Photoroom API

by Photoroom HTTP API in Programmatic asset production

Hosted

Photoroom SAS · photoroom.com since 1998 · who's behind it

Photoroom's API edits product photos over HTTP. One call removes a background, adds a shadow or generated background, relights, expands, resizes or fills a template, and returns the image. A hosted MCP server wraps the same API.

Good for Product-photo work at volume, such as cutouts, white backgrounds, shadows, generated scenes and clothing shots, one image a call.

Is this your product? Claim this listing or verify it

Assessment. A call costs $0.02 for background removal or $0.10 for any combination of edits, and a sandbox key gives 1,000 free watermarked calls a month without a card. No status page or official SDK was found, and Photoroom's privacy policy and security page disagree on whether API images train its models.

Facts

Transport
HTTP, Streamable HTTP
Endpoint
https://image-api.photoroom.com/v2
Auth
OAuth or key
Pricing
Freemium · $20 / mo
x402
No
Licence
Proprietary service under the Photoroom Terms and Conditions. The sample code repository is MIT
Tools exposed
1
llms.txt
published
Last release
Access
Self-serve. Create an account, activate the API in the dashboard and copy a key. Enterprise plans by sales from 200,000 images a year
Edits
Background removal, colour, image or generated backgrounds, shadows, relighting, blur, outline, text removal, expand, uncrop, upscale (preview), positioning, cropping, prompt edits, image from a prompt, and clothing edits (ironing, flat lay, ghost mannequin, virtual model, virtual try-on)
Templates
Preview. A template made in the Photoroom editor is called with templateId, and text and image layers are replaced by their unique IDs. The template must be shared by public link
Input
One image a call. Image Editing takes PNG, JPEG or WEBP up to 30 MB and 5,000 px on the widest side, as a file or a public URL. Remove Background takes PNG, JPEG, WEBP or HEIC up to 50 MB and 6,000 px
Render formats
PNG by default, JPEG, WEBP or AVIF from the Image Editing API, returned as the response body. export.dpi from 72 to 1200
MCP server
Hosted at https://mcp.photoroom.com/mcp (Streamable HTTP, OAuth with PKCE and dynamic client registration). One tool, per Photoroom. Not in the official MCP registry
Free tier
Sandbox mode, 1,000 watermarked Image Editing calls a month and 100 a day, plus 10 free production background removals on a new account. No card
Rate limits
60 images a minute by default, higher on Enterprise plans. 429 at the limit
Data handling
Images are discarded when the response returns, operational logs after 15 days and API access logs after one year, per the security page. Hosting is in the United States
Support
Discourse community at photoroom.discourse.group. The docs say there is no email support for integration questions

Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Prices are per image and public, $0.02 for the Remove Background API and $0.10 for an Image Editing call with any number of edits combined
  • A sandbox_ key prefix gives 1,000 free watermarked Image Editing calls a month (100 a day) with no card, per the docs and pricing page
  • Calls that end in an error do not consume an image, per the pricing page of the docs
  • A public OpenAPI 3.1 file, an llms.txt index and a Markdown twin of every docs page, plus a ready-made prompt for coding agents
  • The security page says images sent to the API are discarded when the response returns and names five sub-processors and US hosting

Weaknesses

  • No status page was found on the site or in the docs, so there is no public incident history to read
  • The privacy policy says model improvement does not apply to API images. The security page says self-serve API plans train by default with an opt-out
  • No official SDK. The vendor publishes MIT sample code for web, Node.js, Python and iOS and tells callers to use a plain HTTP client
  • The changelog's last dated entry is 21 April 2026, while the docs list Virtual Try-On, which has no changelog entry
  • The terms forbid any automated system that sends more requests than a person could from a browser. This matters before any probe is run

