{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/easyship.json",
        "name": "Easyship",
        "score": 68.8,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "easyship"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/shippo.json",
        "name": "Shippo",
        "score": 61.9,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "shippo"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/shipstation.json",
        "name": "ShipStation API",
        "score": 59.3,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "shipstation"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/easypost.json",
        "name": "EasyPost",
        "score": 54.3,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "easypost"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/taxjar.json",
        "name": "TaxJar",
        "score": 57.6,
        "shared": [
          "shipping.address-validation"
        ],
        "slug": "taxjar"
      }
    ],
    "tool": {
      "slug": "sendcloud",
      "name": "Sendcloud",
      "vendor": "Sendcloud B.V.",
      "vendorUrl": "https://www.sendcloud.com",
      "kind": "http-api",
      "category": "shipping",
      "summary": "Shipping platform for European online shops from Sendcloud B.V. in Eindhoven. Its API v3 and hosted MCP server quote carrier rates, create labels, validate addresses, track parcels and handle returns across the carriers an account has enabled.",
      "url": "https://www.anchorterminal.com/tools/sendcloud",
      "markdownUrl": "https://www.anchorterminal.com/tools/sendcloud.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sendcloud.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sendcloud.json",
      "license": "Proprietary service under Sendcloud's terms and conditions",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.sendcloud.com/mcp",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Self-serve. A person signs up at account.sendcloud.com, adds an invoice and sender address, then creates a Sendcloud API integration in the panel, which issues a public and secret key pair. The pair works as HTTP Basic or is exchanged at https://account.sendcloud.com/oauth2/token for a one-hour Bearer token (client credentials, scope `api`). The MCP server uses an OAuth 2.0 sign-in at account.sendcloud.com, found through RFC 9728 metadata, with the same single scope. No partner or sales approval is needed for API v3.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at €0 for up to 20 parcels a month at Sendcloud's carrier rates, and a 14-day trial of paid plans with no card per the pricing page. Lite is €28 a month plus €0.10 a label, Growth €87 plus €0.09, Premium €175 plus €0.08, Pro €639 plus €0.07, Enterprise on request, with 20 per cent off for yearly billing. Carrier postage is extra. There is no sandbox, but 50 Unstamped letter test labels are free. The pricing table has an API access row whose per-plan marks we couldn't read (https://www.sendcloud.com/pricing/).",
      "priceSummary": "$31.30 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://sendcloud.dev",
      "llmsTxt": "https://sendcloud.dev/llms.txt",
      "openapi": "https://sendcloud.dev/.openapi/v3/shipments/openapi.yaml",
      "capabilities": [
        "shipping.rates",
        "shipping.labels",
        "shipping.tracking",
        "shipping.address-validation",
        "shipping.returns"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "status-page",
        "europe",
        "iso27001"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62,
        "grade": "B",
        "agentReady": false,
        "rank": 314,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 67,
          "payments": 37,
          "reliability": 68,
          "schema": 89,
          "security": 49,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 68,
            "points": 13.6,
            "reason": "Graded on API v3 and the hosted MCP server, with the hosted lines. Statuspage at status.sendcloud.com with components for the API, the panel and each carrier and integration (20). 25 incidents between 8 July and 7 October 2026. Twelve are marked major or critical and each concerns one carrier's label announcements, mostly labelled third-party. Platform-side entries are minor, the longest a four-hour integration connection problem on 14 September and 94 minutes of label announcement issues across several carriers on 8 September. None names the Sendcloud API component, so we scored between minor-only and one major (15). Limits published, 1,000 safe and 100 unsafe requests a minute with a burst of 15 a second (15). 429 is documented without Retry-After or backoff guidance. A repeated `external_reference_id` returns the existing shipment (8). The home page claims 99.99 per cent uptime, and no SLA document was found (0). API v3 is the current version and the MCP page carries no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 89,
            "points": 14.46,
            "reason": "29 OpenAPI 3.1 specs for API v3, 104 operations, linked from llms.txt (25). llms.txt and a Markdown copy of every docs page (10). Every operation has a description. Some state limits, such as when a cancellation is rejected, and many are one sentence. MCP tools take their text from the same specs (13). 243 enums, required fields and maxima such as `page_size` up to 100 (13). 216 example blocks and JSON:API error objects with `status`, `code` and `detail`. 429 responses appear only in the Support API spec (13). Versioned v2 and v3 with a dated v3 changelog of 155 entries back to 25 May 2023 (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 71,
            "points": 11.54,
            "reason": "The MCP server makes one tool per operation, about 98 by the specs for its 24 toolsets, all on by default, which scores 5, and a `?toolsets=` filter enforced on calls adds 10. The API has `page_size` and no field selection (15). Cursor pagination through Link headers and filters by status, tracking number, reference and dates on shipments (18). JSON:API errors, though a carrier failure on a synchronous announce arrives in an `errors` array inside a success response (15). `external_reference_id` deduplicates shipment creation, and the docs say tools carry read-only, idempotent and destructive hints by HTTP method, which we couldn't confirm without an account (16). Shipping rules and defaults cut required fields. No official SDK was found (7)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 49,
            "points": 8.57,
            "reason": "A key pair per API integration, usable as Basic or exchanged for a one-hour Bearer token, and OAuth with PKCE for MCP. The only scope is `api`, which covers the whole account (20). No read-only credential found. The MCP toolset filter is enforced on the server, and annotations let a client prompt before creates and cancels (8). Responses carry text written by others, such as addresses, order data and support tickets. The MCP page says results are reference information only and gives no injection guidance (3). Integration exception logs are in the API. No per-call audit view found (3). ISO/IEC 27001:2022, annual penetration tests, a private HackerOne programme and a disclosure address. No security.txt and no SOC 2 found (15)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 37,
