{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/teamwork.json",
        "name": "Teamwork.com",
        "score": 65.9,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting",
          "automation.webhooks"
        ],
        "slug": "teamwork"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/wrike.json",
        "name": "Wrike",
        "score": 60.1,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting",
          "automation.webhooks"
        ],
        "slug": "wrike"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/monday.json",
        "name": "monday.com",
        "score": 76.4,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting"
        ],
        "slug": "monday"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/asana.json",
        "name": "Asana",
        "score": 70.1,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting"
        ],
        "slug": "asana"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/basecamp.json",
        "name": "Basecamp",
        "score": 67.9,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting"
        ],
        "slug": "basecamp"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/plane.json",
        "name": "Plane",
        "score": 67.6,
        "shared": [
          "tasks.create",
          "tasks.update",
          "projects.manage",
          "tasks.comments",
          "projects.reporting"
        ],
        "slug": "plane"
      }
    ],
    "tool": {
      "slug": "shortcut",
      "name": "Shortcut",
      "vendor": "Shortcut Software Company",
      "vendorUrl": "https://www.shortcut.com",
      "kind": "http-api",
      "category": "project-management",
      "summary": "Shortcut is a hosted project tracker for software teams, with stories, epics, iterations, objectives and docs. Agents reach it through REST API v3 with a personal token, or the hosted MCP server at mcp.shortcut.com/mcp with OAuth.",
      "url": "https://www.anchorterminal.com/tools/shortcut",
      "markdownUrl": "https://www.anchorterminal.com/tools/shortcut.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shortcut.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shortcut.json",
      "repo": "https://github.com/useshortcut/shortcut-client-js",
      "license": "Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.app.shortcut.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@shortcut/client"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. Any workspace member creates an API token under Settings, API Tokens, with no app review. REST API v3 takes it in the `Shortcut-Token` header, and tokens can be read-only or read-write since 20 January 2026. An Observer's token can read but not change data. The hosted MCP server at mcp.shortcut.com/mcp takes OAuth only (authorisation code with PKCE, dynamic client registration) with the scopes read, write, story-write, comment-write and admin, and access can be revoked in Shortcut settings. The v4 alpha uses `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens.",
      "pricing": "freemium",
      "pricingNotes": "The API, webhooks and the MCP server are listed on every plan, and Shortcut charges nothing per call. Free is $0 for up to 10 users, Team $8.50 a user a month billed yearly ($10 monthly), Business $12 ($16 monthly), and Enterprise is quoted by sales. A 14-day trial needs no card, so an agent's owner can start on Free or the trial without a contract (checked 2026-10-08).",
      "priceSummary": "$8.50 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API reference, the OpenAPI files, llms.txt or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 142,
        "npmWeekly": 102825,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.shortcut.com/api/rest/v3",
      "llmsTxt": "https://www.shortcut.com/llms.txt",
      "openapi": "https://developer.shortcut.com/api/rest/v3/shortcut.openapi.json",
      "capabilities": [
        "tasks.create",
        "tasks.update",
        "projects.manage",
        "tasks.comments",
        "projects.reporting",
        "automation.webhooks"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "freemium",
        "free-tier",
        "no-card",
        "closed-source",
        "typescript",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.2,
        "grade": "C",
        "agentReady": false,
        "rank": 411,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 73,
          "payments": 30,
          "reliability": 64,
          "schema": 75,
          "security": 54,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 64,
            "points": 12.8,
            "reason": "Graded on the hosted lines for REST API v3 and the hosted MCP server. status.shortcut.com is a Statuspage site with API and Shortcut MCP components and history back to March 2023 (20). In the 90 days to 8 October 2026 it shows three incidents, the MCP server unavailable for about 6 minutes on 14 July, tokens newly created through the MCP server unable to write for 2 hours 21 minutes on 15 July (rated major by Shortcut, fix in place after 22 minutes), and search indexing behind on 4 August. None names the API component. One vendor-rated major that affected only new MCP tokens sits between the minor and major lines (15 of 30). The docs give 200 requests a minute (15). A 429 is documented, with no Retry-After header, backoff guidance or idempotency keys found (4 of 15). The Enterprise plan lists 'Premier support SLAs', and no uptime SLA was found (0). v3 is described as the current version with backwards-compatible changes only, and the hosted MCP server carries no beta label. v4 is alpha and isn't graded (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 75,
            "points": 12.19,
            "reason": "Swagger 2.0 and OpenAPI 3.0 files for v3 are downloadable from the docs (143 operations on 85 paths), and an OpenAPI 3.0.3 file for the v4 alpha (247 operations) is at www.shortcut.com/openapi.json. The hosted MCP server's tool schemas need an account and were not read (25). www.shortcut.com/llms.txt links the spec, and help centre pages have Markdown copies. developer.shortcut.com has no llms.txt and is a single HTML page per version (7 of 10). 127 of 143 operations carry a description, mostly one line, with a few usage rules such as the `workflow_state_id` or `project_id` choice on story creation (12 of 20). Enums, maxLength, formats and required flags throughout (13 of 15). Every endpoint has a curl example and an example response, but errors are the same three lines everywhere (400 schema mismatch, 404, 422) with no documented error body (9 of 15). Versions are in the path (v2 deprecated, v3 current, v4 alpha). No API changelog was found, although the v4 page refers to one, and API changes appear in the product release notes (9 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 57,
            "points": 9.26,
            "reason": "Graded on the API. Search takes `detail=slim` to drop descriptions and comments, and list responses use slim types. Field selection (`fields`) exists only in the v4 alpha (17 of 25). Search has operators, `page_size` up to 250 and a `next` token, and epics have a paginated list, but the v4 migration note says v3 list endpoints return all results at once (14 of 20). Errors are HTTP codes with one-line meanings. A live 401 returned JSON with `message` and `tag`, which the reference doesn't catalogue (9 of 20). No idempotency keys. `external_id` fields exist on some entities. The archived MCP source (v0.25.0) sets readOnlyHint, destructiveHint and idempotentHint on its 78 tools, and the hosted server's annotations were not read (8 of 20). A story needs only a name and a workflow state. One official SDK, `@shortcut/client` for JavaScript and TypeScript (9 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 54,
            "points": 9.45,
