Outline

by General Outline, Inc. HTTP API in Work & productivity

Hosted

General Outline, Inc. · getoutline.com since 2017 · status page · who's behind it

Outline is a team wiki and knowledge base from General Outline, available hosted or self-hosted. Agents reach it through an RPC-style HTTP API with a public OpenAPI description, or an MCP server built into each workspace.

Good for Teams that keep their wiki in Outline and want an agent to search, read, write and comment on Markdown documents, on the hosted service or a self-hosted copy with the same API.

Is this your product? Claim this listing or verify it

Assessment. API keys and OAuth tokens can be limited to single endpoints, all 154 operations document a 429 response with Retry-After, and the workspace MCP server registers tools by granted scope. Two scope-bypass flaws were published and fixed in May and June 2026, rate limits carry no published numbers, and there are no official client libraries.

Facts

Transport
HTTP, Streamable HTTP
Endpoint
https://app.getoutline.com/api
Auth
OAuth or key
Pricing
Paid · $10 / mo
x402
No
Licence
Source available under BSL 1.1, which bars running it as a document service for third parties and converts each release to Apache 2.0 on its change date (2030-09-09 for 1.10.1). The OpenAPI description is BSD-3-Clause. The hosted service is under the vendor's terms
Tools exposed
19
llms.txt
published
Last release
GitHub stars
41k
Surface graded
The hosted Outline Cloud API at https://app.getoutline.com/api, with the built-in MCP server described alongside it. The same API and MCP server ship in the self-hosted editions
API
OpenAPI 3.0, 154 operations in 26 groups, all POST with JSON bodies. Documents (30 operations), collections (19), users (12), comments (9), groups (9), templates (7), plus shares, revisions, attachments, events and webhook subscriptions
Documents
Bodies are Markdown up to 1,536,000 characters. documents.update takes editMode with findText for patch edits and lastRevision for a 409 on a stale write. documents.delete moves to the trash for 30 days unless permanent is set
Search
documents.search returns a context snippet and ranking per hit with structured filters, documents.search_titles matches titles only, and documents.answerQuestion answers from documents where the workspace has AI answers on
MCP server
https://<subdomain>.getoutline.com/mcp, Streamable HTTP only, 19 tools (documents, collections, comments, templates, attachments, users and a fetch tool), OAuth or API key, off or on per workspace. The source limits it to 1,000 requests an hour
Credentials
API keys with optional expiry and scopes, or OAuth 2.0 with PKCE, refresh tokens, revocation and dynamic client registration. Scopes are read, write, namespaced such as documents:read, or single methods and wildcards
Rate limits
No numbers in the API documentation. A 429 carries Retry-After, RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset. The source defaults to 1,000 requests a minute overall, with document methods at 25 or 100 a minute and some at 10 or 100 an hour
Errors
JSON with ok, error, message and status, for example validation_error at 400 and rate_limit_exceeded at 429. 401 and 429 are documented on every operation, 403 on 151
Paging
limit and offset with sort and direction on list methods, and a nextPath in each response. No field selection
Webhooks
Workspace webhooks post JSON for document, collection, comment, user, group and share events, signed where a secret is set, and are managed through four webhookSubscriptions methods. Repeatedly failing webhooks are disabled
Client libraries
None official. The vendor publishes the OpenAPI description in outline/openapi for generating clients
Audit
Audit log with actor, IP address and authentication type, kept for one year, in Settings and through events.list with auditLog
Status
status.getoutline.com on Oh Dear with three monitors (Application, Website, Collaboration). The history page showed no incidents on 8 October 2026 and gives no uptime figures
Data
Servers in the US on AWS, AES-256 at rest, daily backups kept at least three months, per the vendor's security page. The DPA lists 13 sub-processors with countries, OpenAI among them for generative AI
Releases
v1.10.1 on 9 September 2026 and five tagged releases since 11 July 2026. The hosted changelog has 172 dated entries, the newest on 9 September 2026

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Public OpenAPI 3.0 description with 154 operations, each with a summary and description, plus llms.txt on the vendor site
  • API keys take an expiry and scopes down to one endpoint such as documents.info, and OAuth supports PKCE and dynamic client registration
  • Every operation documents 429 with Retry-After and three RateLimit-* response headers
  • Each workspace has an MCP server with 19 tools, registered according to the token's scopes, with read-only and idempotent hints on all of them
  • Audit log kept for one year on every cloud tier and readable through events.list with auditLog set

