org/legal/privacy/), read 2026-10-08, gives no date, states 6 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. Names a period of 90 days.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Gives a privacy contact. privacy@openproject.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). An Enterprise Cloud instance is deleted automatically six months after the contract expires. \"Your instance of the OpenProject Enterprise Cloud will be automatically deleted six months after the expiry of your contract.\"\n\n## Live (updated 2026-10-09 07:58 UTC)\n\n- Vendor status page: unknown, no machine-readable status found\n- Always current: https://www.anchorterminal.com/api/v1/live/openproject.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Community (self-hosted) | free | per seat per month | free, REST API included; not sold as a cloud plan |\n| Basic (cloud) | $7.25 | per seat per month | yearly term, from 5 users; $8.50 on a monthly term |\n| Professional (cloud) | $13.50 | per seat per month | yearly term, from 25 users; includes the MCP server |\n| Premium (cloud) | $19.50 | per seat per month | yearly term, from 100 users |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- OpenAPI 3.1 document with 234 paths and 320 operations, public on the docs site and served by every instance at `/api/v3/spec.json`\n- Errors carry a stable `errorIdentifier` URN, and validation failures list one entry per property\n- The Community edition is GPL-3.0 and free to self-host with the REST API included, and the cloud trial needs no credit card\n- Seven releases between 5 August and 1 October 2026, with security fixes published as GitHub advisories and CVEs\n- The service description commits to 99.9 per cent yearly availability with service credits, and an EU shard keeps all sub-processors in the EU\n\n## Weaknesses\n\n- 83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection\n- No request limit, 429 behaviour or Retry-After guidance is published for the cloud API\n- Personal API tokens act with their user's full permissions, and OAuth has one scope per API with no read-only form\n- No official SDK. The client libraries the docs list are community projects the vendor says it does not vet\n- The MCP server is an Enterprise add-on for the Professional plan and above, which starts at 25 users\n\n## Before you call it (notes for agents)\n\n1. Send the API token as `Authorization: Bearer \u003ctoken\u003e`, or as the Basic auth password with the user name `apikey`\n2. Read the resource first and send its current `lockVersion` with every PATCH. A stale value returns 409 `UpdateConflict`\n3. POST to the `/form` endpoint of a work package to learn writable fields and allowed values before creating or updating\n4. URL-encode `filters` as a JSON array, and add `pageSize`, `offset` and `select` to keep work package lists small\n5. Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42\n```\n\nThrough letme (picks today, calling later): https://letme.dev/openproject. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Basecamp | B | 67.9 | 220 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send | no | https://www.anchorterminal.com/tools/basecamp.md |\n| Plane | B | 67.6 | 229 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send | no | https://www.anchorterminal.com/tools/plane.md |\n| Taiga | F | 31.7 | 830 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send | no | https://www.anchorterminal.com/tools/taiga.md |\n| monday.com | BB | 76.4 | 33 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/monday.md |\n| Asana | BB | 70.1 | 154 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/asana.md |\n| Todoist | B | 66.9 | 252 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/todoist.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- APIv3 is a hypermedia REST API in HAL+JSON, documented in one OpenAPI 3.1 file with 234 paths and 320 operations, which each instance also serves at `/api/v3/spec.json` (source: \u003chttps://www.openproject.org/docs/api/introduction/\u003e)\n- The MCP server at `/mcp` is an Enterprise add-on for the Professional, Premium and Corporate plans. The docs list 23 tools and ten resources, and version 17.9 added time entry tools (source: \u003chttps://www.openproject.org/docs/system-admin-guide/integrations/mcp-server/\u003e)\n- 83 security advisories were published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical. Several