            "reason": "The hosted MCP server uses the OAuth authorisation code flow with PKCE (S256), dynamic client registration and the scopes read, write, story-write, comment-write and admin. REST tokens are created per user, can be read-only or read-write since 20 January 2026, and the v4 alpha lets an admin list and disable workspace tokens. The v3 docs still accept the token as a `token` query parameter, marked deprecated, which costs 10 (20 of 30). Read-only tokens, a read scope, narrow story and comment scopes and the view-only Observer role. No confirmation step for deletes was found (14 of 20). Stories, comments and docs written by other people reach the model, and no injection guidance was found (3 of 15). Story history is readable by API. No workspace audit log of API or MCP calls was found in the pages read (5 of 15). No security.txt (404). A disclosure policy promises acknowledgement within a week, and the security page states SOC 2 Type 2 with the report on request. No bug bounty or public advisories found (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 (0). Plan prices are public, Free $0 for up to 10 users, Team $8.50 a user a month billed yearly or $10 monthly, Business $12 or $16, Enterprise by quote. API calls aren't priced (10). The Free plan lists API and webhook access and the MCP server, and the 14-day trial needs no card (20). A person signs up in a browser and creates a token or approves the OAuth grant (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 73,
            "points": 6.39,
            "reason": "The newest release notes are dated 18 September 2026 and `@shortcut/client` 3.4.1 was published on 22 September 2026 (30). Release notes on 31 July, 14 August and 18 September, and four client releases in September (20). Closed service with public release notes, a community Slack and a support address. Response times were not checked (9 of 15). The official client is current, but the official MCP registry has only third-party Shortcut servers (com.mcparmory/shortcut, io.github.stayce/shortcut-mcp) (8 of 15). The client repository was last pushed on 1 October 2026 under MIT. The MCP server repository is archived at v0.25.0 (23 June 2026) with a notice that development moved to the hosted server (6 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 73,
            "points": 6.39,
            "note": "editorial 57, provenance 88",
            "reason": "Closed service under terms naming Shortcut Software Company, with an MIT client library and the archived MIT MCP server (15). The privacy policy of 11 July 2025 covers the platform and says inputs and outputs aren't used to train models by default. Retention is 'only for as long as it serves the purpose', the terms give at least 30 days of data access after termination, and the DPA (last updated 23 August 2018) is sent on request, not published (17 of 30). No deprecation policy found. v2, the Projects endpoints and the token query parameter are marked deprecated with no dates (5 of 20). The sub-processor list, updated 12 November 2025, names 33 providers with product, type and country, hosting on AWS in the US (20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the API. Search takes `detail=slim` to drop descriptions and comments, and list responses use slim types. Field selection (`fields`) exists only in the v4 alpha (17 of 25). Search has operators, `page_size` up to 250 and a `next` token, and epics have a paginated list, but the v4 migration note says v3 list endpoints return all results at once (14 of 20). Errors are HTTP codes with one-line meanings. A live 401 returned JSON with `message` and `tag`, which the reference doesn't catalogue (9 of 20). No idempotency keys. `external_id` fields exist on some entities. The archived MCP source (v0.25.0) sets readOnlyHint, destructiveHint and idempotentHint on its 78 tools, and the hosted server's annotations were not read (8 of 20). A story needs only a name and a workflow state. One official SDK, `@shortcut/client` for JavaScript and TypeScript (9 of 15).",
            "maintenance": "The newest release notes are dated 18 September 2026 and `@shortcut/client` 3.4.1 was published on 22 September 2026 (30). Release notes on 31 July, 14 August and 18 September, and four client releases in September (20). Closed service with public release notes, a community Slack and a support address. Response times were not checked (9 of 15). The official client is current, but the official MCP registry has only third-party Shortcut servers (com.mcparmory/shortcut, io.github.stayce/shortcut-mcp) (8 of 15). The client repository was last pushed on 1 October 2026 under MIT. The MCP server repository is archived at v0.25.0 (23 June 2026) with a notice that development moved to the hosted server (6 of 10).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public, Free $0 for up to 10 users, Team $8.50 a user a month billed yearly or $10 monthly, Business $12 or $16, Enterprise by quote. API calls aren't priced (10). The Free plan lists API and webhook access and the MCP server, and the 14-day trial needs no card (20). A person signs up in a browser and creates a token or approves the OAuth grant (0).",
            "reliability": "Graded on the hosted lines for REST API v3 and the hosted MCP server. status.shortcut.com is a Statuspage site with API and Shortcut MCP components and history back to March 2023 (20). In the 90 days to 8 October 2026 it shows three incidents, the MCP server unavailable for about 6 minutes on 14 July, tokens newly created through the MCP server unable to write for 2 hours 21 minutes on 15 July (rated major by Shortcut, fix in place after 22 minutes), and search indexing behind on 4 August. None names the API component. One vendor-rated major that affected only new MCP tokens sits between the minor and major lines (15 of 30). The docs give 200 requests a minute (15). A 429 is documented, with no Retry-After header, backoff guidance or idempotency keys found (4 of 15). The Enterprise plan lists 'Premier support SLAs', and no uptime SLA was found (0). v3 is described as the current version with backwards-compatible changes only, and the hosted MCP server carries no beta label. v4 is alpha and isn't graded (10).",
            "schema": "Swagger 2.0 and OpenAPI 3.0 files for v3 are downloadable from the docs (143 operations on 85 paths), and an OpenAPI 3.0.3 file for the v4 alpha (247 operations) is at www.shortcut.com/openapi.json. The hosted MCP server's tool schemas need an account and were not read (25). www.shortcut.com/llms.txt links the spec, and help centre pages have Markdown copies. developer.shortcut.com has no llms.txt and is a single HTML page per version (7 of 10). 127 of 143 operations carry a description, mostly one line, with a few usage rules such as the `workflow_state_id` or `project_id` choice on story creation (12 of 20). Enums, maxLength, formats and required flags throughout (13 of 15). Every endpoint has a curl example and an example response, but errors are the same three lines everywhere (400 schema mismatch, 404, 422) with no documented error body (9 of 15). Versions are in the path (v2 deprecated, v3 current, v4 alpha). No API changelog was found, although the v4 page refers to one, and API changes appear in the product release notes (9 of 15).",
            "security": "The hosted MCP server uses the OAuth authorisation code flow with PKCE (S256), dynamic client registration and the scopes read, write, story-write, comment-write and admin. REST tokens are created per user, can be read-only or read-write since 20 January 2026, and the v4 alpha lets an admin list and disable workspace tokens. The v3 docs still accept the token as a `token` query parameter, marked deprecated, which costs 10 (20 of 30). Read-only tokens, a read scope, narrow story and comment scopes and the view-only Observer role. No confirmation step for deletes was found (14 of 20). Stories, comments and docs written by other people reach the model, and no injection guidance was found (3 of 15). Story history is readable by API. No workspace audit log of API or MCP calls was found in the pages read (5 of 15). No security.txt (404). A disclosure policy promises acknowledgement within a week, and the security page states SOC 2 Type 2 with the report on request. No bug bounty or public advisories found (12 of 20).",
            "transparency": "Closed service under terms naming Shortcut Software Company, with an MIT client library and the archived MIT MCP server (15). The privacy policy of 11 July 2025 covers the platform and says inputs and outputs aren't used to train models by default. Retention is 'only for as long as it serves the purpose', the terms give at least 30 days of data access after termination, and the DPA (last updated 23 August 2018) is sent on request, not published (17 of 30). No deprecation policy found. v2, the Projects endpoints and the token query parameter are marked deprecated with no dates (5 of 20). The sub-processor list, updated 12 November 2025, names 33 providers with product, type and country, hosting on AWS in the US (20)."
