Sendblue
by Round One, Inc. HTTP API in Messaging APIs
Hosted Local
Round One, Inc. · sendblue.com since 2011 · status page · who's behind it
Sendblue is a hosted API from Round One, Inc. for sending and receiving iMessage, RCS, SMS and MMS from dedicated or shared phone numbers. Agents use a REST API, TypeScript and Python SDKs, a CLI and an MCP server.
Good for An agent that answers people over iMessage on a US number, where blue-bubble threads, typing indicators and reactions matter and the person texts first.
Is this your product? Claim this listing or verify it
Assessment. Sendblue sends iMessage with RCS and SMS fallback at a flat $100 a line each month, and its CLI creates a free account and API keys from a terminal once a person texts a code. Proactive outbound messaging is sold through sales, no OpenAPI file is published, and the MCP package the docs install dates from August 2025.
Facts
- Transport
- HTTP, stdio
- Endpoint
https://api.sendblue.com- Auth
- API key
- Pricing
- Freemium · $100 / mo
- x402
- No
- Licence
- Proprietary service under Round One, Inc.'s terms of service. The TypeScript and Python SDKs and the MCP server are Apache-2.0, and the CLI is MIT
- Tools exposed
- 18
- Packages
npmsendbluepypisendbluenpmsendblue-api-mcpnpm@sendblue/cli- llms.txt
- published
- Last release
- npm / week
- 250k
- PyPI / week
- 40k
- Channels
- iMessage, RCS, SMS and MMS, with group messages, tapback reactions, typing indicators, read receipts, carousels, App Cards and voice notes on iMessage. FaceTime audio and Twilio voice are separate add-ons. No WhatsApp
- Fallback
- Ordinary messages fall back from iMessage to RCS and then SMS at no extra charge. App Cards and inline replies never fall back
- Sender registration
- Sendblue says no A2P registration is needed. Each line is a phone number Sendblue assigns, shared on the free plan and dedicated on paid plans
- Plans
- Free Sandbox $0 (shared number, up to 10 verified contacts). AI Agent $100 a month per line (inbound-first). Enterprise or Blue Ocean for outbound, price on request
- Rate limits
- 10 messages a second per line, HTTP 429 above that. Blue Ocean 50 new contacts a day and 15 an hour per line. AI Agent 1,000 inbound contacts a day and 200 follow-ups a day per line. Contacts API 100 requests per 10 seconds. Lookups 30 an hour and 100 a day per line
- Before the first reply
- At most six messages of up to 300 characters with no media, links, phone numbers or email addresses, until the contact replies. One
pre_reply_overrideper contact per line per day - Inbound
- Seven webhook types (receive, outbound, typing_indicator, call_log, line_blocked, line_assigned, contact_created), managed at
/api/account/webhooks, three retries on 5xx, a shared secret sent in thesb-signing-secretheader - Credentials
sb-api-key-idandsb-api-secret-keyheaders for the account. Temporary bearer tokens from/v3/auth/tokens, account-wide or limited to named phone numbers, 900 seconds by default, revocable- MCP server
sendblue-api-mcpon npm (stdio, 2.0.1, 5 August 2025), 18 tools,--operation=readand--resourcefilters and a--tools=dynamicmode with three meta-tools. Not in the official MCP registry- SDKs and CLI
sendblueon npm 3.19.1 and on PyPI 1.31.1, both 7 October 2026, Apache-2.0, generated by Stainless.@sendblue/cli0.10.0 (17 August 2026, MIT). Community Go, Rust and Ruby clients- Verify
- An inverted one-time code under
/api/v2/verify. The user texts a code to a Sendblue number and the verification turnsapproved - Sandboxes
- Cloud Linux machines under
/v3/sandboxes, a separate product on the same keys, with $100 of compute for new free accounts per the docs - Status
- status.sendblue.com on UptimeRobot, five monitors (API health, API ingestion health, API root, Dashboard, Datacenter) with 90 days of daily ratios and no written incidents
- Certifications
- Sendblue says it is SOC 2 Type 2 audited, with the report and penetration test reports on request, and HIPAA on a dedicated instance
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- One request to
/api/send-messagesends iMessage and can fall back to RCS or SMS, with no per-message fee on any plan - The CLI creates a free account, a shared line and API keys from a terminal, with no card, once a person texts a one-time code