Weaknesses

  • No rate limit numbers in the API documentation. The limits we found are in the source code, not stated for the hosted service
  • Two flaws that let a restricted key or token exceed its scopes were published in May and June 2026, both fixed (GHSA-7732-6qrg-wjf4, GHSA-5x79-rj4g-qrh8)
  • No official client libraries. The vendor points to the OpenAPI description for generating clients
  • No idempotency keys, and no MCP tool carries a destructive hint or a confirmation step
  • The published terms of service read as website terms, and the privacy policy states no retention periods
  • No security.txt, bug bounty or SOC 2 or ISO 27001 report was found on the vendor's pages

Before you call it notes for agents

  1. Send every call as POST with a JSON body to https://app.getoutline.com/api/<method>, for example documents.search, with a Bearer key in the header
  2. Ask for a key scoped to the methods the task needs, such as documents.info documents.search. An unscoped key has all of its owner's access
  3. Pass lastRevision on documents.update so a stale write is rejected with 409, and use editMode patch with findText to change one passage
  4. Wait for the seconds in Retry-After on a 429. Write methods have tighter limits than reads
  5. Leave permanent unset on documents.delete. The default moves the document to the trash, where it can be restored for 30 days

Who's behind it provenance 79/100

  • Legal entity namedGeneral Outline, Inc.20/20
  • Domain agegetoutline.com, registered 2017-11-08 (8 years)11/15
  • Endpoint on the vendor's domainapp.getoutline.com15/15
  • Terms of serviceread, states 4 of the 7 things a reader expects7.4/10
  • Privacy policyread, states 2 of the 8 things a reader expects5.5/10
  • Status pagestatus.getoutline.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 4 of 7

TL;DR Gives no date. States 4 of the 7 things a reader expects, and we didn't find how it ends or a service level. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of San Francisco County
Except to the extent any applicable law provides otherwise, these terms and conditions are governed by and construed in accordance with the laws of San Francisco County, California and you irrevocably submit to the exclusive jurisdiction of the courts in that State.

Says where a dispute would be heard and under whose law.

States a limit on its liability
In no event shall Outline or its suppliers be liable for any damages (including, without limitation, damages for loss of data or profit, or due to business interruption) arising out of the use or inability to use the materials on Outline’s website, even if Outline or a Outline authorized representative has been notifi…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended

Not found in the text.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
Outline may revise these terms of service for its website at any time without notice.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
This is the grant of a license, not a transfer of title, and under this license you may not:

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

The terms cover materials on the Outline website and grant licences over them for personal, non-commercial viewing only.
Permission is granted to temporarily download one copy of the materials (information or software) on Outline’s website for personal, non-commercial transitory viewing only.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 712 words

Privacy policy gives no date, states 2 of 8

TL;DR Gives no date. States 2 of the 8 things a reader expects, and we didn't find how long data is kept, whether data is sold, people's rights, a privacy contact or where data goes. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
It is Outline’s policy to respect your privacy regarding any information we may collect while operating our websites.

The basic statement a privacy policy exists to make.

Says how long data is kept

Not found in the text.

Says when data sent to the service is deleted.

Says who else receives the data
Other than to its employees, contractors and affiliated organizations, as described above, Outline discloses potentially personally-identifying and personally-identifying information only in response to a subpoena, court order or other governmental request, or when Outline believes in good faith that disclosure is rea…

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data

Not found in the text.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact

Not found in the text.

An address or officer to send a request to.

Says where data is transferred or stored

Not found in the text.

The countries data goes to and the safeguard used.

Outline reserves the right to publish a request sent to it, such as a support email.
If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 1,024 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The data processing agreement at docs.getoutline.com/s/dpa names General Outline, Inc., a Delaware corporation at 228 Park Ave S, PMB 377005, New York, and says it supplements the Terms of Service, which it calls the Agreement.

The page at www.getoutline.com/terms is titled Terms of Service and is the only terms document found. Its clauses cover the website's materials and say nothing on the hosted service, payment or customer content.

