{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/easyship.json",
        "name": "Easyship",
        "score": 68.8,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "easyship"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/sendcloud.json",
        "name": "Sendcloud",
        "score": 62,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "sendcloud"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/shippo.json",
        "name": "Shippo",
        "score": 61.9,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "shippo"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/easypost.json",
        "name": "EasyPost",
        "score": 54.3,
        "shared": [
          "shipping.rates",
          "shipping.labels",
          "shipping.tracking",
          "shipping.address-validation",
          "shipping.returns"
        ],
        "slug": "easypost"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/taxjar.json",
        "name": "TaxJar",
        "score": 57.6,
        "shared": [
          "shipping.address-validation"
        ],
        "slug": "taxjar"
      }
    ],
    "tool": {
      "slug": "shipstation",
      "name": "ShipStation API",
      "vendor": "Auctane LLC d/b/a ShipStation",
      "vendorUrl": "https://www.shipstation.com",
      "kind": "http-api",
      "category": "shipping",
      "summary": "Multi-carrier shipping API from ShipStation, an Auctane brand. API v2 at api.shipstation.com/v2 quotes rates, buys and voids labels, validates addresses, tracks parcels and creates return labels, with batches, manifests, pickups and inventory.",
      "url": "https://www.anchorterminal.com/tools/shipstation",
      "markdownUrl": "https://www.anchorterminal.com/tools/shipstation.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shipstation.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shipstation.json",
      "repo": "https://github.com/ShipEngine/shipengine-openapi",
      "license": "Proprietary service under ShipStation's terms of service. The v2 OpenAPI file is marked MIT and the SDKs on GitHub are Apache 2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.shipstation.com/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "shipengine"
        },
        {
          "registry": "pypi",
          "name": "shipengine"
        }
      ],
      "auth": "api-key",
      "authNotes": "Self-serve API key sent in an `API-Key` header, with no partner or sales approval. Two routes lead to a v2 key. A ShipStation API account (formerly ShipEngine) gets production keys and `TEST_` sandbox keys from api-portal.shipstation.com on every plan, Free included. A ShipStation platform account needs the Standard or Premium plan and generates one v2 key at a time in API Settings, shown once. The docs say the key gives full access to the account. No OAuth, scopes or read-only keys were found.",
      "pricing": "freemium",
      "pricingNotes": "ShipStation API (formerly ShipEngine) has a Free plan at $0 with a sandbox and, by the pricing page, no card. Advanced is $75 a month for 1,000 labels ($0.075 a label over), $325 for 5,000 ($0.065) or $600 for 10,000 ($0.060), and Enterprise is by quote from 25,000 shipments a month. On the ShipStation platform the API comes with Standard (from $29.99 a month for 50 shipments) and Premium (from $349.99), after a 30-day trial with no card, and has no sandbox. Postage is charged separately at carrier rates (checked 2026-10-07).",
      "priceSummary": "$75 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the v2 docs, the OpenAPI spec or the pricing pages (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 6835,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://docs.shipstation.com/api-overview",
      "llmsTxt": "https://docs.shipstation.com/llms.txt",
      "openapi": "https://docs.shipstation.com/_bundle/apis/@shipstation-v2/openapi.yaml",
      "capabilities": [
        "shipping.rates",
        "shipping.labels",
        "shipping.tracking",
        "shipping.address-validation",
        "shipping.returns"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "sandbox",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "python",
        "javascript",
        "dotnet",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.3,
        "grade": "C",
        "agentReady": false,
        "rank": 382,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 73,
          "payments": 40,
          "reliability": 64,
          "schema": 83,
          "security": 32,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 64,
            "points": 12.8,
            "reason": "Graded on ShipStation API v2 at api.shipstation.com/v2, with the hosted lines. Statuspage at status.shipstation.com with components for Companion API V1 and V2, carriers and marketplaces (20). From 9 July to 7 October 2026 it lists 12 incidents, three marked major. Two were carrier-specific (Evri label creation for 29 hours from 24 September, DPD Local and DX for 6 hours on 11 September) and one was a duplicate package option for 79 minutes on 14 July. None names the API component, so we scored between minor-only and one major (15). 200 requests a minute by default (15). 429 responses carry `Retry-After` and the docs ask for retries handled globally, but no idempotency key exists for label purchases (9). No SLA found (0). The getting-started page says v2 \"is currently in an early release stage\" while calling it tested and stable (5)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 83,
            "points": 13.49,
            "reason": "OpenAPI 3.1 for v2 at docs.shipstation.com/_bundle/apis/@shipstation-v2/openapi.yaml, 173 operations on 123 paths and 372 schemas (25). llms.txt with 480 lines of links and a Markdown copy of each docs page (10). Guides explain when to use rates against estimates and webhooks against polling. Operation descriptions in the spec are one line each (13). 152 enums, required fields and read-only markers, though carrier and service codes are free strings that depend on the account (12). 1,648 example entries and enumerated `error_code` and `error_type` values. The spec documents 400, 404 and 500 but no 401 or 429 response (11). Release notes are dated by month and the spec version has stayed 2.0.0 through every addition (12)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 64,
            "points": 10.4,
            "reason": "No MCP server that performs shipping operations. The MCP server at docs.shipstation.com/mcp reads documentation only. List endpoints take `page_size`. No field selection was found (12). `page`, `page_size`, `sort_by`, `sort_dir` and filters by status, tag, dates, store and external id on list calls (20). Errors carry `error_source`, `error_type`, `error_code`, `message`, field names and a `request_id` (18). No idempotency keys. `external_shipment_id` is unique per shipment, labels can be voided and `test_label` exists, which we counted as partial safe-retry support (6). Official SDKs in six languages call api.shipengine.com/v1, not v2, and a label needs a `carrier_id` and `service_code` looked up first (8)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 32,
            "points": 5.6,