Before you call it notes for agents

  1. Send the key in the x-api-key header. Prefix it with sandbox_ while testing, because calls with the plain key consume paid images
  2. Save the response body as a file. A 200 returns image bytes, PNG by default, and any other status returns JSON with error.message or detail
  3. Send model selectors such as pr-ai-shadows-model-version: 2026-04-15 as HTTP headers, not form fields. They are not in the OpenAPI file
  4. Stay under 60 images a minute. On 429 back off with an exponential delay, and set a client timeout of at least 60 seconds for AI edits
  5. Use POST /v2/edit with imageFile for local files and GET /v2/edit with imageUrl for hosted ones. Each call takes one image

Who's behind it provenance 78/100

  • Legal entity namedPhotoroom SAS20/20
  • Domain agephotoroom.com, registered 1998-11-21 (27 years)15/15
  • Endpoint on the vendor's domainimage-api.photoroom.com15/15
  • Terms of serviceread, states 7 of the 7 things a reader expects, and has 1 clause that costs points8/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagenot found0/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2026-07-29, states 7 of 7, 4 to know

TL;DR Dated 2026-07-29. States all 7 things a reader expects. To know before relying on it, model training with an opt-out, limits on automated access, cut-off without notice or for any reason and arbitration or a class action waiver.

Says it may use customer content to train or improve models, and gives an opt-out
By using the Services, you acknowledge and expressly authorize Photoroom to use User Content to improve, train and develop Photoroom’s products and services. You can opt-out of this at any time by changing the settings on your account in the app under Data Control.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Restricts automated accesscosts points
You agree not to engage in any of the following prohibited activities: (i) copying, distributing, or disclosing any part of the Services in any medium, including without limitation by any automated or non-automated “scraping”;

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Says access can be ended without notice or for any reason
You may terminate your Subscription immediately without cause, and we may also terminate the Subscription without cause, but we will provide Customer with twenty-four (24) hours prior notice.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
YOU AGREE THAT, BY ENTERING INTO THESE TERMS, YOU AND PHOTOROOM ARE EACH WAIVING THE RIGHT TO A TRIAL BY JURY OR TO PARTICIPATE IN A CLASS ACTION, COLLECTIVE ACTION, PRIVATE ATTORNEY GENERAL ACTION, OR OTHER REPRESENTATIVE PROCEEDING OF ANY KIND.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2026-07-29
Effective date: July 29, 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of France, with disputes in the courts of Paris, France
(i) in Europe, the Middle East, or Africa, these Terms are governed by the laws of France, with the jurisdiction of the Courts of Paris, France.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at $100
PHOTOROOM DISCLAIMS ANY IMPLIED WARRANTIES INCLUDING WITHOUT LIMITATION MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, AND PHOTOROOM’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO YOUR USE OF THE FREE ACCOUNT IS $100.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
If the Customer is unhappy with the increase, the Customer may give notice to terminate the Subscription, by giving at least twenty-four (24) hours’ written notice to us prior to the next billing date.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
otherwise, any change to such pricing shall become effective in the billing cycle following notice of such change as provided under the Terms.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
Customer may not submit any Customer Content that includes a social security number, passport number, driver’s license number, or similar identifier, credit card or debit card number, or any other information which may be subject to specific data privacy and security laws including, but not limited to, the Gramm-Leach…

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Growing BrandsStartups & SMBs getting to market fastScaling BusinessesMid-market teams needing volume & speedEnterpriseGovernance, API, compliance & SLA

Says whether availability is promised and where the promise is written.

The customer consents to use of its company name, logo and a general description of the relationship in press releases and other marketing materials.
You consent to Photoroom’s use of your company name and logo and general description of your relationship with Photoroom in press releases and other marketing materials that we may share from time to time.

Noted by a second reader on 2026-10-08.

The vendor owns usage data and anonymised or aggregated data derived from user content, and may use it in perpetuity for any purpose the law permits.
All Company Data will be owned solely and exclusively by us and, for purposes of clarity, you agree that we may use the Company Data in perpetuity for any purpose permitted by applicable law.

Noted by a second reader on 2026-10-08.

