Sendcloud
by Sendcloud B.V. HTTP API in Shipping & fulfilment
Hosted
Sendcloud B.V. · sendcloud.com since 2008 · status page · who's behind it
Shipping platform for European online shops from Sendcloud B.V. in Eindhoven. Its API v3 and hosted MCP server quote carrier rates, create labels, validate addresses, track parcels and handle returns across the carriers an account has enabled.
Good for An agent shipping parcels for a European shop that wants many carriers behind one account, including its own carrier contracts on paid plans.
Is this your product? Claim this listing or verify it
Assessment. API v3 has 29 public OpenAPI 3.1 specs, an llms.txt index, a dated changelog and a hosted MCP server with toolset filtering. OAuth has one scope, api, so a credential can't be limited to reading. The changelog records response fields removed from tracking events on 25 September 2026 with no earlier deprecation entry.
Facts
- Transport
- HTTP
- Endpoint
https://mcp.sendcloud.com/mcp- Auth
- OAuth or key
- Pricing
- Freemium · $31.30 / mo
- x402
- No
- Licence
- Proprietary service under Sendcloud's terms and conditions
- Docs
- sendcloud.dev
- llms.txt
- published
- Last release
- Surfaces
- API v3 at https://panel.sendcloud.sc/api/v3 (104 operations in 29 OpenAPI 3.1 specs) and a hosted MCP server at https://mcp.sendcloud.com/mcp. API v2 is legacy
- MCP server
- Streamable HTTP, OAuth 2.0 with discovery through RFC 9728 metadata, scope
api. 24 toolsets, all on by default, narrowed with?toolsets=. Tool names follow<toolset>_<operationId> - Credentials
- A public and secret key pair per API integration, created in the panel, sent as HTTP Basic or exchanged for a one-hour Bearer token (client credentials, scope
api) - Rate limits
- 1,000 GET requests a minute. 100 POST, PATCH, PUT or DELETE requests a minute, burst 15 a second. 429 when exceeded
- Pagination
- Cursor-based,
cursorandpage_size(up to 100 on shipments), with next and prev links in the HTTP Link header - Errors
- JSON:API error objects with
status,codeanddetail. Synchronous announce responses carry carrier failures in anerrorsarray - Safe retries
- A repeated
external_reference_idon shipment creation returns the existing shipment with 409. Tracking registration is idempotent on source_id and carrier_code - Testing
- No sandbox.
sendcloud:letterandsendcloud:letterreturnlabels are free, limited to 50 per the pricing page. Other labels are charged unless cancelled in time - Webhooks
- Five webhook payloads (parcel status changed, return created, integration connected, modified, deleted) and an Event Subscriptions API with 12 operations
- Status
- status.sendcloud.com, with components for the Sendcloud API, panel, returns, tracking page and each carrier and shop integration
- Certifications
- ISO/IEC 27001:2022 per trust.sendcloud.com. Annual third-party penetration tests per the security page. Private HackerOne programme
- Hosting and sub-processors
- AWS EU Central and EU North, with availability zones in Frankfurt. Trust centre lists Twilio, Trustpilot, Zendesk, CM.com and AWS
Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- 29 public OpenAPI 3.1 specs covering 104 API v3 operations, with an llms.txt index and Markdown copies of every docs page
- Hosted MCP server at mcp.sendcloud.com/mcp with 24 toolsets, a
?toolsets=filter and read-only, idempotent and destructive annotations per the docs - A repeated
external_reference_idon shipment creation returns the existing shipment with a 409 instead of buying a second label - Free test labels through the
sendcloud:letterandsendcloud:letterreturnshipping options, up to 50 before charges apply - Dated API v3 changelog with 37 entries between 9 July and 5 October 2026
Weaknesses
- One OAuth scope,
api, and key pairs with full account access. No read-only credential was found in the reviewed documentation - Changelog entries of 21 and 25 September 2026 record removed request and response fields on parcel tracking with no earlier deprecation entry
- No Retry-After header or backoff guidance was found for 429 responses
- No official SDK was found in the reviewed documentation, and the MCP server isn't in the official MCP registry
- No test environment. Labels other than the Unstamped letter options are charged unless the carrier accepts a cancellation
Before you call it notes for agents
- Use API v3 at https://panel.sendcloud.sc/api/v3. The v2 create-parcel endpoint is closed to accounts created from April 2026
- Test with
shipping_option_codesendcloud:letter(returns usesendcloud:letterreturn). Any other label is billed unless cancelled within the carrier's deadline - Set
external_reference_idon every shipment so a retry returns the existing shipment (409) instead of a second label - Read the
errorsarray on synchronous announce responses. A carrier failure can arrive inside a success status - Connect MCP with
?toolsets=shipments,shipping-options,parcel-tracking,returnsto keep the tool list short. Create and cancel tools act on the live account
Who's behind it provenance 81/100
- Legal entity namedSendcloud B.V.20/20
- Domain agesendcloud.com, registered 2008-07-29 (18 years)15/15
- Endpoint on the vendor's domainmcp.sendcloud.com15/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 3 clauses that cost points2.3/10
- Privacy policyread, states 6 of the 8 things a reader expects8.5/10
- Status pagestatus.sendcloud.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 3 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking and changes without notice.
