# OpenProject (slim) > OpenProject is open-source project management software for work packages, Gantt plans, boards and time tracking, sold as a cloud service and for self-hosting. Agents reach it through the APIv3 REST API, and paid plans add an MCP server. - Full: https://www.anchorterminal.com/tools/openproject.md (~7,900 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/openproject.json · canonical https://www.anchorterminal.com/tools/openproject - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 57.4/100 · rank #550 of 842 · #11 in Project & task management · not agent-ready · confidence medium** Assessment: OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical. ## Facts - Kind: HTTP API · vendor: OpenProject GmbH · category: Project & task management · legal entity: OpenProject GmbH · provenance 95/100 - Local only (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service - Probe metrics: not measured yet (probes haven't run) - Surface graded: APIv3 of OpenProject Enterprise cloud at `https://.openproject.com/api/v3` (or an openproject.eu host on the EU shard). The same API ships in the free Community edition for self-hosting - API: OpenAPI 3.1, 234 paths and 320 operations (178 GET, 80 POST, 32 PATCH, 30 DELETE). HAL+JSON responses. Covers work packages, projects, portfolios, time entries, memberships, queries, versions, wiki pages, notifications and more - Authentication: Personal API token as Bearer or as Basic auth with user name `apikey`. OAuth 2.0 authorisation code, PKCE and client credentials with scopes `api_v3`, `mcp`, `scim_v2` and `bcf_v2_1`. JWTs from a configured OIDC provider - MCP server: Enterprise add-on for Professional, Premium and Corporate, at `/mcp` on the instance. 23 tools per the docs, among them `search_work_packages`, `create_work_package`, `update_work_package`, `create_work_package_comment` and four time entry tools, plus ten resources. Tools can be switched off one by one - Rate limits: None published for the cloud API. Self-hosted installs can turn on a rule of six requests per three seconds on API form endpoints - Pagination and sizing: `pageSize` and `offset` on collections, with a maximum page size set by the administrator. `select` on eight collection endpoints. `filters` with operators and `sortBy` - Errors: `errorIdentifier` URNs such as `urn:openproject-org:api:v3:errors:MissingPermission`, with `MultipleErrors` grouping per-property validation failures. 409 `UpdateConflict` on a stale `lockVersion` - Webhooks: Set by an administrator, with a signature secret, per-project selection and events for projects, work packages, comments, time entries and attachments - SLA: 99.9 per cent availability a calendar year excluding scheduled maintenance, with a credit of 5 per cent of the monthly fee per hour beyond it, claimed within 30 days - Security programme: Signed security.txt, disclosure policy, GitHub advisories with CVEs, a YesWeHack bounty sponsored by the European Commission, signed container images with SBOM and VEX documents - Status: status.openproject.com on UptimeRobot. Figures load by script from a path robots.txt disallows - Sub-processors: openproject.com shard, AWS, MessageBird, Postmark and mailbox.org. openproject.eu shard, Scaleway, rapidmail and mailbox.org. List updated 18 May 2026 - Releases: 17.9.1 on 1 October 2026, 17.9.0 and 17.8.1 on 30 September, 17.8.0 on 2 September, 17.7.x in August - Prices: Community (self-hosted) free per seat per month; Basic (cloud) $7.25 per seat per month; Professional (cloud) $13.50 per seat per month; Premium (cloud) $19.50 per seat per month - Scores: Reliability 52, Performance pending, Schema & documentation 76, Agent ergonomics 70, Security & auth 59, Payments & pricing 30, Task success pending, Maintenance & community 75, Transparency & trust 87 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Graded on the APIv3 of OpenProject Enterprise cloud, with the hosted lines. · Schema & documentation, A public OpenAPI 3.1 document with 234 paths and 320 operations, downloadable from the docs site and served by every instance at… · Agent ergonomics, Graded on the REST API. · Security & auth, OAuth 2.0 with the authorisation code grant, PKCE and client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`) an… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Version 17.9.1 was released on 1 October 2026 (30). · Transparency & trust, The source is public under GPL-3.0, Enterprise add-ons included, with those add-ons unlocked by a paid token. - Sources: 17, open questions: 8, both in the full twin - Capabilities: tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send - JSON: https://www.anchorterminal.com/api/v1/tools/openproject.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/openproject.svg` or a link to https://www.anchorterminal.com/tools/openproject from a page on openproject.org or one of its subdomains, or the README of github.com/opf/openproject, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the API token as `Authorization: Bearer `, or as the Basic auth password with the user name `apikey` 2. Read the resource first and send its current `lockVersion` with every PATCH. A stale value returns 409 `UpdateConflict` 3. POST to the `/form` endpoint of a work package to learn writable fields and allowed values before creating or updating 4. URL-encode `filters` as a JSON array, and add `pageSize`, `offset` and `select` to keep work package lists small 5. Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input ## Connect ```bash curl -H "Authorization: Bearer $API_KEY" https://community.openproject.org/api/v3/users/42 ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/openproject ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Basecamp | B | 67.9 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send | https://www.anchorterminal.com/tools/basecamp.min.md | | Plane | B | 67.6 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send | https://www.anchorterminal.com/tools/plane.min.md | | Taiga | F | 31.7 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, events.webhooks-send | https://www.anchorterminal.com/tools/taiga.min.md | | monday.com | BB | 76.4 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/monday.min.md | | Asana | BB | 70.1 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | https://www.anchorterminal.com/tools/asana.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)