          },
          "sources": [
            {
              "what": "REST API v3 reference (auth, rate limit, endpoints)",
              "url": "https://developer.shortcut.com/api/rest/v3",
              "seen": "2026-10-08"
            },
            {
              "what": "v3 Swagger 2.0 file",
              "url": "https://developer.shortcut.com/api/rest/v3/shortcut.swagger.json",
              "seen": "2026-10-08"
            },
            {
              "what": "REST API v4 alpha reference",
              "url": "https://developer.shortcut.com/api/rest/v4",
              "seen": "2026-10-08"
            },
            {
              "what": "v4 OpenAPI 3.0.3 file",
              "url": "https://www.shortcut.com/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "outgoing webhooks reference",
              "url": "https://developer.shortcut.com/api/webhook/v1",
              "seen": "2026-10-08"
            },
            {
              "what": "hosted MCP server landing page",
              "url": "https://mcp.shortcut.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP protected-resource metadata",
              "url": "https://mcp.shortcut.com/.well-known/oauth-protected-resource",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth authorisation server metadata",
              "url": "https://api.app.shortcut.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "help centre article on the MCP server",
              "url": "https://www.shortcut.com/help/integrations/mcp-server",
              "seen": "2026-10-08"
            },
            {
              "what": "help centre article on webhooks",
              "url": "https://www.shortcut.com/help/admin/webhooks.md",
              "seen": "2026-10-08"
            },
            {
              "what": "help centre article on user roles",
              "url": "https://www.shortcut.com/help/admin/user-roles.md",
              "seen": "2026-10-08"
            },
            {
              "what": "help centre article on GDPR and the DPA",
              "url": "https://www.shortcut.com/help/admin/gdpr.md",
              "seen": "2026-10-08"
            },
            {
              "what": "archived MCP server repository",
              "url": "https://github.com/useshortcut/mcp-server-shortcut",
              "seen": "2026-10-08"
            },
            {
              "what": "JavaScript client repository",
              "url": "https://github.com/useshortcut/shortcut-client-js",
              "seen": "2026-10-08"
            },
            {
              "what": "npm, @shortcut/client",
              "url": "https://registry.npmjs.org/@shortcut/client",
              "seen": "2026-10-08"
            },
            {
              "what": "npm, @shortcut/mcp",
              "url": "https://registry.npmjs.org/@shortcut/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=shortcut",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents feed",
              "url": "https://status.shortcut.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "status components",
              "url": "https://status.shortcut.com/api/v2/components.json",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.shortcut.com/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "release notes",
              "url": "https://www.shortcut.com/release-notes/",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://www.shortcut.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.shortcut.com/terms/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.shortcut.com/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "GDPR and Data Privacy Framework notice",
              "url": "https://www.shortcut.com/gdpr-privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://www.shortcut.com/gdpr-subprocessors/",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.shortcut.com/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "responsible disclosure policy",
              "url": "https://www.shortcut.com/disclosure/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (404)",
              "url": "https://www.shortcut.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for shortcut.com",
              "url": "https://rdap.verisign.com/com/v1/domain/shortcut.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the hosted MCP server's tool list, schemas and annotations, because tools/list needs a Shortcut account (the endpoint answers 401 without a token). The 78 tools counted are in the archived source at v0.25.0, so `toolCount` is left empty.",
            "unchecked: whether the read-only and read-write tokens of 20 January 2026 work on v3 as well as v4. The v4 page describes the `sct_ro_` and `sct_rw_` prefixes and says v3 tokens don't work on v4.",
            "unchecked: whether the live API sends a Retry-After header on 429. None is documented.",
            "unchecked: the DPA (last updated 23 August 2018) and the SOC 2 report, which are sent on request only.",
            "unchecked: response times in the community Slack and from support.",
            "No API changelog was found, although the v4 page tells readers to review one. No workspace audit log was found in the help centre pages read.",
            "The lead said the MCP server was unconfirmed. Shortcut runs a hosted one at https://mcp.shortcut.com/mcp, and the open-source `@shortcut/mcp` repository is archived. The lead also missed the v4 alpha.",
            "The Enterprise plan lists 'Premier support SLAs'. Whether an Enterprise contract carries an uptime commitment was not established."
          ]
        },
        "negative": 0,
        "verdict": "REST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.",
        "bestFor": "Software teams already on Shortcut that want an agent to search, create and update stories, epics, iterations and docs, and coding agents that pick up assigned stories.",
        "strengths": [
          "REST API v3, webhooks and the MCP server are listed on every plan, Free (up to 10 users) among them, and the 14-day trial needs no card",
          "Swagger 2.0 and OpenAPI 3.0 files for v3 (143 operations) are downloadable, with enums, string limits and required fields",
          "The hosted MCP server uses OAuth with PKCE, dynamic client registration and the scopes read, write, story-write, comment-write and admin",
          "API tokens can be read-only or read-write since 20 January 2026, and Observers' tokens can read but not change data",
          "status.shortcut.com has separate API and Shortcut MCP components with incident history back to 2023"
        ],
        "weaknesses": [
          "The v3 docs still allow the API token as a `token` query parameter, marked deprecated with no removal date",
          "No idempotency keys, Retry-After header or backoff guidance found. The docs state only 200 requests a minute and a 429",
          "No API changelog or deprecation policy found. API changes appear as lines in the product release notes",
          "The open-source MCP server is archived at v0.25.0, and the hosted server's tool list can't be read without a Shortcut account",
          "One official SDK, `@shortcut/client` for JavaScript and TypeScript, and no vendor entry in the official MCP registry"
        ],
        "agentNotes": [
          "Send the v3 token in the `Shortcut-Token` header. v4 (alpha) takes `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens, and v3 tokens don't work there.",
          "Create a story with `name` and `workflow_state_id`. Sending both `workflow_state_id` and `project_id`, or neither, is rejected.",
          "Use `GET /api/v3/search/stories` with `detail=slim`, `page_size` (1 to 250) and the `next` token. Many other v3 list endpoints return every record at once.",
          "Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.",
          "For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as `read` or `story-write`."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.2
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 73,
          "payments": 30,
          "reliability": 64,
          "schema": 75,
          "security": 54,
          "transparency": 57
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "npm install @shortcut/client",
        "http": "curl -X GET -H \"Content-Type: application/json\" -H \"Shortcut-Token: $SHORTCUT_API_TOKEN\" -L \"https://api.app.shortcut.com/api/v3/categories\"",
        "claudeCode": "claude mcp add --transport http shortcut https://mcp.shortcut.com/mcp",
        "config": {
          "mcpServers": {
            "shortcut": {
              "url": "https://mcp.shortcut.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/tasks.create",
        "tool": "https://letme.dev/shortcut"
      },
      "notable": [
        "The hosted MCP server is at https://mcp.shortcut.com/mcp with OAuth and no API token, and covers stories (with comments and sub-tasks), epics, iterations, docs and read-only objectives, teams, members and workflows (https://www.shortcut.com/help/integrations/mcp-server)",