            "points": 4.63,
            "reason": "No x402, MPP or L402 (0). Plan prices and per-label fees are public in euros, from €28 a month plus €0.10 a label to €639 plus €0.07, with sample carrier rates. We couldn't read which plans the API access row covers (17). A Free plan for 20 parcels a month and a 14-day trial, both stated as needing no card, plus free Unstamped letter test labels (20). A person signs up in a browser, adds an invoice address and creates the keys in the panel (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 67,
            "points": 5.86,
            "reason": "Latest API v3 changelog entry 5 October 2026 (30). 37 dated entries between 9 July and 5 October (20). Closed service with a dated changelog and a help centre with email and chat support. No developer forum or public issue tracker found (9). The MCP server isn't in the official MCP registry, and no official SDK was found. A public Postman workspace exists (3). No packages to assess. The specs change with the changelog (5)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "note": "editorial 62, provenance 81",
            "reason": "Closed service with terms dated 1 September 2026 naming Sendcloud B.V. and four country entities (15). The privacy policy keeps server logs for at most 7 days and contact forms for 6 years. The DPA deletes customers' order data within 365 days of shipment completion and gives 30 days' notice of new sub-processors. Neither page showed a version date we could read (22). API v2 maintenance mode announced for April 2026, and one endpoint deprecated with a date (9 June 2026). Other deprecated fields are to go \"in a future version\", and no notice-period policy was found (10). Trust centre names five sub-processors, and the security page names AWS EU Central and EU North (15)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP server makes one tool per operation, about 98 by the specs for its 24 toolsets, all on by default, which scores 5, and a `?toolsets=` filter enforced on calls adds 10. The API has `page_size` and no field selection (15). Cursor pagination through Link headers and filters by status, tracking number, reference and dates on shipments (18). JSON:API errors, though a carrier failure on a synchronous announce arrives in an `errors` array inside a success response (15). `external_reference_id` deduplicates shipment creation, and the docs say tools carry read-only, idempotent and destructive hints by HTTP method, which we couldn't confirm without an account (16). Shipping rules and defaults cut required fields. No official SDK was found (7).",
            "maintenance": "Latest API v3 changelog entry 5 October 2026 (30). 37 dated entries between 9 July and 5 October (20). Closed service with a dated changelog and a help centre with email and chat support. No developer forum or public issue tracker found (9). The MCP server isn't in the official MCP registry, and no official SDK was found. A public Postman workspace exists (3). No packages to assess. The specs change with the changelog (5).",
            "payments": "No x402, MPP or L402 (0). Plan prices and per-label fees are public in euros, from €28 a month plus €0.10 a label to €639 plus €0.07, with sample carrier rates. We couldn't read which plans the API access row covers (17). A Free plan for 20 parcels a month and a 14-day trial, both stated as needing no card, plus free Unstamped letter test labels (20). A person signs up in a browser, adds an invoice address and creates the keys in the panel (0).",
            "reliability": "Graded on API v3 and the hosted MCP server, with the hosted lines. Statuspage at status.sendcloud.com with components for the API, the panel and each carrier and integration (20). 25 incidents between 8 July and 7 October 2026. Twelve are marked major or critical and each concerns one carrier's label announcements, mostly labelled third-party. Platform-side entries are minor, the longest a four-hour integration connection problem on 14 September and 94 minutes of label announcement issues across several carriers on 8 September. None names the Sendcloud API component, so we scored between minor-only and one major (15). Limits published, 1,000 safe and 100 unsafe requests a minute with a burst of 15 a second (15). 429 is documented without Retry-After or backoff guidance. A repeated `external_reference_id` returns the existing shipment (8). The home page claims 99.99 per cent uptime, and no SLA document was found (0). API v3 is the current version and the MCP page carries no beta label (10).",
            "schema": "29 OpenAPI 3.1 specs for API v3, 104 operations, linked from llms.txt (25). llms.txt and a Markdown copy of every docs page (10). Every operation has a description. Some state limits, such as when a cancellation is rejected, and many are one sentence. MCP tools take their text from the same specs (13). 243 enums, required fields and maxima such as `page_size` up to 100 (13). 216 example blocks and JSON:API error objects with `status`, `code` and `detail`. 429 responses appear only in the Support API spec (13). Versioned v2 and v3 with a dated v3 changelog of 155 entries back to 25 May 2023 (15).",
            "security": "A key pair per API integration, usable as Basic or exchanged for a one-hour Bearer token, and OAuth with PKCE for MCP. The only scope is `api`, which covers the whole account (20). No read-only credential found. The MCP toolset filter is enforced on the server, and annotations let a client prompt before creates and cancels (8). Responses carry text written by others, such as addresses, order data and support tickets. The MCP page says results are reference information only and gives no injection guidance (3). Integration exception logs are in the API. No per-call audit view found (3). ISO/IEC 27001:2022, annual penetration tests, a private HackerOne programme and a disclosure address. No security.txt and no SOC 2 found (15).",
            "transparency": "Closed service with terms dated 1 September 2026 naming Sendcloud B.V. and four country entities (15). The privacy policy keeps server logs for at most 7 days and contact forms for 6 years. The DPA deletes customers' order data within 365 days of shipment completion and gives 30 days' notice of new sub-processors. Neither page showed a version date we could read (22). API v2 maintenance mode announced for April 2026, and one endpoint deprecated with a date (9 June 2026). Other deprecated fields are to go \"in a future version\", and no notice-period policy was found (10). Trust centre names five sub-processors, and the security page names AWS EU Central and EU North (15)."