Restricts automated accesscosts points
(ix) not to engage in scraping, data mining, or any other automated methods to access or extract data from the Services without Sendcloud’s prior written consent;
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
(iii) not to access or use the Services to build a competitive product or service, or to benchmark the Services against other products;
A clause against publishing test results or using the service to build something that competes.
Says the terms or the service can change without noticecosts points
12.2 Sendcloud is permitted to make interim unilateral changes to Transport Fees with immediate effect and without any prior notice.
A customer may not hear about a change before it applies.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
All disputes arising from the Services and Terms between the Parties will be settled by the competent Dutch court in the judicial district of Oost-Brabant.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at €10,000.00
If and insofar as no payment can be made under this insurance, for whatever reason, the total liability, regardless of its basis, will always be limited to the amount charged by Sendcloud under the relevant Subscription and capped at €10,000.00.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
In case such a change of these Terms has a material adverse effect on the Customer, the Customer may terminate its active Subscription by sending a written notice to Sendcloud.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives thirty days of notice before a change
1.3 Sendcloud is permitted to make interim unilateral amendments to these Terms, giving a thirty (30) days prior notice to the Customer.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
(i) not to use the Services in any way that is illegal, fraudulent, deceptive, or harmful;
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Breach of the confidentiality or intellectual property articles carries a penalty of 10,000 euros for each contravention, plus 100 euros for each day it continues.
the Customer, with no need for a demand or other prior notice, will forfeit an immediately due and payable penalty of €10,000.00 (ten thousand euros) for each contravention
Noted by a second reader on 2026-10-08.
Transport fees fall due when a shipping label is created, whether or not the label is used.
12.5 The Transport Fees for shipping labels are due upon label creation, regardless of the actual use of the shipping label by the Customer.
Noted by a second reader on 2026-10-08.
Prices may rise once every twelve months by the greater of five per cent or euro area inflation, and the customer has no termination right for that rise.
The adjustment shall be the greater of either: (i) a five percent (5%) increase; or (ii) the percentage change in the Harmonised Index of Consumer Prices (HICP) for the Euro area as published by Eurostat over the preceding twelve (12) months.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 4,863 words
Privacy policy gives no date, states 6 of 8
TL;DR Gives no date. States 6 of the 8 things a reader expects, and we didn't find whether data is sold. The rules found no clause to flag.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
In any case, we collect the following access and web access data (which we call “Usage Data”):
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 7 days
These server log files are deleted after a maximum of 7 days.
Says when data sent to the service is deleted.
Says who else receives the data
This means that Sendcloud, according to a contractual agreement, is strictly subject to the customer’s instructions and will process all data as the customer’s technical service provider without its own decision-making authority with regard to the processing of personal data by the customer.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
You can assert the following rights against us within the framework of the GDPR with regard to your personal data:
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@sendcloud.com
If you have any questions regarding this Privacy Policy, please reach out to us at privacy@sendcloud.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
In such cases and in accordance with the regulations in force, Sendcloud requires its data processors to provide the necessary safeguards to ensure regulated, secure transfers, mainly by requiring them to sign the European Commission’s standard contractual clauses.
The countries data goes to and the safeguard used.
The policy covers the Sendcloud website, and says that for its integrations Sendcloud processes data only on the instructions of the customer that installed them.
In this case, Sendcloud will only act as an order processor.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 1,630 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms, last updated 1 September 2026, name Sendcloud B.V., registration 66572959, Stadhuisplein 10, 5611 EM Eindhoven, with Sendcloud GmbH, Ltd., SAS and Srl for Germany and Austria, the UK, France and Italy. Dutch law applies.
The MCP server answers at mcp.sendcloud.com and tokens come from account.sendcloud.com. The REST API answers at panel.sendcloud.sc, a second Sendcloud domain.
www.sendcloud.com/.well-known/security.txt and /security.txt return 404. The bug bounty page sends reports to security@sendcloud.com.