            "reason": "One secret in an `API-Key` header. The docs say the key gives full access. Platform accounts hold one active v2 key that can be regenerated, and ShipStation API accounts have separate `TEST_` sandbox keys (17). No scopes, read-only keys or confirmation before a label purchase. The sandbox key is the only lower-risk mode (5). Responses carry order text, addresses and carrier messages written by others, with no injection guidance (3). A `request_id` on every response. No per-key audit log found in the docs (3). TLS 1.2 or higher required, HSTS on the API host and RSA-SHA256 signed webhooks with a JWKS. security.txt returns 404 on three hosts, and no certification, bug bounty or disclosure policy was found on the pages we read (4)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). ShipStation API prices are public without a login. Free at $0, Advanced at $75 a month for 1,000 labels with $0.075 per label over, $325 for 5,000 and $600 for 10,000, Enterprise by quote. Platform plans are public too, with API access from Standard at $29.99 a month for 50 shipments (20). The Free plan and its sandbox need no card according to the pricing page (20). A person signs up in a browser to get a key (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 73,
            "points": 6.39,
            "reason": "Release notes list packing slips for batches under October 2026 (30). Dated entries for August, September and October 2026, each adding endpoints (20). Closed service with monthly release notes, an API support address (apisupport@shipstation.com) and a community forum. We couldn't measure reply times (10). Official SDKs exist in six languages. Python 2.1.1 shipped on 6 May 2026 and .NET v3.2.1 on 27 May 2026, while JavaScript 1.0.7 dates from 31 January 2024 and PHP 1.0.0 from 2021, and all call the v1 ShipEngine host (8). SDK repositories have CI workflows. The OpenAPI repository on GitHub was last changed on 11 June 2026 (5)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 64,
            "points": 5.6,
            "note": "editorial 42, provenance 85",
            "reason": "Closed service under terms of service effective 16 July 2026 that name Auctane LLC d/b/a ShipStation. The v2 OpenAPI file is marked MIT and the SDKs are Apache 2.0 (16). The privacy policy, effective 18 March 2026, is Auctane, Inc.'s for all its brands. It keeps data \"as long as necessary\" with no periods, and says third parties may not train AI models on personal information. No public DPA was found (12). The legacy V1 API is described as deprecated with removal \"in the future\" and no date, and the terms let ShipStation withdraw API access at its discretion (6). US persons' data stays in the United States and EEA and UK data may move there under the Data Privacy Framework. Service providers are named by type, with no subprocessor list (8)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "No MCP server that performs shipping operations. The MCP server at docs.shipstation.com/mcp reads documentation only. List endpoints take `page_size`. No field selection was found (12). `page`, `page_size`, `sort_by`, `sort_dir` and filters by status, tag, dates, store and external id on list calls (20). Errors carry `error_source`, `error_type`, `error_code`, `message`, field names and a `request_id` (18). No idempotency keys. `external_shipment_id` is unique per shipment, labels can be voided and `test_label` exists, which we counted as partial safe-retry support (6). Official SDKs in six languages call api.shipengine.com/v1, not v2, and a label needs a `carrier_id` and `service_code` looked up first (8).",
            "maintenance": "Release notes list packing slips for batches under October 2026 (30). Dated entries for August, September and October 2026, each adding endpoints (20). Closed service with monthly release notes, an API support address (apisupport@shipstation.com) and a community forum. We couldn't measure reply times (10). Official SDKs exist in six languages. Python 2.1.1 shipped on 6 May 2026 and .NET v3.2.1 on 27 May 2026, while JavaScript 1.0.7 dates from 31 January 2024 and PHP 1.0.0 from 2021, and all call the v1 ShipEngine host (8). SDK repositories have CI workflows. The OpenAPI repository on GitHub was last changed on 11 June 2026 (5).",
            "payments": "No x402, MPP or L402 (0). ShipStation API prices are public without a login. Free at $0, Advanced at $75 a month for 1,000 labels with $0.075 per label over, $325 for 5,000 and $600 for 10,000, Enterprise by quote. Platform plans are public too, with API access from Standard at $29.99 a month for 50 shipments (20). The Free plan and its sandbox need no card according to the pricing page (20). A person signs up in a browser to get a key (0).",
            "reliability": "Graded on ShipStation API v2 at api.shipstation.com/v2, with the hosted lines. Statuspage at status.shipstation.com with components for Companion API V1 and V2, carriers and marketplaces (20). From 9 July to 7 October 2026 it lists 12 incidents, three marked major. Two were carrier-specific (Evri label creation for 29 hours from 24 September, DPD Local and DX for 6 hours on 11 September) and one was a duplicate package option for 79 minutes on 14 July. None names the API component, so we scored between minor-only and one major (15). 200 requests a minute by default (15). 429 responses carry `Retry-After` and the docs ask for retries handled globally, but no idempotency key exists for label purchases (9). No SLA found (0). The getting-started page says v2 \"is currently in an early release stage\" while calling it tested and stable (5).",
            "schema": "OpenAPI 3.1 for v2 at docs.shipstation.com/_bundle/apis/@shipstation-v2/openapi.yaml, 173 operations on 123 paths and 372 schemas (25). llms.txt with 480 lines of links and a Markdown copy of each docs page (10). Guides explain when to use rates against estimates and webhooks against polling. Operation descriptions in the spec are one line each (13). 152 enums, required fields and read-only markers, though carrier and service codes are free strings that depend on the account (12). 1,648 example entries and enumerated `error_code` and `error_type` values. The spec documents 400, 404 and 500 but no 401 or 429 response (11). Release notes are dated by month and the spec version has stayed 2.0.0 through every addition (12).",
            "security": "One secret in an `API-Key` header. The docs say the key gives full access. Platform accounts hold one active v2 key that can be regenerated, and ShipStation API accounts have separate `TEST_` sandbox keys (17). No scopes, read-only keys or confirmation before a label purchase. The sandbox key is the only lower-risk mode (5). Responses carry order text, addresses and carrier messages written by others, with no injection guidance (3). A `request_id` on every response. No per-key audit log found in the docs (3). TLS 1.2 or higher required, HSTS on the API host and RSA-SHA256 signed webhooks with a JWKS. security.txt returns 404 on three hosts, and no certification, bug bounty or disclosure policy was found on the pages we read (4).",
            "transparency": "Closed service under terms of service effective 16 July 2026 that name Auctane LLC d/b/a ShipStation. The v2 OpenAPI file is marked MIT and the SDKs are Apache 2.0 (16). The privacy policy, effective 18 March 2026, is Auctane, Inc.'s for all its brands. It keeps data \"as long as necessary\" with no periods, and says third parties may not train AI models on personal information. No public DPA was found (12). The legacy V1 API is described as deprecated with removal \"in the future\" and no date, and the terms let ShipStation withdraw API access at its discretion (6). US persons' data stays in the United States and EEA and UK data may move there under the Data Privacy Framework. Service providers are named by type, with no subprocessor list (8)."