The privacy policy is undated, names General Outline, Inc. as operator of getoutline.com, and covers registered and signed-in users as well as visitors.

The hosted API answers at https://app.getoutline.com/api and each workspace at <subdomain>.getoutline.com, both on the vendor's domain.

www.getoutline.com/.well-known/security.txt and app.getoutline.com/.well-known/security.txt both return 404. Reports go through GitHub security advisories per docs/SECURITY.md in the repository.

RDAP for getoutline.com gives a registration date of 2017-11-08.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-09 01:58 UTC

Right nowUpHTTP 404 · 296 ms · 3 minutes ago
Uptime 24h100.0%71 probes
Uptime 30 days100.0%71 probes
p50 24h259 msget
p95 24h296 msopen endpoint

Probed every five minutes at https://app.getoutline.com/api. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 6 hours ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/outline.json

Notable

  • The API is RPC style. Every one of 154 operations is a POST to https://app.getoutline.com/api/<method>, and the vendor says its own application runs on the same API source
  • Each workspace has had a built-in MCP server since 18 February 2026, at https://<subdomain>.getoutline.com/mcp over Streamable HTTP, switched on or off by an admin under Settings, Workspace, AI source
  • The MCP source registers 19 tools and filters them by the token's scopes. All carry readOnlyHint and idempotentHint, and none carries destructiveHint source
  • The repository is under BSL 1.1, which its own text says is not an open source licence, while the vendor's security page calls the product open-source at its core source
  • Twenty-two advisories were published on the repository between 16 November 2025 and 30 July 2026, one critical and eight high, all with a patched version named source
  • CVE-2026-43886 let an OAuth client add the wildcard scope to a read-only request, fixed in 1.7.0, and CVE-2026-54573 let a scoped key reach other methods through a URL fragment, fixed in 1.8.0 source
  • WebMCP support, added on 9 September 2026, registers command bar actions as in-page tools for browser agents and leaves out deletes source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 13.4
Graded on the hosted Outline Cloud API with the hosted lines. Status page at status.getoutline.com on Oh Dear with three monitors, Application, Website and Collaboration (20). The history page read No incident history available on 8 October 2026, the seven-day view was clean and the RSS feed was empty, with no uptime figures, so we could not tell a clean record from an unused page and gave 20 of 30. The API documentation says write methods are limited more tightly than reads and gives no numbers. The numbers are in the public source (1,000 requests a minute by default, 25 or 100 a minute on document methods, 1,000 an hour on MCP), which is not a statement about the hosted service (5). Every operation documents 429 with Retry-After and three RateLimit-* headers, and documents.update takes lastRevision for a 409 on a stale write. No idempotency keys (12). No SLA found (0). The API and MCP server are generally available (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 12.3
Public OpenAPI 3.0 description at www.getoutline.com/openapi.json and in outline/openapi, 154 operations, and MCP tools typed with zod schemas (25). llms.txt on the vendor site, and changelog and integration pages served as Markdown with a .md suffix (10). All 154 operations have a summary and a description. Most are one or two sentences and few say when not to use a method (13). 51 schemas, 60 enums, maxLength and format constraints and 123 required lists. Scopes on apiKeys.create are free strings and request bodies do not close off extra properties (12). 153 example values, a curl and a JavaScript sample in the introduction only, and shared 400, 401, 403, 404 and 429 responses (10). The description is versioned 0.1.0 with no version in the path and no API changelog. The outline/openapi commit log and 19 fields marked deprecated are the record (6).
Agent ergonomics 13%16.2 10.1
documents.search returns a context snippet and ranking with each hit, and list methods take limit. No field selection, and hits embed the document object. The MCP server has 19 tools, registered according to the token's scopes (13). limit and offset paging with nextPath, sort and direction, and structured filters on document lists and search (17). Errors return ok, error, message and status with codes such as validation_error and rate_limit_exceeded (14). No idempotency keys. documents.create accepts a client-chosen id, documents.update rejects stale writes with 409 through lastRevision, and all 19 MCP tools carry readOnlyHint and idempotentHint. None carries destructiveHint (11). Few required parameters and sensible defaults. No official client libraries (7).
Security & auth 14%17.5 12.4
OAuth 2.0 with PKCE (S256), refresh tokens, revocation and dynamic client registration, and API keys that are shown once, revocable, optionally expiring and scoped down to single methods (30). The user guide allows the key in the request payload as token. The source also reads token from the query string, which the documentation does not mention, so no deduction. A read scope, per-method scopes, MCP tools filtered by scope, a workspace switch for MCP, and deletes that go to the trash for 30 days unless permanent is set. No confirmation step for writes or deletes (15). Documents and comments are text written by other users. No prompt-injection guidance was found. WebMCP leaves destructive actions out (3). Audit log with actor, IP address and authentication type, kept one year, on every cloud tier and through events.list (14). A disclosure policy through GitHub advisories with 26 advisories published and patched in public, and CodeQL in CI. No security.txt, bug bounty, SOC 2 or ISO 27001 found (9). The 2026 scope-bypass advisories are counted under incidents.
Payments & pricing 10%12.5 3.8
No x402, MPP or L402 (0). Prices are public as plans by team size, $10, $79 and $249 a month, with nothing per call (10). A new workspace is free for 30 days and becomes read-only until a payment method is added, so no card is needed to start (20). A person creates the workspace and the first key or OAuth approval in a browser. apiKeys.create and /oauth/register exist but need a signed-in user first (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.3
v1.10.1 was released on 9 September 2026, 29 days before the check, and the main branch had 200 commits since 5 September (30). Five tagged releases since 11 July 2026, and seven dated changelog entries in the same period (20). The 30 newest open issues and pull requests on 8 October 2026 show the maintainer opening and answering items daily, with 83 open in total on a repository of 40,842 stars (22). No vendor entry in the official MCP registry, where a search returned community servers only, and no official client libraries. The OpenAPI description was updated on 7 October 2026 (3). CI, CodeQL and Dependabot are configured in the repository (8).
Transparency & trusteditorial 58, provenance 79 7%8.8 6.0
The source is public under BSL 1.1, which is not an OSI licence and bars running a competing document service, with each release converting to Apache 2.0 after its change date. The OpenAPI description is BSD-3-Clause. Between closed and open source (22). A privacy policy, a DPA and a security page exist. The policy is undated and states no retention periods, the DPA points to a Data Security and Retention clause that the policy does not contain, and the terms of service cover the website only. Backups are kept at least three months and audit logs one year (14). Deprecated parameters are marked in the OpenAPI description, 19 of them, with no dates and no deprecation policy (5). The DPA lists 13 sub-processors with purpose and country, and the security page places servers in the US on AWS. No change log for the list (17).
Negative events≤15-5
Total60.3 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 22 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Outline, or have the agent fetch /fixes/outline.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Outline