        "The OAuth server metadata lists dynamic client registration, PKCE S256 and the scopes openid, admin, comment-write, read, story-write and write (https://api.app.shortcut.com/.well-known/oauth-authorization-server)",
        "The open-source MCP server repository is archived. Its README says all future development is on the hosted server, and the last npm release of `@shortcut/mcp` is 0.25.0 of 24 June 2026 (https://github.com/useshortcut/mcp-server-shortcut)",
        "REST API v4 has been in alpha since 12 May 2026, with a workspace slug in the path, cursor pagination, a `fields` parameter and `sct_ro_` or `sct_rw_` Bearer tokens (https://developer.shortcut.com/api/rest/v4)",
        "The v3 docs give a limit of 200 requests a minute and still accept the token as a `token` query parameter, marked deprecated (https://developer.shortcut.com/api/rest/v3)",
        "Outgoing webhooks fire on story and epic changes and can be signed with HMAC-SHA-256 in a `Payload-Signature` header (https://developer.shortcut.com/api/webhook/v1)",
        "On 15 July 2026 tokens newly created through the MCP server could not write for 2 hours 21 minutes, an incident Shortcut rated major (https://status.shortcut.com/history)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surfaces",
          "value": "REST API v3 at https://api.app.shortcut.com/api/v3 (current), REST API v4 (alpha), outgoing webhooks v1, and the hosted MCP server at https://mcp.shortcut.com/mcp"
        },
        {
          "label": "API coverage",
          "value": "143 operations on 85 paths in v3, among them stories (23), epics (17), objectives (9), documents (8), iterations (8), search (7), labels, files, custom fields, workflows and members"
        },
        {
          "label": "MCP server",
          "value": "Hosted, OAuth only. Stories can be retrieved, created and updated with comments and sub-tasks, epics and iterations retrieved and created, docs retrieved, created and updated, and objectives, teams, members and workflows read. The tool list needs an account and was not read"
        },
        {
          "label": "Credentials",
          "value": "Per-user API tokens in the `Shortcut-Token` header, read-only or read-write. OAuth authorisation code flow with PKCE and dynamic client registration for MCP"
        },
        {
          "label": "Scopes",
          "value": "read, write, story-write, comment-write, admin, plus openid for sign-in"
        },
        {
          "label": "Rate limits",
          "value": "200 requests a minute, answered with 429. No Retry-After header is documented"
        },
        {
          "label": "Pagination",
          "value": "Search endpoints take `page_size` (1 to 250), a `next` token and `detail=slim`. Epics have a paginated list. Other v3 lists return every record. v4 adds cursors with `limit` 1 to 100 and a `fields` parameter"
        },
        {
          "label": "Errors",
          "value": "400 schema mismatch, 404 resource does not exist and 422 unprocessable on every operation, 403 on 13. A live 401 returned JSON with `message` and `tag`"
        },
        {
          "label": "Webhooks",
          "value": "Story and epic create, update and delete events, with comments and tasks included. Registered by API at `/api/v3/integrations/webhook`, optional HMAC-SHA-256 signature in `Payload-Signature`"
        },
        {
          "label": "SDKs",
          "value": "`@shortcut/client` 3.4.1 for JavaScript and TypeScript (22 September 2026, MIT). `@shortcut/mcp` 0.25.0 is the last release of the archived local MCP server"
        },
        {
          "label": "Free tier",
          "value": "Free plan at $0 for up to 10 users with API and webhook access and the MCP server, 5 GB of storage. 14-day trial of paid plans with no card"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2 for security, availability and confidentiality per the security page, report by email request. A BAA for HIPAA on Business and Enterprise"
        },
        {
          "label": "Status",
          "value": "status.shortcut.com on Statuspage, with components for API, Shortcut MCP, Web App, Search and integrations, and incidents back to March 2023"
        },
        {
          "label": "Sub-processors",
          "value": "List updated 12 November 2025 with 33 providers and countries. Hosting on Amazon Web Services in the US. Anthropic is listed for Korey only"
        }
      ],
      "unitPrices": [
        {
          "item": "Free (API, webhooks and MCP server included)",
          "unit": "seat-month",
          "usd": 0,
          "note": "up to 10 users, 5 GB of storage"
        },
        {
          "item": "Team, billed yearly",
          "unit": "seat-month",
          "usd": 8.5,
          "note": "$10 billed monthly, as shown on 2026-10-08"
        },
        {
          "item": "Business, billed yearly",
          "unit": "seat-month",
          "usd": 12,
          "note": "$16 billed monthly, as shown on 2026-10-08"
        }
      ],
      "provenance": {
        "legalEntity": "Shortcut Software Company",
        "domain": "shortcut.com",
        "domainRegistered": "1997-08-01",
        "endpointOnVendorDomain": true,
        "terms": "https://www.shortcut.com/terms/",
        "privacy": "https://www.shortcut.com/privacy/",
        "statusPage": "https://status.shortcut.com",
        "changelog": "https://www.shortcut.com/release-notes/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (effective 18 September 2025) name Shortcut Software Company, govern the Service on shortcut.com and korey.ai, and are under New York law. The GDPR notice gives the address 201 Allen St, Unit #10004, New York, NY 10002.",
          "The privacy policy (effective 11 July 2025) covers the websites, the app and the platform.",
          "The API answers at api.app.shortcut.com and the MCP server at mcp.shortcut.com.",
          "www.shortcut.com/.well-known/security.txt returns 404. Reports go to security@shortcut.com under the disclosure policy at shortcut.com/disclosure.",
          "The changelog link is the product release notes. No separate API changelog was found.",
          "RDAP for shortcut.com gives a registration date of 1997-08-01. Shortcut was named Clubhouse until September 2021 per its llms.txt."
        ],
        "score": 88,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Shortcut Software Company",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "shortcut.com, registered 1997-08-01 (29 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.app.shortcut.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects",
            "points": 8.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.shortcut.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.shortcut.com/terms/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-09-18",
            "words": 2683,
            "points": 8.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective as of September 18, 2025",
                "says": "Last updated 2025-09-18"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These Terms of Service and performance hereunder shall be construed and governed by the laws of the State of New York without giving effect to conflicts of laws principles.",
                "says": "The law of the State of New York"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "SHORTCUT’S AGGREGATE LIABILITY FOR DIRECT DAMAGES UNDER THESE TERMS OF SERVICE WILL NOT EXCEED THE TOTAL FEES PAID BY SUBSCRIBER HEREUNDER DURING THE SIX (6) MONTHS IMMEDIATELY PRIOR TO THE EVENT GIVING RISE TO THE CLAIM.",
                "says": "Capped at the fees paid in the 6 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If we so choose, all amounts due must be paid by the date specified in the invoice or access and use of the Service may be terminated."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "We may change these Terms of Service from time to time, and will post any changes on the Websites or notify you via email, at our option, as soon as such changes are in effect.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": false
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Shortcut may suspend or terminate your access to and use of the Service, in whole or in part, at any time and for any reason;"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The subscriber grants a licence for Shortcut to use its name, logos and trademarks for promotion and marketing, and may opt out by email.",
                "quote": "Subscriber grants Shortcut a non-exclusive, non-transferrable, non-sublicensable, and royalty-free license to use and reproduce Subscriber’s name, logos, and trademarks for promotional and marketing purposes including on Shortcut’s customer lists, advertising, and applicable Websites."
              },
              {
                "date": "2026-10-08",
                "text": "After suspension or termination Shortcut gives access to subscriber data for at least 30 days, except where the account was locked for fraud or potential harm.",
                "quote": "Shortcut will provide you with access to your Subscriber Data for at least 30 days following such termination."