RDAP for sendcloud.com gives a registration date of 2008-07-29.
Unit prices are converted from euros at the ECB reference rate of 1.1177 for 7 October 2026, read through api.frankfurter.dev.
Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://mcp.sendcloud.com/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/sendcloud.json
Notable
- The MCP server is hosted at https://mcp.sendcloud.com/mcp over Streamable HTTP with OAuth 2.0, one tool per API v3 operation in 24 toolsets, and a
?toolsets=filter that also rejects calls outside the selection source - API v2 entered maintenance mode in April 2026. Its create-parcel endpoint is closed to new accounts, and llms.txt tells assistants to write v3 code only source
- Default rate limits are 1,000 GET requests a minute and 100 POST, PATCH, PUT or DELETE requests a minute with a burst of 15 a second source
- Two free shipping options exist for testing,
sendcloud:letterandsendcloud:letterreturn. There is no separate test environment source - status.sendcloud.com lists 25 incidents between 8 July and 7 October 2026. Most are one carrier's label announcements, and none names the Sendcloud API component source
- ISO/IEC 27001:2022 on the trust centre, hosting on AWS in Frankfurt, and a private HackerOne programme reached through security@sendcloud.com source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.6 | |
Graded on API v3 and the hosted MCP server, with the hosted lines. Statuspage at status.sendcloud.com with components for the API, the panel and each carrier and integration (20). 25 incidents between 8 July and 7 October 2026. Twelve are marked major or critical and each concerns one carrier's label announcements, mostly labelled third-party. Platform-side entries are minor, the longest a four-hour integration connection problem on 14 September and 94 minutes of label announcement issues across several carriers on 8 September. None names the Sendcloud API component, so we scored between minor-only and one major (15). Limits published, 1,000 safe and 100 unsafe requests a minute with a burst of 15 a second (15). 429 is documented without Retry-After or backoff guidance. A repeated external_reference_id returns the existing shipment (8). The home page claims 99.99 per cent uptime, and no SLA document was found (0). API v3 is the current version and the MCP page carries no beta label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.5 | |
29 OpenAPI 3.1 specs for API v3, 104 operations, linked from llms.txt (25). llms.txt and a Markdown copy of every docs page (10). Every operation has a description. Some state limits, such as when a cancellation is rejected, and many are one sentence. MCP tools take their text from the same specs (13). 243 enums, required fields and maxima such as page_size up to 100 (13). 216 example blocks and JSON:API error objects with status, code and detail. 429 responses appear only in the Support API spec (13). Versioned v2 and v3 with a dated v3 changelog of 155 entries back to 25 May 2023 (15). | |||
| Agent ergonomics | 13%16.2 | 11.5 | |
The MCP server makes one tool per operation, about 98 by the specs for its 24 toolsets, all on by default, which scores 5, and a ?toolsets= filter enforced on calls adds 10. The API has page_size and no field selection (15). Cursor pagination through Link headers and filters by status, tracking number, reference and dates on shipments (18). JSON:API errors, though a carrier failure on a synchronous announce arrives in an errors array inside a success response (15). external_reference_id deduplicates shipment creation, and the docs say tools carry read-only, idempotent and destructive hints by HTTP method, which we couldn't confirm without an account (16). Shipping rules and defaults cut required fields. No official SDK was found (7). | |||
| Security & auth | 14%17.5 | 8.6 | |
A key pair per API integration, usable as Basic or exchanged for a one-hour Bearer token, and OAuth with PKCE for MCP. The only scope is api, which covers the whole account (20). No read-only credential found. The MCP toolset filter is enforced on the server, and annotations let a client prompt before creates and cancels (8). Responses carry text written by others, such as addresses, order data and support tickets. The MCP page says results are reference information only and gives no injection guidance (3). Integration exception logs are in the API. No per-call audit view found (3). ISO/IEC 27001:2022, annual penetration tests, a private HackerOne programme and a disclosure address. No security.txt and no SOC 2 found (15). | |||
| Payments & pricing | 10%12.5 | 4.6 | |
| No x402, MPP or L402 (0). Plan prices and per-label fees are public in euros, from €28 a month plus €0.10 a label to €639 plus €0.07, with sample carrier rates. We couldn't read which plans the API access row covers (17). A Free plan for 20 parcels a month and a 14-day trial, both stated as needing no card, plus free Unstamped letter test labels (20). A person signs up in a browser, adds an invoice address and creates the keys in the panel (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.9 | |