          },
          "sources": [
            {
              "what": "API overview, three APIs and base URLs",
              "url": "https://docs.shipstation.com/api-overview",
              "seen": "2026-10-07"
            },
            {
              "what": "v2 getting started, early release statement",
              "url": "https://docs.shipstation.com/getting-started.md",
              "seen": "2026-10-07"
            },
            {
              "what": "authentication, key types and sandbox availability",
              "url": "https://docs.shipstation.com/authentication.md",
              "seen": "2026-10-07"
            },
            {
              "what": "rate limits and 429 handling",
              "url": "https://docs.shipstation.com/rate-limits.md",
              "seen": "2026-10-07"
            },
            {
              "what": "sandbox",
              "url": "https://docs.shipstation.com/sandbox.md",
              "seen": "2026-10-07"
            },
            {
              "what": "v2 OpenAPI 3.1 spec",
              "url": "https://docs.shipstation.com/_bundle/apis/@shipstation-v2/openapi.yaml",
              "seen": "2026-10-07"
            },
            {
              "what": "v2 release notes",
              "url": "https://docs.shipstation.com/apis/release-notes.md",
              "seen": "2026-10-07"
            },
            {
              "what": "llms.txt",
              "url": "https://docs.shipstation.com/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "documentation MCP server",
              "url": "https://docs.shipstation.com/connect-mcp.md",
              "seen": "2026-10-07"
            },
            {
              "what": "endpoints by plan",
              "url": "https://docs.shipstation.com/plans/shipstation-api-free",
              "seen": "2026-10-07"
            },
            {
              "what": "error handling",
              "url": "https://docs.shipstation.com/apis/shipengine/docs/guides/errors.md",
              "seen": "2026-10-07"
            },
            {
              "what": "webhook signature validation",
              "url": "https://docs.shipstation.com/apis/docs/guides/webhooks-validation.md",
              "seen": "2026-10-07"
            },
            {
              "what": "tracking",
              "url": "https://docs.shipstation.com/tracking.md",
              "seen": "2026-10-07"
            },
            {
              "what": "status incidents",
              "url": "https://status.shipstation.com/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "ShipStation API pricing",
              "url": "https://www.shipstation.com/shipping-api/pricing/",
              "seen": "2026-10-07"
            },
            {
              "what": "platform pricing",
              "url": "https://www.shipstation.com/pricing/",
              "seen": "2026-10-07"
            },
            {
              "what": "terms of service",
              "url": "https://www.shipstation.com/terms-of-service/",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy policy",
              "url": "https://www.shipstationglobal.com/legal/privacy-policy/",
              "seen": "2026-10-07"
            },
            {
              "what": "SDK list",
              "url": "https://docs.shipstation.com/apis/shipengine/docs/getting-started/tools.md",
              "seen": "2026-10-07"
            },
            {
              "what": "Python SDK repository and tags",
              "url": "https://github.com/ShipEngine/shipengine-python",
              "seen": "2026-10-07"
            },
            {
              "what": "JavaScript SDK on npm",
              "url": "https://registry.npmjs.org/shipengine/latest",
              "seen": "2026-10-07"
            },
            {
              "what": "official MCP registry search, no entries",
              "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=shipstation",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: weekly PyPI downloads for shipengine (pypistats.org answered with a rate limit)",
            "unchecked: www.shipstation.com answered our shell with a bot check, so pricing, terms and the API pricing page were read through the fetch tool's summary and not as raw pages",
            "No security page, certification, bug bounty, DPA or subprocessor list was found from the docs, the legal page or a site search. One may exist behind a sales or customer login",
            "Whether the Free plan's label and call allowances are capped. The pricing page says no API usage charges without a number",
            "Whether an SLA exists on the Enterprise plan",
            "Whether the API portal shows a per-key request log, which would count as an audit trail",
            "The release notes date entries by month only. `lastRelease` 2026-10-01 stands for the October 2026 entry, whose day isn't published",
            "How long v2 stays in its stated early release stage, and the removal date for the legacy V1 API"
          ]
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.1 contract with 173 operations, Markdown docs for agents and a free ShipStation API plan with a sandbox make a first rate quote or test label reachable without a contract. One API key carries full account access, with no scopes, read-only mode or idempotency keys on label purchases.",
        "bestFor": "An agent working inside a merchant's existing ShipStation account (orders, batches, inventory, labels), or a developer who wants a free sandbox through the ShipStation API plans.",
        "strengths": [
          "Public OpenAPI 3.1 spec for v2 with 173 operations and 372 schemas, plus llms.txt and a Markdown copy of every docs page",
          "ShipStation API Free plan at $0 with no card stated, and a sandbox on every ShipStation API plan through `TEST_` keys",
          "200 requests a minute by default, with `Retry-After` on 429 responses",
          "Errors carry `error_source`, `error_type`, `error_code` and a `request_id`, and separate carrier faults from ShipStation's own",
          "Release notes show new v2 endpoints in every month from June to October 2026"
        ],
        "weaknesses": [
          "One API key with full account access. No scopes, read-only keys or approval step before a label is bought",
          "No idempotency key on label purchase, so a retry after a timeout can buy a second label",
          "ShipStation platform accounts have no sandbox, and API access needs the Standard plan (from $29.99 a month) or Premium",
          "The official SDKs call api.shipengine.com/v1, and the JavaScript SDK was last tagged on 31 January 2024",
          "No security.txt, certification, disclosure policy, DPA or named subprocessor list found on the pages we read"
        ],
        "agentNotes": [
          "Send the key in an `API-Key` header to https://api.shipstation.com/v2. A key that starts `TEST_` runs in the sandbox on the same host",
          "Call GET /v2/carriers first. Rate and label calls need `carrier_ids` or a `carrier_id` and a `service_code` from that account",
          "Don't blindly retry POST /v2/labels after a timeout. List labels first, then void a duplicate with PUT /v2/labels/{label_id}/void",
          "Check the `errors` array on 2XX responses too, and read `error_source` to tell a carrier fault from a ShipStation one",
          "On a platform (Standard or Premium) key every label is real and charged. Ask the owner before buying, and void test labels at once"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.3
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 73,
          "payments": 40,
          "reliability": 64,
          "schema": 83,
          "security": 32,
          "transparency": 42
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl -iX GET https://api.shipstation.com/v2/carriers \\\n-H 'API-Key: __YOUR_API_KEY_HERE__'",
        "claudeCode": "claude mcp add --transport http shipstation-api https://docs.shipstation.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/shipping.rates",
        "tool": "https://letme.dev/shipstation"
      },
      "notable": [
        "Three APIs sit under the ShipStation name. API v2 at api.shipstation.com/v2, the ShipStation API (formerly ShipEngine, renamed on 28 February 2025) at api.shipengine.com/v1, and the legacy V1 API at ssapi.shipstation.com (https://docs.shipstation.com/api-overview)",