              },
              {
                "date": "2026-10-08",
                "text": "A paying subscriber may end the account before paying the full committed subscription fees only where Shortcut has breached the terms and not cured the breach within 10 business days.",
                "quote": "your right to terminate your account before paying the full amount of fees for the subscription period that you have committed to will be limited to cases where Shortcut has breached these Terms of Service"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.shortcut.com/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-07-11",
            "words": 1942,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Effective as of July 11th, 2025",
                "says": "Last updated 2025-07-11"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We use one or more third-party analytics services (such as Google Analytics) to evaluate your use of our Websites, and the Platform, compile reports on activity (based on their collection of IP addresses, Internet service provider, browser type, operating system and language, referring and exit pages and URLs, data an…"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We will retain your personal information in a form that identifies you only for as long as it serves the purpose(s) for which it was initially collected as stated in this Privacy Policy, subsequently authorized, or as allowed under applicable law."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Jump to policy Terms of Service Security Privacy Policy GDPR \u0026 Data Privacy Framework Notice GDPR \u0026 Subprocessors Responsible Disclosure AI Info"
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "In the event of a merger, dissolution or similar corporate event, or the sale of all or substantially all of our assets, we expect that the information that we have collected, including personal information, would be transferred to the surviving entity in a merger or the acquiring entity."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "You have the right to access, correct, delete, or export your personal data."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have questions about this Privacy Policy, please e-mail us at privacy@shortcut.com.",
                "says": "privacy@shortcut.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Jump to policy Terms of Service Security Privacy Policy GDPR \u0026 Data Privacy Framework Notice GDPR \u0026 Subprocessors Responsible Disclosure AI Info",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Inputs and outputs are not used for model training by default, but material sent as explicit feedback or bug reports may be used to train Shortcut's models.",
                "quote": "Only if you explicitly report feedback or bugs to us or otherwise explicitly opt in to our model training (if/when we enable this in the future), then we may use the materials provided to train our models."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shortcut.json",
      "live": {
        "slug": "shortcut",
        "probe": {
          "target": "https://api.app.shortcut.com",
          "method": "get",
          "lastAt": "2026-10-09T02:43:06.665726714Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 269,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 252,
          "p95ms24h": 306,
          "samples24h": 79,
          "samples30d": 79,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shortcut.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T02:46:03.47636588Z"
        },
        "updatedAt": "2026-10-09T02:46:03.47636588Z"
      }
    },
    "verify": {
      "accepts": "a page on shortcut.com or one of its subdomains, or the README of github.com/useshortcut/shortcut-client-js",
      "badgeUrl": "https://www.anchorterminal.com/badges/shortcut.svg",
      "body": {
        "slug": "shortcut",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/shortcut",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/shortcut\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/shortcut.svg\" alt=\"Shortcut on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Shortcut on Anchor Terminal](https://www.anchorterminal.com/badges/shortcut.svg)](https://www.anchorterminal.com/tools/shortcut)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/shortcut\"\u003eShortcut on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/shortcut",
    "json": "https://www.anchorterminal.com/tools/shortcut.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/shortcut.md",
    "slim": "https://www.anchorterminal.com/tools/shortcut.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 60.2/100 · rank #411 of 722 · #9 in Project \u0026 task management · not agent-ready · confidence medium**\n\n\n## Assessment\n\nREST API v3 and the hosted MCP server are included on the Free plan, with downloadable OpenAPI files and OAuth scopes down to story or comment writes on the MCP side. The API still accepts the token in a query string, and no idempotency keys, Retry-After header, uptime SLA or API changelog were found in the reviewed documentation.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Shortcut Software Company (https://www.shortcut.com) |\n| Kind | HTTP API |\n| Category | Project \u0026 task management (https://www.anchorterminal.com/categories/project-management) |\n| Transport | HTTP, Streamable HTTP |\n| Endpoint | `https://api.app.shortcut.com` |\n| Auth | OAuth or key · Self-serve. Any workspace member creates an API token under Settings, API Tokens, with no app review. REST API v3 takes it in the `Shortcut-Token` header, and tokens can be read-only or read-write since 20 January 2026. An Observer's token can read but not change data. The hosted MCP server at mcp.shortcut.com/mcp takes OAuth only (authorisation code with PKCE, dynamic client registration) with the scopes read, write, story-write, comment-write and admin, and access can be revoked in Shortcut settings. The v4 alpha uses `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens. |\n| Pricing | Freemium ($8.50 / seat-mo) · The API, webhooks and the MCP server are listed on every plan, and Shortcut charges nothing per call. Free is $0 for up to 10 users, Team $8.50 a user a month billed yearly ($10 monthly), Business $12 ($16 monthly), and Enterprise is quoted by sales. A 14-day trial needs no card, so an agent's owner can start on Free or the trial without a contract (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the API reference, the OpenAPI files, llms.txt or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Shortcut's terms of service. The JavaScript client and the archived MCP server on GitHub are MIT |\n| Packages | npm: `@shortcut/client` |\n| Source | https://github.com/useshortcut/shortcut-client-js |\n| Docs | https://developer.shortcut.com/api/rest/v3 |\n| llms.txt | https://www.shortcut.com/llms.txt |\n| Last release | 2026-09-22 |\n| GitHub stars | 142 (as of 2026-10-08) |\n| npm downloads / week | 102,825 |\n| Surfaces | REST API v3 at https://api.app.shortcut.com/api/v3 (current), REST API v4 (alpha), outgoing webhooks v1, and the hosted MCP server at https://mcp.shortcut.com/mcp |\n| API coverage | 143 operations on 85 paths in v3, among them stories (23), epics (17), objectives (9), documents (8), iterations (8), search (7), labels, files, custom fields, workflows and members |\n| MCP server | Hosted, OAuth only. Stories can be retrieved, created and updated with comments and sub-tasks, epics and iterations retrieved and created, docs retrieved, created and updated, and objectives, teams, members and workflows read. The tool list needs an account and was not read |\n| Credentials | Per-user API tokens in the `Shortcut-Token` header, read-only or read-write. OAuth authorisation code flow with PKCE and dynamic client registration for MCP |\n| Scopes | read, write, story-write, comment-write, admin, plus openid for sign-in |\n| Rate limits | 200 requests a minute, answered with 429. No Retry-After header is documented |\n| Pagination | Search endpoints take `page_size` (1 to 250), a `next` token and `detail=slim`. Epics have a paginated list. Other v3 lists return every record. v4 adds cursors with `limit` 1 to 100 and a `fields` parameter |\n| Errors | 400 schema mismatch, 404 resource does not exist and 422 unprocessable on every operation, 403 on 13. A live 401 returned JSON with `message` and `tag` |\n| Webhooks | Story and epic create, update and delete events, with comments and tasks included. Registered by API at `/api/v3/integrations/webhook`, optional HMAC-SHA-256 signature in `Payload-Signature` |\n| SDKs | `@shortcut/client` 3.4.1 for JavaScript and TypeScript (22 September 2026, MIT). `@shortcut/mcp` 0.25.0 is the last release of the archived local MCP server |\n| Free tier | Free plan at $0 for up to 10 users with API and webhook access and the MCP server, 5 GB of storage. 