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/outline, the October 2026 research run, assessed 8 October 2026. Grade C, 60.3 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Outline: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 30 out of 100, up to 8.8 more on the total

Why it scored 30: No x402, MPP or L402 (0). Prices are public as plans by team size, $10, $79 and $249 a month, with nothing per call (10). A new workspace is free for 30 days and becomes read-only until a payment method is added, so no card is needed to start (20). A person creates the workspace and the first key or OAuth approval in a browser. `apiKeys.create` and `/oauth/register` exist but need a signed-in user first (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Reliability, 67 out of 100, up to 6.6 more on the total

Why it scored 67: Graded on the hosted Outline Cloud API with the hosted lines. Status page at status.getoutline.com on Oh Dear with three monitors, Application, Website and Collaboration (20). The history page read No incident history available on 8 October 2026, the seven-day view was clean and the RSS feed was empty, with no uptime figures, so we could not tell a clean record from an unused page and gave 20 of 30. The API documentation says write methods are limited more tightly than reads and gives no numbers. The numbers are in the public source (1,000 requests a minute by default, 25 or 100 a minute on document methods, 1,000 an hour on MCP), which is not a statement about the hosted service (5). Every operation documents 429 with `Retry-After` and three `RateLimit-*` headers, and `documents.update` takes `lastRevision` for a 409 on a stale write. No idempotency keys (12). No SLA found (0). The API and MCP server are generally available (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 3. Agent ergonomics, 62 out of 100, up to 6.2 more on the total