          },
          "sources": [
            {
              "what": "home page claims and links",
              "url": "https://www.sendcloud.com/",
              "seen": "2026-10-07"
            },
            {
              "what": "docs index (llms.txt)",
              "url": "https://sendcloud.dev/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP server docs",
              "url": "https://sendcloud.dev/docs/getting-started/mcp-server.md",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP protected-resource metadata",
              "url": "https://mcp.sendcloud.com/.well-known/oauth-protected-resource/mcp",
              "seen": "2026-10-07"
            },
            {
              "what": "authentication",
              "url": "https://sendcloud.dev/docs/getting-started/authentication.md",
              "seen": "2026-10-07"
            },
            {
              "what": "rate limits",
              "url": "https://sendcloud.dev/docs/getting-started/rate-limits.md",
              "seen": "2026-10-07"
            },
            {
              "what": "pagination",
              "url": "https://sendcloud.dev/api/v3/pagination.md",
              "seen": "2026-10-07"
            },
            {
              "what": "test labels",
              "url": "https://sendcloud.dev/docs/getting-started/creating-test-labels.md",
              "seen": "2026-10-07"
            },
            {
              "what": "API version guide",
              "url": "https://sendcloud.dev/docs/getting-started/api-version-guide.md",
              "seen": "2026-10-07"
            },
            {
              "what": "API v3 changelog",
              "url": "https://sendcloud.dev/api/v3/changelog.md",
              "seen": "2026-10-07"
            },
            {
              "what": "Shipments OpenAPI spec (one of 29 read)",
              "url": "https://sendcloud.dev/.openapi/v3/shipments/openapi.yaml",
              "seen": "2026-10-07"
            },
            {
              "what": "status incidents",
              "url": "https://status.sendcloud.com/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "pricing",
              "url": "https://www.sendcloud.com/pricing/",
              "seen": "2026-10-07"
            },
            {
              "what": "terms and conditions",
              "url": "https://www.sendcloud.com/terms-conditions/",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy policy",
              "url": "https://www.sendcloud.com/privacy-policy/",
              "seen": "2026-10-07"
            },
            {
              "what": "data processing addendum",
              "url": "https://www.sendcloud.com/data-processing-addendum/",
              "seen": "2026-10-07"
            },
            {
              "what": "security page",
              "url": "https://www.sendcloud.com/security/",
              "seen": "2026-10-07"
            },
            {
              "what": "trust centre",
              "url": "https://trust.sendcloud.com/",
              "seen": "2026-10-07"
            },
            {
              "what": "bug bounty programme",
              "url": "https://www.sendcloud.com/bug-bounty-program/",
              "seen": "2026-10-07"
            },
            {
              "what": "official MCP registry search (no result)",
              "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=sendcloud",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: which plans include API access. The pricing table has the row, and its per-plan marks didn't survive our reader",
            "unchecked: the live MCP tool list, tool count and annotations, which need an account. About 98 tools is our count from the specs",
            "unchecked: effective dates of the privacy policy and the DPA",
            "Whether the September 2026 field removals changed live responses or corrected the specs to match them",
            "Whether a payment method is required before the first paid label on the Free plan",
            "Whether an SLA exists on Enterprise, and whether Sendcloud keeps official SDKs or a public GitHub organisation (github.com was not reachable from our shell)",
            "Home-page figures (170+ carriers, 30,000+ merchants, 99.99 per cent uptime) are Sendcloud's claims"
          ]
        },
        "negative": -3,
        "negativeNotes": [
          "21 and 25 September 2026. The API v3 changelog records `insurance.currency` and `insurance.value` removed from POST /parcels/tracking, and `status_code`, `status_description` and `sub_status_code` removed from tracking event responses, with no earlier deprecation entry for those fields. The changes are documented on the day, so the deduction is the minimum (https://sendcloud.dev/api/v3/changelog.md)"
        ],
        "verdict": "API v3 has 29 public OpenAPI 3.1 specs, an llms.txt index, a dated changelog and a hosted MCP server with toolset filtering. OAuth has one scope, `api`, so a credential can't be limited to reading. The changelog records response fields removed from tracking events on 25 September 2026 with no earlier deprecation entry.",
        "bestFor": "An agent shipping parcels for a European shop that wants many carriers behind one account, including its own carrier contracts on paid plans.",
        "strengths": [
          "29 public OpenAPI 3.1 specs covering 104 API v3 operations, with an llms.txt index and Markdown copies of every docs page",
          "Hosted MCP server at mcp.sendcloud.com/mcp with 24 toolsets, a `?toolsets=` filter and read-only, idempotent and destructive annotations per the docs",
          "A repeated `external_reference_id` on shipment creation returns the existing shipment with a 409 instead of buying a second label",
          "Free test labels through the `sendcloud:letter` and `sendcloud:letterreturn` shipping options, up to 50 before charges apply",
          "Dated API v3 changelog with 37 entries between 9 July and 5 October 2026"
        ],
        "weaknesses": [
          "One OAuth scope, `api`, and key pairs with full account access. No read-only credential was found in the reviewed documentation",
          "Changelog entries of 21 and 25 September 2026 record removed request and response fields on parcel tracking with no earlier deprecation entry",
          "No Retry-After header or backoff guidance was found for 429 responses",
          "No official SDK was found in the reviewed documentation, and the MCP server isn't in the official MCP registry",
          "No test environment. Labels other than the Unstamped letter options are charged unless the carrier accepts a cancellation"
        ],
        "agentNotes": [
          "Use API v3 at https://panel.sendcloud.sc/api/v3. The v2 create-parcel endpoint is closed to accounts created from April 2026",
          "Test with `shipping_option_code` `sendcloud:letter` (returns use `sendcloud:letterreturn`). Any other label is billed unless cancelled within the carrier's deadline",
          "Set `external_reference_id` on every shipment so a retry returns the existing shipment (409) instead of a second label",
          "Read the `errors` array on synchronous announce responses. A carrier failure can arrive inside a success status",
          "Connect MCP with `?toolsets=shipments,shipping-options,parcel-tracking,returns` to keep the tool list short. Create and cancel tools act on the live account"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 67,
          "payments": 37,
          "reliability": 68,
          "schema": 89,
          "security": 49,
          "transparency": 62
        },
        "provenanceScore": 81
      },
      "connect": {
        "http": "curl -X POST --location \"https://account.sendcloud.com/oauth2/token\" \\\n  --header \"Content-Type: application/x-www-form-urlencoded\" \\\n  -d \"grant_type=client_credentials\u0026scope=api\" \\\n  --basic --user your_sendcloud_public_key:your_sendcloud_private_key",
        "claudeCode": "claude mcp add --transport http sendcloud https://mcp.sendcloud.com/mcp",
        "config": {
          "mcpServers": {
            "sendcloud": {
              "type": "http",
              "url": "https://mcp.sendcloud.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/shipping.rates",
        "tool": "https://letme.dev/sendcloud"
      },
      "notable": [
        "The MCP server is hosted at https://mcp.sendcloud.com/mcp over Streamable HTTP with OAuth 2.0, one tool per API v3 operation in 24 toolsets, and a `?toolsets=` filter that also rejects calls outside the selection (https://sendcloud.dev/docs/getting-started/mcp-server.md)",
        "API v2 entered maintenance mode in April 2026. Its create-parcel endpoint is closed to new accounts, and llms.txt tells assistants to write v3 code only (https://sendcloud.dev/docs/getting-started/api-version-guide.md)",