14-day trial of paid plans with no card |\n| Certifications | SOC 2 Type 2 for security, availability and confidentiality per the security page, report by email request. A BAA for HIPAA on Business and Enterprise |\n| Status | status.shortcut.com on Statuspage, with components for API, Shortcut MCP, Web App, Search and integrations, and incidents back to March 2023 |\n| Sub-processors | List updated 12 November 2025 with 33 providers and countries. Hosting on Amazon Web Services in the US. Anthropic is listed for Korey only |\n| Capabilities | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, automation.webhooks |\n| Tags | official, hosted, mcp, oauth, openapi, llms-txt, webhooks, freemium, free-tier, no-card, closed-source, typescript, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/shortcut.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 64 | 12.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 75 | 12.2 |\n| Agent ergonomics | 13% | 16.2 | 57 | 9.3 |\n| Security \u0026 auth | 14% | 17.5 | 54 | 9.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 73 | 6.4 |\n| Transparency \u0026 trust (editorial 57, provenance 88) | 7% | 8.8 | 73 | 6.4 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **60.2 → C** |\n\n### Why each score\n\n- Reliability 64: Graded on the hosted lines for REST API v3 and the hosted MCP server. status.shortcut.com is a Statuspage site with API and Shortcut MCP components and history back to March 2023 (20). In the 90 days to 8 October 2026 it shows three incidents, the MCP server unavailable for about 6 minutes on 14 July, tokens newly created through the MCP server unable to write for 2 hours 21 minutes on 15 July (rated major by Shortcut, fix in place after 22 minutes), and search indexing behind on 4 August. None names the API component. One vendor-rated major that affected only new MCP tokens sits between the minor and major lines (15 of 30). The docs give 200 requests a minute (15). A 429 is documented, with no Retry-After header, backoff guidance or idempotency keys found (4 of 15). The Enterprise plan lists 'Premier support SLAs', and no uptime SLA was found (0). v3 is described as the current version with backwards-compatible changes only, and the hosted MCP server carries no beta label. v4 is alpha and isn't graded (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 75: Swagger 2.0 and OpenAPI 3.0 files for v3 are downloadable from the docs (143 operations on 85 paths), and an OpenAPI 3.0.3 file for the v4 alpha (247 operations) is at www.shortcut.com/openapi.json. The hosted MCP server's tool schemas need an account and were not read (25). www.shortcut.com/llms.txt links the spec, and help centre pages have Markdown copies. developer.shortcut.com has no llms.txt and is a single HTML page per version (7 of 10). 127 of 143 operations carry a description, mostly one line, with a few usage rules such as the `workflow_state_id` or `project_id` choice on story creation (12 of 20). Enums, maxLength, formats and required flags throughout (13 of 15). Every endpoint has a curl example and an example response, but errors are the same three lines everywhere (400 schema mismatch, 404, 422) with no documented error body (9 of 15). Versions are in the path (v2 deprecated, v3 current, v4 alpha). No API changelog was found, although the v4 page refers to one, and API changes appear in the product release notes (9 of 15).\n- Agent ergonomics 57: Graded on the API. Search takes `detail=slim` to drop descriptions and comments, and list responses use slim types. Field selection (`fields`) exists only in the v4 alpha (17 of 25). Search has operators, `page_size` up to 250 and a `next` token, and epics have a paginated list, but the v4 migration note says v3 list endpoints return all results at once (14 of 20). Errors are HTTP codes with one-line meanings. A live 401 returned JSON with `message` and `tag`, which the reference doesn't catalogue (9 of 20). No idempotency keys. `external_id` fields exist on some entities. The archived MCP source (v0.25.0) sets readOnlyHint, destructiveHint and idempotentHint on its 78 tools, and the hosted server's annotations were not read (8 of 20). A story needs only a name and a workflow state. One official SDK, `@shortcut/client` for JavaScript and TypeScript (9 of 15).\n- Security \u0026 auth 54: The hosted MCP server uses the OAuth authorisation code flow with PKCE (S256), dynamic client registration and the scopes read, write, story-write, comment-write and admin. REST tokens are created per user, can be read-only or read-write since 20 January 2026, and the v4 alpha lets an admin list and disable workspace tokens. The v3 docs still accept the token as a `token` query parameter, marked deprecated, which costs 10 (20 of 30). Read-only tokens, a read scope, narrow story and comment scopes and the view-only Observer role. No confirmation step for deletes was found (14 of 20). Stories, comments and docs written by other people reach the model, and no injection guidance was found (3 of 15). Story history is readable by API. No workspace audit log of API or MCP calls was found in the pages read (5 of 15). No security.txt (404). A disclosure policy promises acknowledgement within a week, and the security page states SOC 2 Type 2 with the report on request. No bug bounty or public advisories found (12 of 20).\n- Payments \u0026 pricing 30: No x402, MPP or L402 (0). Plan prices are public, Free $0 for up to 10 users, Team $8.50 a user a month billed yearly or $10 monthly, Business $12 or $16, Enterprise by quote. API calls aren't priced (10). The Free plan lists API and webhook access and the MCP server, and the 14-day trial needs no card (20). A person signs up in a browser and creates a token or approves the OAuth grant (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 73: The newest release notes are dated 18 September 2026 and `@shortcut/client` 3.4.1 was published on 22 September 2026 (30). Release notes on 31 July, 14 August and 18 September, and four client releases in September (20). Closed service with public release notes, a community Slack and a support address. Response times were not checked (9 of 15). The official client is current, but the official MCP registry has only third-party Shortcut servers (com.mcparmory/shortcut, io.github.stayce/shortcut-mcp) (8 of 15). The client repository was last pushed on 1 October 2026 under MIT. The MCP server repository is archived at v0.25.0 (23 June 2026) with a notice that development moved to the hosted server (6 of 10).\n- Transparency \u0026 trust 73: Closed service under terms naming Shortcut Software Company, with an MIT client library and the archived MIT MCP server (15). The privacy policy of 11 July 2025 covers the platform and says inputs and outputs aren't used to train models by default. Retention is 'only for as long as it serves the purpose', the terms give at least 30 days of data access after termination, and the DPA (last updated 23 August 2018) is sent on request, not published (17 of 30). No deprecation policy found. v2, the Projects endpoints and the token query parameter are marked deprecated with no dates (5 of 20). The sub-processor list, updated 12 November 2025, names 33 providers with product, type and country, hosting on AWS in the US (20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/shortcut.md (JSON https://www.anchorterminal.com/fixes/shortcut.json)\n\n### What we couldn't check\n\n- unchecked: the hosted MCP server's tool list, schemas and annotations, because tools/list needs a Shortcut account (the endpoint answers 401 without a token). The 78 tools counted are in the archived source at v0.25.0, so `toolCount` is left empty.