Why it scored 62: `documents.search` returns a context snippet and ranking with each hit, and list methods take `limit`. No field selection, and hits embed the document object. The MCP server has 19 tools, registered according to the token's scopes (13). `limit` and `offset` paging with `nextPath`, `sort` and `direction`, and structured `filters` on document lists and search (17). Errors return `ok`, `error`, `message` and `status` with codes such as `validation_error` and `rate_limit_exceeded` (14). No idempotency keys. `documents.create` accepts a client-chosen `id`, `documents.update` rejects stale writes with 409 through `lastRevision`, and all 19 MCP tools carry `readOnlyHint` and `idempotentHint`. None carries `destructiveHint` (11). Few required parameters and sensible defaults. No official client libraries (7).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Security & auth, 71 out of 100, up to 5.1 more on the total

Why it scored 71: OAuth 2.0 with PKCE (S256), refresh tokens, revocation and dynamic client registration, and API keys that are shown once, revocable, optionally expiring and scoped down to single methods (30). The user guide allows the key in the request payload as `token`. The source also reads `token` from the query string, which the documentation does not mention, so no deduction. A `read` scope, per-method scopes, MCP tools filtered by scope, a workspace switch for MCP, and deletes that go to the trash for 30 days unless `permanent` is set. No confirmation step for writes or deletes (15). Documents and comments are text written by other users. No prompt-injection guidance was found. WebMCP leaves destructive actions out (3). Audit log with actor, IP address and authentication type, kept one year, on every cloud tier and through `events.list` (14). A disclosure policy through GitHub advisories with 26 advisories published and patched in public, and CodeQL in CI. No security.txt, bug bounty, SOC 2 or ISO 27001 found (9). The 2026 scope-bypass advisories are counted under incidents.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 5. Schema & documentation, 76 out of 100, up to 3.9 more on the total

Why it scored 76: Public OpenAPI 3.0 description at www.getoutline.com/openapi.json and in outline/openapi, 154 operations, and MCP tools typed with zod schemas (25). llms.txt on the vendor site, and changelog and integration pages served as Markdown with a `.md` suffix (10). All 154 operations have a summary and a description. Most are one or two sentences and few say when not to use a method (13). 51 schemas, 60 enums, `maxLength` and `format` constraints and 123 required lists. Scopes on `apiKeys.create` are free strings and request bodies do not close off extra properties (12). 153 example values, a curl and a JavaScript sample in the introduction only, and shared 400, 401, 403, 404 and 429 responses (10). The description is versioned 0.1.0 with no version in the path and no API changelog. The outline/openapi commit log and 19 fields marked deprecated are the record (6).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 69 out of 100, up to 2.7 more on the total

Made of editorial 58, provenance 79.

Why it scored 69: The source is public under BSL 1.1, which is not an OSI licence and bars running a competing document service, with each release converting to Apache 2.0 after its change date. The OpenAPI description is BSD-3-Clause. Between closed and open source (22). A privacy policy, a DPA and a security page exist. The policy is undated and states no retention periods, the DPA points to a Data Security and Retention clause that the policy does not contain, and the terms of service cover the website only. Backups are kept at least three months and audit logs one year (14). Deprecated parameters are marked in the OpenAPI description, 19 of them, with no dates and no deprecation policy (5). The DPA lists 13 sub-processors with purpose and country, and the security page places servers in the US on AWS. No change log for the list (17).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: getoutline.com, registered 2017-11-08 (8 years) (11 of 15)
- Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10)
- Privacy policy: read, states 2 of the 8 things a reader expects (5.5 of 10)
- security.txt: not found (0 of 10)

