# Outline > Outline is a team wiki and knowledge base from General Outline, available hosted or self-hosted. Agents reach it through an RPC-style HTTP API with a public OpenAPI description, or an MCP server built into each workspace. - Canonical: https://www.anchorterminal.com/tools/outline - Markdown: https://www.anchorterminal.com/tools/outline.md (~8,000 tokens) - Slim: https://www.anchorterminal.com/tools/outline.min.md (~2,080 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/outline.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 60.3/100 · rank #408 of 722 · #2 in Work & productivity · not agent-ready · confidence medium** ## Assessment API keys and OAuth tokens can be limited to single endpoints, all 154 operations document a 429 response with Retry-After, and the workspace MCP server registers tools by granted scope. Two scope-bypass flaws were published and fixed in May and June 2026, rate limits carry no published numbers, and there are no official client libraries. ## Facts | Field | Value | | --- | --- | | Vendor | General Outline, Inc. (https://www.getoutline.com) | | Kind | HTTP API | | Category | Work & productivity (https://www.anchorterminal.com/categories/productivity) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://app.getoutline.com/api` | | Auth | OAuth or key · Self-serve. A workspace member creates an API key under Settings, API & Apps, and sends it as a Bearer token. Keys start with `ol_api_`, are shown once, can carry an expiry and scopes, and can be revoked by their creator or an admin. An unscoped key has all of its owner's access. OAuth 2.0 uses the authorisation code grant with PKCE (S256), refresh tokens, a revocation endpoint and dynamic client registration at `/oauth/register`, with no app review. Scopes are `read` and `write`, namespaced forms such as `documents:read`, and single methods or wildcards such as `documents.info` and `documents.*`. The MCP server takes OAuth by default or an API key. The user guide also allows the key in the request payload as `token`. | | Pricing | Paid ($10 / mo) · Outline Cloud is priced by team size a month, $10 for 1 to 10 members, $79 for 11 to 100 and $249 for 101 to 200, with larger teams by quote and annual billing available (https://www.getoutline.com/pricing). The API, webhooks and audit log are on every tier, and API calls are not charged. A new workspace gets 30 days free and turns read-only until a payment method is added, so an agent's owner can start without a contract. The self-hosted price table is drawn in the browser and was not read. | | x402 | No · No x402, MPP or L402 in the API documentation, the OpenAPI description or the pricing page (checked 2026-10-08). | | Licence | Source available under BSL 1.1, which bars running it as a document service for third parties and converts each release to Apache 2.0 on its change date (2030-09-09 for 1.10.1). The OpenAPI description is BSD-3-Clause. The hosted service is under the vendor's terms | | Tools exposed | 19 | | Source | https://github.com/outline/outline | | Docs | https://www.getoutline.com/developers | | llms.txt | https://www.getoutline.com/llms.txt | | Last release | 2026-09-09 | | GitHub stars | 40,842 (as of 2026-10-08) | | Surface graded | The hosted Outline Cloud API at https://app.getoutline.com/api, with the built-in MCP server described alongside it. The same API and MCP server ship in the self-hosted editions | | API | OpenAPI 3.0, 154 operations in 26 groups, all POST with JSON bodies. Documents (30 operations), collections (19), users (12), comments (9), groups (9), templates (7), plus shares, revisions, attachments, events and webhook subscriptions | | Documents | Bodies are Markdown up to 1,536,000 characters. `documents.update` takes `editMode` with `findText` for patch edits and `lastRevision` for a 409 on a stale write. `documents.delete` moves to the trash for 30 days unless `permanent` is set | | Search | `documents.search` returns a context snippet and ranking per hit with structured `filters`, `documents.search_titles` matches titles only, and `documents.answerQuestion` answers from documents where the workspace has AI answers on | | MCP server | https://.getoutline.com/mcp, Streamable HTTP only, 19 tools (documents, collections, comments, templates, attachments, users and a `fetch` tool), OAuth or API key, off or on per workspace. The source limits it to 1,000 requests an hour | | Credentials | API keys with optional expiry and scopes, or OAuth 2.0 with PKCE, refresh tokens, revocation and dynamic client registration. Scopes are `read`, `write`, namespaced such as `documents:read`, or single methods and wildcards | | Rate limits | No numbers in the API documentation. A 429 carries `Retry-After`, `RateLimit-Limit`, `RateLimit-Remaining` and `RateLimit-Reset`. The source defaults to 1,000 requests a minute overall, with document methods at 25 or 100 a minute and some at 10 or 100 an hour | | Errors | JSON with `ok`, `error`, `message` and `status`, for example `validation_error` at 400 and `rate_limit_exceeded` at 429. 