        "Default rate limits are 1,000 GET requests a minute and 100 POST, PATCH, PUT or DELETE requests a minute with a burst of 15 a second (https://sendcloud.dev/docs/getting-started/rate-limits.md)",
        "Two free shipping options exist for testing, `sendcloud:letter` and `sendcloud:letterreturn`. There is no separate test environment (https://sendcloud.dev/docs/getting-started/creating-test-labels.md)",
        "status.sendcloud.com lists 25 incidents between 8 July and 7 October 2026. Most are one carrier's label announcements, and none names the Sendcloud API component (https://status.sendcloud.com/api/v2/incidents.json)",
        "ISO/IEC 27001:2022 on the trust centre, hosting on AWS in Frankfurt, and a private HackerOne programme reached through security@sendcloud.com (https://trust.sendcloud.com/, https://www.sendcloud.com/bug-bounty-program/)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surfaces",
          "value": "API v3 at https://panel.sendcloud.sc/api/v3 (104 operations in 29 OpenAPI 3.1 specs) and a hosted MCP server at https://mcp.sendcloud.com/mcp. API v2 is legacy"
        },
        {
          "label": "MCP server",
          "value": "Streamable HTTP, OAuth 2.0 with discovery through RFC 9728 metadata, scope `api`. 24 toolsets, all on by default, narrowed with `?toolsets=`. Tool names follow `\u003ctoolset\u003e_\u003coperationId\u003e`"
        },
        {
          "label": "Credentials",
          "value": "A public and secret key pair per API integration, created in the panel, sent as HTTP Basic or exchanged for a one-hour Bearer token (client credentials, scope `api`)"
        },
        {
          "label": "Rate limits",
          "value": "1,000 GET requests a minute. 100 POST, PATCH, PUT or DELETE requests a minute, burst 15 a second. 429 when exceeded"
        },
        {
          "label": "Pagination",
          "value": "Cursor-based, `cursor` and `page_size` (up to 100 on shipments), with next and prev links in the HTTP Link header"
        },
        {
          "label": "Errors",
          "value": "JSON:API error objects with `status`, `code` and `detail`. Synchronous announce responses carry carrier failures in an `errors` array"
        },
        {
          "label": "Safe retries",
          "value": "A repeated `external_reference_id` on shipment creation returns the existing shipment with 409. Tracking registration is idempotent on source_id and carrier_code"
        },
        {
          "label": "Testing",
          "value": "No sandbox. `sendcloud:letter` and `sendcloud:letterreturn` labels are free, limited to 50 per the pricing page. Other labels are charged unless cancelled in time"
        },
        {
          "label": "Webhooks",
          "value": "Five webhook payloads (parcel status changed, return created, integration connected, modified, deleted) and an Event Subscriptions API with 12 operations"
        },
        {
          "label": "Status",
          "value": "status.sendcloud.com, with components for the Sendcloud API, panel, returns, tracking page and each carrier and shop integration"
        },
        {
          "label": "Certifications",
          "value": "ISO/IEC 27001:2022 per trust.sendcloud.com. Annual third-party penetration tests per the security page. Private HackerOne programme"
        },
        {
          "label": "Hosting and sub-processors",
          "value": "AWS EU Central and EU North, with availability zones in Frankfurt. Trust centre lists Twilio, Trustpilot, Zendesk, CM.com and AWS"
        }
      ],
      "unitPrices": [
        {
          "item": "Lite plan",
          "unit": "month",
          "usd": 31.3,
          "note": "€28, 400 labels a month, plus €0.10 a label"
        },
        {
          "item": "Growth plan",
          "unit": "month",
          "usd": 97.24,
          "note": "€87, 1,000 labels a month, plus €0.09 a label"
        },
        {
          "item": "Premium plan",
          "unit": "month",
          "usd": 195.6,
          "note": "€175, 10,000 labels a month, plus €0.08 a label"
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 714.21,
          "note": "€639, 30,000 labels a month, plus €0.07 a label"
        },
        {
          "item": "Label fee on Lite",
          "unit": "tx",
          "usd": 0.11,
          "note": "€0.10 a label on top of carrier postage, €0.25 above the monthly limit"
        }
      ],
      "provenance": {
        "legalEntity": "Sendcloud B.V.",
        "domain": "sendcloud.com",
        "domainRegistered": "2008-07-29",
        "endpointOnVendorDomain": true,
        "terms": "https://www.sendcloud.com/terms-conditions/",
        "privacy": "https://www.sendcloud.com/privacy-policy/",
        "statusPage": "https://status.sendcloud.com",
        "changelog": "https://sendcloud.dev/api/v3/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The terms, last updated 1 September 2026, name Sendcloud B.V., registration 66572959, Stadhuisplein 10, 5611 EM Eindhoven, with Sendcloud GmbH, Ltd., SAS and Srl for Germany and Austria, the UK, France and Italy. Dutch law applies.",
          "The MCP server answers at mcp.sendcloud.com and tokens come from account.sendcloud.com. The REST API answers at panel.sendcloud.sc, a second Sendcloud domain.",
          "www.sendcloud.com/.well-known/security.txt and /security.txt return 404. The bug bounty page sends reports to security@sendcloud.com.",
          "RDAP for sendcloud.com gives a registration date of 2008-07-29.",
          "Unit prices are converted from euros at the ECB reference rate of 1.1177 for 7 October 2026, read through api.frankfurter.dev."
        ],
        "score": 81,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Sendcloud B.V.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "sendcloud.com, registered 2008-07-29 (18 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "mcp.sendcloud.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 2.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 6 of the 8 things a reader expects",
            "points": 8.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.sendcloud.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.sendcloud.com/terms-conditions/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 4863,
            "points": 2.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "All disputes arising from the Services and Terms between the Parties will be settled by the competent Dutch court in the judicial district of Oost-Brabant."
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "If and insofar as no payment can be made under this insurance, for whatever reason, the total liability, regardless of its basis, will always be limited to the amount charged by Sendcloud under the relevant Subscription and capped at €10,000.00.",
                "says": "Capped at €10,000.00"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "In case such a change of these Terms has a material adverse effect on the Customer, the Customer may terminate its active Subscription by sending a written notice to Sendcloud."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "1.3 Sendcloud is permitted to make interim unilateral amendments to these Terms, giving a thirty (30) days prior notice to the Customer.",
                "says": "Gives thirty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "(i) not to use the Services in any way that is illegal, fraudulent, deceptive, or harmful;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "(ix) not to engage in scraping, data mining, or any other automated methods to access or extract data from the Services without Sendcloud’s prior written consent;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(iii) not to access or use the Services to build a competitive product or service, or to benchmark the Services against other products;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "12.2 Sendcloud is permitted to make interim unilateral changes to Transport Fees with immediate effect and without any prior notice.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Breach of the confidentiality or intellectual property articles carries a penalty of 10,000 euros for each contravention, plus 100 euros for each day it continues.",
                "quote": "the Customer, with no need for a demand or other prior notice, will forfeit an immediately due and payable penalty of €10,000.00 (ten thousand euros) for each contravention"
              },
              {
                "date": "2026-10-08",
                "text": "Transport fees fall due when a shipping label is created, whether or not the label is used.",
                "quote": "12.5 The Transport Fees for shipping labels are due upon label creation, regardless of the actual use of the shipping label by the Customer."