Total liability is capped at the amount the customer paid in the six months before the last event giving rise to liability.
IN NO EVENT WILL OUR AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS (WHETHER IN CONTRACT OR TORT OR UNDER ANY OTHER THEORY OF LIABILITY) EXCEED THE TOTAL AMOUNT PAID BY CUSTOMER HEREUNDER IN THE SIX (6) MONTHS PRECEDING THE LAST EVENT GIVING RISE TO LIABILITY.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 8,541 words

Privacy policy dated 2026-03-01, states 8 of 8, 1 to know

TL;DR Dated 2026-03-01. States all 8 things a reader expects. To know before relying on it, model training with an opt-out.

Says it may use customer content to train or improve models, and gives an opt-out
By using Photoroom, you acknowledge that Photoroom processes and uses the images you upload to improve, train and develop Photoroom’s products, services and models. You can opt-out of this at any time by changing the settings on your account.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Gives the date it was last updated Last updated 2026-03-01
Updated: March 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
…as well as rights to access, delete, correct, limit, and opt-out of the sales of certain Personal Data we collect about them, as well as to opt-out of the sharing of certain Personal Data for purposes of cross-context behavioral advertising (called “sharing” under California law).

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 2 years
Duration of use of the services (=Until the account is deleted by you or up to a period of 2 years from your last connection to your account), and then archived for 5 years

Says when data sent to the service is deleted.

Says who else receives the data
Your Personal data may be transmitted to third-party processors involved in the provision of the Services (technical and hosting service providers, sending of notifications or newsletters, user tracking, management of security incidents, etc.).

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
…about them, as well as to opt-out of the sharing of certain Personal Data for purposes of cross-context behavioral advertising (called “sharing” under California law).

A plain statement either way.

Says what rights people have over their data
In application of the GDPR, you have rights over your personal data.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact Names a data protection officer
Photoroom has an external Data Protection Officer (DPO), who has been declared to the CNIL, and whom you can contact by writing to: [email protected]

An address or officer to send a request to.

Says where data is transferred or stored
IS YOUR PERSONAL DATA TRANSFERRED OUTSIDE THE EUROPEAN UNION?

The countries data goes to and the safeguard used.

Images processed through the API are excluded from model improvement.
For clarity, our model improvement does not apply to the images processed through our Application Programming Interface (API).

Noted by a second reader on 2026-10-08.

Opting out of model training does not undo processing already carried out.
This opt out shall not have retroactive effect on processing activities already carried out.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-09 · 3,971 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Terms and Conditions, effective 29 July 2026, cover the platform, the application programming interface and related services of Photoroom SAS. No separate API terms were found.

The legal notice gives PHOTOROOM, SAS, RCS Paris 853 059 384, 229 rue Saint-Honoré, 75001 Paris. The site footer reads Photoroom, Inc.

The privacy policy, updated March 2026, names Photoroom as controller for photoroom.com, app.photoroom.com and the apps, and has one sentence on API images.

The API answers at image-api.photoroom.com and sdk.photoroom.com and the MCP server at mcp.photoroom.com.

https://www.photoroom.com/.well-known/security.txt returns 404.

RDAP for photoroom.com gives a registration date of 1998-11-21, which predates the company.

No status page was found. status.photoroom.com did not answer one request.

Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-10 00:51 UTC

Right nowUpHTTP 404 · 194 ms · 2 minutes ago
Uptime 24h100.0%94 probes
Uptime 30 days100.0%94 probes
p50 24h135 msget
p95 24h262 msopen endpoint

Probed every five minutes at https://image-api.photoroom.com/v2. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • GitHub stars 25

Pages we watch

PageKindLast checkedLast changed
docs.photoroom.com/getting-started/changelogchangelog6 hours ago · 200no change seen
docs.photoroom.com/getting-started/pricing.mdpricing6 hours ago · 200no change seen
www.photoroom.com/api/pricingpricing6 hours ago · 200no change seen
www.photoroom.com/legal/privacyprivacy6 hours ago · 200no change seen
www.photoroom.com/legal/terms-and-conditionsterms6 hours ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/photoroom.json