401 and 429 are documented on every operation, 403 on 151 | | Paging | `limit` and `offset` with `sort` and `direction` on list methods, and a `nextPath` in each response. No field selection | | Webhooks | Workspace webhooks post JSON for document, collection, comment, user, group and share events, signed where a secret is set, and are managed through four `webhookSubscriptions` methods. Repeatedly failing webhooks are disabled | | Client libraries | None official. The vendor publishes the OpenAPI description in outline/openapi for generating clients | | Audit | Audit log with actor, IP address and authentication type, kept for one year, in Settings and through `events.list` with `auditLog` | | Status | status.getoutline.com on Oh Dear with three monitors (Application, Website, Collaboration). The history page showed no incidents on 8 October 2026 and gives no uptime figures | | Data | Servers in the US on AWS, AES-256 at rest, daily backups kept at least three months, per the vendor's security page. The DPA lists 13 sub-processors with countries, OpenAI among them for generative AI | | Releases | v1.10.1 on 9 September 2026 and five tagged releases since 11 July 2026. The hosted changelog has 172 dated entries, the newest on 9 September 2026 | | Capabilities | work.docs, knowledge.search | | Tags | official, hosted, self-hosted, source-available, paid, free-trial, api-key, oauth, mcp, openapi, llms-txt, webhooks, status-page | | JSON | https://www.anchorterminal.com/api/v1/tools/outline.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 67 | 13.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 76 | 12.3 | | Agent ergonomics | 13% | 16.2 | 62 | 10.1 | | Security & auth | 14% | 17.5 | 71 | 12.4 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 83 | 7.3 | | Transparency & trust (editorial 58, provenance 79) | 7% | 8.8 | 69 | 6.0 | | Negative events | up to −15 | up to −15 | 2026-05-07 and 2026-06-15. CVE-2026-43886 (GHSA-7732-6qrg-wjf4, high) let an OAuth client request `read *` and receive wildcard access, fixed in 1.7.0. CVE-2026-54573 (GHSA-5x79-rj4g-qrh8, high) let a scoped API key or token reach other methods by adding a URL fragment, fixed in 1.8.0. Both defeat the scopes an agent's owner relies on. Fixed and published, so 2 points (https://github.com/outline/outline/security/advisories/GHSA-7732-6qrg-wjf4, https://github.com/outline/outline/security/advisories/GHSA-5x79-rj4g-qrh8). 2026-06-06 and 2026-07-27. Two MCP advisories, `list_documents` returning metadata of private documents on an exact slug match (GHSA-pp65-6cc2-4mx9, medium) and viewers publishing into restricted collections through MCP (GHSA-c43v-wwv4-9mcc, medium), both fixed in 1.8.0. Fixed and published, 1 point (https://github.com/outline/outline/security/advisories/GHSA-pp65-6cc2-4mx9, https://github.com/outline/outline/security/advisories/GHSA-c43v-wwv4-9mcc). 2025-11-16 to 2026-07-30. Eighteen further advisories in twelve months, among them a critical rate-limit bypass allowing brute force of the email login code (CVE-2026-33640, fixed in 1.6.0) and cross-workspace access to private documents through share creation (CVE-2026-41649, fixed in 1.7.0). All fixed and published by the vendor, so 2 points (https://github.com/outline/outline/security/advisories). | -5 | | **Total** | | | | **60.3 → C** | ### Why each score - Reliability 67: Graded on the hosted Outline Cloud API with the hosted lines. Status page at status.getoutline.com on Oh Dear with three monitors, Application, Website and Collaboration (20). The history page read No incident history available on 8 October 2026, the seven-day view was clean and the RSS feed was empty, with no uptime figures, so we could not tell a clean record from an unused page and gave 20 of 30. The API documentation says write methods are limited more tightly than reads and gives no numbers. The numbers are in the public source (1,000 requests a minute by default, 25 or 100 a minute on document methods, 1,000 an hour on MCP), which is not a statement about the hosted service (5). Every operation documents 429 with `Retry-After` and three `RateLimit-*` headers, and `documents.update` takes `lastRevision` for a 409 on a stale write. No idempotency keys (12). No SLA found (0). The API and MCP server are generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 76: Public OpenAPI 3.0 description at www.getoutline.com/openapi.json and in outline/openapi, 154 operations, and MCP tools typed with zod schemas (25). llms.txt on the vendor site, and changelog and integration pages served as Markdown with a `.md` suffix (10). All 154 operations have a summary and a description. Most are one or two sentences and few say when not to use a method (13). 51 schemas, 60 enums, `maxLength` and `format` constraints and 123 required lists. Scopes on `apiKeys.create` are free strings and request bodies do not close off extra properties (12). 