              },
              {
                "date": "2026-10-08",
                "text": "Prices may rise once every twelve months by the greater of five per cent or euro area inflation, and the customer has no termination right for that rise.",
                "quote": "The adjustment shall be the greater of either: (i) a five percent (5%) increase; or (ii) the percentage change in the Harmonised Index of Consumer Prices (HICP) for the Euro area as published by Eurostat over the preceding twelve (12) months."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.sendcloud.com/privacy-policy/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 1630,
            "points": 8.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "In any case, we collect the following access and web access data (which we call “Usage Data”):"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "These server log files are deleted after a maximum of 7 days.",
                "says": "Names a period of 7 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "This means that Sendcloud, according to a contractual agreement, is strictly subject to the customer’s instructions and will process all data as the customer’s technical service provider without its own decision-making authority with regard to the processing of personal data by the customer."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You can assert the following rights against us within the framework of the GDPR with regard to your personal data:"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions regarding this Privacy Policy, please reach out to us at privacy@sendcloud.com.",
                "says": "privacy@sendcloud.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "In such cases and in accordance with the regulations in force, Sendcloud requires its data processors to provide the necessary safeguards to ensure regulated, secure transfers, mainly by requiring them to sign the European Commission’s standard contractual clauses.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The policy covers the Sendcloud website, and says that for its integrations Sendcloud processes data only on the instructions of the customer that installed them.",
                "quote": "In this case, Sendcloud will only act as an order processor."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/sendcloud.json",
      "live": {
        "slug": "sendcloud",
        "probe": {
          "target": "https://mcp.sendcloud.com/mcp",
          "method": "get",
          "lastAt": "2026-10-08T17:36:45.156031945Z",
          "lastOk": true,
          "lastStatus": 405,
          "lastMs": 74,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 84,
          "p95ms24h": 126,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.sendcloud.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T17:25:42.672960135Z"
        },
        "securityTxt": {
          "url": "https://sendcloud.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:40.272539649Z"
        },
        "updatedAt": "2026-10-08T17:36:45.156031945Z"
      }
    },
    "verify": {
      "accepts": "a page on sendcloud.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/sendcloud.svg",
      "body": {
        "slug": "sendcloud",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/sendcloud",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/sendcloud\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/sendcloud.svg\" alt=\"Sendcloud on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Sendcloud on Anchor Terminal](https://www.anchorterminal.com/badges/sendcloud.svg)](https://www.anchorterminal.com/tools/sendcloud)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/sendcloud\"\u003eSendcloud on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/sendcloud",
    "json": "https://www.anchorterminal.com/tools/sendcloud.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/sendcloud.md",
    "slim": "https://www.anchorterminal.com/tools/sendcloud.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 62/100 · rank #314 of 629 · #2 in Shipping \u0026 fulfilment · not agent-ready · confidence medium**\n\n\n## Assessment\n\nAPI v3 has 29 public OpenAPI 3.1 specs, an llms.txt index, a dated changelog and a hosted MCP server with toolset filtering. OAuth has one scope, `api`, so a credential can't be limited to reading. The changelog records response fields removed from tracking events on 25 September 2026 with no earlier deprecation entry.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Sendcloud B.V. (https://www.sendcloud.com) |\n| Kind | HTTP API |\n| Category | Shipping \u0026 fulfilment (https://www.anchorterminal.com/categories/shipping) |\n| Transport | HTTP |\n| Endpoint | `https://mcp.sendcloud.com/mcp` |\n| Auth | OAuth or key · Self-serve. A person signs up at account.sendcloud.com, adds an invoice and sender address, then creates a Sendcloud API integration in the panel, which issues a public and secret key pair. The pair works as HTTP Basic or is exchanged at https://account.sendcloud.com/oauth2/token for a one-hour Bearer token (client credentials, scope `api`). The MCP server uses an OAuth 2.0 sign-in at account.sendcloud.com, found through RFC 9728 metadata, with the same single scope. No partner or sales approval is needed for API v3. |\n| Pricing | Freemium ($31.30 / mo) · Free plan at €0 for up to 20 parcels a month at Sendcloud's carrier rates, and a 14-day trial of paid plans with no card per the pricing page. Lite is €28 a month plus €0.10 a label, Growth €87 plus €0.09, Premium €175 plus €0.08, Pro €639 plus €0.07, Enterprise on request, with 20 per cent off for yearly billing. Carrier postage is extra. There is no sandbox, but 50 Unstamped letter test labels are free. The pricing table has an API access row whose per-plan marks we couldn't read (https://www.sendcloud.com/pricing/). |\n| x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-07). |\n| Licence | Proprietary service under Sendcloud's terms and conditions |\n| Docs | https://sendcloud.dev |\n| llms.txt | https://sendcloud.dev/llms.txt |\n| Last release | 2026-10-05 |\n| Surfaces | API v3 at https://panel.sendcloud.sc/api/v3 (104 operations in 29 OpenAPI 3.1 specs) and a hosted MCP server at https://mcp.sendcloud.com/mcp. API v2 is legacy |\n| MCP server | Streamable HTTP, OAuth 2.0 with discovery through RFC 9728 metadata, scope `api`. 24 toolsets, all on by default, narrowed with `?toolsets=`. Tool names follow `\u003ctoolset\u003e_\u003coperationId\u003e` |\n| Credentials | A public and secret key pair per API integration, created in the panel, sent as HTTP Basic or exchanged for a one-hour Bearer token (client credentials, scope `api`) |\n| Rate limits | 1,000 GET requests a minute. 100 POST, PATCH, PUT or DELETE requests a minute, burst 15 a second. 