- Temporary bearer tokens from
/v3/auth/tokenscan be limited to named phone numbers, expire after 900 seconds by default and can be revoked - Every docs page has a Markdown twin at
/index.md, andllms.txtsummarises each page with its limits and conditions - Rate limits are published with numbers for each plan, and declined sends return an
error_keyan agent can branch on
Weaknesses
- Proactive outbound messaging needs the Blue Ocean plan, which has no public price. The $100 AI Agent plan is inbound-first
- No OpenAPI file was found at any public address, although the SDKs and the reference are generated from one
- The docs install
sendblue-api-mcp, last published on 5 August 2025 with 18 tools. The API now has 54 configured endpoints /api/send-messagetakes no idempotency key, and the SDKs retry 429 and 5xx responses twice by default- No public DPA, sub-processor list, retention period, deprecation policy or security.txt was found
Before you call it notes for agents
- Send
from_numberon every request. Read the account's numbers fromGET /api/linesfirst, because a send without it fails - On the free plan a recipient must text the Sendblue number once before any message to them is accepted
- Before a contact's first reply keep messages under 300 characters with no links, media, phone numbers or email addresses, and stop at six
- Branch on
error_keyin an HTTP 400 decline and don't retry it. Only HTTP 429 clears by waiting - Set
maxRetries: 0on sends where a duplicate matters, and treat504 outcome_unknownon group changes as possibly applied - Mint a token at
/v3/auth/tokenslimited to one phone number for a sub-agent, and keep the account key pair out of its context
Who's behind it provenance 86/100
- Legal entity namedRound One, Inc.20/20
- Domain agesendblue.com, registered 2011-06-25 (15 years)15/15
- Endpoint on the vendor's domainapi.sendblue.com15/15
- Terms of serviceread, states 5 of the 7 things a reader expects8.3/10
- Privacy policyread, states 5 of the 8 things a reader expects7.8/10
- Status pagestatus.sendblue.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2025-03-19, states 5 of 7, 2 to know
TL;DR Dated 2025-03-19. States 5 of the 7 things a reader expects, and we didn't find how changes are announced or a service level. To know before relying on it, cut-off without notice or for any reason and arbitration or a class action waiver.
Says access can be ended without notice or for any reason
If a User is found to have violated any of these restrictions, or there is reasonable suspicion of such violation, Sendblue reserves the right to terminate the Services immediately without prior notice.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
THIS AGREEMENT IS LEGALLY BINDING UPON YOUR ACCEPTANCE.THIS AGREEMENT INCLUDES A MANDATORY ARBITRATION PROVISION THAT REQUIRES THE USE OF ARBITRATION ON AN INDIVIDUAL BASIS TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS ACTIONS, AND ALSO LIMITS THE REMEDIES AVAILABLE TO YOU IN THE EVENT OF A DISPUTE.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2025-03-19
Effective Date: Mar 19th, 2025
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of New York
This Agreement shall be governed by and construed in accordance with the laws of New York, without regard to its conflict of law principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 6 months before the claim
SENDBLUE'S TOTAL LIABILITY FOR ALL CLAIMS UNDER THESE TERMS, INCLUDING FOR ANY IMPLIED WARRANTIES, IS LIMITED TO THE AMOUNT YOU PAID US TO USE THE SERVICES DURING THE SIX (6) MONTHS BEFORE THE CLAIM.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
If a User is found to have violated any of these restrictions, or there is reasonable suspicion of such violation, Sendblue reserves the right to terminate the Services immediately without prior notice.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced
Not found in the text.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
IF YOU DO NOT AGREE TO THIS AGREEMENT, YOU MUST NOT ACCESS OR USE ANY Sendblue SERVICES.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Customers grant Sendblue and its partners a global licence to use, modify, publish and distribute their content for operating, promoting and enhancing the services and developing new ones.