\n- unchecked: whether the read-only and read-write tokens of 20 January 2026 work on v3 as well as v4. The v4 page describes the `sct_ro_` and `sct_rw_` prefixes and says v3 tokens don't work on v4.\n- unchecked: whether the live API sends a Retry-After header on 429. None is documented.\n- unchecked: the DPA (last updated 23 August 2018) and the SOC 2 report, which are sent on request only.\n- unchecked: response times in the community Slack and from support.\n- No API changelog was found, although the v4 page tells readers to review one. No workspace audit log was found in the help centre pages read.\n- The lead said the MCP server was unconfirmed. Shortcut runs a hosted one at https://mcp.shortcut.com/mcp, and the open-source `@shortcut/mcp` repository is archived. The lead also missed the v4 alpha.\n- The Enterprise plan lists 'Premier support SLAs'. Whether an Enterprise contract carries an uptime commitment was not established.\n\n### Sources\n\n- REST API v3 reference (auth, rate limit, endpoints): \u003chttps://developer.shortcut.com/api/rest/v3\u003e (seen 2026-10-08)\n- v3 Swagger 2.0 file: \u003chttps://developer.shortcut.com/api/rest/v3/shortcut.swagger.json\u003e (seen 2026-10-08)\n- REST API v4 alpha reference: \u003chttps://developer.shortcut.com/api/rest/v4\u003e (seen 2026-10-08)\n- v4 OpenAPI 3.0.3 file: \u003chttps://www.shortcut.com/openapi.json\u003e (seen 2026-10-08)\n- outgoing webhooks reference: \u003chttps://developer.shortcut.com/api/webhook/v1\u003e (seen 2026-10-08)\n- hosted MCP server landing page: \u003chttps://mcp.shortcut.com/\u003e (seen 2026-10-08)\n- MCP protected-resource metadata: \u003chttps://mcp.shortcut.com/.well-known/oauth-protected-resource\u003e (seen 2026-10-08)\n- OAuth authorisation server metadata: \u003chttps://api.app.shortcut.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- help centre article on the MCP server: \u003chttps://www.shortcut.com/help/integrations/mcp-server\u003e (seen 2026-10-08)\n- help centre article on webhooks: \u003chttps://www.shortcut.com/help/admin/webhooks.md\u003e (seen 2026-10-08)\n- help centre article on user roles: \u003chttps://www.shortcut.com/help/admin/user-roles.md\u003e (seen 2026-10-08)\n- help centre article on GDPR and the DPA: \u003chttps://www.shortcut.com/help/admin/gdpr.md\u003e (seen 2026-10-08)\n- archived MCP server repository: \u003chttps://github.com/useshortcut/mcp-server-shortcut\u003e (seen 2026-10-08)\n- JavaScript client repository: \u003chttps://github.com/useshortcut/shortcut-client-js\u003e (seen 2026-10-08)\n- npm, @shortcut/client: \u003chttps://registry.npmjs.org/@shortcut/client\u003e (seen 2026-10-08)\n- npm, @shortcut/mcp: \u003chttps://registry.npmjs.org/@shortcut/mcp\u003e (seen 2026-10-08)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=shortcut\u003e (seen 2026-10-08)\n- status incidents feed: \u003chttps://status.shortcut.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- status components: \u003chttps://status.shortcut.com/api/v2/components.json\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.shortcut.com/pricing/\u003e (seen 2026-10-08)\n- release notes: \u003chttps://www.shortcut.com/release-notes/\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://www.shortcut.com/llms.txt\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.shortcut.com/terms/\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.shortcut.com/privacy/\u003e (seen 2026-10-08)\n- GDPR and Data Privacy Framework notice: \u003chttps://www.shortcut.com/gdpr-privacy/\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://www.shortcut.com/gdpr-subprocessors/\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.shortcut.com/security/\u003e (seen 2026-10-08)\n- responsible disclosure policy: \u003chttps://www.shortcut.com/disclosure/\u003e (seen 2026-10-08)\n- security.txt (404): \u003chttps://www.shortcut.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- RDAP for shortcut.com: \u003chttps://rdap.verisign.com/com/v1/domain/shortcut.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 88/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Shortcut Software Company | 20/20 |\n| Domain age | shortcut.com, registered 1997-08-01 (29 years) | 15/15 |\n| Endpoint on the vendor's domain | api.app.shortcut.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects | 8.3/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.shortcut.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe terms of service (effective 18 September 2025) name Shortcut Software Company, govern the Service on shortcut.com and korey.ai, and are under New York law. The GDPR notice gives the address 201 Allen St, Unit #10004, New York, NY 10002.\n\nThe privacy policy (effective 11 July 2025) covers the websites, the app and the platform.\n\nThe API answers at api.app.shortcut.com and the MCP server at mcp.shortcut.com.\n\nwww.shortcut.com/.well-known/security.txt returns 404. Reports go to security@shortcut.com under the disclosure policy at shortcut.com/disclosure.\n\nThe changelog link is the product release notes. No separate API changelog was found.\n\nRDAP for shortcut.com gives a registration date of 1997-08-01. Shortcut was named Clubhouse until September 2021 per its llms.txt.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.shortcut.com/terms/), read 2026-10-08, dated 2025-09-18, states 5 of the 7 things a reader expects.\n\n- To know. Says access can be ended without notice or for any reason. \"Shortcut may suspend or terminate your access to and use of the Service, in whole or in part, at any time and for any reason;\"\n- Gives the date it was last updated. Last updated 2025-09-18.\n- Names the governing law or courts. The law of the State of New York.\n- States a limit on its liability. Capped at the fees paid in the 6 months before the claim.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Lists what users may not do.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). The subscriber grants a licence for Shortcut to use its name, logos and trademarks for promotion and marketing, and may opt out by email. \"Subscriber grants Shortcut a non-exclusive, non-transferrable, non-sublicensable, and royalty-free license to use and reproduce Subscriber’s name, logos, and trademarks for promotional and marketing purposes including on Shortcut’s customer lists, advertising, and applicable Websites.\"\n- Also in the text (2026-10-08). After suspension or termination Shortcut gives access to subscriber data for at least 30 days, except where the account was locked for fraud or potential harm. \"Shortcut will provide you with access to your Subscriber Data for at least 30 days following such termination.\"\n- Also in the text (2026-10-08). A paying subscriber may end the account before paying the full committed subscription fees only where Shortcut has breached the terms and not cured the breach within 10 business days. \"your right to terminate your account before paying the full amount of fees for the subscription period that you have committed to will be limited to cases where Shortcut has breached these Terms of Service\"\n\n**Privacy policy** (https://www.shortcut.com/privacy/), read 2026-10-08, dated 2025-07-11, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2025-07-11.\n- Gives a privacy contact. privacy@shortcut.com.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). Inputs and outputs are not used for model training by default, but material sent as explicit feedback or bug reports may be used to train Shortcut's models. \"Only if you explicitly report feedback or bugs to us or otherwise explicitly opt in to our model training (if/when we enable this in the future), then we may use the materials provided to train our models.\"\n\n## Live (updated 2026-10-09 02:46 UTC)\n\n- Right now: up, HTTP 200, 269 ms, checked 2026-10-09 02:43 UTC (get on `https://api.app.shortcut.com`)\n- Uptime 24h 100.0% (79 probes) · 30 days 100.0% (79 probes) · p50 252 ms · p95 306 ms\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/shortcut.