429 when exceeded |\n| Pagination | Cursor-based, `cursor` and `page_size` (up to 100 on shipments), with next and prev links in the HTTP Link header |\n| Errors | JSON:API error objects with `status`, `code` and `detail`. Synchronous announce responses carry carrier failures in an `errors` array |\n| Safe retries | A repeated `external_reference_id` on shipment creation returns the existing shipment with 409. Tracking registration is idempotent on source_id and carrier_code |\n| Testing | No sandbox. `sendcloud:letter` and `sendcloud:letterreturn` labels are free, limited to 50 per the pricing page. Other labels are charged unless cancelled in time |\n| Webhooks | Five webhook payloads (parcel status changed, return created, integration connected, modified, deleted) and an Event Subscriptions API with 12 operations |\n| Status | status.sendcloud.com, with components for the Sendcloud API, panel, returns, tracking page and each carrier and shop integration |\n| Certifications | ISO/IEC 27001:2022 per trust.sendcloud.com. Annual third-party penetration tests per the security page. Private HackerOne programme |\n| Hosting and sub-processors | AWS EU Central and EU North, with availability zones in Frankfurt. Trust centre lists Twilio, Trustpilot, Zendesk, CM.com and AWS |\n| Capabilities | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns |\n| Tags | hosted, freemium, free-tier, mcp, oauth, api-key, openapi, llms-txt, webhooks, status-page, europe, iso27001 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/sendcloud.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 68 | 13.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 89 | 14.5 |\n| Agent ergonomics | 13% | 16.2 | 71 | 11.5 |\n| Security \u0026 auth | 14% | 17.5 | 49 | 8.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 37 | 4.6 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 67 | 5.9 |\n| Transparency \u0026 trust (editorial 62, provenance 81) | 7% | 8.8 | 72 | 6.3 |\n| Negative events | up to −15 | up to −15 | 21 and 25 September 2026. The API v3 changelog records `insurance.currency` and `insurance.value` removed from POST /parcels/tracking, and `status_code`, `status_description` and `sub_status_code` removed from tracking event responses, with no earlier deprecation entry for those fields. The changes are documented on the day, so the deduction is the minimum (https://sendcloud.dev/api/v3/changelog.md)  | -3 |\n| **Total** | | | | **62 → B** |\n\n### Why each score\n\n- Reliability 68: Graded on API v3 and the hosted MCP server, with the hosted lines. Statuspage at status.sendcloud.com with components for the API, the panel and each carrier and integration (20). 25 incidents between 8 July and 7 October 2026. Twelve are marked major or critical and each concerns one carrier's label announcements, mostly labelled third-party. Platform-side entries are minor, the longest a four-hour integration connection problem on 14 September and 94 minutes of label announcement issues across several carriers on 8 September. None names the Sendcloud API component, so we scored between minor-only and one major (15). Limits published, 1,000 safe and 100 unsafe requests a minute with a burst of 15 a second (15). 429 is documented without Retry-After or backoff guidance. A repeated `external_reference_id` returns the existing shipment (8). The home page claims 99.99 per cent uptime, and no SLA document was found (0). API v3 is the current version and the MCP page carries no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 89: 29 OpenAPI 3.1 specs for API v3, 104 operations, linked from llms.txt (25). llms.txt and a Markdown copy of every docs page (10). Every operation has a description. Some state limits, such as when a cancellation is rejected, and many are one sentence. MCP tools take their text from the same specs (13). 243 enums, required fields and maxima such as `page_size` up to 100 (13). 216 example blocks and JSON:API error objects with `status`, `code` and `detail`. 429 responses appear only in the Support API spec (13). Versioned v2 and v3 with a dated v3 changelog of 155 entries back to 25 May 2023 (15).\n- Agent ergonomics 71: The MCP server makes one tool per operation, about 98 by the specs for its 24 toolsets, all on by default, which scores 5, and a `?toolsets=` filter enforced on calls adds 10. The API has `page_size` and no field selection (15). Cursor pagination through Link headers and filters by status, tracking number, reference and dates on shipments (18). JSON:API errors, though a carrier failure on a synchronous announce arrives in an `errors` array inside a success response (15). `external_reference_id` deduplicates shipment creation, and the docs say tools carry read-only, idempotent and destructive hints by HTTP method, which we couldn't confirm without an account (16). Shipping rules and defaults cut required fields. No official SDK was found (7).\n- Security \u0026 auth 49: A key pair per API integration, usable as Basic or exchanged for a one-hour Bearer token, and OAuth with PKCE for MCP. The only scope is `api`, which covers the whole account (20). No read-only credential found. The MCP toolset filter is enforced on the server, and annotations let a client prompt before creates and cancels (8). Responses carry text written by others, such as addresses, order data and support tickets. The MCP page says results are reference information only and gives no injection guidance (3). Integration exception logs are in the API. No per-call audit view found (3). ISO/IEC 27001:2022, annual penetration tests, a private HackerOne programme and a disclosure address. No security.txt and no SOC 2 found (15).\n- Payments \u0026 pricing 37: No x402, MPP or L402 (0). Plan prices and per-label fees are public in euros, from €28 a month plus €0.10 a label to €639 plus €0.07, with sample carrier rates. We couldn't read which plans the API access row covers (17). A Free plan for 20 parcels a month and a 14-day trial, both stated as needing no card, plus free Unstamped letter test labels (20). A person signs up in a browser, adds an invoice address and creates the keys in the panel (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 67: Latest API v3 changelog entry 5 October 2026 (30). 37 dated entries between 9 July and 5 October (20). Closed service with a dated changelog and a help centre with email and chat support. No developer forum or public issue tracker found (9). The MCP server isn't in the official MCP registry, and no official SDK was found. A public Postman workspace exists (3). No packages to assess. The specs change with the changelog (5).\n- Transparency \u0026 trust 72: Closed service with terms dated 1 September 2026 naming Sendcloud B.V. and four country entities (15). The privacy policy keeps server logs for at most 7 days and contact forms for 6 years. The DPA deletes customers' order data within 365 days of shipment completion and gives 30 days' notice of new sub-processors. Neither page showed a version date we could read (22). API v2 maintenance mode announced for April 2026, and one endpoint deprecated with a date (9 June 2026). Other deprecated fields are to go \"in a future version\", and no notice-period policy was found (10). Trust centre names five sub-processors, and the security page names AWS EU Central and EU North (15).