153 example values, a curl and a JavaScript sample in the introduction only, and shared 400, 401, 403, 404 and 429 responses (10). The description is versioned 0.1.0 with no version in the path and no API changelog. The outline/openapi commit log and 19 fields marked deprecated are the record (6). - Agent ergonomics 62: `documents.search` returns a context snippet and ranking with each hit, and list methods take `limit`. No field selection, and hits embed the document object. The MCP server has 19 tools, registered according to the token's scopes (13). `limit` and `offset` paging with `nextPath`, `sort` and `direction`, and structured `filters` on document lists and search (17). Errors return `ok`, `error`, `message` and `status` with codes such as `validation_error` and `rate_limit_exceeded` (14). No idempotency keys. `documents.create` accepts a client-chosen `id`, `documents.update` rejects stale writes with 409 through `lastRevision`, and all 19 MCP tools carry `readOnlyHint` and `idempotentHint`. None carries `destructiveHint` (11). Few required parameters and sensible defaults. No official client libraries (7). - Security & auth 71: OAuth 2.0 with PKCE (S256), refresh tokens, revocation and dynamic client registration, and API keys that are shown once, revocable, optionally expiring and scoped down to single methods (30). The user guide allows the key in the request payload as `token`. The source also reads `token` from the query string, which the documentation does not mention, so no deduction. A `read` scope, per-method scopes, MCP tools filtered by scope, a workspace switch for MCP, and deletes that go to the trash for 30 days unless `permanent` is set. No confirmation step for writes or deletes (15). Documents and comments are text written by other users. No prompt-injection guidance was found. WebMCP leaves destructive actions out (3). Audit log with actor, IP address and authentication type, kept one year, on every cloud tier and through `events.list` (14). A disclosure policy through GitHub advisories with 26 advisories published and patched in public, and CodeQL in CI. No security.txt, bug bounty, SOC 2 or ISO 27001 found (9). The 2026 scope-bypass advisories are counted under incidents. - Payments & pricing 30: No x402, MPP or L402 (0). Prices are public as plans by team size, $10, $79 and $249 a month, with nothing per call (10). A new workspace is free for 30 days and becomes read-only until a payment method is added, so no card is needed to start (20). A person creates the workspace and the first key or OAuth approval in a browser. `apiKeys.create` and `/oauth/register` exist but need a signed-in user first (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 83: v1.10.1 was released on 9 September 2026, 29 days before the check, and the main branch had 200 commits since 5 September (30). Five tagged releases since 11 July 2026, and seven dated changelog entries in the same period (20). The 30 newest open issues and pull requests on 8 October 2026 show the maintainer opening and answering items daily, with 83 open in total on a repository of 40,842 stars (22). No vendor entry in the official MCP registry, where a search returned community servers only, and no official client libraries. The OpenAPI description was updated on 7 October 2026 (3). CI, CodeQL and Dependabot are configured in the repository (8). - Transparency & trust 69: The source is public under BSL 1.1, which is not an OSI licence and bars running a competing document service, with each release converting to Apache 2.0 after its change date. The OpenAPI description is BSD-3-Clause. Between closed and open source (22). A privacy policy, a DPA and a security page exist. The policy is undated and states no retention periods, the DPA points to a Data Security and Retention clause that the policy does not contain, and the terms of service cover the website only. Backups are kept at least three months and audit logs one year (14). Deprecated parameters are marked in the OpenAPI description, 19 of them, with no dates and no deprecation policy (5). The DPA lists 13 sub-processors with purpose and country, and the security page places servers in the US on AWS. No change log for the list (17). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/outline.md (JSON https://www.anchorterminal.com/fixes/outline.json) ### What we couldn't check - unchecked: the On-Premises price table on the pricing page is drawn in the browser, so self-hosted editions and prices were not read - unchecked: the rate limits applied on the hosted service. The numbers quoted come from the public source and its defaults - unchecked: the MCP tool list as served by a live workspace, which needs a signed-in session. The 19 tools were counted on the main branch - The status history page shows no incidents at all and no uptime figures. Whether that is a clean record or an unused page could not be established - The only terms document found reads as website terms, yet the DPA treats the Terms of Service as the customer agreement. `provenance.terms` points at it for want of another - The lead called Outline open source. The repository is under BSL 1.1, which its own text says is not an open source licence - Whether the hosted service runs the tagged release or the main branch was not established. The pricing page calls it always up to date - No bug bounty, SOC 2 or ISO 27001 statement was found on the