By submitting, uploading, or sharing content via our services, you grant Sendblue and its partners a global license to host, use, reproduce, modify, create derivative works, communicate, publish, publicly display, and distribute your content.
Noted by a second reader on 2026-10-08.
Sendblue may use Customer Data and interactions with its services to develop and improve its systems and offerings.
Sendblue may use Customer Data and interactions with its services to develop and improve its systems and offerings.
Noted by a second reader on 2026-10-08.
A phone number is returned to the upstream carrier once the subscription is no longer active and can then no longer be ported out.
Once a subscription is no longer active, the number will be returned to the upstream carrier and can no longer be ported out.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 4,281 words
Privacy policy dated 2024-05-01, states 5 of 8
TL;DR Dated 2024-05-01. States 5 of the 8 things a reader expects, and we didn't find how long data is kept, whether data is sold or where data goes. The rules found no clause to flag.
Gives the date it was last updated Last updated 2024-05-01
Effective Date: May 1, 2024
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This document explains how we collect, use, protect, and disclose your personal information as you engage with our lead engagement platform and related services ("Services").
The basic statement a privacy policy exists to make.
Says how long data is kept
Not found in the text.
Says when data sent to the service is deleted.
Says who else receives the data
As a service provider, Sendblue acts as a processor of personal data on behalf of our Business Customers.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
Right to Rectification: You have the right to have inaccurate personal data corrected.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact Gives an email address, hidden from our reader by the page
To make a CCPA request, contact us via email at [email protected], or send postal mail to our designated address.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
The privacy policy says users agree Sendblue is not liable for claims or losses arising from their improper use of collected data or failure to comply with data privacy laws.
By using Sendblue’s services, Users agree that Sendblue is not liable for any actions, claims, losses, or damages arising from or related to the Users' improper use of collected data or failure to comply with applicable data privacy laws.
Noted by a second reader on 2026-10-08.
A business user must immediately notify affected individuals, Sendblue and the relevant authorities of a data breach affecting information collected through the services.
In the event of a data breach affecting information collected through Sendblue’s services, you are responsible for immediately notifying the affected individuals, Sendblue, and relevant authorities in accordance with applicable laws.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 3,552 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (effective 19 March 2025) and the privacy policy (effective 1 May 2024) both name Round One, Inc. as Sendblue. The site footer gives 344 West End Avenue, New York NY 10024.
The terms cover registering for and using the services, so they govern API use. The privacy policy covers the website and the services and says Sendblue is a processor for its business customers.
The API answers at api.sendblue.com, and the SDKs default to api.sendblue.co, a second domain the vendor uses.
/.well-known/security.txt returns 404 on www.sendblue.com, docs.sendblue.com and api.sendblue.com.
There is no API changelog in the docs. The changelog link is the TypeScript SDK's, whose recent entries mostly read as regenerated clients.