        "The getting-started page says v2 \"is currently in an early release stage\" and may lack some V1 functions (https://docs.shipstation.com/getting-started)",
        "A sandbox with `TEST_` keys exists only for ShipStation API accounts. On a platform account every v2 call is production and labels are charged (https://docs.shipstation.com/sandbox)",
        "The docs say the API key gives full access to the account, and a platform account holds one v2 key at a time (https://docs.shipstation.com/authentication)",
        "The MCP server at docs.shipstation.com/mcp reads documentation only and makes no shipping calls (https://docs.shipstation.com/connect-mcp)",
        "Release notes list new v2 endpoints each month from June to October 2026, among them checkout rates, products, hold and restore, and packing slips for batches (https://docs.shipstation.com/apis/release-notes)",
        "status.shipstation.com lists 12 incidents between 9 July and 7 October 2026, three marked major, two of them limited to Evri and to DPD Local and DX (https://status.shipstation.com/history)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "ShipStation API v2, REST and JSON at https://api.shipstation.com/v2. OpenAPI 3.1, 173 operations on 123 paths"
        },
        {
          "label": "Other APIs",
          "value": "ShipStation API (formerly ShipEngine) at https://api.shipengine.com/v1, which still works with the same keys, and the legacy V1 API at https://ssapi.shipstation.com, described as deprecated with no removal date"
        },
        {
          "label": "Access",
          "value": "Self-serve API key. A ShipStation API account on any plan, Free included, or a ShipStation platform account on Standard or Premium. Platform Free and Starter plans have no API access"
        },
        {
          "label": "Sandbox",
          "value": "ShipStation API accounts only, on every plan. Keys start `TEST_` and use the same host. Test labels are free, tracking is simulated and data may be cleared. Platform accounts have no sandbox"
        },
        {
          "label": "Endpoints by plan",
          "value": "159 on ShipStation API Free, 173 on Advanced and Enterprise, 147 on platform Standard and Premium, per the docs' plan pages. POST /v2/addresses/validate and the standalone tracking calls are Advanced and Enterprise only"
        },
        {
          "label": "Rate limits",
          "value": "200 requests a minute by default, higher on request. 429 with `Retry-After` in seconds"
        },
        {
          "label": "Errors",
          "value": "An `errors` array with `error_source` (carrier, order_source, ShipStation, shipengine), `error_type`, `error_code`, `message` and a `request_id`. 2XX responses can carry partial errors"
        },
        {
          "label": "Pagination",
          "value": "`page`, `page_size`, `sort_by`, `sort_dir`, with `total`, `pages` and `links` in the response"
        },
        {
          "label": "Webhooks",
          "value": "Created with POST /v2/environment/webhooks, production only. Signed with RSA-SHA256, verified against the JWKS at https://api.shipengine.com/jwks"
        },
        {
          "label": "MCP server",
          "value": "Documentation only, at https://docs.shipstation.com/mcp, no key needed. Tools such as list-apis, get-endpoints and get-endpoint-info read the specs. It makes no shipping calls"
        },
        {
          "label": "SDKs",
          "value": "JavaScript (npm shipengine 1.0.7), Python (shipengine 2.1.1, 6 May 2026), .NET (v3.2.1, 27 May 2026), Java, Ruby and PHP, Apache 2.0, all written for api.shipengine.com/v1"
        },
        {
          "label": "Carriers",
          "value": "The pricing page says 250+ carriers on the Advanced plan. The Free plan uses ShipStation's own carrier accounts"
        },
        {
          "label": "Status",
          "value": "status.shipstation.com on Statuspage, with components for Companion API V1 and V2, carriers and marketplaces"
        }
      ],
      "unitPrices": [
        {
          "item": "ShipStation API Free",
          "unit": "month",
          "usd": 0,
          "note": "sandbox included, postage extra"
        },
        {
          "item": "ShipStation API Advanced, 1,000 labels",
          "unit": "month",
          "usd": 75,
          "note": "$325 for 5,000 labels, $600 for 10,000"
        },
        {
          "item": "Label over the Advanced 1,000 allowance",
          "unit": "tx",
          "usd": 0.075,
          "note": "$0.065 on the 5,000 tier, $0.060 on the 10,000 tier"
        },
        {
          "item": "ShipStation platform Standard, 50 shipments",
          "unit": "month",
          "usd": 29.99,
          "note": "lowest platform plan with API access"
        }
      ],
      "provenance": {
        "legalEntity": "Auctane LLC d/b/a ShipStation",
        "domain": "shipstation.com",
        "domainRegistered": "2005-04-14",
        "endpointOnVendorDomain": true,
        "terms": "https://www.shipstation.com/terms-of-service/",
        "privacy": "https://www.shipstationglobal.com/legal/privacy-policy/",
        "statusPage": "https://status.shipstation.com",
        "changelog": "https://docs.shipstation.com/apis/release-notes",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The terms of service, effective 16 July 2026, name Auctane LLC d/b/a ShipStation and its affiliates, with Auctane, Inc. as parent.",
          "www.shipstation.com/privacy-policy/ redirects through auctane.com to www.shipstationglobal.com/legal/privacy-policy/, Auctane, Inc.'s policy for ShipStation, ShipEngine, Stamps.com and its other brands, effective 18 March 2026.",
          "/.well-known/security.txt returns 404 on www.shipstation.com, api.shipstation.com, docs.shipstation.com and www.shipstationglobal.com.",
          "The v2 API answers at api.shipstation.com. Webhook signing keys and the older v1 endpoints sit on api.shipengine.com, and the docs link a dashboard at dashboard.shipengine.com.",
          "RDAP for shipstation.com gives a registration date of 2005-04-14."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Auctane LLC d/b/a ShipStation",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "shipstation.com, registered 2005-04-14 (21 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.shipstation.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.shipstation.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.shipstation.com/terms-of-service/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 56513,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The laws of the State of Texas, USA (or U.S.",
                "says": "The law of the State of Texas"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…YOU FOR DAMAGES IN ANY WAY RELATING TO THE SERVICES, YOU AGREE THAT PROVIDER’S AGGREGATE LIABILITY IS LIMITED TO THE GREATER OF (A) THE SERVICE FEES AND ADDITIONAL CHARGES YOU PAID PROVIDER TO USE THE APPLICABLE SERVICES FOR WHICH THE LIABILITY AROSE, EXCLUDING ANY CARRIER CHARGES OR OTHER CHARGES, DURING THE SIX MONT…",
                "says": "Capped at the greater of US $1,000.00 and the fees paid in the 6 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Provider may terminate or suspend your account at any time for lack of use, lack of payment, or breach of these Terms or for any other reason at its sole discretion."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Modifications, amendments or supplements to these Terms shall automatically be effective seven (7) days after Provider has posted the modifications, amendments or supplements.",
                "says": "Gives seven days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Provider bills in advance (i.e., at the beginning of the applicable billing cycle), if you cancel in the middle of a billing cycle you will not be refunded for your Service fees and your account will remain available for usage for the remainder of that billing cycle."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "For instance, it may not be possible for Provider to determine if a label is eligible for refund due to missing the appropriate service level."