## 7. Maintenance & community, 83 out of 100, up to 1.5 more on the total

Why it scored 83: v1.10.1 was released on 9 September 2026, 29 days before the check, and the main branch had 200 commits since 5 September (30). Five tagged releases since 11 July 2026, and seven dated changelog entries in the same period (20). The 30 newest open issues and pull requests on 8 October 2026 show the maintainer opening and answering items daily, with 83 open in total on a repository of 40,842 stars (22). No vendor entry in the official MCP registry, where a search returned community servers only, and no official client libraries. The OpenAPI description was updated on 7 October 2026 (3). CI, CodeQL and Dependabot are configured in the repository (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- 2026-05-07 and 2026-06-15. CVE-2026-43886 (GHSA-7732-6qrg-wjf4, high) let an OAuth client request `read *` and receive wildcard access, fixed in 1.7.0. CVE-2026-54573 (GHSA-5x79-rj4g-qrh8, high) let a scoped API key or token reach other methods by adding a URL fragment, fixed in 1.8.0. Both defeat the scopes an agent's owner relies on. Fixed and published, so 2 points (https://github.com/outline/outline/security/advisories/GHSA-7732-6qrg-wjf4, https://github.com/outline/outline/security/advisories/GHSA-5x79-rj4g-qrh8).
- 2026-06-06 and 2026-07-27. Two MCP advisories, `list_documents` returning metadata of private documents on an exact slug match (GHSA-pp65-6cc2-4mx9, medium) and viewers publishing into restricted collections through MCP (GHSA-c43v-wwv4-9mcc, medium), both fixed in 1.8.0. Fixed and published, 1 point (https://github.com/outline/outline/security/advisories/GHSA-pp65-6cc2-4mx9, https://github.com/outline/outline/security/advisories/GHSA-c43v-wwv4-9mcc).
- 2025-11-16 to 2026-07-30. Eighteen further advisories in twelve months, among them a critical rate-limit bypass allowing brute force of the email login code (CVE-2026-33640, fixed in 1.6.0) and cross-workspace access to private documents through share creation (CVE-2026-41649, fixed in 1.7.0). All fixed and published by the vendor, so 2 points (https://github.com/outline/outline/security/advisories).

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the On-Premises price table on the pricing page is drawn in the browser, so self-hosted editions and prices were not read
- unchecked: the rate limits applied on the hosted service. The numbers quoted come from the public source and its defaults
- unchecked: the MCP tool list as served by a live workspace, which needs a signed-in session. The 19 tools were counted on the main branch
- The status history page shows no incidents at all and no uptime figures. Whether that is a clean record or an unused page could not be established
- The only terms document found reads as website terms, yet the DPA treats the Terms of Service as the customer agreement. `provenance.terms` points at it for want of another
- The lead called Outline open source. The repository is under BSL 1.1, which its own text says is not an open source licence
- Whether the hosted service runs the tagged release or the main branch was not established. The pricing page calls it always up to date
- No bug bounty, SOC 2 or ISO 27001 statement was found on the pages read. One may exist under a confidentiality agreement

## Weaknesses

- No rate limit numbers in the API documentation. The limits we found are in the source code, not stated for the hosted service
- Two flaws that let a restricted key or token exceed its scopes were published in May and June 2026, both fixed (GHSA-7732-6qrg-wjf4, GHSA-5x79-rj4g-qrh8)
- No official client libraries. The vendor points to the OpenAPI description for generating clients
- No idempotency keys, and no MCP tool carries a destructive hint or a confirmation step
- The published terms of service read as website terms, and the privacy policy states no retention periods
- No security.txt, bug bounty or SOC 2 or ISO 27001 report was found on the vendor's pages

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send every call as POST with a JSON body to `https://app.getoutline.com/api/<method>`, for example `documents.search`, with a Bearer key in the header
- Ask for a key scoped to the methods the task needs, such as `documents.info documents.search`. An unscoped key has all of its owner's access
- Pass `lastRevision` on `documents.update` so a stale write is rejected with 409, and use `editMode` `patch` with `findText` to change one passage
- Wait for the seconds in `Retry-After` on a 429. Write methods have tighter limits than reads
- Leave `permanent` unset on `documents.delete`. The default moves the document to the trash, where it can be restored for 30 days

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the On-Premises price table on the pricing page is drawn in the browser, so self-hosted editions and prices were not read
  • unchecked: the rate limits applied on the hosted service. The numbers quoted come from the public source and its defaults
  • unchecked: the MCP tool list as served by a live workspace, which needs a signed-in session. The 19 tools were counted on the main branch
  • The status history page shows no incidents at all and no uptime figures. Whether that is a clean record or an unused page could not be established
  • The only terms document found reads as website terms, yet the DPA treats the Terms of Service as the customer agreement. provenance.terms points at it for want of another
  • The lead called Outline open source. The repository is under BSL 1.1, which its own text says is not an open source licence
  • Whether the hosted service runs the tagged release or the main branch was not established. The pricing page calls it always up to date
  • No bug bounty, SOC 2 or ISO 27001 statement was found on the pages read. One may exist under a confidentiality agreement