RDAP for sendblue.com gives a registration date of 2011-06-25.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 21:12 UTC
Probed every five minutes at https://api.sendblue.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page unknown, no machine-readable status found · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/sendblue.json
Notable
- Three plans on the pricing page. Free Sandbox at $0 on a shared number with up to 10 verified contacts, AI Agent at $100 a month per dedicated line, and Enterprise at a custom price for outbound messaging source
- The CLI flow
npx -y @sendblue/cli@latest sandbox initcreates the account and API keys after a person texts a one-time phrase to a Sendblue number, with no card and no browser source - Both
llms.txtfiles are written as instructions to an AI model. The one on www.sendblue.com opens by telling the model that the user clicked a copy button and wants help setting up. We record this as a fact and took no deduction source - The MCP package the docs install,
sendblue-api-mcp, is at 2.0.1 from 5 August 2025 and depends on SDK^2.0.1. The repository's current MCP source is namedsendblue-mcpat 3.19.1, and npm has that name at 2.1.0 from 9 December 2025 source - Limits are per line. Blue Ocean allows 50 new contacts a day, 15 an hour and 10 messages a second. AI Agent allows 1,000 inbound contacts a day and 200 follow-ups a day after the 24-hour window source
- The SDKs default to
https://api.sendblue.coand the reference examples use that host, while the docs namehttps://api.sendblue.comas the canonical base URL source - The status page is an UptimeRobot page with five monitors and no written incidents. The API ingestion monitor shows 95.349 per cent for 16 July 2026 source
- The terms add a 3 per cent fee for card payments, a $60 fee per line to port a number out, and say fees are non-refundable source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 14.2 | |
Read with the hosted lines. status.sendblue.com is an UptimeRobot page with five monitors and 90 days of daily ratios (20). No incident is written up there. The API ingestion health monitor shows 95.349 per cent for 16 July 2026 (about 67 minutes, and we can't tell whether it was one outage), 98.770 per cent for 24 July, and API root 98.192 per cent for 7 October, so between minor incidents and one major (15 of 30). Rate limits are published with numbers per plan and per line (15). The docs say to slow down or spread traffic on a 429 and to verify state after 504 outcome_unknown, with no Retry-After header documented and an idempotency key only on App Card updates (8 of 15). The API page shows a 99.9% Uptime SLA figure and the docs list custom SLAs for enterprise, but no SLA document was found and the terms disclaim availability (3 of 10). The REST API is generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.7 | |
We graded the REST API. The SDKs and the reference are generated from an OpenAPI spec by Stainless, but no spec file answered at the four addresses we tried and the SDK repository records only an endpoint count of 54. The published MCP package has JSON Schema inputs on its 18 tools (12 of 25). llms.txt and a Markdown twin of every docs page at /index.md (10). The reference and llms.txt state conditions, such as which calls need a V2 line and which never fall back to SMS (15 of 20). Typed parameters with enums for send_style, statuses and reactions (12 of 15). Curl examples and an error code table, which itself says some codes are not yet documented (11 of 15). Paths mix /api, /api/v2, /v3 and /accounts, there is no API changelog in the docs, and the SDK changelog mostly records regenerated clients (6 of 15). | |||
| Agent ergonomics | 13%16.2 | 12.3 | |
Message lists take limit from 1 to 100, and the MCP server adds a jq_filter on every tool, a read-only filter and a three-tool dynamic mode (20 of 25). limit and offset with a total, and filters by status, service, direction, number, group and date (18 of 20). Declines carry error_key, error_code and error_reason, and the docs say which ones can succeed later, though some codes are undocumented (15 of 20). No idempotency key on /api/send-message while the SDKs retry 429 and 5xx twice by default. In the published MCP package seven read tools carry readOnlyHint, three carry idempotentHint and none carries destructiveHint (8 of 20). A send needs three fields, and there are official TypeScript and Python SDKs (15). | |||
| Security & auth | 14%17.5 | 8.1 | |