Notable

  • Two APIs on two hosts. The Image Editing API is /v2/edit on image-api.photoroom.com and the Remove Background API is /v1/segment on sdk.photoroom.com source
  • An Image Editing call costs the same whatever edits it combines, and counts as five images on a Basic plan source
  • A hosted MCP server at https://mcp.photoroom.com/mcp has one tool for the whole API, per Photoroom, and bills the same credits source
  • Models are chosen with request headers such as pr-ai-shadows-model-version: 2026-04-15, not with parameters source
  • The docs FAQ says the terms do not allow training a machine learning model with the API source
  • The security page says self-serve API plans are used for model training by default with an opt-out. The privacy policy says model improvement does not apply to API images source
  • Templating mode, a preview, needs the template shared by public link so the API can read it source
  • Every docs page ends with a block addressed to agents describing a ?ask= query on the docs host. We record it as a fact and did not use it source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 9.2
Read with the hosted lines. No status page was found on photoroom.com, the docs or the security page, and status.photoroom.com did not answer one request (0). With no history to read, the incident line takes the floor of 5. The security page states one incident on record, a 30-minute availability disruption in October 2024, which is the vendor's own account (5). Limits are published, 60 images a minute by default and 1,000 a month and 100 a day in sandbox mode (15). The docs say a 429 is returned at the limit and tell callers to back off exponentially and to retry a 500 up to three times. No Retry-After header or idempotency key is documented (11). The API page states a 99.9 per cent uptime target on Enterprise accounts, with no SLA document found, and the terms say availability is not guaranteed, so half credit (5). The Image Editing API left beta on 3 April 2024. Upscale, text-guided segmentation and templating are labelled preview (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 14.0
A public OpenAPI 3.1.0 description at image-api.photoroom.com/openapi, read as embedded on the docs reference page, with four operations (25). llms.txt, a Markdown twin of every page and a page with a prompt written for coding agents (10). 86 of the 87 parameters of GET /v2/edit carry a description, the operation description lists every edit, and the agent page says when to call each of the two APIs (17). 31 of 87 parameters have enums, but booleans are strings, no field of /v2/edit is marked required, and the embedded description declares neither the x-api-key header nor the pr-* model headers (10). Curl examples on every page and 400, 402 and 500 bodies in the description. 401, 403 and 429 are documented in prose only, and the two APIs use different error shapes (11). Paths are /v1 and /v2, models are pinned by dated headers and the changelog is dated back to June 2023, but the description's version is fixed at 1.0.0 and the last changelog entry is 21 April 2026 (13).
Agent ergonomics 13%16.2 10.4
The response body is the image itself, so an agent saves a file and reads nothing into context. outputSize, maxWidth, maxHeight, export.format and the size presets set what comes back, and the MCP server has one tool, per Photoroom (18). Nothing to paginate. Output size, format and DPI controls (15). JSON errors with a message and a documented meaning for 400, 401, 403, 402, 429 and 500, but the two APIs use different shapes and Unauthorized covers both a missing key and an empty balance (13). No idempotency key. Calls keep no state, failed calls are not billed and background.seed repeats a generated background, but a retried success is billed again. The MCP tool's annotations were not read (10). Only the image is required and defaults are sensible. No official SDK, only sample code for four platforms (8).
Security & auth 14%17.5 9.4
A team can hold several API keys and revoke each in the dashboard, with no scopes found. The key travels in the x-api-key header only. The MCP server uses an OAuth authorisation code grant with PKCE, dynamic client registration and a revocation endpoint, and creates its own key for the connection (20). No read-only key. The API stores nothing to change, a sandbox key cannot spend, and a prepaid monthly allowance bounds spend (8). Returns images, not untrusted text (10). The dashboard shows usage history, GET /v2/account returns the balance, and the security page says API access logs are kept for one year on Photoroom's side (6). The security page states a SOC 2 Type 2 attestation scoped to the API with a report of April 2026. The trust centre is drawn by script and was not read. security.txt returns 404 and no disclosure policy or bug bounty was found (10).
Payments & pricing 10%12.5 5.0
No x402, MPP or L402 in the docs, the OpenAPI description or the pricing pages (0). Per-image prices are public, $0.02 for background removal and $0.10 for an Image Editing call (20). Sandbox mode gives 1,000 free watermarked calls a month and a new account 10 free production calls on the Remove Background API, with no card, per the pricing page (20). A person has to create an account and activate the API in the dashboard. The MCP server's OAuth flow registers clients dynamically but still needs a Photoroom sign-in (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 2.0
The last dated changelog entry is 21 April 2026, 171 days before the check (10). We took the strict reading. The docs sitemap shows page edits up to 5 October 2026, and the docs list Virtual Try-On, which has no changelog entry. No dated changelog entry in the last 90 days (0). A public changelog and a Discourse community where each of the 17 topics dated 30 September to 3 October 2026 had a reply. We did not open the topics to see who replied (11). No official SDK, and no Photoroom entry in the official MCP registry (0). The sample code repository's last commit is a README change on 23 April 2026 and it has no CI (2).
Transparency & trusteditorial 57, provenance 78 7%8.8 6.0
Closed hosted service under the Photoroom Terms and Conditions effective 29 July 2026, which name the application programming interface. Sample code is MIT (15). The security page gives retention figures (images discarded after the call, operational logs 15 days, API access logs one year). The statements on training disagree. The privacy policy of March 2026 says model improvement does not apply to API images, the security page says self-serve API plans train by default with an opt-out, and the terms authorise training on user content with an opt-out. A DPA is for Enterprise customers only (14). Preview and alpha functions carry a two-week notice, the 2024 base URL change gave a dated deadline, and the AI Backgrounds v2 model is marked deprecated with no removal date (12). The security page names GCP, AWS, Cloudflare, Datadog and Vercel and says hosting is in the United States. The full list is in the trust centre, which was not read (16).
Negative events≤15None recorded0
Total56 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 21 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Photoroom API, or have the agent fetch /fixes/photoroom.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Photoroom API