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Scrape, build databases, or otherwise create permanent copies of such content, or keep cached copies longer than permitted by the cache header;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "SERVICE CHANGES: Provider reserves the right, periodically and at any time, to modify or discontinue, temporarily or permanently, any functions and features of its Services, in its sole discretion, with or without notice, except where prohibited by law.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Provider may terminate or suspend your account at any time for lack of use, lack of payment, or breach of these Terms or for any other reason at its sole discretion."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "Both you and the Provider agree, with the limited exceptions noted below and as further provided below, to resolve all disputes between you and the Provider through BINDING ARBITRATION."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.shipstationglobal.com/legal/privacy-policy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-03-18",
            "words": 15692,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective: March 18, 2026",
                "says": "Last updated 2026-03-18"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Policy describes how we collect and maintain certain information collected about you, through our websites, in our apps, and in our offices."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We retain Device Contacts only for as long as your account remains active or as needed to provide the relevant features, unless a longer retention period is required or permitted by law.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may also receive your Personal Information from vendors that have provided us with information to send you goods, products, services or information offered by the vendor, during which we act as a Service Provider to the vendor."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not sell Personal Information, but we recognize that some privacy laws define “Personal Information” in such a way that making available identifiers linked to you for a benefit may be considered a “sale.” To opt-out of this, please use the tools in the “How to Contact Us” section.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "• Right to Know (Categories): To know the categories of Personal Information we collect, the categories of sources from which it is collected, the purposes for which we use it, whether we sell or share it, and the categories of third parties to whom we disclose it."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you are located within the UK or EEA and have an unresolved privacy or data use concern, you may also contact our Data Protection Officer as follows, depending on the applicable brand:",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Data Privacy Framework (“EU-US DPF”) and the UK Extension to the EU-U.S.",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We also share hashed information with third party advertising platforms."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The policy says personal information is used to improve and develop services, and that this includes training, testing and the use of AI.",
                "quote": "This includes training, testing and the use of AI (see section 2(e) (“Use of ADMT and AI”) below)."
              },
              {
                "date": "2026-10-08",
                "text": "The policy covers only personal information Auctane handles as controller, and leaves data it processes for customers to the terms of service or data processing agreement.",
                "quote": "Please note that this Policy does not cover the processing of Personal Information for which we are a processor."
              },
              {
                "date": "2026-10-08",
                "text": "After an account is closed, Auctane says it may keep using some of the information for business purposes and to improve or develop its services.",
                "quote": "We may also continue to use some of your information for business purposes and to improve our offerings or in some cases to develop new ones."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shipstation.json",
      "live": {
        "slug": "shipstation",
        "probe": {
          "target": "https://api.shipstation.com/v2",
          "method": "get",
          "lastAt": "2026-10-08T19:08:58.391948636Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 352,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 344,
          "p95ms24h": 389,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shipstation.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:58.859959332Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "shipengine",
            "version": "1.0.7",
            "seenAt": "2026-10-08T16:29:10.143981506Z"
          },
          {
            "registry": "pypi",
            "name": "shipengine",
            "version": "2.1.1",
            "released": "2026-05-06",
            "seenAt": "2026-10-08T16:29:10.99861941Z"
          }
        ],
        "githubStars": 29,
        "npmWeekly": 6835,
        "pypiWeekly": 3230,
        "securityTxt": {
          "url": "https://shipstation.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:39.702773194Z"
        },
        "pages": [
          {
            "url": "https://docs.shipstation.com/apis/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:24.519853433Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0c732bd7a0dc"
          },
          {
            "url": "https://www.shipstationglobal.com/legal/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:24.90838573Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6fef845000ca"
          },
          {
            "url": "https://www.shipstation.com/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:23.462749118Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d03451a2fa29"
          }
        ],
        "updatedAt": "2026-10-08T19:08:58.391948636Z"
      }
    },
    "verify": {
      "accepts": "a page on shipstation.com or one of its subdomains, or the README of github.com/ShipEngine/shipengine-openapi",
      "badgeUrl": "https://www.anchorterminal.com/badges/shipstation.svg",
      "body": {
        "slug": "shipstation",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/shipstation",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/shipstation\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/shipstation.svg\" alt=\"ShipStation API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![ShipStation API on Anchor Terminal](https://www.anchorterminal.com/badges/shipstation.svg)](https://www.anchorterminal.com/tools/shipstation)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/shipstation\"\u003eShipStation API on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/shipstation",
    "json": "https://www.anchorterminal.com/tools/shipstation.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/shipstation.md",