| Latest API v3 changelog entry 5 October 2026 (30). 37 dated entries between 9 July and 5 October (20). Closed service with a dated changelog and a help centre with email and chat support. No developer forum or public issue tracker found (9). The MCP server isn't in the official MCP registry, and no official SDK was found. A public Postman workspace exists (3). No packages to assess. The specs change with the changelog (5). | |||
| Transparency & trusteditorial 62, provenance 81 | 7%8.8 | 6.3 | |
| Closed service with terms dated 1 September 2026 naming Sendcloud B.V. and four country entities (15). The privacy policy keeps server logs for at most 7 days and contact forms for 6 years. The DPA deletes customers' order data within 365 days of shipment completion and gives 30 days' notice of new sub-processors. Neither page showed a version date we could read (22). API v2 maintenance mode announced for April 2026, and one endpoint deprecated with a date (9 June 2026). Other deprecated fields are to go "in a future version", and no notice-period policy was found (10). Trust centre names five sub-processors, and the security page names AWS EU Central and EU North (15). | |||
| Negative events | ≤15 |
| -3 |
| Total | 62 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Sendcloud, or have the agent fetch /fixes/sendcloud.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Sendcloud From Anchor Terminal's listing at https://www.anchorterminal.com/tools/sendcloud, the October 2026 research run, assessed 7 October 2026. Grade B, 62 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Sendcloud: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 49 out of 100, up to 8.9 more on the total Why it scored 49: A key pair per API integration, usable as Basic or exchanged for a one-hour Bearer token, and OAuth with PKCE for MCP. The only scope is `api`, which covers the whole account (20). No read-only credential found. The MCP toolset filter is enforced on the server, and annotations let a client prompt before creates and cancels (8). Responses carry text written by others, such as addresses, order data and support tickets. The MCP page says results are reference information only and gives no injection guidance (3). Integration exception logs are in the API. No per-call audit view found (3). ISO/IEC 27001:2022, annual penetration tests, a private HackerOne programme and a disclosure address. No security.txt and no SOC 2 found (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Payments & pricing, 37 out of 100, up to 7.9 more on the total Why it scored 37: No x402, MPP or L402 (0). Plan prices and per-label fees are public in euros, from €28 a month plus €0.10 a label to €639 plus €0.07, with sample carrier rates. We couldn't read which plans the API access row covers (17). A Free plan for 20 parcels a month and a 14-day trial, both stated as needing no card, plus free Unstamped letter test labels (20). A person signs up in a browser, adds an invoice address and creates the keys in the panel (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Reliability, 68 out of 100, up to 6.4 more on the total Why it scored 68: Graded on API v3 and the hosted MCP server, with the hosted lines. Statuspage at status.sendcloud.com with components for the API, the panel and each carrier and integration (20). 25 incidents between 8 July and 7 October 2026. Twelve are marked major or critical and each concerns one carrier's label announcements, mostly labelled third-party. Platform-side entries are minor, the longest a four-hour integration connection problem on 14 September and 94 minutes of label announcement issues across several carriers on 8 September. None names the Sendcloud API component, so we scored between minor-only and one major (15). Limits published, 1,000 safe and 100 unsafe requests a minute with a burst of 15 a second (15). 429 is documented without Retry-After or backoff guidance. A repeated `external_reference_id` returns the existing shipment (8). The home page claims 99.99 per cent uptime, and no SLA document was found (0). API v3 is the current version and the MCP page carries no beta label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Agent ergonomics, 71 out of 100, up to 4.7 more on the total Why it scored 71: The MCP server makes one tool per operation, about 98 by the specs for its 24 toolsets, all on by default, which scores 5, and a `?toolsets=` filter enforced on calls adds 10. The API has `page_size` and no field selection (15). Cursor pagination through Link headers and filters by status, tracking number, reference and dates on shipments (18). JSON:API errors, though a carrier failure on a synchronous announce arrives in an `errors` array inside a success response (15). `external_reference_id` deduplicates shipment creation, and the docs say tools carry read-only, idempotent and destructive hints by HTTP method, which we couldn't confirm without an account (16). Shipping rules and defaults cut required fields. No official SDK was found (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Maintenance & community, 67 out of 100, up to 2.9 more on the total Why it scored 67: Latest API v3 changelog entry 5 October 2026 (30). 