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/photoroom, the October 2026 research run, assessed 9 October 2026. Grade C, 56 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Photoroom API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 46 out of 100, up to 10.8 more on the total

Why it scored 46: Read with the hosted lines. No status page was found on photoroom.com, the docs or the security page, and status.photoroom.com did not answer one request (0). With no history to read, the incident line takes the floor of 5. The security page states one incident on record, a 30-minute availability disruption in October 2024, which is the vendor's own account (5). Limits are published, 60 images a minute by default and 1,000 a month and 100 a day in sandbox mode (15). The docs say a 429 is returned at the limit and tell callers to back off exponentially and to retry a 500 up to three times. No `Retry-After` header or idempotency key is documented (11). The API page states a 99.9 per cent uptime target on Enterprise accounts, with no SLA document found, and the terms say availability is not guaranteed, so half credit (5). The Image Editing API left beta on 3 April 2024. Upscale, text-guided segmentation and templating are labelled preview (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Security & auth, 54 out of 100, up to 8.1 more on the total

Why it scored 54: A team can hold several API keys and revoke each in the dashboard, with no scopes found. The key travels in the `x-api-key` header only. The MCP server uses an OAuth authorisation code grant with PKCE, dynamic client registration and a revocation endpoint, and creates its own key for the connection (20). No read-only key. The API stores nothing to change, a sandbox key cannot spend, and a prepaid monthly allowance bounds spend (8). Returns images, not untrusted text (10). The dashboard shows usage history, `GET /v2/account` returns the balance, and the security page says API access logs are kept for one year on Photoroom's side (6). The security page states a SOC 2 Type 2 attestation scoped to the API with a report of April 2026. The trust centre is drawn by script and was not read. `security.txt` returns 404 and no disclosure policy or bug bounty was found (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Payments & pricing, 40 out of 100, up to 7.5 more on the total

Why it scored 40: No x402, MPP or L402 in the docs, the OpenAPI description or the pricing pages (0). Per-image prices are public, $0.02 for background removal and $0.10 for an Image Editing call (20). Sandbox mode gives 1,000 free watermarked calls a month and a new account 10 free production calls on the Remove Background API, with no card, per the pricing page (20). A person has to create an account and activate the API in the dashboard. The MCP server's OAuth flow registers clients dynamically but still needs a Photoroom sign-in (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 4. Maintenance & community, 23 out of 100, up to 6.7 more on the total