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/sendcloud.md (JSON https://www.anchorterminal.com/fixes/sendcloud.json)\n\n### What we couldn't check\n\n- unchecked: which plans include API access. The pricing table has the row, and its per-plan marks didn't survive our reader\n- unchecked: the live MCP tool list, tool count and annotations, which need an account. About 98 tools is our count from the specs\n- unchecked: effective dates of the privacy policy and the DPA\n- Whether the September 2026 field removals changed live responses or corrected the specs to match them\n- Whether a payment method is required before the first paid label on the Free plan\n- Whether an SLA exists on Enterprise, and whether Sendcloud keeps official SDKs or a public GitHub organisation (github.com was not reachable from our shell)\n- Home-page figures (170+ carriers, 30,000+ merchants, 99.99 per cent uptime) are Sendcloud's claims\n\n### Sources\n\n- home page claims and links: \u003chttps://www.sendcloud.com/\u003e (seen 2026-10-07)\n- docs index (llms.txt): \u003chttps://sendcloud.dev/llms.txt\u003e (seen 2026-10-07)\n- MCP server docs: \u003chttps://sendcloud.dev/docs/getting-started/mcp-server.md\u003e (seen 2026-10-07)\n- MCP protected-resource metadata: \u003chttps://mcp.sendcloud.com/.well-known/oauth-protected-resource/mcp\u003e (seen 2026-10-07)\n- authentication: \u003chttps://sendcloud.dev/docs/getting-started/authentication.md\u003e (seen 2026-10-07)\n- rate limits: \u003chttps://sendcloud.dev/docs/getting-started/rate-limits.md\u003e (seen 2026-10-07)\n- pagination: \u003chttps://sendcloud.dev/api/v3/pagination.md\u003e (seen 2026-10-07)\n- test labels: \u003chttps://sendcloud.dev/docs/getting-started/creating-test-labels.md\u003e (seen 2026-10-07)\n- API version guide: \u003chttps://sendcloud.dev/docs/getting-started/api-version-guide.md\u003e (seen 2026-10-07)\n- API v3 changelog: \u003chttps://sendcloud.dev/api/v3/changelog.md\u003e (seen 2026-10-07)\n- Shipments OpenAPI spec (one of 29 read): \u003chttps://sendcloud.dev/.openapi/v3/shipments/openapi.yaml\u003e (seen 2026-10-07)\n- status incidents: \u003chttps://status.sendcloud.com/api/v2/incidents.json\u003e (seen 2026-10-07)\n- pricing: \u003chttps://www.sendcloud.com/pricing/\u003e (seen 2026-10-07)\n- terms and conditions: \u003chttps://www.sendcloud.com/terms-conditions/\u003e (seen 2026-10-07)\n- privacy policy: \u003chttps://www.sendcloud.com/privacy-policy/\u003e (seen 2026-10-07)\n- data processing addendum: \u003chttps://www.sendcloud.com/data-processing-addendum/\u003e (seen 2026-10-07)\n- security page: \u003chttps://www.sendcloud.com/security/\u003e (seen 2026-10-07)\n- trust centre: \u003chttps://trust.sendcloud.com/\u003e (seen 2026-10-07)\n- bug bounty programme: \u003chttps://www.sendcloud.com/bug-bounty-program/\u003e (seen 2026-10-07)\n- official MCP registry search (no result): \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=sendcloud\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 81/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Sendcloud B.V. | 20/20 |\n| Domain age | sendcloud.com, registered 2008-07-29 (18 years) | 15/15 |\n| Endpoint on the vendor's domain | mcp.sendcloud.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 |\n| Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 |\n| Status page | status.sendcloud.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe terms, last updated 1 September 2026, name Sendcloud B.V., registration 66572959, Stadhuisplein 10, 5611 EM Eindhoven, with Sendcloud GmbH, Ltd., SAS and Srl for Germany and Austria, the UK, France and Italy. Dutch law applies.\n\nThe MCP server answers at mcp.sendcloud.com and tokens come from account.sendcloud.com. The REST API answers at panel.sendcloud.sc, a second Sendcloud domain.\n\nwww.sendcloud.com/.well-known/security.txt and /security.txt return 404. The bug bounty page sends reports to security@sendcloud.com.\n\nRDAP for sendcloud.com gives a registration date of 2008-07-29.\n\nUnit prices are converted from euros at the ECB reference rate of 1.1177 for 7 October 2026, read through api.frankfurter.dev.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.sendcloud.com/terms-conditions/), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"(ix) not to engage in scraping, data mining, or any other automated methods to access or extract data from the Services without Sendcloud’s prior written consent;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"(iii) not to access or use the Services to build a competitive product or service, or to benchmark the Services against other products;\"\n- To know. Says the terms or the service can change without notice (costs points). \"12.2 Sendcloud is permitted to make interim unilateral changes to Transport Fees with immediate effect and without any prior notice.\"\n- Not found in the text. Gives the date it was last updated.\n- States a limit on its liability. Capped at €10,000.00.\n- Says how changes to the terms are announced. Gives thirty days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Breach of the confidentiality or intellectual property articles carries a penalty of 10,000 euros for each contravention, plus 100 euros for each day it continues. \"the Customer, with no need for a demand or other prior notice, will forfeit an immediately due and payable penalty of €10,000.00 (ten thousand euros) for each contravention\"\n- Also in the text (2026-10-08). Transport fees fall due when a shipping label is created, whether or not the label is used. \"12.5 The Transport Fees for shipping labels are due upon label creation, regardless of the actual use of the shipping label by the Customer.\"\n- Also in the text (2026-10-08). Prices may rise once every twelve months by the greater of five per cent or euro area inflation, and the customer has no termination right for that rise. \"The adjustment shall be the greater of either: (i) a five percent (5%) increase; or (ii) the percentage change in the Harmonised Index of Consumer Prices (HICP) for the Euro area as published by Eurostat over the preceding twelve (12) months.\"\n\n**Privacy policy** (https://www.sendcloud.com/privacy-policy/), read 2026-10-08, gives no date, states 6 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. Names a period of 7 days.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Gives a privacy contact. privacy@sendcloud.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). The policy covers the Sendcloud website, and says that for its integrations Sendcloud processes data only on the instructions of the customer that installed them. \"In this case, Sendcloud will only act as an order processor.\"\n\n## Live (updated 2026-10-08 17:36 UTC)\n\n- Right now: up, HTTP 405, 74 ms, checked 2026-10-08 17:36 UTC (get on `https://mcp.sendcloud.com/mcp`)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 84 ms · p95 126 ms\n- Vendor status page: none, All Systems Operational\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/sendcloud.