    "slim": "https://www.anchorterminal.com/tools/shipstation.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 59.3/100 · rank #382 of 629 · #4 in Shipping \u0026 fulfilment · not agent-ready · confidence medium**\n\n\n## Assessment\n\nA public OpenAPI 3.1 contract with 173 operations, Markdown docs for agents and a free ShipStation API plan with a sandbox make a first rate quote or test label reachable without a contract. One API key carries full account access, with no scopes, read-only mode or idempotency keys on label purchases.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Auctane LLC d/b/a ShipStation (https://www.shipstation.com) |\n| Kind | HTTP API |\n| Category | Shipping \u0026 fulfilment (https://www.anchorterminal.com/categories/shipping) |\n| Transport | HTTP |\n| Endpoint | `https://api.shipstation.com/v2` |\n| Auth | API key · Self-serve API key sent in an `API-Key` header, with no partner or sales approval. Two routes lead to a v2 key. A ShipStation API account (formerly ShipEngine) gets production keys and `TEST_` sandbox keys from api-portal.shipstation.com on every plan, Free included. A ShipStation platform account needs the Standard or Premium plan and generates one v2 key at a time in API Settings, shown once. The docs say the key gives full access to the account. No OAuth, scopes or read-only keys were found. |\n| Pricing | Freemium ($75 / mo) · ShipStation API (formerly ShipEngine) has a Free plan at $0 with a sandbox and, by the pricing page, no card. Advanced is $75 a month for 1,000 labels ($0.075 a label over), $325 for 5,000 ($0.065) or $600 for 10,000 ($0.060), and Enterprise is by quote from 25,000 shipments a month. On the ShipStation platform the API comes with Standard (from $29.99 a month for 50 shipments) and Premium (from $349.99), after a 30-day trial with no card, and has no sandbox. Postage is charged separately at carrier rates (checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the v2 docs, the OpenAPI spec or the pricing pages (checked 2026-10-07). |\n| Licence | Proprietary service under ShipStation's terms of service. The v2 OpenAPI file is marked MIT and the SDKs on GitHub are Apache 2.0 |\n| Packages | npm: `shipengine`; pypi: `shipengine` |\n| Source | https://github.com/ShipEngine/shipengine-openapi |\n| Docs | https://docs.shipstation.com/api-overview |\n| llms.txt | https://docs.shipstation.com/llms.txt |\n| Last release | 2026-10-01 |\n| npm downloads / week | 6,835 |\n| Surface graded | ShipStation API v2, REST and JSON at https://api.shipstation.com/v2. OpenAPI 3.1, 173 operations on 123 paths |\n| Other APIs | ShipStation API (formerly ShipEngine) at https://api.shipengine.com/v1, which still works with the same keys, and the legacy V1 API at https://ssapi.shipstation.com, described as deprecated with no removal date |\n| Access | Self-serve API key. A ShipStation API account on any plan, Free included, or a ShipStation platform account on Standard or Premium. Platform Free and Starter plans have no API access |\n| Sandbox | ShipStation API accounts only, on every plan. Keys start `TEST_` and use the same host. Test labels are free, tracking is simulated and data may be cleared. Platform accounts have no sandbox |\n| Endpoints by plan | 159 on ShipStation API Free, 173 on Advanced and Enterprise, 147 on platform Standard and Premium, per the docs' plan pages. POST /v2/addresses/validate and the standalone tracking calls are Advanced and Enterprise only |\n| Rate limits | 200 requests a minute by default, higher on request. 429 with `Retry-After` in seconds |\n| Errors | An `errors` array with `error_source` (carrier, order_source, ShipStation, shipengine), `error_type`, `error_code`, `message` and a `request_id`. 2XX responses can carry partial errors |\n| Pagination | `page`, `page_size`, `sort_by`, `sort_dir`, with `total`, `pages` and `links` in the response |\n| Webhooks | Created with POST /v2/environment/webhooks, production only. Signed with RSA-SHA256, verified against the JWKS at https://api.shipengine.com/jwks |\n| MCP server | Documentation only, at https://docs.shipstation.com/mcp, no key needed. Tools such as list-apis, get-endpoints and get-endpoint-info read the specs. It makes no shipping calls |\n| SDKs | JavaScript (npm shipengine 1.0.7), Python (shipengine 2.1.1, 6 May 2026), .NET (v3.2.1, 27 May 2026), Java, Ruby and PHP, Apache 2.0, all written for api.shipengine.com/v1 |\n| Carriers | The pricing page says 250+ carriers on the Advanced plan. The Free plan uses ShipStation's own carrier accounts |\n| Status | status.shipstation.com on Statuspage, with components for Companion API V1 and V2, carriers and marketplaces |\n| Capabilities | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns |\n| Tags | hosted, freemium, free-tier, sandbox, api-key, openapi, llms-txt, webhooks, python, javascript, dotnet, status-page |\n| JSON | https://www.anchorterminal.com/api/v1/tools/shipstation.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 64 | 12.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 83 | 13.5 |\n| Agent ergonomics | 13% | 16.2 | 64 | 10.4 |\n| Security \u0026 auth | 14% | 17.5 | 32 | 5.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 73 | 6.4 |\n| Transparency \u0026 trust (editorial 42, provenance 85) | 7% | 8.8 | 64 | 5.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **59.3 → C** |\n\n### Why each score\n\n- Reliability 64: Graded on ShipStation API v2 at api.shipstation.com/v2, with the hosted lines. Statuspage at status.shipstation.com with components for Companion API V1 and V2, carriers and marketplaces (20). From 9 July to 7 October 2026 it lists 12 incidents, three marked major. Two were carrier-specific (Evri label creation for 29 hours from 24 September, DPD Local and DX for 6 hours on 11 September) and one was a duplicate package option for 79 minutes on 14 July. None names the API component, so we scored between minor-only and one major (15). 200 requests a minute by default (15). 429 responses carry `Retry-After` and the docs ask for retries handled globally, but no idempotency key exists for label purchases (9). No SLA found (0). The getting-started page says v2 \"is currently in an early release stage\" while calling it tested and stable (5).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 83: OpenAPI 3.1 for v2 at docs.shipstation.com/_bundle/apis/@shipstation-v2/openapi.yaml, 173 operations on 123 paths and 372 schemas (25). llms.txt with 480 lines of links and a Markdown copy of each docs page (10). Guides explain when to use rates against estimates and webhooks against polling. Operation descriptions in the spec are one line each (13). 152 enums, required fields and read-only markers, though carrier and service codes are free strings that depend on the account (12). 1,648 example entries and enumerated `error_code` and `error_type` values. The spec documents 400, 404 and 500 but no 401 or 429 response (11). Release notes are dated by month and the spec version has stayed 2.0.0 through every addition (12).\n- Agent ergonomics 64: No MCP server that performs shipping operations. The MCP server at docs.shipstation.com/mcp reads documentation only. List endpoints take `page_size`. No field selection was found (12). `page`, `page_size`, `sort_by`, `sort_dir` and filters by status, tag, dates, store and external id on list calls (20). Errors carry `error_source`, `error_type`, `error_code`, `message`, field names and a `request_id` (18). No idempotency keys. `external_shipment_id` is unique per shipment, labels can be voided and `test_label` exists, which we counted as partial safe-retry support (6). Official SDKs in six languages call api.shipengine.com/v1, not v2, and a label needs a `carrier_id` and `service_code` looked up first (8).\n- Security \u0026 auth 32: One secret in an `API-Key` header. The docs say the key gives full access. Platform accounts hold one active v2 key that can be regenerated, and ShipStation API accounts have separate `TEST_` sandbox keys (17). No scopes, read-only keys or confirmation before a label purchase. The sandbox key is the only lower-risk mode (5). Responses carry order text, addresses and carrier messages written by others, with no injection guidance (3). A `request_id` on every response. No per-key audit log found in the docs (3). TLS 1.2 or higher required, HSTS on the API host and RSA-SHA256 signed webhooks with a JWKS. security.txt returns 404 on three hosts, and no certification, bug bounty or disclosure policy was found on the pages we read (4).\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). ShipStation API prices are public without a login. Free at $0, Advanced at $75 a month for 1,000 labels with $0.075 per label over, $325 for 5,000 and $600 for 10,000, Enterprise by quote. Platform plans are public too, with API access from Standard at $29.99 a month for 50 shipments (20). The Free plan and its sandbox need no card according to the pricing page (20). A person signs up in a browser to get a key (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 73: Release notes list packing slips for batches under October 2026 (30). Dated entries for August, September and October 2026, each adding endpoints (20). Closed service with monthly release notes, an API support address (apisupport@shipstation.com) and a community forum. We couldn't measure reply times (10). Official SDKs exist in six languages. Python 2.1.1 shipped on 6 May 2026 and .NET v3.2.1 on 27 May 2026, while JavaScript 1.0.7 dates from 31 January 2024 and PHP 1.0.0 from 2021, and all call the v1 ShipEngine host (8). SDK repositories have CI workflows. The OpenAPI repository on GitHub was last changed on 11 June 2026 (5).