37 dated entries between 9 July and 5 October (20). Closed service with a dated changelog and a help centre with email and chat support. No developer forum or public issue tracker found (9). The MCP server isn't in the official MCP registry, and no official SDK was found. A public Postman workspace exists (3). No packages to assess. The specs change with the changelog (5). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Transparency & trust, 72 out of 100, up to 2.5 more on the total Made of editorial 62, provenance 81. Why it scored 72: Closed service with terms dated 1 September 2026 naming Sendcloud B.V. and four country entities (15). The privacy policy keeps server logs for at most 7 days and contact forms for 6 years. The DPA deletes customers' order data within 365 days of shipment completion and gives 30 days' notice of new sub-processors. Neither page showed a version date we could read (22). API v2 maintenance mode announced for April 2026, and one endpoint deprecated with a date (9 June 2026). Other deprecated fields are to go "in a future version", and no notice-period policy was found (10). Trust centre names five sub-processors, and the security page names AWS EU Central and EU North (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points (2.3 of 10) - Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10) - security.txt: not found (0 of 10) ## 7. Schema & documentation, 89 out of 100, up to 1.8 more on the total Why it scored 89: 29 OpenAPI 3.1 specs for API v3, 104 operations, linked from llms.txt (25). llms.txt and a Markdown copy of every docs page (10). Every operation has a description. Some state limits, such as when a cancellation is rejected, and many are one sentence. MCP tools take their text from the same specs (13). 243 enums, required fields and maxima such as `page_size` up to 100 (13). 216 example blocks and JSON:API error objects with `status`, `code` and `detail`. 429 responses appear only in the Support API spec (13). Versioned v2 and v3 with a dated v3 changelog of 155 entries back to 25 May 2023 (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 21 and 25 September 2026. The API v3 changelog records `insurance.currency` and `insurance.value` removed from POST /parcels/tracking, and `status_code`, `status_description` and `sub_status_code` removed from tracking event responses, with no earlier deprecation entry for those fields. The changes are documented on the day, so the deduction is the minimum (https://sendcloud.dev/api/v3/changelog.md) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: which plans include API access. The pricing table has the row, and its per-plan marks didn't survive our reader - unchecked: the live MCP tool list, tool count and annotations, which need an account. About 98 tools is our count from the specs - unchecked: effective dates of the privacy policy and the DPA - Whether the September 2026 field removals changed live responses or corrected the specs to match them - Whether a payment method is required before the first paid label on the Free plan - Whether an SLA exists on Enterprise, and whether Sendcloud keeps official SDKs or a public GitHub organisation (github.com was not reachable from our shell) - Home-page figures (170+ carriers, 30,000+ merchants, 99.99 per cent uptime) are Sendcloud's claims ## Weaknesses - One OAuth scope, `api`, and key pairs with full account access. No read-only credential was found in the reviewed documentation - Changelog entries of 21 and 25 September 2026 record removed request and response fields on parcel tracking with no earlier deprecation entry - No Retry-After header or backoff guidance was found for 429 responses - No official SDK was found in the reviewed documentation, and the MCP server isn't in the official MCP registry - No test environment. Labels other than the Unstamped letter options are charged unless the carrier accepts a cancellation ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Use API v3 at https://panel.sendcloud.sc/api/v3. The v2 create-parcel endpoint is closed to accounts created from April 2026 - Test with `shipping_option_code` `sendcloud:letter` (returns use `sendcloud:letterreturn`). Any other label is billed unless cancelled within the carrier's deadline - Set `external_reference_id` on every shipment so a retry returns the existing shipment (409) instead of a second label - Read the `errors` array on synchronous announce responses. A carrier failure can arrive inside a success status - Connect MCP with `?toolsets=shipments,shipping-options,parcel-tracking,returns` to keep the tool list short. Create and cancel tools act on the live account ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: which plans include API access. The pricing table has the row, and its per-plan marks didn't survive our reader
- unchecked: the live MCP tool list, tool count and annotations, which need an account. About 98 tools is our count from the specs
- unchecked: effective dates of the privacy policy and the DPA