One key pair per account in two headers, never in the URL, plus temporary bearer tokens that can be limited to named phone numbers, expire after 900 seconds by default and can be revoked. Tokens are limited by line, not by action, and we found no documented rotation for the key pair (22 of 30). No read-only key. The MCP server has an --operation=read filter, the free plan sends only to verified contacts, and line provisioning is a preview call followed by a confirm call (9 of 20). Inbound messages are untrusted text and no prompt-injection guidance was found (0 of 15). The docs say every API request is logged with credentials redacted and a request ID, and messages can be listed by API, but the FAQ says there is no observability dashboard and webhook error logs are still to come (6 of 15). Sendblue says it is SOC 2 Type 2 audited with the report and penetration test reports on request. No security.txt, disclosure policy or bug bounty was found (9 of 20). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
| No x402, MPP or L402 (0). Plan prices are public, $0 and $100 a month per line with no per-message fee, while the outbound plan is priced through sales (10 of 20). The free plan needs no card (20). The CLI creates an account and API keys with no browser, but a person has to text a one-time code from a phone or supply an email code, so half (10 of 20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.3 | |
sendblue 3.19.1 on npm and 1.31.1 on PyPI on 7 October 2026 (30). Eight npm releases between 22 September and 7 October alone (20). No API changelog in the docs, support by email, and we couldn't read the GitHub issue trackers (6 of 15). Official TypeScript and Python SDKs are current, but sendblue-api-mcp, the MCP package the docs install, is still 2.0.1 from 5 August 2025 and no Sendblue messaging server is in the official MCP registry (10 of 15). The SDK repository has CI and release workflows, and the published MCP package pins the SDK at ^2.0.1 (6 of 10). | |||
| Transparency & trusteditorial 29, provenance 86 | 7%8.8 | 5.1 | |
| Closed service with clear terms from Round One, Inc., and Apache-2.0 SDKs (15 of 30). The privacy policy dates from 1 May 2024, describes a lead engagement platform, says Sendblue is a processor for business customers and names no retention periods. The docs say inbound media links expire after 30 days. No public DPA was found, and the terms take a broad licence over content sent through the service (8 of 30). No deprecation policy. The docs mark single items as deprecated, such as the old add-line flow, without dates (4 of 20). No sub-processor list or data locations. The docs name Twilio and Agora for calling only (2 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 61.7 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Sendblue, or have the agent fetch /fixes/sendblue.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Sendblue From Anchor Terminal's listing at https://www.anchorterminal.com/tools/sendblue, the October 2026 research run, assessed 8 October 2026. Grade C, 61.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Sendblue: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 46 out of 100, up to 9.5 more on the total Why it scored 46: One key pair per account in two headers, never in the URL, plus temporary bearer tokens that can be limited to named phone numbers, expire after 900 seconds by default and can be revoked. Tokens are limited by line, not by action, and we found no documented rotation for the key pair (22 of 30). No read-only key. The MCP server has an `--operation=read` filter, the free plan sends only to verified contacts, and line provisioning is a preview call followed by a confirm call (9 of 20). Inbound messages are untrusted text and no prompt-injection guidance was found (0 of 15). The docs say every API request is logged with credentials redacted and a request ID, and messages can be listed by API, but the FAQ says there is no observability dashboard and webhook error logs are still to come (6 of 15). Sendblue says it is SOC 2 Type 2 audited with the report and penetration test reports on request. No security.txt, disclosure policy or bug bounty was found (9 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Payments & pricing, 40 out of 100, up to 7.5 more on the total Why it scored 40: No x402, MPP or L402 (0). Plan prices are public, $0 and $100 a month per line with no per-message fee, while the outbound plan is priced through sales (10 of 20). The free plan needs no card (20). The CLI creates an account and API keys with no browser, but a person has to text a one-time code from a phone or supply an email code, so half (10 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Reliability, 71 out of 100, up to 5.8 more on the total Why it scored 71: Read with the hosted lines. status.sendblue.com is an UptimeRobot page with five monitors and 90 days of daily ratios (20). No incident is written up there. The API ingestion health monitor shows 95.349 per cent for 16 July 2026 (about 67 minutes, and we can't tell whether it was one outage), 98.770 per cent for 24 July, and API root 98.192 per cent for 7 October, so between minor incidents and one major (15 of 30). Rate limits are published with numbers per plan and per line (15). The docs say to slow down or spread traffic on a 429 and to verify state after `504 outcome_unknown`, with no Retry-After header documented and an idempotency key only on App Card updates (8 of 