\n- Transparency \u0026 trust 64: Closed service under terms of service effective 16 July 2026 that name Auctane LLC d/b/a ShipStation. The v2 OpenAPI file is marked MIT and the SDKs are Apache 2.0 (16). The privacy policy, effective 18 March 2026, is Auctane, Inc.'s for all its brands. It keeps data \"as long as necessary\" with no periods, and says third parties may not train AI models on personal information. No public DPA was found (12). The legacy V1 API is described as deprecated with removal \"in the future\" and no date, and the terms let ShipStation withdraw API access at its discretion (6). US persons' data stays in the United States and EEA and UK data may move there under the Data Privacy Framework. Service providers are named by type, with no subprocessor list (8).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/shipstation.md (JSON https://www.anchorterminal.com/fixes/shipstation.json)\n\n### What we couldn't check\n\n- unchecked: weekly PyPI downloads for shipengine (pypistats.org answered with a rate limit)\n- unchecked: www.shipstation.com answered our shell with a bot check, so pricing, terms and the API pricing page were read through the fetch tool's summary and not as raw pages\n- No security page, certification, bug bounty, DPA or subprocessor list was found from the docs, the legal page or a site search. One may exist behind a sales or customer login\n- Whether the Free plan's label and call allowances are capped. The pricing page says no API usage charges without a number\n- Whether an SLA exists on the Enterprise plan\n- Whether the API portal shows a per-key request log, which would count as an audit trail\n- The release notes date entries by month only. `lastRelease` 2026-10-01 stands for the October 2026 entry, whose day isn't published\n- How long v2 stays in its stated early release stage, and the removal date for the legacy V1 API\n\n### Sources\n\n- API overview, three APIs and base URLs: \u003chttps://docs.shipstation.com/api-overview\u003e (seen 2026-10-07)\n- v2 getting started, early release statement: \u003chttps://docs.shipstation.com/getting-started.md\u003e (seen 2026-10-07)\n- authentication, key types and sandbox availability: \u003chttps://docs.shipstation.com/authentication.md\u003e (seen 2026-10-07)\n- rate limits and 429 handling: \u003chttps://docs.shipstation.com/rate-limits.md\u003e (seen 2026-10-07)\n- sandbox: \u003chttps://docs.shipstation.com/sandbox.md\u003e (seen 2026-10-07)\n- v2 OpenAPI 3.1 spec: \u003chttps://docs.shipstation.com/_bundle/apis/@shipstation-v2/openapi.yaml\u003e (seen 2026-10-07)\n- v2 release notes: \u003chttps://docs.shipstation.com/apis/release-notes.md\u003e (seen 2026-10-07)\n- llms.txt: \u003chttps://docs.shipstation.com/llms.txt\u003e (seen 2026-10-07)\n- documentation MCP server: \u003chttps://docs.shipstation.com/connect-mcp.md\u003e (seen 2026-10-07)\n- endpoints by plan: \u003chttps://docs.shipstation.com/plans/shipstation-api-free\u003e (seen 2026-10-07)\n- error handling: \u003chttps://docs.shipstation.com/apis/shipengine/docs/guides/errors.md\u003e (seen 2026-10-07)\n- webhook signature validation: \u003chttps://docs.shipstation.com/apis/docs/guides/webhooks-validation.md\u003e (seen 2026-10-07)\n- tracking: \u003chttps://docs.shipstation.com/tracking.md\u003e (seen 2026-10-07)\n- status incidents: \u003chttps://status.shipstation.com/api/v2/incidents.json\u003e (seen 2026-10-07)\n- ShipStation API pricing: \u003chttps://www.shipstation.com/shipping-api/pricing/\u003e (seen 2026-10-07)\n- platform pricing: \u003chttps://www.shipstation.com/pricing/\u003e (seen 2026-10-07)\n- terms of service: \u003chttps://www.shipstation.com/terms-of-service/\u003e (seen 2026-10-07)\n- privacy policy: \u003chttps://www.shipstationglobal.com/legal/privacy-policy/\u003e (seen 2026-10-07)\n- SDK list: \u003chttps://docs.shipstation.com/apis/shipengine/docs/getting-started/tools.md\u003e (seen 2026-10-07)\n- Python SDK repository and tags: \u003chttps://github.com/ShipEngine/shipengine-python\u003e (seen 2026-10-07)\n- JavaScript SDK on npm: \u003chttps://registry.npmjs.org/shipengine/latest\u003e (seen 2026-10-07)\n- official MCP registry search, no entries: \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=shipstation\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 85/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Auctane LLC d/b/a ShipStation | 20/20 |\n| Domain age | shipstation.com, registered 2005-04-14 (21 years) | 15/15 |\n| Endpoint on the vendor's domain | api.shipstation.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.shipstation.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe terms of service, effective 16 July 2026, name Auctane LLC d/b/a ShipStation and its affiliates, with Auctane, Inc. as parent.\n\nwww.shipstation.com/privacy-policy/ redirects through auctane.com to www.shipstationglobal.com/legal/privacy-policy/, Auctane, Inc.'s policy for ShipStation, ShipEngine, Stamps.com and its other brands, effective 18 March 2026.\n\n/.well-known/security.txt returns 404 on www.shipstation.com, api.shipstation.com, docs.shipstation.com and www.shipstationglobal.com.\n\nThe v2 API answers at api.shipstation.com. Webhook signing keys and the older v1 endpoints sit on api.shipengine.com, and the docs link a dashboard at dashboard.shipengine.com.\n\nRDAP for shipstation.com gives a registration date of 2005-04-14.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.shipstation.com/terms-of-service/), read 2026-10-08, gives no date, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"Scrape, build databases, or otherwise create permanent copies of such content, or keep cached copies longer than permitted by the cache header;\"\n- To know. Says the terms or the service can change without notice (costs points). \"SERVICE CHANGES: Provider reserves the right, periodically and at any time, to modify or discontinue, temporarily or permanently, any functions and features of its Services, in its sole discretion, with or without notice, except where prohibited by law.\"\n- To know. Says access can be ended without notice or for any reason. \"Provider may terminate or suspend your account at any time for lack of use, lack of payment, or breach of these Terms or for any other reason at its sole discretion.\"\n- To know. Requires arbitration or waives class actions. \"Both you and the Provider agree, with the limited exceptions noted below and as further provided below, to resolve all disputes between you and the Provider through BINDING ARBITRATION.\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of Texas.\n- States a limit on its liability. Capped at the greater of US $1,000.00 and the fees paid in the 6 months before the claim.\n- Says how changes to the terms are announced. Gives seven days of notice before a change.\n\n**Privacy policy** (https://www.shipstationglobal.com/legal/privacy-policy/), read 2026-10-08, dated 2026-03-18, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"We also share hashed information with third party advertising platforms.\"\n- Gives the date it was last updated. Last updated 2026-03-18.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). The policy says personal information is used to improve and develop services, and that this includes training, testing and the use of AI. \"This includes training, testing and the use of AI (see section 2(e) (“Use of ADMT and AI”) below).\"\n- Also in the text (2026-10-08). The policy covers only personal information Auctane handles as controller, and leaves data it processes for customers to the terms of service or data processing agreement. \"Please note that this Policy does not cover the processing of Personal Information for which we are a processor.