credit a YesWeHack bounty sponsored by the European Commission (source: \u003chttps://github.com/opf/openproject/security/advisories\u003e)\n- The service description commits to 99.9 per cent availability a year for the cloud, with a 5 per cent credit per hour beyond it (source: \u003chttps://www.openproject.org/legal/description-of-services/\u003e)\n- The cloud runs as two shards, openproject.com on AWS and openproject.eu on Scaleway, with every EU-shard sub-processor based in the EU (source: \u003chttps://www.openproject.org/legal/data-processing-agreement/sub-processors/\u003e)\n- No request limit for the API is published. The configuration docs describe one optional rule for self-hosted installs, six requests per three seconds on form endpoints (source: \u003chttps://github.com/opf/openproject/blob/dev/docs/installation-and-operations/configuration/README.md\u003e)\n- The security statement says OpenProject has no bug bounty programme of its own and targets a fix for critical and high findings within 21 days of confirmation (source: \u003chttps://www.openproject.org/docs/security-and-privacy/statement-on-security/\u003e)\n\n## Compare\n\n- [Asana vs OpenProject](https://www.anchorterminal.com/compare/asana-vs-openproject.md): BB 70.1 vs C 57.4\n- [Basecamp vs OpenProject](https://www.anchorterminal.com/compare/basecamp-vs-openproject.md): B 67.9 vs C 57.4\n- [ClickUp vs OpenProject](https://www.anchorterminal.com/compare/clickup-vs-openproject.md): C 60.9 vs C 57.4\n- [monday.com vs OpenProject](https://www.anchorterminal.com/compare/monday-vs-openproject.md): BB 76.4 vs C 57.4\n- [OpenProject vs Plane](https://www.anchorterminal.com/compare/openproject-vs-plane.md): C 57.4 vs B 67.6\n- [OpenProject vs Roma](https://www.anchorterminal.com/compare/openproject-vs-roma.md): C 57.4 vs D 51.1\n- [OpenProject vs Shortcut](https://www.anchorterminal.com/compare/openproject-vs-shortcut.md): C 57.4 vs C 60.2\n- [OpenProject vs Taiga](https://www.anchorterminal.com/compare/openproject-vs-taiga.md): C 57.4 vs F 31.7\n- [OpenProject vs Teamwork.com](https://www.anchorterminal.com/compare/openproject-vs-teamwork.md): C 57.4 vs B 65.9\n- [OpenProject vs Todoist](https://www.anchorterminal.com/compare/openproject-vs-todoist.md): C 57.4 vs B 66.9\n- [OpenProject vs Trello](https://www.anchorterminal.com/compare/openproject-vs-trello.md): C 57.4 vs C 61.1\n- [OpenProject vs Wrike](https://www.anchorterminal.com/compare/openproject-vs-wrike.md): C 57.4 vs C 60.1\n- [OpenProject vs YouTrack](https://www.anchorterminal.com/compare/openproject-vs-youtrack.md): C 57.4 vs D 49.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on openproject.org or one of its subdomains, or the README of github.com/opf/openproject. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"openproject\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/openproject\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/openproject.svg\" alt=\"OpenProject on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![OpenProject on Anchor Terminal](https://www.anchorterminal.com/badges/openproject.svg)](https://www.anchorterminal.com/tools/openproject)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/openproject\"\u003eOpenProject on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say OpenProject is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/openproject-dark.png\n- Light: https://www.anchorterminal.com/assets/share/openproject-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Project \u0026 task management",
        "url": "https://www.anchorterminal.com/categories/project-management"
      },
      {
        "name": "OpenProject",
        "url": ""
      }
    ],
    "description": "OpenProject is open-source project management software for work packages, Gantt plans, boards and time tracking, sold as a cloud service and for self-hosting. Agents reach it through the APIv3 REST API, and paid plans add an MCP server.",
    "facts": [
      "rank #550 of 842",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "OpenProject",
    "image": "https://www.anchorterminal.com/assets/og/tools-openproject.png",
    "path": "/tools/openproject",
    "published": "2026-10-01",
    "section": "tools",
    "title": "OpenProject review for AI agents, grade C (57.4/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/openproject"
  },
  "tokens": {
    "markdown": 7900,
    "slim": 1880
  },
  "version": 1
}