15). The API page shows a 99.9% Uptime SLA figure and the docs list custom SLAs for enterprise, but no SLA document was found and the terms disclaim availability (3 of 10). The REST API is generally available (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Schema & documentation, 66 out of 100, up to 5.5 more on the total Why it scored 66: We graded the REST API. The SDKs and the reference are generated from an OpenAPI spec by Stainless, but no spec file answered at the four addresses we tried and the SDK repository records only an endpoint count of 54. The published MCP package has JSON Schema inputs on its 18 tools (12 of 25). `llms.txt` and a Markdown twin of every docs page at `/index.md` (10). The reference and `llms.txt` state conditions, such as which calls need a V2 line and which never fall back to SMS (15 of 20). Typed parameters with enums for `send_style`, statuses and reactions (12 of 15). Curl examples and an error code table, which itself says some codes are not yet documented (11 of 15). Paths mix `/api`, `/api/v2`, `/v3` and `/accounts`, there is no API changelog in the docs, and the SDK changelog mostly records regenerated clients (6 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Agent ergonomics, 76 out of 100, up to 3.9 more on the total Why it scored 76: Message lists take `limit` from 1 to 100, and the MCP server adds a `jq_filter` on every tool, a read-only filter and a three-tool dynamic mode (20 of 25). `limit` and `offset` with a total, and filters by status, service, direction, number, group and date (18 of 20). Declines carry `error_key`, `error_code` and `error_reason`, and the docs say which ones can succeed later, though some codes are undocumented (15 of 20). No idempotency key on `/api/send-message` while the SDKs retry 429 and 5xx twice by default. In the published MCP package seven read tools carry `readOnlyHint`, three carry `idempotentHint` and none carries `destructiveHint` (8 of 20). A send needs three fields, and there are official TypeScript and Python SDKs (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Transparency & trust, 58 out of 100, up to 3.7 more on the total Made of editorial 29, provenance 86. Why it scored 58: Closed service with clear terms from Round One, Inc., and Apache-2.0 SDKs (15 of 30). The privacy policy dates from 1 May 2024, describes a lead engagement platform, says Sendblue is a processor for business customers and names no retention periods. The docs say inbound media links expire after 30 days. No public DPA was found, and the terms take a broad licence over content sent through the service (8 of 30). No deprecation policy. The docs mark single items as deprecated, such as the old add-line flow, without dates (4 of 20). No sub-processor list or data locations. The docs name Twilio and Agora for calling only (2 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 5 of the 7 things a reader expects (8.3 of 10) - Privacy policy: read, states 5 of the 8 things a reader expects (7.8 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 72 out of 100, up to 2.5 more on the total Why it scored 72: `sendblue` 3.19.1 on npm and 1.31.1 on PyPI on 7 October 2026 (30). Eight npm releases between 22 September and 7 October alone (20). No API changelog in the docs, support by email, and we couldn't read the GitHub issue trackers (6 of 15). Official TypeScript and Python SDKs are current, but `sendblue-api-mcp`, the MCP package the docs install, is still 2.0.1 from 5 August 2025 and no Sendblue messaging server is in the official MCP registry (10 of 15). The SDK repository has CI and release workflows, and the published MCP package pins the SDK at `^2.0.1` (6 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: GitHub stars and open issues for sendblue-api/sendblue-ts, because the GitHub API refused us for its rate limit - unchecked: whether CI passes on the SDK's default branch, which a clone doesn't show - unchecked: the SOC 2 Type 2 report and penetration test reports, which Sendblue supplies on request - No public OpenAPI file was found at `/openapi.json`, `/openapi.yaml`, `/openapi.yml` on docs.sendblue.com or `/openapi.json` on api.sendblue.com - Whether the 67 minutes missing from the API ingestion monitor on 16 July 2026 were one outage. The status page has no written incident for it - The pricing page says the free plan has no outbound messaging and no webhooks, while the docs say free accounts can message verified contacts. We didn't test which holds - Whether the 99.9% Uptime SLA figure on the API page is backed by a contract term. No SLA document was found - Which countries' numbers Sendblue can assign and reach. The docs describe E.164 numbers and area codes without a coverage list - Whether the account key pair can be rotated or more than one pair issued - The lead's interface line reads REST API (v2). The API has no single version, with paths under `/api`, `/api/v2`, `/v3` and `/accounts` ## Weaknesses - Proactive outbound