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Lite plan | $31.30 | per month (plan) | €28, 400 labels a month, plus €0.10 a label |\n| Growth plan | $97.24 | per month (plan) | €87, 1,000 labels a month, plus €0.09 a label |\n| Premium plan | $195.60 | per month (plan) | €175, 10,000 labels a month, plus €0.08 a label |\n| Pro plan | $714.21 | per month (plan) | €639, 30,000 labels a month, plus €0.07 a label |\n| Label fee on Lite | $0.11 | per transaction | €0.10 a label on top of carrier postage, €0.25 above the monthly limit |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- 29 public OpenAPI 3.1 specs covering 104 API v3 operations, with an llms.txt index and Markdown copies of every docs page\n- Hosted MCP server at mcp.sendcloud.com/mcp with 24 toolsets, a `?toolsets=` filter and read-only, idempotent and destructive annotations per the docs\n- A repeated `external_reference_id` on shipment creation returns the existing shipment with a 409 instead of buying a second label\n- Free test labels through the `sendcloud:letter` and `sendcloud:letterreturn` shipping options, up to 50 before charges apply\n- Dated API v3 changelog with 37 entries between 9 July and 5 October 2026\n\n## Weaknesses\n\n- One OAuth scope, `api`, and key pairs with full account access. No read-only credential was found in the reviewed documentation\n- Changelog entries of 21 and 25 September 2026 record removed request and response fields on parcel tracking with no earlier deprecation entry\n- No Retry-After header or backoff guidance was found for 429 responses\n- No official SDK was found in the reviewed documentation, and the MCP server isn't in the official MCP registry\n- No test environment. Labels other than the Unstamped letter options are charged unless the carrier accepts a cancellation\n\n## Before you call it (notes for agents)\n\n1. Use API v3 at https://panel.sendcloud.sc/api/v3. The v2 create-parcel endpoint is closed to accounts created from April 2026\n2. Test with `shipping_option_code` `sendcloud:letter` (returns use `sendcloud:letterreturn`). Any other label is billed unless cancelled within the carrier's deadline\n3. Set `external_reference_id` on every shipment so a retry returns the existing shipment (409) instead of a second label\n4. Read the `errors` array on synchronous announce responses. A carrier failure can arrive inside a success status\n5. Connect MCP with `?toolsets=shipments,shipping-options,parcel-tracking,returns` to keep the tool list short. Create and cancel tools act on the live account\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X POST --location \"https://account.sendcloud.com/oauth2/token\" \\\n  --header \"Content-Type: application/x-www-form-urlencoded\" \\\n  -d \"grant_type=client_credentials\u0026scope=api\" \\\n  --basic --user your_sendcloud_public_key:your_sendcloud_private_key\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http sendcloud https://mcp.sendcloud.com/mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"sendcloud\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.sendcloud.com/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/sendcloud. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Easyship | B | 68.8 | 163 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/easyship.md |\n| Shippo | C | 61.9 | 317 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/shippo.md |\n| ShipStation API | C | 59.3 | 382 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/shipstation.md |\n| EasyPost | C | 54.3 | 468 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/easypost.md |\n| TaxJar | C | 57.6 | 417 | shipping.address-validation | no | https://www.anchorterminal.com/tools/taxjar.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The MCP server is hosted at https://mcp.sendcloud.com/mcp over Streamable HTTP with OAuth 2.0, one tool per API v3 operation in 24 toolsets, and a `?toolsets=` filter that also rejects calls outside the selection (source: \u003chttps://sendcloud.dev/docs/getting-started/mcp-server.md\u003e)\n- API v2 entered maintenance mode in April 2026. Its create-parcel endpoint is closed to new accounts, and llms.txt tells assistants to write v3 code only (source: \u003chttps://sendcloud.dev/docs/getting-started/api-version-guide.md\u003e)\n- Default rate limits are 1,000 GET requests a minute and 100 POST, PATCH, PUT or DELETE requests a minute with a burst of 15 a second (source: \u003chttps://sendcloud.dev/docs/getting-started/rate-limits.md\u003e)\n- Two free shipping options exist for testing, `sendcloud:letter` and `sendcloud:letterreturn`. There is no separate test environment (source: \u003chttps://sendcloud.dev/docs/getting-started/creating-test-labels.md\u003e)\n- status.sendcloud.com lists 25 incidents between 8 July and 7 October 2026. Most are one carrier's label announcements, and none names the Sendcloud API component (source: \u003chttps://status.sendcloud.com/api/v2/incidents.json\u003e)\n- ISO/IEC 27001:2022 on the trust centre, hosting on AWS in Frankfurt, and a private HackerOne programme reached through security@sendcloud.com (source: \u003chttps://trust.sendcloud.com/, https://www.sendcloud.com/bug-bounty-program/\u003e)\n\n## Compare\n\n- [EasyPost vs Sendcloud](https://www.anchorterminal.com/compare/easypost-vs-sendcloud.md): C 54.3 vs B 62\n- [Easyship vs Sendcloud](https://www.anchorterminal.com/compare/easyship-vs-sendcloud.md): B 68.8 vs B 62\n- [Sendcloud vs Shippo](https://www.anchorterminal.com/compare/sendcloud-vs-shippo.md): B 62 vs C 61.9\n- [Sendcloud vs ShipStation API](https://www.anchorterminal.com/compare/sendcloud-vs-shipstation.md): B 62 vs C 59.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on sendcloud.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"sendcloud\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/sendcloud\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/sendcloud.svg\" alt=\"Sendcloud on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Sendcloud on Anchor Terminal](https://www.anchorterminal.com/badges/sendcloud.svg)](https://www.anchorterminal.com/tools/sendcloud)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/sendcloud\"\u003eSendcloud on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Sendcloud is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/sendcloud-dark.png\n- Light: https://www.anchorterminal.com/assets/share/sendcloud-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Shipping \u0026 fulfilment",
        "url": "https://www.anchorterminal.com/categories/shipping"
      },
      {
        "name": "Sendcloud",
        "url": ""
      }
    ],
    "description": "Shipping platform for European online shops from Sendcloud B.V. in Eindhoven. Its API v3 and hosted MCP server quote carrier rates, create labels, validate addresses, track parcels and handle returns across the carriers an account has enabled.",
    "facts": [
      "rank #314 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Sendcloud",
    "image": "https://www.anchorterminal.com/assets/og/tools-sendcloud.png",
    "path": "/tools/sendcloud",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Sendcloud review for AI agents, grade B (62/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/sendcloud"
  },
  "tokens": {
    "markdown": 7050,
    "slim": 1780
  },
  "version": 1
}