pages read. One may exist under a confidentiality agreement ### Sources - API reference: (seen 2026-10-08) - OpenAPI description, 154 operations: (seen 2026-10-08) - OpenAPI repository and commit log: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - user guide, API keys and scopes: (seen 2026-10-08) - user guide, MCP setup: (seen 2026-10-08) - user guide, audit log: (seen 2026-10-08) - user guide, security: (seen 2026-10-08) - MCP tool definitions in the source: (seen 2026-10-08) - rate limiter strategies in the source: (seen 2026-10-08) - OAuth authorisation server metadata: (seen 2026-10-08) - MCP protected resource metadata: (seen 2026-10-08) - changelog, MCP launch: (seen 2026-10-08) - changelog, MCP improvements: (seen 2026-10-08) - changelog, WebMCP support: (seen 2026-10-08) - changelog feed: (seen 2026-10-08) - pricing: (seen 2026-10-08) - status page: (seen 2026-10-08) - status history: (seen 2026-10-08) - terms of service: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - data processing agreement and sub-processors: (seen 2026-10-08) - webhooks: (seen 2026-10-08) - licence: (seen 2026-10-08) - security policy: (seen 2026-10-08) - security advisories: (seen 2026-10-08) - releases: (seen 2026-10-08) - repository metadata and open issues: (seen 2026-10-08) - security.txt, 404: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - RDAP for getoutline.com: (seen 2026-10-08) ## Who's behind it (provenance 79/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | General Outline, Inc. | 20/20 | | Domain age | getoutline.com, registered 2017-11-08 (8 years) | 11/15 | | Endpoint on the vendor's domain | app.getoutline.com | 15/15 | | Terms of service | read, states 4 of the 7 things a reader expects | 7.4/10 | | Privacy policy | read, states 2 of the 8 things a reader expects | 5.5/10 | | Status page | status.getoutline.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The data processing agreement at docs.getoutline.com/s/dpa names General Outline, Inc., a Delaware corporation at 228 Park Ave S, PMB 377005, New York, and says it supplements the Terms of Service, which it calls the Agreement. The page at www.getoutline.com/terms is titled Terms of Service and is the only terms document found. Its clauses cover the website's materials and say nothing on the hosted service, payment or customer content. The privacy policy is undated, names General Outline, Inc. as operator of getoutline.com, and covers registered and signed-in users as well as visitors. The hosted API answers at https://app.getoutline.com/api and each workspace at .getoutline.com, both on the vendor's domain. www.getoutline.com/.well-known/security.txt and app.getoutline.com/.well-known/security.txt both return 404. Reports go through GitHub security advisories per docs/SECURITY.md in the repository. RDAP for getoutline.com gives a registration date of 2017-11-08. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.getoutline.com/terms), read 2026-10-08, gives no date, states 4 of the 7 things a reader expects. - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of San Francisco County. - Not found in the text. Says how the agreement or account can be ended. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). The terms cover materials on the Outline website and grant licences over them for personal, non-commercial viewing only. "Permission is granted to temporarily download one copy of the materials (information or software) on Outline’s website for personal, non-commercial transitory viewing only." **Privacy policy** (https://www.getoutline.com/privacy), read 2026-10-08, gives no date, states 2 of the 8 things a reader expects. - Not found in the text. Gives the date it was last updated. - Not found in the text. Says how long data is kept. - Not found in the text. Says whether personal data is sold or shared for advertising. - Not found in the text. Says what rights people have over their data. - Not found in the text. Gives a privacy contact. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Outline reserves the right to publish a request sent to it, such as a support email. "If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users." ## Live (updated 2026-10-09 02:43 UTC) - Right now: up, HTTP 404, 258 ms, checked 2026-10-09 02:43 UTC (get on `https://app.getoutline.com/api`) - Uptime 24h 100.0% (79 probes) · 30 days 100.0% (79 probes) · p50 259 ms · p95 296 ms - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/outline.