messaging needs the Blue Ocean plan, which has no public price. The $100 AI Agent plan is inbound-first - No OpenAPI file was found at any public address, although the SDKs and the reference are generated from one - The docs install `sendblue-api-mcp`, last published on 5 August 2025 with 18 tools. The API now has 54 configured endpoints - `/api/send-message` takes no idempotency key, and the SDKs retry 429 and 5xx responses twice by default - No public DPA, sub-processor list, retention period, deprecation policy or security.txt was found ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send `from_number` on every request. Read the account's numbers from `GET /api/lines` first, because a send without it fails - On the free plan a recipient must text the Sendblue number once before any message to them is accepted - Before a contact's first reply keep messages under 300 characters with no links, media, phone numbers or email addresses, and stop at six - Branch on `error_key` in an HTTP 400 decline and don't retry it. Only HTTP 429 clears by waiting - Set `maxRetries: 0` on sends where a duplicate matters, and treat `504 outcome_unknown` on group changes as possibly applied - Mint a token at `/v3/auth/tokens` limited to one phone number for a sub-agent, and keep the account key pair out of its context ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: GitHub stars and open issues for sendblue-api/sendblue-ts, because the GitHub API refused us for its rate limit
- unchecked: whether CI passes on the SDK's default branch, which a clone doesn't show
- unchecked: the SOC 2 Type 2 report and penetration test reports, which Sendblue supplies on request
- No public OpenAPI file was found at
/openapi.json,/openapi.yaml,/openapi.ymlon docs.sendblue.com or/openapi.jsonon api.sendblue.com - Whether the 67 minutes missing from the API ingestion monitor on 16 July 2026 were one outage. The status page has no written incident for it
- The pricing page says the free plan has no outbound messaging and no webhooks, while the docs say free accounts can message verified contacts. We didn't test which holds
- Whether the 99.9% Uptime SLA figure on the API page is backed by a contract term. No SLA document was found
- Which countries' numbers Sendblue can assign and reach. The docs describe E.164 numbers and area codes without a coverage list
- Whether the account key pair can be rotated or more than one pair issued
- The lead's interface line reads REST API (v2). The API has no single version, with paths under
/api,/api/v2,/v3and/accounts
Sources 29
- docs index for agents docs.sendblue.com · seen 2026-10-08
- site llms.txt sendblue.com · seen 2026-10-08
- pricing sendblue.com · seen 2026-10-08
- API product page, uptime and SOC 2 claims sendblue.com · seen 2026-10-08
- rate limits and queues docs.sendblue.com · seen 2026-10-08
- security and compliance docs.sendblue.com · seen 2026-10-08
- credentials docs.sendblue.com · seen 2026-10-08
- MCP server docs docs.sendblue.com · seen 2026-10-08
- temporary tokens reference docs.sendblue.com · seen 2026-10-08
- send-message reference docs.sendblue.com · seen 2026-10-08
- sending messages, statuses and error codes docs.sendblue.com · seen 2026-10-08
- messages list and pagination docs.sendblue.com · seen 2026-10-08
- webhooks docs.sendblue.com · seen 2026-10-08
- Verify docs.sendblue.com · seen 2026-10-08
- FAQ docs.sendblue.com · seen 2026-10-08
- docs sitemap docs.sendblue.com · seen 2026-10-08
- status page status.sendblue.com · seen 2026-10-08
- status page monitor feed, 90 days of daily ratios status.sendblue.com · seen 2026-10-08
- terms of service sendblue.com · seen 2026-10-08
- privacy policy sendblue.com · seen 2026-10-08
- TypeScript SDK and MCP source, cloned github.com · seen 2026-10-08
- SDK on npm registry.npmjs.org · seen 2026-10-08
- MCP package on npm, tarball unpacked registry.npmjs.org · seen 2026-10-08
- second MCP package name on npm registry.npmjs.org · seen 2026-10-08
- CLI on npm registry.npmjs.org · seen 2026-10-08
- Python SDK on PyPI pypi.org · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- security.txt, 404 sendblue.com · seen 2026-10-08
- domain registration rdap.verisign.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $100 / mo Flat price per line with no per-message fee. The Free Sandbox is $0 with no card, on a shared number with up to 10 verified contacts. The AI Agent plan is $100 a month per dedicated line and is inbound-first. Proactive outbound messaging is on the Enterprise or Blue Ocean plan, priced through sales. The terms add 3 per cent for card payments and $60 per line to port a number out (https://www.sendblue.com/pricing, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| AI Agent plan, dedicated line | $100 | per month (plan) | Per line, inbound-first, no per-message fee. Outbound plans are priced through sales |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/sendblue.xml, or this listing's score history at history.json.