Why it scored 23: The last dated changelog entry is 21 April 2026, 171 days before the check (10). We took the strict reading. The docs sitemap shows page edits up to 5 October 2026, and the docs list Virtual Try-On, which has no changelog entry. No dated changelog entry in the last 90 days (0). A public changelog and a Discourse community where each of the 17 topics dated 30 September to 3 October 2026 had a reply. We did not open the topics to see who replied (11). No official SDK, and no Photoroom entry in the official MCP registry (0). The sample code repository's last commit is a README change on 23 April 2026 and it has no CI (2).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 5. Agent ergonomics, 64 out of 100, up to 5.9 more on the total

Why it scored 64: The response body is the image itself, so an agent saves a file and reads nothing into context. `outputSize`, `maxWidth`, `maxHeight`, `export.format` and the `size` presets set what comes back, and the MCP server has one tool, per Photoroom (18). Nothing to paginate. Output size, format and DPI controls (15). JSON errors with a message and a documented meaning for 400, 401, 403, 402, 429 and 500, but the two APIs use different shapes and `Unauthorized` covers both a missing key and an empty balance (13). No idempotency key. Calls keep no state, failed calls are not billed and `background.seed` repeats a generated background, but a retried success is billed again. The MCP tool's annotations were not read (10). Only the image is required and defaults are sensible. No official SDK, only sample code for four platforms (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 6. Transparency & trust, 68 out of 100, up to 2.8 more on the total

Made of editorial 57, provenance 78.

Why it scored 68: Closed hosted service under the Photoroom Terms and Conditions effective 29 July 2026, which name the application programming interface. Sample code is MIT (15). The security page gives retention figures (images discarded after the call, operational logs 15 days, API access logs one year). The statements on training disagree. The privacy policy of March 2026 says model improvement does not apply to API images, the security page says self-serve API plans train by default with an opt-out, and the terms authorise training on user content with an opt-out. A DPA is for Enterprise customers only (14). Preview and alpha functions carry a two-week notice, the 2024 base URL change gave a dated deadline, and the AI Backgrounds v2 model is marked deprecated with no removal date (12). The security page names GCP, AWS, Cloudflare, Datadog and Vercel and says hosting is in the United States. The full list is in the trust centre, which was not read (16).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 7 of the 7 things a reader expects, and has 1 clause that costs points (8 of 10)
- Status page: not found (0 of 10)
- security.txt: not found (0 of 10)

## 7. Schema & documentation, 86 out of 100, up to 2.3 more on the total

Why it scored 86: A public OpenAPI 3.1.0 description at image-api.photoroom.com/openapi, read as embedded on the docs reference page, with four operations (25). `llms.txt`, a Markdown twin of every page and a page with a prompt written for coding agents (10). 86 of the 87 parameters of `GET /v2/edit` carry a description, the operation description lists every edit, and the agent page says when to call each of the two APIs (17). 31 of 87 parameters have enums, but booleans are strings, no field of `/v2/edit` is marked required, and the embedded description declares neither the `x-api-key` header nor the `pr-*` model headers (10). Curl examples on every page and 400, 402 and 500 bodies in the description. 401, 403 and 429 are documented in prose only, and the two APIs use different error shapes (11). Paths are `/v1` and `/v2`, models are pinned by dated headers and the changelog is dated back to June 2023, but the description's version is fixed at 1.0.0 and the last changelog entry is 21 April 2026 (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- The lead was right on the interface and the docs. It did not mention the hosted MCP server at https://mcp.photoroom.com/mcp, and upscale is a preview function.
- unchecked: the trust centre at trust.photoroom.com is drawn by script, so the SOC 2 report, the full sub-processor list and the DPA were not read.
- unchecked: the MCP server's tool definition and annotations. The server answers 401 without a token. The count of one tool is Photoroom's statement.
- unchecked: the plan sizes and monthly prices on the pricing page selector, which is drawn by script. The per-image prices come from the page's FAQ and the docs.
- No status page was found. status.photoroom.com did not answer one request, so we cannot say whether one exists under another address.
- The privacy policy, the security page and the terms disagree on whether images sent to the API on a self-serve plan are used for training. No deduction was taken. It is counted under Transparency.
- The terms (section on restrictions) forbid using any automated system to send more requests than a person could produce from a web browser, and forbid scraping. Recorded as a fact with no deduction. It matters before any probe is run.
- Every docs page and `llms.txt` end with a block addressed to agents that describes a `?ask=` query on the docs host. We did not use it.
- The security page describes asynchronous API jobs. The reviewed docs describe synchronous calls only.
- The terms name Photoroom SAS (RCS Paris 853 059 384). The site footer reads Photoroom, Inc.
- No launch date for the Remove Background API was found, so `firstReleased` is empty. The changelog starts on 4 June 2023.