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Free (API, webhooks and MCP server included) | free | per seat per month | up to 10 users, 5 GB of storage |\n| Team, billed yearly | $8.50 | per seat per month | $10 billed monthly, as shown on 2026-10-08 |\n| Business, billed yearly | $12 | per seat per month | $16 billed monthly, as shown on 2026-10-08 |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- REST API v3, webhooks and the MCP server are listed on every plan, Free (up to 10 users) among them, and the 14-day trial needs no card\n- Swagger 2.0 and OpenAPI 3.0 files for v3 (143 operations) are downloadable, with enums, string limits and required fields\n- The hosted MCP server uses OAuth with PKCE, dynamic client registration and the scopes read, write, story-write, comment-write and admin\n- API tokens can be read-only or read-write since 20 January 2026, and Observers' tokens can read but not change data\n- status.shortcut.com has separate API and Shortcut MCP components with incident history back to 2023\n\n## Weaknesses\n\n- The v3 docs still allow the API token as a `token` query parameter, marked deprecated with no removal date\n- No idempotency keys, Retry-After header or backoff guidance found. The docs state only 200 requests a minute and a 429\n- No API changelog or deprecation policy found. API changes appear as lines in the product release notes\n- The open-source MCP server is archived at v0.25.0, and the hosted server's tool list can't be read without a Shortcut account\n- One official SDK, `@shortcut/client` for JavaScript and TypeScript, and no vendor entry in the official MCP registry\n\n## Before you call it (notes for agents)\n\n1. Send the v3 token in the `Shortcut-Token` header. v4 (alpha) takes `Authorization: Bearer` with `sct_ro_` or `sct_rw_` tokens, and v3 tokens don't work there.\n2. Create a story with `name` and `workflow_state_id`. Sending both `workflow_state_id` and `project_id`, or neither, is rejected.\n3. Use `GET /api/v3/search/stories` with `detail=slim`, `page_size` (1 to 250) and the `next` token. Many other v3 list endpoints return every record at once.\n4. Stay under 200 requests a minute and add your own backoff on 429, because no Retry-After header is documented.\n5. For MCP, connect to https://mcp.shortcut.com/mcp and request only the scopes needed, such as `read` or `story-write`.\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @shortcut/client\n```\n\nFirst request:\n\n```bash\ncurl -X GET -H \"Content-Type: application/json\" -H \"Shortcut-Token: $SHORTCUT_API_TOKEN\" -L \"https://api.app.shortcut.com/api/v3/categories\"\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http shortcut https://mcp.shortcut.com/mcp\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"shortcut\": {\n      \"url\": \"https://mcp.shortcut.com/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/shortcut. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Teamwork.com | B | 65.9 | 251 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, automation.webhooks | no | https://www.anchorterminal.com/tools/teamwork.md |\n| Wrike | C | 60.1 | 413 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting, automation.webhooks | no | https://www.anchorterminal.com/tools/wrike.md |\n| monday.com | BB | 76.4 | 32 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/monday.md |\n| Asana | BB | 70.1 | 141 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/asana.md |\n| Basecamp | B | 67.9 | 197 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/basecamp.md |\n| Plane | B | 67.6 | 204 | tasks.create, tasks.update, projects.manage, tasks.comments, projects.reporting | no | https://www.anchorterminal.com/tools/plane.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The hosted MCP server is at https://mcp.shortcut.com/mcp with OAuth and no API token, and covers stories (with comments and sub-tasks), epics, iterations, docs and read-only objectives, teams, members and workflows (source: \u003chttps://www.shortcut.com/help/integrations/mcp-server\u003e)\n- The OAuth server metadata lists dynamic client registration, PKCE S256 and the scopes openid, admin, comment-write, read, story-write and write (source: \u003chttps://api.app.shortcut.com/.well-known/oauth-authorization-server\u003e)\n- The open-source MCP server repository is archived. Its README says all future development is on the hosted server, and the last npm release of `@shortcut/mcp` is 0.25.0 of 24 June 2026 (source: \u003chttps://github.com/useshortcut/mcp-server-shortcut\u003e)\n- REST API v4 has been in alpha since 12 May 2026, with a workspace slug in the path, cursor pagination, a `fields` parameter and `sct_ro_` or `sct_rw_` Bearer tokens (source: \u003chttps://developer.shortcut.com/api/rest/v4\u003e)\n- The v3 docs give a limit of 200 requests a minute and still accept the token as a `token` query parameter, marked deprecated (source: \u003chttps://developer.shortcut.com/api/rest/v3\u003e)\n- Outgoing webhooks fire on story and epic changes and can be signed with HMAC-SHA-256 in a `Payload-Signature` header (source: \u003chttps://developer.shortcut.com/api/webhook/v1\u003e)\n- On 15 July 2026 tokens newly created through the MCP server could not write for 2 hours 21 minutes, an incident Shortcut rated major (source: \u003chttps://status.shortcut.com/history\u003e)\n\n## Compare\n\n- [Asana vs Shortcut](https://www.anchorterminal.com/compare/asana-vs-shortcut.md): BB 70.1 vs C 60.2\n- [Basecamp vs Shortcut](https://www.anchorterminal.com/compare/basecamp-vs-shortcut.md): B 67.9 vs C 60.2\n- [ClickUp vs Shortcut](https://www.anchorterminal.com/compare/clickup-vs-shortcut.md): C 60.9 vs C 60.2\n- [monday.com vs Shortcut](https://www.anchorterminal.com/compare/monday-vs-shortcut.md): BB 76.4 vs C 60.2\n- [Plane vs Shortcut](https://www.anchorterminal.com/compare/plane-vs-shortcut.md): B 67.6 vs C 60.2\n- [Roma vs Shortcut](https://www.anchorterminal.com/compare/roma-vs-shortcut.md): D 51.1 vs C 60.2\n- [Shortcut vs Teamwork.com](https://www.anchorterminal.com/compare/shortcut-vs-teamwork.md): C 60.2 vs B 65.9\n- [Shortcut vs Todoist](https://www.anchorterminal.com/compare/shortcut-vs-todoist.md): C 60.2 vs B 66.9\n- [Shortcut vs Trello](https://www.anchorterminal.com/compare/shortcut-vs-trello.md): C 60.2 vs C 61.1\n- [Shortcut vs Wrike](https://www.anchorterminal.com/compare/shortcut-vs-wrike.md): C 60.2 vs C 60.1\n- [Shortcut vs YouTrack](https://www.anchorterminal.com/compare/shortcut-vs-youtrack.md): C 60.2 vs D 49.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on shortcut.com or one of its subdomains, or the README of github.com/useshortcut/shortcut-client-js. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"shortcut\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/shortcut\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/shortcut.svg\" alt=\"Shortcut on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Shortcut on Anchor Terminal](https://www.anchorterminal.com/badges/shortcut.svg)](https://www.anchorterminal.com/tools/shortcut)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/shortcut\"\u003eShortcut on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Shortcut is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/shortcut-dark.png\n- Light: https://www.anchorterminal.com/assets/share/shortcut-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Project \u0026 task management",
        "url": "https://www.anchorterminal.com/categories/project-management"
      },
      {
        "name": "Shortcut",
        "url": ""
      }
    ],
    "description": "Shortcut is a hosted project tracker for software teams, with stories, epics, iterations, objectives and docs. Agents reach it through REST API v3 with a personal token, or the hosted MCP server at mcp.shortcut.com/mcp with OAuth.",
    "facts": [
      "rank #411 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Shortcut",
    "image": "https://www.anchorterminal.com/assets/og/tools-shortcut.png",
    "path": "/tools/shortcut",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Shortcut review for AI agents, grade C (60.2/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/shortcut"
  },
  "tokens": {
    "markdown": 7950,
    "slim": 1930
  },
  "version": 1
}