Connect
Install
npm install sendblue
First request
curl -X POST https://api.sendblue.com/api/send-message \
-H "sb-api-key-id: $SENDBLUE_API_KEY_ID" -H "sb-api-secret-key: $SENDBLUE_API_KEY_SECRET" \
-H "Content-Type: application/json" \
-d '{"number":"+19998887777","from_number":"+18887776666","content":"Hello from Sendblue!"}'
Claude Code
claude mcp add sendblue_api --env SENDBLUE_API_API_KEY=your-api-key --env SENDBLUE_API_API_SECRET=your-api-secret -- npx -y sendblue-api-mcp --client=claude-code --tools=all
MCP client configuration
{
"mcpServers": {
"sendblue_api": {
"args": [
"-y",
"sendblue-api-mcp",
"--tools=all"
],
"command": "npx",
"env": {
"SENDBLUE_API_API_KEY": "your-api-key",
"SENDBLUE_API_API_SECRET": "your-api-secret"
}
}
}
}
Through letme picks today, calling later
GET https://letme.dev/sendblue
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Twilio API + MCP AAWS End User Messaging BBTelnyx API + MCP BBVonage Messages API + MCP BBandwidth Messaging API + MCP BPlivo API C
Head to head AWS End User Messaging vs Sendblue · Bandwidth Messaging API + MCP vs Sendblue · Bird API + MCP vs Sendblue · ClickSend SMS API + MCP vs Sendblue · Infobip API + MCP vs Sendblue · Plivo API vs Sendblue · Sendblue vs Sinch Messaging APIs + MCP · Sendblue vs Telnyx API + MCP · Sendblue vs Twilio API + MCP · Sendblue vs Vonage Messages API + MCP · 360dialog WhatsApp API + MCP vs Sendblue · Sendblue vs WhatsApp Business Platform (Cloud API)
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Twilio API + MCP Twilio | A | 80.4 | messaging.sms messaging.mms messaging.rcs messaging.verify messaging.inbound | no |
| AWS End User Messaging Amazon Web Services | BB | 74.3 | messaging.sms messaging.mms messaging.rcs messaging.verify messaging.inbound | no |
| Telnyx API + MCP Telnyx | BB | 73.6 | messaging.sms messaging.mms messaging.rcs messaging.verify messaging.inbound | no |
| Vonage Messages API + MCP Vonage (Ericsson) | B | 66.8 | messaging.sms messaging.mms messaging.rcs messaging.verify messaging.inbound | no |
| Bandwidth Messaging API + MCP Bandwidth | B | 64.3 | messaging.sms messaging.mms messaging.rcs messaging.verify messaging.inbound | no |
| Plivo API Plivo | C | 60.3 | messaging.sms messaging.mms messaging.rcs messaging.verify messaging.inbound | no |
Machine-readable
- JSON
/api/v1/tools/sendblue.json· historyhistory.json· badge/badges/sendblue.svg· changes feed/feeds/tools/sendblue.xml - Markdown
/tools/sendblue.md· slim/tools/sendblue.min.md(or sendAccept: text/markdown) - Fix list
/fixes/sendblue.md·/fixes/sendblue.json - From a terminal
anchor tool sendblue --md(the CLI) · over MCPget_tool {"slug": "sendblue"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/sendblue"><img src="https://www.anchorterminal.com/badges/sendblue.svg" alt="Sendblue on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/sendblue)<a href="https://www.anchorterminal.com/tools/sendblue">Sendblue on Anchor Terminal</a>It counts on a page on sendblue.com or one of its subdomains, or the README of github.com/sendblue-api/sendblue-ts.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "sendblue", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