## Weaknesses

- No status page was found on the site or in the docs, so there is no public incident history to read
- The privacy policy says model improvement does not apply to API images. The security page says self-serve API plans train by default with an opt-out
- No official SDK. The vendor publishes MIT sample code for web, Node.js, Python and iOS and tells callers to use a plain HTTP client
- The changelog's last dated entry is 21 April 2026, while the docs list Virtual Try-On, which has no changelog entry
- The terms forbid any automated system that sends more requests than a person could from a browser. This matters before any probe is run

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send the key in the `x-api-key` header. Prefix it with `sandbox_` while testing, because calls with the plain key consume paid images
- Save the response body as a file. A 200 returns image bytes, PNG by default, and any other status returns JSON with `error.message` or `detail`
- Send model selectors such as `pr-ai-shadows-model-version: 2026-04-15` as HTTP headers, not form fields. They are not in the OpenAPI file
- Stay under 60 images a minute. On 429 back off with an exponential delay, and set a client timeout of at least 60 seconds for AI edits
- Use `POST /v2/edit` with `imageFile` for local files and `GET /v2/edit` with `imageUrl` for hosted ones. Each call takes one image

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • The lead was right on the interface and the docs. It did not mention the hosted MCP server at https://mcp.photoroom.com/mcp, and upscale is a preview function.
  • unchecked: the trust centre at trust.photoroom.com is drawn by script, so the SOC 2 report, the full sub-processor list and the DPA were not read.
  • unchecked: the MCP server's tool definition and annotations. The server answers 401 without a token. The count of one tool is Photoroom's statement.
  • unchecked: the plan sizes and monthly prices on the pricing page selector, which is drawn by script. The per-image prices come from the page's FAQ and the docs.
  • No status page was found. status.photoroom.com did not answer one request, so we cannot say whether one exists under another address.
  • The privacy policy, the security page and the terms disagree on whether images sent to the API on a self-serve plan are used for training. No deduction was taken. It is counted under Transparency.
  • The terms (section on restrictions) forbid using any automated system to send more requests than a person could produce from a web browser, and forbid scraping. Recorded as a fact with no deduction. It matters before any probe is run.
  • Every docs page and llms.txt end with a block addressed to agents that describes a ?ask= query on the docs host. We did not use it.
  • The security page describes asynchronous API jobs. The reviewed docs describe synchronous calls only.
  • The terms name Photoroom SAS (RCS Paris 853 059 384). The site footer reads Photoroom, Inc.
  • No launch date for the Remove Background API was found, so firstReleased is empty. The changelog starts on 4 June 2023.