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Cloud, 1 to 10 members | $10 | per month (plan) | billed monthly, annual billing available | | Cloud, 11 to 100 members | $79 | per month (plan) | billed monthly, annual billing available | | Cloud, 101 to 200 members | $249 | per month (plan) | billed monthly, annual billing available | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Public OpenAPI 3.0 description with 154 operations, each with a summary and description, plus llms.txt on the vendor site - API keys take an expiry and scopes down to one endpoint such as `documents.info`, and OAuth supports PKCE and dynamic client registration - Every operation documents 429 with `Retry-After` and three `RateLimit-*` response headers - Each workspace has an MCP server with 19 tools, registered according to the token's scopes, with read-only and idempotent hints on all of them - Audit log kept for one year on every cloud tier and readable through `events.list` with `auditLog` set ## Weaknesses - No rate limit numbers in the API documentation. The limits we found are in the source code, not stated for the hosted service - Two flaws that let a restricted key or token exceed its scopes were published in May and June 2026, both fixed (GHSA-7732-6qrg-wjf4, GHSA-5x79-rj4g-qrh8) - No official client libraries. The vendor points to the OpenAPI description for generating clients - No idempotency keys, and no MCP tool carries a destructive hint or a confirmation step - The published terms of service read as website terms, and the privacy policy states no retention periods - No security.txt, bug bounty or SOC 2 or ISO 27001 report was found on the vendor's pages ## Before you call it (notes for agents) 1. Send every call as POST with a JSON body to `https://app.getoutline.com/api/`, for example `documents.search`, with a Bearer key in the header 2. Ask for a key scoped to the methods the task needs, such as `documents.info documents.search`. An unscoped key has all of its owner's access 3. Pass `lastRevision` on `documents.update` so a stale write is rejected with 409, and use `editMode` `patch` with `findText` to change one passage 4. Wait for the seconds in `Retry-After` on a 429. Write methods have tighter limits than reads 5. Leave `permanent` unset on `documents.delete`. The default moves the document to the trash, where it can be restored for 30 days ## Connect First request: ```bash curl https://app.getoutline.com/api/documents.info -X POST -H 'authorization: Bearer MY_API_KEY' -H 'content-type: application/json' -H 'accept: application/json' -d '{"id": "outline-api-NTpezNwhUP"}' ``` Claude Code: ```bash claude mcp add --transport http outline https://.getoutline.com/mcp ``` MCP client configuration: ```json { "mcpServers": { "outline": { "url": "https://\u003cyoursubdomain\u003e.getoutline.com/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/outline. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Atlan | B | 62.5 | 332 | knowledge.search, work.docs | no | https://www.anchorterminal.com/tools/atlan.md | | Guru | E | 45.1 | 663 | knowledge.search, work.docs | no | https://www.anchorterminal.com/tools/guru.md | | Google Drive API + MCP | A | 79.6 | 11 | work.docs | no | https://www.anchorterminal.com/tools/google-drive-api.md | | monday.com | BB | 76.4 | 32 | work.docs | no | https://www.anchorterminal.com/tools/monday.md | | Glean | B | 69.8 | 145 | knowledge.search | no | https://www.anchorterminal.com/tools/glean.md | | Box API + MCP | B | 69.4 | 158 | work.docs | no | https://www.anchorterminal.com/tools/box-api.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The API is RPC style. Every one of 154 operations is a POST to `https://app.getoutline.com/api/`, and the vendor says its own application runs on the same API (source: ) - Each workspace has had a built-in MCP server since 18 February 2026, at https://.getoutline.com/mcp over Streamable HTTP, switched on or off by an admin under Settings, Workspace, AI (source: ) - The MCP source registers 19 tools and filters them by the token's scopes. All carry `readOnlyHint` and `idempotentHint`, and none carries `destructiveHint` (source: ) - The repository is under BSL 1.1, which its own text says is not an open source licence, while the vendor's security page calls the product open-source at its core (source: ) - Twenty-two advisories were published on the repository between 16 November 2025 and 30 July 2026, one critical and eight high, all with a patched version named (source: ) - CVE-2026-43886 let an OAuth client add the wildcard scope to a read-only request, fixed in 1.7.0, and CVE-2026-54573 let a scoped key reach other methods through a URL fragment, fixed in 1.8.0 (source: ) - WebMCP support, added on 9 September 2026, registers command bar actions as in-page tools for browser agents and leaves out deletes (source: ) ## Compare - [Atlassian Rovo MCP Server vs Outline](https://www.anchorterminal.com/compare/atlassian-rovo-mcp-vs-outline.md): C 57.9 vs C 60.3 - [Notion MCP vs Outline](https://www.anchorterminal.com/compare/notion-mcp-vs-outline.md): C 58.9 vs C 60.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on getoutline.com or one of its subdomains, or the README of github.com/outline/outline. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "outline", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Outline on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Outline on Anchor Terminal](https://www.anchorterminal.com/badges/outline.svg)](https://www.anchorterminal.com/tools/outline) ``` Plain link: ```html Outline on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Outline is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/outline-dark.png - Light: https://www.anchorterminal.com/assets/share/outline-light.png