\"\n- Also in the text (2026-10-08). After an account is closed, Auctane says it may keep using some of the information for business purposes and to improve or develop its services. \"We may also continue to use some of your information for business purposes and to improve our offerings or in some cases to develop new ones.\"\n\n## Live (updated 2026-10-08 19:08 UTC)\n\n- Right now: up, HTTP 404, 352 ms, checked 2026-10-08 19:08 UTC (get on `https://api.shipstation.com/v2`)\n- Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 344 ms · p95 389 ms\n- Vendor status page: none, All Systems Operational\n- npm `shipengine` 1.0.7\n- pypi `shipengine` 2.1.1, released 2026-05-06\n- security.txt: none\n- Watching changelog \u003chttps://docs.shipstation.com/apis/release-notes\u003e\n- Watching privacy \u003chttps://www.shipstationglobal.com/legal/privacy-policy/\u003e\n- Watching terms \u003chttps://www.shipstation.com/terms-of-service/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/shipstation.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| ShipStation API Free | free | per month (plan) | sandbox included, postage extra |\n| ShipStation API Advanced, 1,000 labels | $75 | per month (plan) | $325 for 5,000 labels, $600 for 10,000 |\n| Label over the Advanced 1,000 allowance | $0.075 | per transaction | $0.065 on the 5,000 tier, $0.060 on the 10,000 tier |\n| ShipStation platform Standard, 50 shipments | $29.99 | per month (plan) | lowest platform plan with API access |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.1 spec for v2 with 173 operations and 372 schemas, plus llms.txt and a Markdown copy of every docs page\n- ShipStation API Free plan at $0 with no card stated, and a sandbox on every ShipStation API plan through `TEST_` keys\n- 200 requests a minute by default, with `Retry-After` on 429 responses\n- Errors carry `error_source`, `error_type`, `error_code` and a `request_id`, and separate carrier faults from ShipStation's own\n- Release notes show new v2 endpoints in every month from June to October 2026\n\n## Weaknesses\n\n- One API key with full account access. No scopes, read-only keys or approval step before a label is bought\n- No idempotency key on label purchase, so a retry after a timeout can buy a second label\n- ShipStation platform accounts have no sandbox, and API access needs the Standard plan (from $29.99 a month) or Premium\n- The official SDKs call api.shipengine.com/v1, and the JavaScript SDK was last tagged on 31 January 2024\n- No security.txt, certification, disclosure policy, DPA or named subprocessor list found on the pages we read\n\n## Before you call it (notes for agents)\n\n1. Send the key in an `API-Key` header to https://api.shipstation.com/v2. A key that starts `TEST_` runs in the sandbox on the same host\n2. Call GET /v2/carriers first. Rate and label calls need `carrier_ids` or a `carrier_id` and a `service_code` from that account\n3. Don't blindly retry POST /v2/labels after a timeout. List labels first, then void a duplicate with PUT /v2/labels/{label_id}/void\n4. Check the `errors` array on 2XX responses too, and read `error_source` to tell a carrier fault from a ShipStation one\n5. On a platform (Standard or Premium) key every label is real and charged. Ask the owner before buying, and void test labels at once\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -iX GET https://api.shipstation.com/v2/carriers \\\n-H 'API-Key: __YOUR_API_KEY_HERE__'\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http shipstation-api https://docs.shipstation.com/mcp\n```\n\nThrough letme (picks today, calling later): https://letme.dev/shipstation. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Easyship | B | 68.8 | 163 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/easyship.md |\n| Sendcloud | B | 62 | 314 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/sendcloud.md |\n| Shippo | C | 61.9 | 317 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/shippo.md |\n| EasyPost | C | 54.3 | 468 | shipping.rates, shipping.labels, shipping.tracking, shipping.address-validation, shipping.returns | no | https://www.anchorterminal.com/tools/easypost.md |\n| TaxJar | C | 57.6 | 417 | shipping.address-validation | no | https://www.anchorterminal.com/tools/taxjar.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Three APIs sit under the ShipStation name. API v2 at api.shipstation.com/v2, the ShipStation API (formerly ShipEngine, renamed on 28 February 2025) at api.shipengine.com/v1, and the legacy V1 API at ssapi.shipstation.com (source: \u003chttps://docs.shipstation.com/api-overview\u003e)\n- The getting-started page says v2 \"is currently in an early release stage\" and may lack some V1 functions (source: \u003chttps://docs.shipstation.com/getting-started\u003e)\n- A sandbox with `TEST_` keys exists only for ShipStation API accounts. On a platform account every v2 call is production and labels are charged (source: \u003chttps://docs.shipstation.com/sandbox\u003e)\n- The docs say the API key gives full access to the account, and a platform account holds one v2 key at a time (source: \u003chttps://docs.shipstation.com/authentication\u003e)\n- The MCP server at docs.shipstation.com/mcp reads documentation only and makes no shipping calls (source: \u003chttps://docs.shipstation.com/connect-mcp\u003e)\n- Release notes list new v2 endpoints each month from June to October 2026, among them checkout rates, products, hold and restore, and packing slips for batches (source: \u003chttps://docs.shipstation.com/apis/release-notes\u003e)\n- status.shipstation.com lists 12 incidents between 9 July and 7 October 2026, three marked major, two of them limited to Evri and to DPD Local and DX (source: \u003chttps://status.shipstation.com/history\u003e)\n\n## Compare\n\n- [EasyPost vs ShipStation API](https://www.anchorterminal.com/compare/easypost-vs-shipstation.md): C 54.3 vs C 59.3\n- [Easyship vs ShipStation API](https://www.anchorterminal.com/compare/easyship-vs-shipstation.md): B 68.8 vs C 59.3\n- [Sendcloud vs ShipStation API](https://www.anchorterminal.com/compare/sendcloud-vs-shipstation.md): B 62 vs C 59.3\n- [Shippo vs ShipStation API](https://www.anchorterminal.com/compare/shippo-vs-shipstation.md): C 61.9 vs C 59.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on shipstation.com or one of its subdomains, or the README of github.com/ShipEngine/shipengine-openapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"shipstation\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/shipstation\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/shipstation.svg\" alt=\"ShipStation API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![ShipStation API on Anchor Terminal](https://www.anchorterminal.com/badges/shipstation.svg)](https://www.anchorterminal.com/tools/shipstation)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/shipstation\"\u003eShipStation API on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say ShipStation API is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/shipstation-dark.png\n- Light: https://www.anchorterminal.com/assets/share/shipstation-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Shipping \u0026 fulfilment",
        "url": "https://www.anchorterminal.com/categories/shipping"
      },
      {
        "name": "ShipStation API",
        "url": ""
      }
    ],
    "description": "Multi-carrier shipping API from ShipStation, an Auctane brand. API v2 at api.shipstation.com/v2 quotes rates, buys and voids labels, validates addresses, tracks parcels and creates return labels, with batches, manifests, pickups and inventory.",
    "facts": [
      "rank #382 of 629",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "ShipStation API",
    "image": "https://www.anchorterminal.com/assets/og/tools-shipstation.png",
    "path": "/tools/shipstation",
    "published": "2026-10-01",
    "section": "tools",
    "title": "ShipStation API review for AI agents, grade C (59.3/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/shipstation"
  },
  "tokens": {
    "markdown": 7250,
    "slim": 1830
  },
  "version": 1
}