Sources 26

  1. docs index for agents docs.photoroom.com · seen 2026-10-09
  2. introduction (APIs, keys, sample code) docs.photoroom.com · seen 2026-10-09
  3. prompt for coding agents (endpoints, errors, limits) docs.photoroom.com · seen 2026-10-09
  4. billing rules and account endpoint docs.photoroom.com · seen 2026-10-09
  5. Image Editing price per call docs.photoroom.com · seen 2026-10-09
  6. FAQ (rate limit, storage, server location, MCP) docs.photoroom.com · seen 2026-10-09
  7. troubleshooting (error bodies, support route) docs.photoroom.com · seen 2026-10-09
  8. changelog docs.photoroom.com · seen 2026-10-09
  9. API reference with the OpenAPI description embedded (we read the description, not a rendered viewer) docs.photoroom.com · seen 2026-10-09
  10. sandbox mode docs.photoroom.com · seen 2026-10-09
  11. templating mode (preview) docs.photoroom.com · seen 2026-10-09
  12. AI Backgrounds model versions and deprecation docs.photoroom.com · seen 2026-10-09
  13. docs sitemap (page modification dates) docs.photoroom.com · seen 2026-10-09
  14. API pricing page and its FAQ photoroom.com · seen 2026-10-09
  15. API product page (uptime target, SOC 2 statement) photoroom.com · seen 2026-10-09
  16. MCP connector page photoroom.com · seen 2026-10-09
  17. MCP server OAuth metadata mcp.photoroom.com · seen 2026-10-09
  18. security and data handling page photoroom.com · seen 2026-10-09
  19. Terms and Conditions, effective 29 July 2026 photoroom.com · seen 2026-10-09
  20. privacy policy, updated March 2026 photoroom.com · seen 2026-10-09
  21. legal notice (company details) photoroom.com · seen 2026-10-09
  22. security.txt (404) photoroom.com · seen 2026-10-09
  23. API community, latest topics photoroom.discourse.group · seen 2026-10-09
  24. sample code repository (clone) github.com · seen 2026-10-09
  25. official MCP registry search for photoroom (no entry) registry.modelcontextprotocol.io · seen 2026-10-09
  26. RDAP for photoroom.com rdap.org · seen 2026-10-09

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $20 / mo $0.02 an image on the Remove Background API (Basic plan) and $0.10 a call on the Image Editing API (Plus plan), bought as a monthly subscription of images that do not roll over. Sandbox mode is free for 1,000 watermarked calls a month, and a new account gets 10 free production background removals, with no card. Failed calls are not billed. Enterprise pricing from 200,000 images a year is by sales (https://www.photoroom.com/api/pricing, https://docs.photoroom.com/getting-started/pricing.md).

Prices

ItemPriceUnitNote
Remove Background API$0.02per imageBasic plan, `/v1/segment`
Image Editing API$0.10per imagePlus plan, `/v2/edit`, any number of edits in the call
Basic plan, 1,000 images$20per month (plan)example from the pricing page FAQ

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/photoroom.xml, or this listing's score history at history.json.

Connect

First request

curl --request POST \
  --url https://image-api.photoroom.com/v2/edit \
  --header 'x-api-key: YOUR_API_KEY' \
  --form imageFile=@/absolute/path/to/image.jpg \
  --form removeBackground=true \
  --form background.color=FFFFFF \
  --form padding=0.15 \
  --form shadow.mode=ai.soft \
  --output result.png

Claude Code

claude mcp add --transport http Photoroom https://mcp.photoroom.com/mcp

Through letme picks today, calling later

GET https://letme.dev/photoroom

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
fal image models fal (Features & Labels, Inc.)B65.2image.generate image.edit image.upscaleno
Bria API Bria AIB63.7image.generate image.edit image.upscaleno
Melius Melius AI, Inc.C54.1image.generate image.edit image.upscaleno
Recraft API RecraftD52.8image.generate image.edit image.upscaleno
Replicate image models Replicate (Cloudflare)D50.2image.generate image.edit image.upscaleno
Ideogram API IdeogramD50image.generate image.edit image.upscaleno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Photoroom API on Anchor Terminal, C, 56/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/photoroom"><img src="https://www.anchorterminal.com/badges/photoroom.svg" alt="Photoroom API on Anchor Terminal" height="20"></a>
    [![Photoroom API on Anchor Terminal](https://www.anchorterminal.com/badges/photoroom.svg)](https://www.anchorterminal.com/tools/photoroom)

    It counts on a page on photoroom.com or one of its subdomains, or the README of github.com/PhotoRoom/api-code-samples.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "photoroom", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.