Sources 31

  1. API reference getoutline.com · seen 2026-10-08
  2. OpenAPI description, 154 operations getoutline.com · seen 2026-10-08
  3. OpenAPI repository and commit log github.com · seen 2026-10-08
  4. llms.txt getoutline.com · seen 2026-10-08
  5. user guide, API keys and scopes docs.getoutline.com · seen 2026-10-08
  6. user guide, MCP setup docs.getoutline.com · seen 2026-10-08
  7. user guide, audit log docs.getoutline.com · seen 2026-10-08
  8. user guide, security docs.getoutline.com · seen 2026-10-08
  9. MCP tool definitions in the source github.com · seen 2026-10-08
  10. rate limiter strategies in the source github.com · seen 2026-10-08
  11. OAuth authorisation server metadata app.getoutline.com · seen 2026-10-08
  12. MCP protected resource metadata app.getoutline.com · seen 2026-10-08
  13. changelog, MCP launch getoutline.com · seen 2026-10-08
  14. changelog, MCP improvements getoutline.com · seen 2026-10-08
  15. changelog, WebMCP support getoutline.com · seen 2026-10-08
  16. changelog feed getoutline.com · seen 2026-10-08
  17. pricing getoutline.com · seen 2026-10-08
  18. status page status.getoutline.com · seen 2026-10-08
  19. status history status.getoutline.com · seen 2026-10-08
  20. terms of service getoutline.com · seen 2026-10-08
  21. privacy policy getoutline.com · seen 2026-10-08
  22. data processing agreement and sub-processors docs.getoutline.com · seen 2026-10-08
  23. webhooks getoutline.com · seen 2026-10-08
  24. licence github.com · seen 2026-10-08
  25. security policy github.com · seen 2026-10-08
  26. security advisories github.com · seen 2026-10-08
  27. releases github.com · seen 2026-10-08
  28. repository metadata and open issues api.github.com · seen 2026-10-08
  29. security.txt, 404 getoutline.com · seen 2026-10-08
  30. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  31. RDAP for getoutline.com rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid $10 / mo Outline Cloud is priced by team size a month, $10 for 1 to 10 members, $79 for 11 to 100 and $249 for 101 to 200, with larger teams by quote and annual billing available (https://www.getoutline.com/pricing). The API, webhooks and audit log are on every tier, and API calls are not charged. A new workspace gets 30 days free and turns read-only until a payment method is added, so an agent's owner can start without a contract. The self-hosted price table is drawn in the browser and was not read.

Prices

ItemPriceUnitNote
Cloud, 1 to 10 members$10per month (plan)billed monthly, annual billing available
Cloud, 11 to 100 members$79per month (plan)billed monthly, annual billing available
Cloud, 101 to 200 members$249per month (plan)billed monthly, annual billing available

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/outline.xml, or this listing's score history at history.json.

Connect

First request

curl https://app.getoutline.com/api/documents.info -X POST -H 'authorization: Bearer MY_API_KEY' -H 'content-type: application/json' -H 'accept: application/json' -d '{"id": "outline-api-NTpezNwhUP"}'

Claude Code

claude mcp add --transport http outline https://<yoursubdomain>.getoutline.com/mcp

MCP client configuration

{
  "mcpServers": {
    "outline": {
      "url": "https://\u003cyoursubdomain\u003e.getoutline.com/mcp"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/outline

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Atlan AtlanB62.5knowledge.search work.docsno
Guru Guru Technologies, Inc.E45.1knowledge.search work.docsno
Google Drive API + MCP GoogleA79.6work.docsno
monday.com monday.com Ltd.BB76.4work.docsno
Glean Glean Technologies, Inc.B69.8knowledge.searchno
Box API + MCP BoxB69.4work.docsno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Outline on Anchor Terminal, C, 60.3/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/outline"><img src="https://www.anchorterminal.com/badges/outline.svg" alt="Outline on Anchor Terminal" height="20"></a>
    [![Outline on Anchor Terminal](https://www.anchorterminal.com/badges/outline.svg)](https://www.anchorterminal.com/tools/outline)

    It counts on a page on getoutline.com or one of its subdomains, or the README of github.com/outline/outline.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "outline", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.