- Whether the September 2026 field removals changed live responses or corrected the specs to match them
- Whether a payment method is required before the first paid label on the Free plan
- Whether an SLA exists on Enterprise, and whether Sendcloud keeps official SDKs or a public GitHub organisation (github.com was not reachable from our shell)
- Home-page figures (170+ carriers, 30,000+ merchants, 99.99 per cent uptime) are Sendcloud's claims
Sources 20
- home page claims and links sendcloud.com · seen 2026-10-07
- docs index (llms.txt) sendcloud.dev · seen 2026-10-07
- MCP server docs sendcloud.dev · seen 2026-10-07
- MCP protected-resource metadata mcp.sendcloud.com · seen 2026-10-07
- authentication sendcloud.dev · seen 2026-10-07
- rate limits sendcloud.dev · seen 2026-10-07
- pagination sendcloud.dev · seen 2026-10-07
- test labels sendcloud.dev · seen 2026-10-07
- API version guide sendcloud.dev · seen 2026-10-07
- API v3 changelog sendcloud.dev · seen 2026-10-07
- Shipments OpenAPI spec (one of 29 read) sendcloud.dev · seen 2026-10-07
- status incidents status.sendcloud.com · seen 2026-10-07
- pricing sendcloud.com · seen 2026-10-07
- terms and conditions sendcloud.com · seen 2026-10-07
- privacy policy sendcloud.com · seen 2026-10-07
- data processing addendum sendcloud.com · seen 2026-10-07
- security page sendcloud.com · seen 2026-10-07
- trust centre trust.sendcloud.com · seen 2026-10-07
- bug bounty programme sendcloud.com · seen 2026-10-07
- official MCP registry search (no result) registry.modelcontextprotocol.io · seen 2026-10-07
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $31.30 / mo Free plan at €0 for up to 20 parcels a month at Sendcloud's carrier rates, and a 14-day trial of paid plans with no card per the pricing page. Lite is €28 a month plus €0.10 a label, Growth €87 plus €0.09, Premium €175 plus €0.08, Pro €639 plus €0.07, Enterprise on request, with 20 per cent off for yearly billing. Carrier postage is extra. There is no sandbox, but 50 Unstamped letter test labels are free. The pricing table has an API access row whose per-plan marks we couldn't read (https://www.sendcloud.com/pricing/).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Lite plan | $31.30 | per month (plan) | €28, 400 labels a month, plus €0.10 a label |
| Growth plan | $97.24 | per month (plan) | €87, 1,000 labels a month, plus €0.09 a label |
| Premium plan | $195.60 | per month (plan) | €175, 10,000 labels a month, plus €0.08 a label |
| Pro plan | $714.21 | per month (plan) | €639, 30,000 labels a month, plus €0.07 a label |
| Label fee on Lite | $0.11 | per transaction | €0.10 a label on top of carrier postage, €0.25 above the monthly limit |
Compared across listings on the price index.
Recent changes
- Sendcloud status page: maintenance → none source
- Latest release
Follow them as a feed at /feeds/tools/sendcloud.xml, or this listing's score history at history.json.
Connect
First request
curl -X POST --location "https://account.sendcloud.com/oauth2/token" \
--header "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials&scope=api" \
--basic --user your_sendcloud_public_key:your_sendcloud_private_key
Claude Code
claude mcp add --transport http sendcloud https://mcp.sendcloud.com/mcp
MCP client configuration
{
"mcpServers": {
"sendcloud": {
"type": "http",
"url": "https://mcp.sendcloud.com/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/sendcloud
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Easyship BShippo CShipStation API CEasyPost CTaxJar C
Head to head EasyPost vs Sendcloud · Easyship vs Sendcloud · Sendcloud vs Shippo · Sendcloud vs ShipStation API
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Easyship Easyship Inc. | B | 68.8 | shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returns | no |
| Shippo Shippo | C | 61.9 | shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returns | no |
| ShipStation API Auctane LLC d/b/a ShipStation | C | 59.3 | shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returns | no |
| EasyPost Simpler Postage, Inc. (d/b/a EasyPost) | C | 54.3 | shipping.rates shipping.labels shipping.tracking shipping.address-validation shipping.returns | no |
| TaxJar TaxJar (Stripe) | C | 57.6 | shipping.address-validation | no |
Machine-readable
- JSON
/api/v1/tools/sendcloud.json· historyhistory.json· badge/badges/sendcloud.svg· changes feed/feeds/tools/sendcloud.xml - Markdown
/tools/sendcloud.md· slim/tools/sendcloud.min.md(or sendAccept: text/markdown) - Fix list
/fixes/sendcloud.md·/fixes/sendcloud.json - From a terminal
anchor tool sendcloud --md(the CLI) · over MCPget_tool {"slug": "sendcloud"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/sendcloud"><img src="https://www.anchorterminal.com/badges/sendcloud.svg" alt="Sendcloud on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/sendcloud)<a href="https://www.anchorterminal.com/tools/sendcloud">Sendcloud on Anchor Terminal</a>It counts on a page on sendcloud.com or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "sendcloud", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
